mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 22:27:48 +00:00
misc: addressed comments and doc changes
This commit is contained in:
@@ -1169,8 +1169,9 @@ export const CERTIFICATE_TEMPLATES = {
|
|||||||
commonName: "The regular expression string to use for validating common names",
|
commonName: "The regular expression string to use for validating common names",
|
||||||
subjectAlternativeName: "The regular expression string to use for validating subject alternative names",
|
subjectAlternativeName: "The regular expression string to use for validating subject alternative names",
|
||||||
ttl: "The max TTL for the template",
|
ttl: "The max TTL for the template",
|
||||||
keyUsages: "The key usage constraint or default value",
|
keyUsages: "The key usage constraint or default value for when template is used during certificate issuance",
|
||||||
extendedKeyUsages: "The extended key usage constraint or default value"
|
extendedKeyUsages:
|
||||||
|
"The extended key usage constraint or default value for when template is used during certificate issuance"
|
||||||
},
|
},
|
||||||
GET: {
|
GET: {
|
||||||
certificateTemplateId: "The ID of the certificate template to get"
|
certificateTemplateId: "The ID of the certificate template to get"
|
||||||
@@ -1183,8 +1184,10 @@ export const CERTIFICATE_TEMPLATES = {
|
|||||||
commonName: "The updated regular expression string for validating common names",
|
commonName: "The updated regular expression string for validating common names",
|
||||||
subjectAlternativeName: "The updated regular expression string for validating subject alternative names",
|
subjectAlternativeName: "The updated regular expression string for validating subject alternative names",
|
||||||
ttl: "The updated max TTL for the template",
|
ttl: "The updated max TTL for the template",
|
||||||
keyUsages: "The updated key usage constraint or default value",
|
keyUsages:
|
||||||
extendedKeyUsages: "The updated extended key usage constraint or default value"
|
"The updated key usage constraint or default value for when template is used during certificate issuance",
|
||||||
|
extendedKeyUsages:
|
||||||
|
"The updated extended key usage constraint or default value for when template is used during certificate issuance"
|
||||||
},
|
},
|
||||||
DELETE: {
|
DELETE: {
|
||||||
certificateTemplateId: "The ID of the certificate template to delete"
|
certificateTemplateId: "The ID of the certificate template to delete"
|
||||||
|
|||||||
@@ -60,6 +60,8 @@ In the following steps, we explore how to issue a X.509 certificate under a CA.
|
|||||||
- Common Name (CN): A regular expression used to validate the common name in certificate requests.
|
- Common Name (CN): A regular expression used to validate the common name in certificate requests.
|
||||||
- Alternative Names (SANs): A regular expression used to validate subject alternative names in certificate requests.
|
- Alternative Names (SANs): A regular expression used to validate subject alternative names in certificate requests.
|
||||||
- TTL: The maximum Time-to-Live (TTL) for certificates issued using this template.
|
- TTL: The maximum Time-to-Live (TTL) for certificates issued using this template.
|
||||||
|
- Key Usage: The key usage constraint or default value for certificates issued using this template.
|
||||||
|
- Extended Key Usage: The extended key usage constraint or default value for certificates issued using this template.
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Creating a certificate">
|
<Step title="Creating a certificate">
|
||||||
To create a certificate, head to your Project > Internal PKI > Certificates and press **Issue** under the Certificates section.
|
To create a certificate, head to your Project > Internal PKI > Certificates and press **Issue** under the Certificates section.
|
||||||
@@ -76,6 +78,8 @@ In the following steps, we explore how to issue a X.509 certificate under a CA.
|
|||||||
- Common Name (CN): The (common) name for the certificate like `service.acme.com`.
|
- Common Name (CN): The (common) name for the certificate like `service.acme.com`.
|
||||||
- Alternative Names (SANs): A comma-delimited list of Subject Alternative Names (SANs) for the certificate; these can be host names or email addresses like `app1.acme.com, app2.acme.com`.
|
- Alternative Names (SANs): A comma-delimited list of Subject Alternative Names (SANs) for the certificate; these can be host names or email addresses like `app1.acme.com, app2.acme.com`.
|
||||||
- TTL: The lifetime of the certificate in seconds.
|
- TTL: The lifetime of the certificate in seconds.
|
||||||
|
- Key Usage: The key usage extension of the certificate.
|
||||||
|
- Extended Key Usage: The extended key usage extension of the certificate.
|
||||||
|
|
||||||
<Note>
|
<Note>
|
||||||
Note that Infisical PKI supports issuing certificates without certificate templates as well. If this is desired, then you can set the **Certificate Template** field to **None**
|
Note that Infisical PKI supports issuing certificates without certificate templates as well. If this is desired, then you can set the **Certificate Template** field to **None**
|
||||||
@@ -83,6 +87,7 @@ In the following steps, we explore how to issue a X.509 certificate under a CA.
|
|||||||
|
|
||||||
That said, we recommend using certificate templates to enforce policies and attach expiration monitoring on issued certificates.
|
That said, we recommend using certificate templates to enforce policies and attach expiration monitoring on issued certificates.
|
||||||
</Note>
|
</Note>
|
||||||
|
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Copying the certificate details">
|
<Step title="Copying the certificate details">
|
||||||
Once you have created the certificate from step 1, you'll be presented with the certificate details including the **Certificate Body**, **Certificate Chain**, and **Private Key**.
|
Once you have created the certificate from step 1, you'll be presented with the certificate details including the **Certificate Body**, **Certificate Chain**, and **Private Key**.
|
||||||
@@ -132,6 +137,7 @@ In the following steps, we explore how to issue a X.509 certificate under a CA.
|
|||||||
ttl: "...",
|
ttl: "...",
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Creating a certificate">
|
<Step title="Creating a certificate">
|
||||||
To create a certificate under the certificate template, make an API request to the [Issue Certificate](/api-reference/endpoints/certificates/issue-cert) API endpoint,
|
To create a certificate under the certificate template, make an API request to the [Issue Certificate](/api-reference/endpoints/certificates/issue-cert) API endpoint,
|
||||||
@@ -197,6 +203,7 @@ In the following steps, we explore how to issue a X.509 certificate under a CA.
|
|||||||
serialNumber: "..."
|
serialNumber: "..."
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
</Tab>
|
</Tab>
|
||||||
|
|||||||
Binary file not shown.
|
Before Width: | Height: | Size: 379 KiB After Width: | Height: | Size: 399 KiB |
Binary file not shown.
|
Before Width: | Height: | Size: 517 KiB After Width: | Height: | Size: 518 KiB |
@@ -1,4 +1,10 @@
|
|||||||
import { CertKeyAlgorithm, CertStatus, CrlReason } from "./enums";
|
import {
|
||||||
|
CertExtendedKeyUsage,
|
||||||
|
CertKeyAlgorithm,
|
||||||
|
CertKeyUsage,
|
||||||
|
CertStatus,
|
||||||
|
CrlReason
|
||||||
|
} from "./enums";
|
||||||
|
|
||||||
export const certStatusToNameMap: { [K in CertStatus]: string } = {
|
export const certStatusToNameMap: { [K in CertStatus]: string } = {
|
||||||
[CertStatus.ACTIVE]: "Active",
|
[CertStatus.ACTIVE]: "Active",
|
||||||
@@ -69,3 +75,24 @@ export const crlReasons = [
|
|||||||
},
|
},
|
||||||
{ label: crlReasonToNameMap[CrlReason.A_A_COMPROMISE], value: CrlReason.A_A_COMPROMISE }
|
{ label: crlReasonToNameMap[CrlReason.A_A_COMPROMISE], value: CrlReason.A_A_COMPROMISE }
|
||||||
];
|
];
|
||||||
|
|
||||||
|
export const KEY_USAGES_OPTIONS = [
|
||||||
|
{ value: CertKeyUsage.DIGITAL_SIGNATURE, label: "Digital Signature" },
|
||||||
|
{ value: CertKeyUsage.KEY_ENCIPHERMENT, label: "Key Encipherment" },
|
||||||
|
{ value: CertKeyUsage.NON_REPUDIATION, label: "Non Repudiation" },
|
||||||
|
{ value: CertKeyUsage.DATA_ENCIPHERMENT, label: "Data Encipherment" },
|
||||||
|
{ value: CertKeyUsage.KEY_AGREEMENT, label: "Key Agreement" },
|
||||||
|
{ value: CertKeyUsage.KEY_CERT_SIGN, label: "Certificate Sign" },
|
||||||
|
{ value: CertKeyUsage.CRL_SIGN, label: "CRL Sign" },
|
||||||
|
{ value: CertKeyUsage.ENCIPHER_ONLY, label: "Encipher Only" },
|
||||||
|
{ value: CertKeyUsage.DECIPHER_ONLY, label: "Decipher Only" }
|
||||||
|
] as const;
|
||||||
|
|
||||||
|
export const EXTENDED_KEY_USAGES_OPTIONS = [
|
||||||
|
{ value: CertExtendedKeyUsage.CLIENT_AUTH, label: "Client Auth" },
|
||||||
|
{ value: CertExtendedKeyUsage.SERVER_AUTH, label: "Server Auth" },
|
||||||
|
{ value: CertExtendedKeyUsage.EMAIL_PROTECTION, label: "Email Protection" },
|
||||||
|
{ value: CertExtendedKeyUsage.OCSP_SIGNING, label: "OCSP Signing" },
|
||||||
|
{ value: CertExtendedKeyUsage.CODE_SIGNING, label: "Code Signing" },
|
||||||
|
{ value: CertExtendedKeyUsage.TIMESTAMPING, label: "Timestamping" }
|
||||||
|
] as const;
|
||||||
|
|||||||
@@ -22,3 +22,24 @@ export enum CrlReason {
|
|||||||
PRIVILEGE_WITHDRAWN = "PRIVILEGE_WITHDRAWN",
|
PRIVILEGE_WITHDRAWN = "PRIVILEGE_WITHDRAWN",
|
||||||
A_A_COMPROMISE = "A_A_COMPROMISE"
|
A_A_COMPROMISE = "A_A_COMPROMISE"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export enum CertKeyUsage {
|
||||||
|
DIGITAL_SIGNATURE = "digitalSignature",
|
||||||
|
KEY_ENCIPHERMENT = "keyEncipherment",
|
||||||
|
NON_REPUDIATION = "nonRepudiation",
|
||||||
|
DATA_ENCIPHERMENT = "dataEncipherment",
|
||||||
|
KEY_AGREEMENT = "keyAgreement",
|
||||||
|
KEY_CERT_SIGN = "keyCertSign",
|
||||||
|
CRL_SIGN = "cRLSign",
|
||||||
|
ENCIPHER_ONLY = "encipherOnly",
|
||||||
|
DECIPHER_ONLY = "decipherOnly"
|
||||||
|
}
|
||||||
|
|
||||||
|
export enum CertExtendedKeyUsage {
|
||||||
|
CLIENT_AUTH = "clientAuth",
|
||||||
|
SERVER_AUTH = "serverAuth",
|
||||||
|
CODE_SIGNING = "codeSigning",
|
||||||
|
EMAIL_PROTECTION = "emailProtection",
|
||||||
|
TIMESTAMPING = "timeStamping",
|
||||||
|
OCSP_SIGNING = "ocspSigning"
|
||||||
|
}
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
import { CertStatus } from "./enums";
|
import { CertExtendedKeyUsage, CertKeyUsage, CertStatus } from "./enums";
|
||||||
|
|
||||||
export type TCertificate = {
|
export type TCertificate = {
|
||||||
id: string;
|
id: string;
|
||||||
@@ -25,45 +25,3 @@ export type TRevokeCertDTO = {
|
|||||||
serialNumber: string;
|
serialNumber: string;
|
||||||
revocationReason: string;
|
revocationReason: string;
|
||||||
};
|
};
|
||||||
|
|
||||||
export enum CertKeyUsage {
|
|
||||||
DIGITAL_SIGNATURE = "digitalSignature",
|
|
||||||
KEY_ENCIPHERMENT = "keyEncipherment",
|
|
||||||
NON_REPUDIATION = "nonRepudiation",
|
|
||||||
DATA_ENCIPHERMENT = "dataEncipherment",
|
|
||||||
KEY_AGREEMENT = "keyAgreement",
|
|
||||||
KEY_CERT_SIGN = "keyCertSign",
|
|
||||||
CRL_SIGN = "cRLSign",
|
|
||||||
ENCIPHER_ONLY = "encipherOnly",
|
|
||||||
DECIPHER_ONLY = "decipherOnly"
|
|
||||||
}
|
|
||||||
|
|
||||||
export const KEY_USAGES_OPTIONS = [
|
|
||||||
{ value: CertKeyUsage.DIGITAL_SIGNATURE, label: "Digital Signature" },
|
|
||||||
{ value: CertKeyUsage.KEY_ENCIPHERMENT, label: "Key Encipherment" },
|
|
||||||
{ value: CertKeyUsage.NON_REPUDIATION, label: "Non Repudiation" },
|
|
||||||
{ value: CertKeyUsage.DATA_ENCIPHERMENT, label: "Data Encipherment" },
|
|
||||||
{ value: CertKeyUsage.KEY_AGREEMENT, label: "Key Agreement" },
|
|
||||||
{ value: CertKeyUsage.KEY_CERT_SIGN, label: "Certificate Sign" },
|
|
||||||
{ value: CertKeyUsage.CRL_SIGN, label: "CRL Sign" },
|
|
||||||
{ value: CertKeyUsage.ENCIPHER_ONLY, label: "Encipher Only" },
|
|
||||||
{ value: CertKeyUsage.DECIPHER_ONLY, label: "Decipher Only" }
|
|
||||||
] as const;
|
|
||||||
|
|
||||||
export enum CertExtendedKeyUsage {
|
|
||||||
CLIENT_AUTH = "clientAuth",
|
|
||||||
SERVER_AUTH = "serverAuth",
|
|
||||||
CODE_SIGNING = "codeSigning",
|
|
||||||
EMAIL_PROTECTION = "emailProtection",
|
|
||||||
TIMESTAMPING = "timeStamping",
|
|
||||||
OCSP_SIGNING = "ocspSigning"
|
|
||||||
}
|
|
||||||
|
|
||||||
export const EXTENDED_KEY_USAGES_OPTIONS = [
|
|
||||||
{ value: CertExtendedKeyUsage.CLIENT_AUTH, label: "Client Auth" },
|
|
||||||
{ value: CertExtendedKeyUsage.SERVER_AUTH, label: "Server Auth" },
|
|
||||||
{ value: CertExtendedKeyUsage.EMAIL_PROTECTION, label: "Email Protection" },
|
|
||||||
{ value: CertExtendedKeyUsage.OCSP_SIGNING, label: "OCSP Signing" },
|
|
||||||
{ value: CertExtendedKeyUsage.CODE_SIGNING, label: "Code Signing" },
|
|
||||||
{ value: CertExtendedKeyUsage.TIMESTAMPING, label: "Timestamping" }
|
|
||||||
] as const;
|
|
||||||
|
|||||||
+5
-6
@@ -34,11 +34,10 @@ import {
|
|||||||
} from "@app/hooks/api";
|
} from "@app/hooks/api";
|
||||||
import { caTypeToNameMap } from "@app/hooks/api/ca/constants";
|
import { caTypeToNameMap } from "@app/hooks/api/ca/constants";
|
||||||
import {
|
import {
|
||||||
CertExtendedKeyUsage,
|
|
||||||
CertKeyUsage,
|
|
||||||
EXTENDED_KEY_USAGES_OPTIONS,
|
EXTENDED_KEY_USAGES_OPTIONS,
|
||||||
KEY_USAGES_OPTIONS
|
KEY_USAGES_OPTIONS
|
||||||
} from "@app/hooks/api/certificates/types";
|
} from "@app/hooks/api/certificates/constants";
|
||||||
|
import { CertExtendedKeyUsage, CertKeyUsage } from "@app/hooks/api/certificates/enums";
|
||||||
import { UsePopUpState } from "@app/hooks/usePopUp";
|
import { UsePopUpState } from "@app/hooks/usePopUp";
|
||||||
|
|
||||||
import { CertificateContent } from "./CertificateContent";
|
import { CertificateContent } from "./CertificateContent";
|
||||||
@@ -428,7 +427,7 @@ export const CertificateModal = ({ popUp, handlePopUpToggle }: Props) => {
|
|||||||
<Accordion type="single" collapsible className="w-full">
|
<Accordion type="single" collapsible className="w-full">
|
||||||
<AccordionItem value="key-usages" className="data-[state=open]:border-none">
|
<AccordionItem value="key-usages" className="data-[state=open]:border-none">
|
||||||
<AccordionTrigger className="h-fit flex-none pl-1 text-sm">
|
<AccordionTrigger className="h-fit flex-none pl-1 text-sm">
|
||||||
<div className="order-1 ml-3">Key Usages</div>
|
<div className="order-1 ml-3">Key Usage</div>
|
||||||
</AccordionTrigger>
|
</AccordionTrigger>
|
||||||
<AccordionContent>
|
<AccordionContent>
|
||||||
<Controller
|
<Controller
|
||||||
@@ -437,7 +436,7 @@ export const CertificateModal = ({ popUp, handlePopUpToggle }: Props) => {
|
|||||||
render={({ field: { onChange, value }, fieldState: { error } }) => {
|
render={({ field: { onChange, value }, fieldState: { error } }) => {
|
||||||
return (
|
return (
|
||||||
<FormControl
|
<FormControl
|
||||||
label="Key Usages"
|
label="Key Usage"
|
||||||
errorText={error?.message}
|
errorText={error?.message}
|
||||||
isError={Boolean(error)}
|
isError={Boolean(error)}
|
||||||
>
|
>
|
||||||
@@ -472,7 +471,7 @@ export const CertificateModal = ({ popUp, handlePopUpToggle }: Props) => {
|
|||||||
render={({ field: { onChange, value }, fieldState: { error } }) => {
|
render={({ field: { onChange, value }, fieldState: { error } }) => {
|
||||||
return (
|
return (
|
||||||
<FormControl
|
<FormControl
|
||||||
label="Extended Key Usages"
|
label="Extended Key Usage"
|
||||||
errorText={error?.message}
|
errorText={error?.message}
|
||||||
isError={Boolean(error)}
|
isError={Boolean(error)}
|
||||||
>
|
>
|
||||||
|
|||||||
+5
-6
@@ -34,11 +34,10 @@ import {
|
|||||||
} from "@app/hooks/api";
|
} from "@app/hooks/api";
|
||||||
import { caTypeToNameMap } from "@app/hooks/api/ca/constants";
|
import { caTypeToNameMap } from "@app/hooks/api/ca/constants";
|
||||||
import {
|
import {
|
||||||
CertExtendedKeyUsage,
|
|
||||||
CertKeyUsage,
|
|
||||||
EXTENDED_KEY_USAGES_OPTIONS,
|
EXTENDED_KEY_USAGES_OPTIONS,
|
||||||
KEY_USAGES_OPTIONS
|
KEY_USAGES_OPTIONS
|
||||||
} from "@app/hooks/api/certificates/types";
|
} from "@app/hooks/api/certificates/constants";
|
||||||
|
import { CertExtendedKeyUsage, CertKeyUsage } from "@app/hooks/api/certificates/enums";
|
||||||
import { UsePopUpState } from "@app/hooks/usePopUp";
|
import { UsePopUpState } from "@app/hooks/usePopUp";
|
||||||
|
|
||||||
const validateTemplateRegexField = z
|
const validateTemplateRegexField = z
|
||||||
@@ -395,7 +394,7 @@ export const CertificateTemplateModal = ({ popUp, handlePopUpToggle, caId }: Pro
|
|||||||
<Accordion type="single" collapsible className="w-full">
|
<Accordion type="single" collapsible className="w-full">
|
||||||
<AccordionItem value="key-usages" className="data-[state=open]:border-none">
|
<AccordionItem value="key-usages" className="data-[state=open]:border-none">
|
||||||
<AccordionTrigger className="h-fit flex-none pl-1 text-sm">
|
<AccordionTrigger className="h-fit flex-none pl-1 text-sm">
|
||||||
<div className="order-1 ml-3">Key Usages</div>
|
<div className="order-1 ml-3">Key Usage</div>
|
||||||
</AccordionTrigger>
|
</AccordionTrigger>
|
||||||
<AccordionContent>
|
<AccordionContent>
|
||||||
<Controller
|
<Controller
|
||||||
@@ -404,7 +403,7 @@ export const CertificateTemplateModal = ({ popUp, handlePopUpToggle, caId }: Pro
|
|||||||
render={({ field: { onChange, value }, fieldState: { error } }) => {
|
render={({ field: { onChange, value }, fieldState: { error } }) => {
|
||||||
return (
|
return (
|
||||||
<FormControl
|
<FormControl
|
||||||
label="Key Usages"
|
label="Key Usage"
|
||||||
errorText={error?.message}
|
errorText={error?.message}
|
||||||
isError={Boolean(error)}
|
isError={Boolean(error)}
|
||||||
>
|
>
|
||||||
@@ -438,7 +437,7 @@ export const CertificateTemplateModal = ({ popUp, handlePopUpToggle, caId }: Pro
|
|||||||
render={({ field: { onChange, value }, fieldState: { error } }) => {
|
render={({ field: { onChange, value }, fieldState: { error } }) => {
|
||||||
return (
|
return (
|
||||||
<FormControl
|
<FormControl
|
||||||
label="Extended Key Usages"
|
label="Extended Key Usage"
|
||||||
errorText={error?.message}
|
errorText={error?.message}
|
||||||
isError={Boolean(error)}
|
isError={Boolean(error)}
|
||||||
>
|
>
|
||||||
|
|||||||
Reference in New Issue
Block a user