Merge pull request #3649 from Infisical/ENG-2820

feat(smtp-service): Custom CA Certs
This commit is contained in:
x032205
2025-05-23 13:10:03 -04:00
committed by GitHub
2 changed files with 34 additions and 14 deletions

View File

@@ -69,6 +69,9 @@ const envSchema = z
SMTP_PASSWORD: zpStr(z.string().optional()), SMTP_PASSWORD: zpStr(z.string().optional()),
SMTP_FROM_ADDRESS: zpStr(z.string().optional()), SMTP_FROM_ADDRESS: zpStr(z.string().optional()),
SMTP_FROM_NAME: zpStr(z.string().optional().default("Infisical")), SMTP_FROM_NAME: zpStr(z.string().optional().default("Infisical")),
SMTP_CUSTOM_CA_CERT: zpStr(
z.string().optional().describe("Base64 encoded custom CA certificate PEM(s) for the SMTP server")
),
COOKIE_SECRET_SIGN_KEY: z COOKIE_SECRET_SIGN_KEY: z
.string() .string()
.min(32) .min(32)
@@ -298,6 +301,17 @@ export const initEnvConfig = (logger?: CustomLogger) => {
}; };
export const formatSmtpConfig = () => { export const formatSmtpConfig = () => {
const tlsOptions: {
rejectUnauthorized: boolean;
ca?: string | string[];
} = {
rejectUnauthorized: envCfg.SMTP_TLS_REJECT_UNAUTHORIZED
};
if (envCfg.SMTP_CUSTOM_CA_CERT) {
tlsOptions.ca = Buffer.from(envCfg.SMTP_CUSTOM_CA_CERT, "base64").toString("utf-8");
}
return { return {
host: envCfg.SMTP_HOST, host: envCfg.SMTP_HOST,
port: envCfg.SMTP_PORT, port: envCfg.SMTP_PORT,
@@ -309,8 +323,6 @@ export const formatSmtpConfig = () => {
from: `"${envCfg.SMTP_FROM_NAME}" <${envCfg.SMTP_FROM_ADDRESS}>`, from: `"${envCfg.SMTP_FROM_NAME}" <${envCfg.SMTP_FROM_ADDRESS}>`,
ignoreTLS: envCfg.SMTP_IGNORE_TLS, ignoreTLS: envCfg.SMTP_IGNORE_TLS,
requireTLS: envCfg.SMTP_REQUIRE_TLS, requireTLS: envCfg.SMTP_REQUIRE_TLS,
tls: { tls: tlsOptions
rejectUnauthorized: envCfg.SMTP_TLS_REJECT_UNAUTHORIZED
}
}; };
}; };

View File

@@ -96,8 +96,7 @@ The platform utilizes Postgres to persist all of its data and Redis for caching
<ParamField query="DB_ROOT_CERT" type="string" default="" optional> <ParamField query="DB_ROOT_CERT" type="string" default="" optional>
Configure the SSL certificate for securing a Postgres connection by first encoding it in base64. Configure the SSL certificate for securing a Postgres connection by first encoding it in base64.
Use the command below to encode your certificate: Use the following command to encode your certificate: `echo "<certificate>" | base64`
`echo "<certificate>" | base64`
</ParamField> </ParamField>
<ParamField query="DB_READ_REPLICAS" type="string" default="" optional> <ParamField query="DB_READ_REPLICAS" type="string" default="" optional>
@@ -111,10 +110,9 @@ DB_READ_REPLICAS=[{"DB_CONNECTION_URI":""}]
</ParamField> </ParamField>
<ParamField query="DB_ROOT_CERT" type="string" default="" optional> <ParamField query="DB_ROOT_CERT" type="string" default="" optional>
Configure the SSL certificate for securing a Postgres replica connection by first encoding it in base64. Configure the SSL certificate for securing a Postgres replica connection by first encoding it in base64.
Use the command below to encode your certificate: Use the following command to encode your certificate: `echo "<certificate>" | base64`
`echo "<certificate>" | base64`
If not provided it will use master SSL certificate. If not provided it will use master SSL certificate.
</ParamField> </ParamField>
</Expandable> </Expandable>
@@ -169,6 +167,16 @@ Without email configuration, Infisical's core functions like sign-up/login and s
<ParamField query="SMTP_TLS_REJECT_UNAUTHORIZED" type="bool" default="true" optional> <ParamField query="SMTP_TLS_REJECT_UNAUTHORIZED" type="bool" default="true" optional>
If this is `true`, Infisical will validate the server's SSL/TLS certificate and reject the connection if the certificate is invalid or not trusted. If set to `false`, the client will accept the server's certificate regardless of its validity, which can be useful in development or testing environments but is not recommended for production use. If this is `true`, Infisical will validate the server's SSL/TLS certificate and reject the connection if the certificate is invalid or not trusted. If set to `false`, the client will accept the server's certificate regardless of its validity, which can be useful in development or testing environments but is not recommended for production use.
</ParamField> </ParamField>
<ParamField query="SMTP_CUSTOM_CA_CERT" type="string" default="none" optional>
If your SMTP server uses a certificate signed by a custom Certificate Authority, you should set this variable so that Infisical can trust the custom CA.
This variable **must be a base64 encoded PEM certificate**. Use the following command to encode your certificate: `echo "<certificate>" | base64`
Infisical highly encourages the following variables be used alongside this one for maximum security:
- `SMTP_REQUIRE_TLS=true`
- `SMTP_TLS_REJECT_UNAUTHORIZED=true`
</ParamField>
</Accordion> </Accordion>
<Accordion title="Twilio SendGrid"> <Accordion title="Twilio SendGrid">