diff --git a/backend/bdd/features/pki/acme/nonce.feature b/backend/bdd/features/pki/acme/nonce.feature index 5475b9cfd..5ae3ab1f8 100644 --- a/backend/bdd/features/pki/acme/nonce.feature +++ b/backend/bdd/features/pki/acme/nonce.feature @@ -6,18 +6,28 @@ Feature: Nonce Then the response status code should be "200" Then the response header "Replay-Nonce" should contains non-empty value - Scenario: Send a bad nonce + Scenario Outline: Send a bad nonce to account endpoints Given I have an ACME cert profile as "acme_profile" When I have an ACME client connecting to {BASE_URL}/api/v1/pki/acme/profiles/{acme_profile.id}/directory Then I register a new ACME account with email fangpen@infisical.com and EAB key id "{acme_profile.eab_kid}" with secret "{acme_profile.eab_secret}" as acme_account Then I memorize acme_account.uri with jq "capture("/(?[^/]+)$") | .id" as account_id - When I send a raw ACME request to "/api/v1/pki/acme/profiles/{acme_profile.id}/accounts/{account_id}/orders" + When I create certificate signing request as csr + Then I add names to certificate signing request csr + """ + { + "COMMON_NAME": "localhost" + } + """ + Then I create a RSA private key pair as cert_key + Then I sign the certificate signing request csr with private key cert_key and output it as csr_pem in PEM format + Then I submit the certificate signing request PEM csr_pem certificate order to the ACME server as order + When I send a raw ACME request to "" """ { "protected": { "alg": "RS256", "nonce": "oFvnlFP1wIhRlYS2jTaXbA", - "url": "{BASE_URL}/api/v1/pki/acme/profiles/{acme_profile.id}/accounts/{account_id}/orders", + "url": "", "kid": "{acme_account.uri}" }, "payload": {} @@ -28,6 +38,12 @@ Feature: Nonce Then the value response with jq ".status" should be equal to 400 Then the value response with jq ".detail" should be equal to "Invalid nonce" + Examples: Endpoints + | path | + | {BASE_URL}/api/v1/pki/acme/profiles/{acme_profile.id}/accounts/{account_id}/orders | + | {BASE_URL}/api/v1/pki/acme/profiles/{acme_profile.id}/new-order | + | {order.uri} | + Scenario: Send the same nonce twice Given I have an ACME cert profile as "acme_profile" When I have an ACME client connecting to {BASE_URL}/api/v1/pki/acme/profiles/{acme_profile.id}/directory