Expose ca / cert endpoints to public api ref

This commit is contained in:
Tuan Dang
2024-06-13 10:16:27 -07:00
parent 8d6f7babff
commit 8686b4abd3
18 changed files with 92 additions and 32 deletions
+29 -12
View File
@@ -728,11 +728,10 @@ export const AUDIT_LOG_STREAMS = {
} }
}; };
// TODO
export const CERTIFICATE_AUTHORITIES = { export const CERTIFICATE_AUTHORITIES = {
CREATE: { CREATE: {
projectSlug: "Slug of the project to create the CA in.", projectSlug: "Slug of the project to create the CA in.",
type: "The type of CA to create (root or intermediate)", type: "The type of CA to create",
friendlyName: "A friendly name for the CA", friendlyName: "A friendly name for the CA",
organization: "The organization (O) for the CA", organization: "The organization (O) for the CA",
ou: "The organization unit (OU) for the CA", ou: "The organization unit (OU) for the CA",
@@ -745,23 +744,27 @@ export const CERTIFICATE_AUTHORITIES = {
maxPathLength: maxPathLength:
"The maximum number of intermediate CAs that may follow this CA in the certificate / CA chain. A maxPathLength of -1 implies no path limit on the chain.", "The maximum number of intermediate CAs that may follow this CA in the certificate / CA chain. A maxPathLength of -1 implies no path limit on the chain.",
keyAlgorithm: keyAlgorithm:
"The type of public key algorithm and size, in bits, of the key pair for the CA; when you create an intermediate CA, you must use a key algorithm supported by the parent CA. This should be one of RSA_2048, RSA_4096, EC_prime256v1, or EC_secp384r1." "The type of public key algorithm and size, in bits, of the key pair for the CA; when you create an intermediate CA, you must use a key algorithm supported by the parent CA."
}, },
GET: { GET: {
caId: "The ID of the CA to get" caId: "The ID of the CA to get"
}, },
UPDATE: { UPDATE: {
caId: "The ID of the CA to get", caId: "The ID of the CA to update",
status: "The status of the CA to update to. This can be one of active or disabled" status: "The status of the CA to update to. This can be one of active or disabled"
}, },
DELETE: { DELETE: {
caId: "The ID of the CA to delete" caId: "The ID of the CA to delete"
}, },
GET_CSR: { GET_CSR: {
caId: "The ID of the CA to generate CSR from" caId: "The ID of the CA to generate CSR from",
csr: "The generated CSR from the CA"
}, },
GET_CERT: { GET_CERT: {
caId: "The ID of the CA to get the certificate body and certificate chain from" caId: "The ID of the CA to get the certificate body and certificate chain from",
certificate: "The certificate body of the CA",
certificateChain: "The certificate chain of the CA",
serialNumber: "The serial number of the CA certificate"
}, },
SIGN_INTERMEDIATE: { SIGN_INTERMEDIATE: {
caId: "The ID of the CA to sign the intermediate certificate with", caId: "The ID of the CA to sign the intermediate certificate with",
@@ -769,7 +772,11 @@ export const CERTIFICATE_AUTHORITIES = {
notBefore: "The date and time when the intermediate CA becomes valid in YYYY-MM-DDTHH:mm:ss.sssZ format", notBefore: "The date and time when the intermediate CA becomes valid in YYYY-MM-DDTHH:mm:ss.sssZ format",
notAfter: "The date and time when the intermediate CA expires in YYYY-MM-DDTHH:mm:ss.sssZ format", notAfter: "The date and time when the intermediate CA expires in YYYY-MM-DDTHH:mm:ss.sssZ format",
maxPathLength: maxPathLength:
"The maximum number of intermediate CAs that may follow this CA in the certificate / CA chain. A maxPathLength of -1 implies no path limit on the chain." "The maximum number of intermediate CAs that may follow this CA in the certificate / CA chain. A maxPathLength of -1 implies no path limit on the chain.",
certificate: "The signed intermediate certificate",
certificateChain: "The certificate chain of the intermediate certificate",
issuingCaCertificate: "The certificate of the issuing CA",
serialNumber: "The serial number of the intermediate certificate"
}, },
IMPORT_CERT: { IMPORT_CERT: {
caId: "The ID of the CA to import the certificate for", caId: "The ID of the CA to import the certificate for",
@@ -782,10 +789,16 @@ export const CERTIFICATE_AUTHORITIES = {
commonName: "The common name (CN) for the certificate", commonName: "The common name (CN) for the certificate",
ttl: "The time to live for the certificate such as 1m, 1h, 1d, 1y, ...", ttl: "The time to live for the certificate such as 1m, 1h, 1d, 1y, ...",
notBefore: "The date and time when the certificate becomes valid in YYYY-MM-DDTHH:mm:ss.sssZ format", notBefore: "The date and time when the certificate becomes valid in YYYY-MM-DDTHH:mm:ss.sssZ format",
notAfter: "The date and time when the certificate expires in YYYY-MM-DDTHH:mm:ss.sssZ format" notAfter: "The date and time when the certificate expires in YYYY-MM-DDTHH:mm:ss.sssZ format",
certificate: "The issued certificate",
issuingCaCertificate: "The certificate of the issuing CA",
certificateChain: "The certificate chain of the issued certificate",
privateKey: "The private key of the issued certificate",
serialNumber: "The serial number of the issued certificate"
}, },
GET_CRL: { GET_CRL: {
caId: "The ID of the CA to get the certificate revocation list (CRL) for" caId: "The ID of the CA to get the certificate revocation list (CRL) for",
crl: "The certificate revocation list (CRL) of the CA"
} }
}; };
@@ -796,14 +809,18 @@ export const CERTIFICATES = {
REVOKE: { REVOKE: {
serialNumber: serialNumber:
"The serial number of the certificate to revoke. The revoked certificate will be added to the certificate revocation list (CRL) of the CA.", "The serial number of the certificate to revoke. The revoked certificate will be added to the certificate revocation list (CRL) of the CA.",
revocationReason: revocationReason: "The reason for revoking the certificate.",
"The reason for revoking the certificate. This can be one of UNSPECIFIED, KEY_COMPROMISE, CA_COMPROMISE, AFFILIATION_CHANGED, SUPERSEDED, CESSATION_OF_OPERATION, CERTIFICATE_HOLD, PRIVILEGE_WITHDRAWN, or A_A_COMPROMISE." revokedAt: "The date and time when the certificate was revoked",
serialNumberRes: "The serial number of the revoked certificate."
}, },
DELETE: { DELETE: {
serialNumber: "The serial number of the certificate to delete" serialNumber: "The serial number of the certificate to delete"
}, },
GET_CERT: { GET_CERT: {
serialNumber: "The serial number of the certificate to get the certificate body and certificate chain for" serialNumber: "The serial number of the certificate to get the certificate body and certificate chain for",
certificate: "The certificate body of the certificate",
certificateChain: "The certificate chain of the certificate",
serialNumberRes: "The serial number of the certificate"
} }
}; };
@@ -237,11 +237,11 @@ export const registerCaRouter = async (server: FastifyZodProvider) => {
schema: { schema: {
description: "Get CA CSR", description: "Get CA CSR",
params: z.object({ params: z.object({
caId: z.string().trim() caId: z.string().trim().describe(CERTIFICATE_AUTHORITIES.GET_CSR.caId)
}), }),
response: { response: {
200: z.object({ 200: z.object({
csr: z.string() csr: z.string().describe(CERTIFICATE_AUTHORITIES.GET_CSR.csr)
}) })
} }
}, },
@@ -286,9 +286,9 @@ export const registerCaRouter = async (server: FastifyZodProvider) => {
}), }),
response: { response: {
200: z.object({ 200: z.object({
certificate: z.string(), certificate: z.string().describe(CERTIFICATE_AUTHORITIES.GET_CERT.certificate),
certificateChain: z.string(), certificateChain: z.string().describe(CERTIFICATE_AUTHORITIES.GET_CERT.certificateChain),
serialNumber: z.string() serialNumber: z.string().describe(CERTIFICATE_AUTHORITIES.GET_CERT.serialNumber)
}) })
} }
}, },
@@ -341,10 +341,13 @@ export const registerCaRouter = async (server: FastifyZodProvider) => {
}), }),
response: { response: {
200: z.object({ 200: z.object({
certificate: z.string().trim(), certificate: z.string().trim().describe(CERTIFICATE_AUTHORITIES.SIGN_INTERMEDIATE.certificate),
certificateChain: z.string().trim(), certificateChain: z.string().trim().describe(CERTIFICATE_AUTHORITIES.SIGN_INTERMEDIATE.certificateChain),
issuingCaCertificate: z.string().trim(), issuingCaCertificate: z
serialNumber: z.string().trim() .string()
.trim()
.describe(CERTIFICATE_AUTHORITIES.SIGN_INTERMEDIATE.issuingCaCertificate),
serialNumber: z.string().trim().describe(CERTIFICATE_AUTHORITIES.SIGN_INTERMEDIATE.serialNumber)
}) })
} }
}, },
@@ -468,11 +471,11 @@ export const registerCaRouter = async (server: FastifyZodProvider) => {
), ),
response: { response: {
200: z.object({ 200: z.object({
certificate: z.string().trim(), certificate: z.string().trim().describe(CERTIFICATE_AUTHORITIES.ISSUE_CERT.certificate),
issuingCaCertificate: z.string().trim(), issuingCaCertificate: z.string().trim().describe(CERTIFICATE_AUTHORITIES.ISSUE_CERT.issuingCaCertificate),
certificateChain: z.string().trim(), certificateChain: z.string().trim().describe(CERTIFICATE_AUTHORITIES.ISSUE_CERT.certificateChain),
privateKey: z.string().trim(), privateKey: z.string().trim().describe(CERTIFICATE_AUTHORITIES.ISSUE_CERT.privateKey),
serialNumber: z.string().trim() serialNumber: z.string().trim().describe(CERTIFICATE_AUTHORITIES.ISSUE_CERT.serialNumber)
}) })
} }
}, },
@@ -524,7 +527,7 @@ export const registerCaRouter = async (server: FastifyZodProvider) => {
}), }),
response: { response: {
200: z.object({ 200: z.object({
crl: z.string() crl: z.string().describe(CERTIFICATE_AUTHORITIES.GET_CRL.crl)
}) })
} }
}, },
@@ -73,8 +73,8 @@ export const registerCertRouter = async (server: FastifyZodProvider) => {
response: { response: {
200: z.object({ 200: z.object({
message: z.string().trim(), message: z.string().trim(),
serialNumber: z.string().trim(), serialNumber: z.string().trim().describe(CERTIFICATES.REVOKE.serialNumberRes),
revokedAt: z.date() revokedAt: z.date().describe(CERTIFICATES.REVOKE.revokedAt)
}) })
} }
}, },
@@ -169,9 +169,9 @@ export const registerCertRouter = async (server: FastifyZodProvider) => {
}), }),
response: { response: {
200: z.object({ 200: z.object({
certificate: z.string().trim(), certificate: z.string().trim().describe(CERTIFICATES.GET_CERT.certificate),
certificateChain: z.string().trim(), certificateChain: z.string().trim().describe(CERTIFICATES.GET_CERT.certificateChain),
serialNumber: z.string().trim() serialNumber: z.string().trim().describe(CERTIFICATES.GET_CERT.serialNumberRes)
}) })
} }
}, },
@@ -0,0 +1,4 @@
---
title: "Get Certificate Body / Chain"
openapi: "GET /api/v1/pki/certificates/{serialNumber}/certificate"
---
@@ -0,0 +1,4 @@
---
title: "Delete"
openapi: "DELETE /api/v1/pki/certificates/{serialNumber}"
---
@@ -0,0 +1,4 @@
---
title: "Retrieve"
openapi: "GET /api/v1/pki/certificates/{serialNumber}"
---
@@ -0,0 +1,4 @@
---
title: "Revoke"
openapi: "POST /api/v1/pki/certificates/{serialNumber}/revoke"
---
+24
View File
@@ -565,6 +565,30 @@
{ {
"group": "Audit Logs", "group": "Audit Logs",
"pages": ["api-reference/endpoints/audit-logs/export-audit-log"] "pages": ["api-reference/endpoints/audit-logs/export-audit-log"]
},
{
"group": "Certificate Authorities",
"pages": [
"api-reference/endpoints/certificate-authorities/create",
"api-reference/endpoints/certificate-authorities/read",
"api-reference/endpoints/certificate-authorities/update",
"api-reference/endpoints/certificate-authorities/delete",
"api-reference/endpoints/certificate-authorities/csr",
"api-reference/endpoints/certificate-authorities/cert",
"api-reference/endpoints/certificate-authorities/sign-intermediate",
"api-reference/endpoints/certificate-authorities/import-cert",
"api-reference/endpoints/certificate-authorities/issue-cert",
"api-reference/endpoints/certificate-authorities/crl"
]
},
{
"group": "Certificates",
"pages": [
"api-reference/endpoints/certificates/read",
"api-reference/endpoints/certificates/revoke",
"api-reference/endpoints/certificates/delete",
"api-reference/endpoints/certificates/cert-body"
]
} }
] ]
}, },