Update ssh issue/sign fns to be based on certificate template id

This commit is contained in:
Tuan Dang
2024-12-17 10:37:05 -08:00
parent 1fa99e5585
commit 86800c0cdb
7 changed files with 28 additions and 53 deletions
@@ -28,9 +28,6 @@ export const createSshCertSerialNumber = () => {
/**
* Return a pair of SSH CA keys based on the specified key algorithm [keyAlgorithm].
* We use this function because the key format generated by `ssh-keygen` is unique.
* @param keyAlgorithm - The key algorithm to use for generating the SSH key pair
* @param comment - The comment to use for the SSH key pair
* @returns The public and private keys for the SSH key pair
*/
export const createSshKeyPair = async (keyAlgorithm: CertKeyAlgorithm) => {
const tempDir = await fs.mkdtemp(path.join(os.tmpdir(), "ssh-key-"));
@@ -82,7 +79,6 @@ export const createSshKeyPair = async (keyAlgorithm: CertKeyAlgorithm) => {
/**
* Return the SSH public key for the given SSH private key.
* @param privateKey - The SSH private key to get the public key for
*/
export const getSshPublicKey = async (privateKey: string) => {
const tempDir = await fs.mkdtemp(path.join(os.tmpdir(), "ssh-key-"));
@@ -101,8 +97,6 @@ export const getSshPublicKey = async (privateKey: string) => {
/**
* Validate the requested SSH certificate type based on the SSH certificate template configuration.
* @param template - The SSH certificate template configuration
* @param certType - The SSH certificate type
*/
export const validateSshCertificateType = (template: TSshCertificateTemplates, certType: SshCertType) => {
if (!template.allowUserCertificates && certType === SshCertType.USER) {
@@ -116,10 +110,6 @@ export const validateSshCertificateType = (template: TSshCertificateTemplates, c
/**
* Validate the requested SSH certificate principals based on the SSH certificate template configuration.
* @param certType - The SSH certificate type
* @param template - The SSH certificate template configuration
* @param principals - The requested SSH certificate principals
* @returns The validated SSH certificate principals
*/
export const validateSshCertificatePrincipals = (
certType: SshCertType,
@@ -128,8 +118,6 @@ export const validateSshCertificatePrincipals = (
) => {
/**
* Validate and sanitize a principal string
* @param principal - the principal to validate and sanitize
* @returns the sanitized principal
*/
const validatePrincipal = (principal: string) => {
const sanitized = principal.trim();
@@ -257,9 +245,6 @@ export const validateSshCertificatePrincipals = (
/**
* Validate the requested SSH certificate TTL based on the SSH certificate template configuration.
* @param template - The SSH certificate template configuration
* @param ttl - The TTL to validate
* @returns The TTL (in seconds) to use for issuing the SSH certificate
*/
export const validateSshCertificateTtl = (template: TSshCertificateTemplates, ttl?: string) => {
if (!ttl) {
@@ -279,7 +264,6 @@ export const validateSshCertificateTtl = (template: TSshCertificateTemplates, tt
/**
* Validate the requested SSH certificate key ID to ensure
* that it only contains alphanumeric characters with no spaces.
* @param keyId - The key ID to validate
*/
export const validateSshCertificateKeyId = (keyId: string) => {
const regex = /^[A-Za-z0-9-]+$/;
@@ -299,7 +283,6 @@ export const validateSshCertificateKeyId = (keyId: string) => {
/**
* Validate the format of the SSH public key
* @param publicKey - the public key to validate
*/
const validateSshPublicKey = async (publicKey: string) => {
const validPrefixes = ["ssh-rsa", "ssh-ed25519", "ecdsa-sha2-nistp256", "ecdsa-sha2-nistp384"];