mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-09 14:28:23 +00:00
Passing CSR
This commit is contained in:
@@ -738,6 +738,7 @@ export const pkiAcmeServiceFactory = ({
|
|||||||
caId: certificateAuthority!.id,
|
caId: certificateAuthority!.id,
|
||||||
commonName: certificateRequest.commonName!,
|
commonName: certificateRequest.commonName!,
|
||||||
altNames: certificateRequest.subjectAlternativeNames?.map((san) => san.value),
|
altNames: certificateRequest.subjectAlternativeNames?.map((san) => san.value),
|
||||||
|
csr: Buffer.from(csr),
|
||||||
// TODO: not 100% sure what are these columns for, but let's put the values for common website SSL certs for now
|
// TODO: not 100% sure what are these columns for, but let's put the values for common website SSL certs for now
|
||||||
keyUsages: [CertKeyUsage.DIGITAL_SIGNATURE, CertKeyUsage.KEY_ENCIPHERMENT, CertKeyUsage.KEY_AGREEMENT],
|
keyUsages: [CertKeyUsage.DIGITAL_SIGNATURE, CertKeyUsage.KEY_ENCIPHERMENT, CertKeyUsage.KEY_AGREEMENT],
|
||||||
extendedKeyUsages: [CertExtendedKeyUsage.SERVER_AUTH]
|
extendedKeyUsages: [CertExtendedKeyUsage.SERVER_AUTH]
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
import * as x509 from "@peculiar/x509";
|
import * as x509 from "@peculiar/x509";
|
||||||
import acme from "acme-client";
|
import acme, { CsrBuffer } from "acme-client";
|
||||||
|
|
||||||
import { TableName } from "@app/db/schemas";
|
import { TableName } from "@app/db/schemas";
|
||||||
import { crypto } from "@app/lib/crypto/cryptography";
|
import { crypto } from "@app/lib/crypto/cryptography";
|
||||||
@@ -126,6 +126,8 @@ export const orderCertificate = async (
|
|||||||
subscriberId,
|
subscriberId,
|
||||||
commonName,
|
commonName,
|
||||||
altNames,
|
altNames,
|
||||||
|
csr,
|
||||||
|
csrPrivateKey,
|
||||||
keyUsages,
|
keyUsages,
|
||||||
extendedKeyUsages
|
extendedKeyUsages
|
||||||
}: {
|
}: {
|
||||||
@@ -133,6 +135,8 @@ export const orderCertificate = async (
|
|||||||
subscriberId?: string;
|
subscriberId?: string;
|
||||||
commonName: string;
|
commonName: string;
|
||||||
altNames?: string[];
|
altNames?: string[];
|
||||||
|
csr: CsrBuffer;
|
||||||
|
csrPrivateKey?: string;
|
||||||
keyUsages?: CertKeyUsage[];
|
keyUsages?: CertKeyUsage[];
|
||||||
extendedKeyUsages?: CertExtendedKeyUsage[];
|
extendedKeyUsages?: CertExtendedKeyUsage[];
|
||||||
},
|
},
|
||||||
@@ -220,25 +224,11 @@ export const orderCertificate = async (
|
|||||||
|
|
||||||
const acmeClient = new acme.Client(acmeClientOptions);
|
const acmeClient = new acme.Client(acmeClientOptions);
|
||||||
|
|
||||||
const alg = keyAlgorithmToAlgCfg(CertKeyAlgorithm.RSA_2048);
|
|
||||||
|
|
||||||
const leafKeys = await crypto.nativeCrypto.subtle.generateKey(alg, true, ["sign", "verify"]);
|
|
||||||
const skLeafObj = crypto.nativeCrypto.KeyObject.from(leafKeys.privateKey);
|
|
||||||
const skLeaf = skLeafObj.export({ format: "pem", type: "pkcs8" }) as string;
|
|
||||||
|
|
||||||
const [, certificateCsr] = await acme.crypto.createCsr(
|
|
||||||
{
|
|
||||||
altNames,
|
|
||||||
commonName
|
|
||||||
},
|
|
||||||
skLeaf
|
|
||||||
);
|
|
||||||
|
|
||||||
const appConnection = await appConnectionDAL.findById(acmeCa.configuration.dnsAppConnectionId);
|
const appConnection = await appConnectionDAL.findById(acmeCa.configuration.dnsAppConnectionId);
|
||||||
const connection = await decryptAppConnection(appConnection, kmsService);
|
const connection = await decryptAppConnection(appConnection, kmsService);
|
||||||
|
|
||||||
const pem = await acmeClient.auto({
|
const pem = await acmeClient.auto({
|
||||||
csr: certificateCsr,
|
csr,
|
||||||
email: acmeCa.configuration.accountEmail,
|
email: acmeCa.configuration.accountEmail,
|
||||||
challengePriority: ["dns-01"],
|
challengePriority: ["dns-01"],
|
||||||
// For ACME development mode, we mock the DNS challenge API calls. So, no real DNS records are created.
|
// For ACME development mode, we mock the DNS challenge API calls. So, no real DNS records are created.
|
||||||
@@ -321,9 +311,11 @@ export const orderCertificate = async (
|
|||||||
plainText: Buffer.from(certificateChainPem)
|
plainText: Buffer.from(certificateChainPem)
|
||||||
});
|
});
|
||||||
|
|
||||||
const { cipherTextBlob: encryptedPrivateKey } = await kmsEncryptor({
|
const { cipherTextBlob: encryptedPrivateKey } = csrPrivateKey
|
||||||
plainText: Buffer.from(skLeaf)
|
? await kmsEncryptor({
|
||||||
});
|
plainText: Buffer.from(csrPrivateKey)
|
||||||
|
})
|
||||||
|
: { cipherTextBlob: undefined };
|
||||||
|
|
||||||
return (tx || certificateDAL).transaction(async (innerTx: Knex) => {
|
return (tx || certificateDAL).transaction(async (innerTx: Knex) => {
|
||||||
const cert = await certificateDAL.create(
|
const cert = await certificateDAL.create(
|
||||||
@@ -353,13 +345,15 @@ export const orderCertificate = async (
|
|||||||
innerTx
|
innerTx
|
||||||
);
|
);
|
||||||
|
|
||||||
await certificateSecretDAL.create(
|
if (encryptedPrivateKey !== undefined) {
|
||||||
{
|
await certificateSecretDAL.create(
|
||||||
certId: cert.id,
|
{
|
||||||
encryptedPrivateKey
|
certId: cert.id,
|
||||||
},
|
encryptedPrivateKey
|
||||||
innerTx
|
},
|
||||||
);
|
innerTx
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
return cert;
|
return cert;
|
||||||
});
|
});
|
||||||
@@ -583,12 +577,26 @@ export const AcmeCertificateAuthorityFns = ({
|
|||||||
if (!subscriber.caId) {
|
if (!subscriber.caId) {
|
||||||
throw new BadRequestError({ message: "Subscriber does not have a CA" });
|
throw new BadRequestError({ message: "Subscriber does not have a CA" });
|
||||||
}
|
}
|
||||||
|
const alg = keyAlgorithmToAlgCfg(CertKeyAlgorithm.RSA_2048);
|
||||||
|
|
||||||
|
const leafKeys = await crypto.nativeCrypto.subtle.generateKey(alg, true, ["sign", "verify"]);
|
||||||
|
const skLeafObj = crypto.nativeCrypto.KeyObject.from(leafKeys.privateKey);
|
||||||
|
const skLeaf = skLeafObj.export({ format: "pem", type: "pkcs8" }) as string;
|
||||||
|
|
||||||
|
const [, certificateCsr] = await acme.crypto.createCsr({
|
||||||
|
altNames: subscriber.subjectAlternativeNames,
|
||||||
|
commonName: subscriber.commonName,
|
||||||
|
key: skLeaf
|
||||||
|
});
|
||||||
|
|
||||||
await orderCertificate(
|
await orderCertificate(
|
||||||
{
|
{
|
||||||
caId: subscriber.caId,
|
caId: subscriber.caId,
|
||||||
subscriberId: subscriber.id,
|
subscriberId: subscriber.id,
|
||||||
commonName: subscriber.commonName,
|
commonName: subscriber.commonName,
|
||||||
altNames: subscriber.subjectAlternativeNames,
|
altNames: subscriber.subjectAlternativeNames,
|
||||||
|
csr: certificateCsr,
|
||||||
|
csrPrivateKey: skLeaf,
|
||||||
keyUsages: subscriber.keyUsages as CertKeyUsage[],
|
keyUsages: subscriber.keyUsages as CertKeyUsage[],
|
||||||
extendedKeyUsages: subscriber.extendedKeyUsages as CertExtendedKeyUsage[]
|
extendedKeyUsages: subscriber.extendedKeyUsages as CertExtendedKeyUsage[]
|
||||||
},
|
},
|
||||||
|
|||||||
Reference in New Issue
Block a user