mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 12:26:38 +00:00
Check more for the CSR
This commit is contained in:
@@ -31,6 +31,12 @@ import { getProjectKmsCertificateKeyId } from "@app/services/project/project-fns
|
|||||||
import { getConfig } from "@app/lib/config/env";
|
import { getConfig } from "@app/lib/config/env";
|
||||||
import { TCertificateAuthorityDALFactory } from "@app/services/certificate-authority/certificate-authority-dal";
|
import { TCertificateAuthorityDALFactory } from "@app/services/certificate-authority/certificate-authority-dal";
|
||||||
import { CaType } from "@app/services/certificate-authority/certificate-authority-enums";
|
import { CaType } from "@app/services/certificate-authority/certificate-authority-enums";
|
||||||
|
import { extractCertificateRequestFromCSR } from "@app/services/certificate-common/certificate-csr-utils";
|
||||||
|
import {
|
||||||
|
CertExtendedKeyUsage,
|
||||||
|
CertKeyUsage,
|
||||||
|
CertSubjectAlternativeNameType
|
||||||
|
} from "@app/services/certificate/certificate-types";
|
||||||
import { TPkiAcmeAccountDALFactory } from "./pki-acme-account-dal";
|
import { TPkiAcmeAccountDALFactory } from "./pki-acme-account-dal";
|
||||||
import { TPkiAcmeAuthDALFactory } from "./pki-acme-auth-dal";
|
import { TPkiAcmeAuthDALFactory } from "./pki-acme-auth-dal";
|
||||||
import { TPkiAcmeChallengeDALFactory } from "./pki-acme-challenge-dal";
|
import { TPkiAcmeChallengeDALFactory } from "./pki-acme-challenge-dal";
|
||||||
@@ -641,7 +647,40 @@ export const pkiAcmeServiceFactory = ({
|
|||||||
if (finalizingOrder.expiresAt < new Date()) {
|
if (finalizingOrder.expiresAt < new Date()) {
|
||||||
throw new AcmeOrderNotReadyError({ message: "ACME order has expired" });
|
throw new AcmeOrderNotReadyError({ message: "ACME order has expired" });
|
||||||
}
|
}
|
||||||
|
|
||||||
const { csr } = payload;
|
const { csr } = payload;
|
||||||
|
|
||||||
|
// Check and validate the CSR
|
||||||
|
const certificateRequest = extractCertificateRequestFromCSR(csr);
|
||||||
|
if (!certificateRequest.commonName) {
|
||||||
|
throw new AcmeBadCSRError({ detail: "Invalid CSR: Common name is required" });
|
||||||
|
}
|
||||||
|
if (
|
||||||
|
certificateRequest.subjectAlternativeNames?.some(
|
||||||
|
(san) => san.type !== CertSubjectAlternativeNameType.DNS_NAME
|
||||||
|
)
|
||||||
|
) {
|
||||||
|
throw new AcmeBadCSRError({ detail: "Invalid CSR: Only DNS subject alternative names are supported" });
|
||||||
|
}
|
||||||
|
const orderWithAuthorizations = (await acmeOrderDAL.findByAccountAndOrderIdWithAuthorizations(
|
||||||
|
accountId,
|
||||||
|
orderId,
|
||||||
|
tx
|
||||||
|
))!;
|
||||||
|
const csrIdentifierValues = new Set(
|
||||||
|
orderWithAuthorizations.authorizations
|
||||||
|
.map((auth) => auth.identifierValue.toLowerCase())
|
||||||
|
.concat([certificateRequest.commonName!.toLowerCase()])
|
||||||
|
);
|
||||||
|
if (
|
||||||
|
csrIdentifierValues.size !== orderWithAuthorizations.authorizations.length ||
|
||||||
|
!orderWithAuthorizations.authorizations.every((auth) =>
|
||||||
|
csrIdentifierValues.has(auth.identifierValue.toLowerCase())
|
||||||
|
)
|
||||||
|
) {
|
||||||
|
throw new AcmeBadCSRError({ detail: "Invalid CSR: Common name + SANs mismatch with order identifiers" });
|
||||||
|
}
|
||||||
|
|
||||||
const ca = await certificateAuthorityDAL.findByIdWithAssociatedCa(profile.caId);
|
const ca = await certificateAuthorityDAL.findByIdWithAssociatedCa(profile.caId);
|
||||||
if (!ca) {
|
if (!ca) {
|
||||||
throw new NotFoundError({ message: "Certificate Authority not found" });
|
throw new NotFoundError({ message: "Certificate Authority not found" });
|
||||||
@@ -672,16 +711,15 @@ export const pkiAcmeServiceFactory = ({
|
|||||||
});
|
});
|
||||||
return { certificateId: result.certificateId };
|
return { certificateId: result.certificateId };
|
||||||
} else {
|
} else {
|
||||||
const orderWithAuthorizations = (await acmeOrderDAL.findByAccountAndOrderIdWithAuthorizations(
|
const { certificateAuthority } = (await certificateProfileDAL.findByIdWithConfigs(profileId, tx))!;
|
||||||
accountId,
|
const cert = await acmeCertificateAuthorityFns.orderCertificate({
|
||||||
orderId,
|
caId: certificateAuthority.id,
|
||||||
tx
|
commonName: certificateRequest.commonName,
|
||||||
))!;
|
altNames: certificateRequest.subjectAlternativeNames?.map((san) => san.value),
|
||||||
const result = await orderCertificateForAcmeProfile(
|
keyUsages: [CertKeyUsage.DIGITAL_SIGNATURE, CertKeyUsage.KEY_ENCIPHERMENT, CertKeyUsage.KEY_AGREEMENT],
|
||||||
profileId,
|
extendedKeyUsages: [CertExtendedKeyUsage.SERVER_AUTH]
|
||||||
orderWithAuthorizations.authorizations[0].identifierValue
|
});
|
||||||
);
|
return { certificateId: cert.id };
|
||||||
return { certificateId: result };
|
|
||||||
}
|
}
|
||||||
})();
|
})();
|
||||||
await acmeOrderDAL.updateById(
|
await acmeOrderDAL.updateById(
|
||||||
|
|||||||
@@ -168,15 +168,12 @@ export const certificateProfileDALFactory = (db: TDbClient) => {
|
|||||||
} as TCertificateProfileWithConfigs["acmeConfig"])
|
} as TCertificateProfileWithConfigs["acmeConfig"])
|
||||||
: undefined;
|
: undefined;
|
||||||
|
|
||||||
const certificateAuthority =
|
const certificateAuthority = {
|
||||||
result.caId && result.caProjectId && result.caStatus && result.caName
|
id: result.caId,
|
||||||
? ({
|
projectId: result.caProjectId,
|
||||||
id: result.caId,
|
status: result.caStatus,
|
||||||
projectId: result.caProjectId,
|
name: result.caName
|
||||||
status: result.caStatus,
|
} as TCertificateProfileWithConfigs["certificateAuthority"];
|
||||||
name: result.caName
|
|
||||||
} as TCertificateProfileWithConfigs["certificateAuthority"])
|
|
||||||
: undefined;
|
|
||||||
|
|
||||||
const certificateTemplate =
|
const certificateTemplate =
|
||||||
result.templateId && result.templateProjectId && result.templateName
|
result.templateId && result.templateProjectId && result.templateName
|
||||||
|
|||||||
Reference in New Issue
Block a user