Handle external ca

# Conflicts:
#	backend/src/ee/services/pki-acme/pki-acme-service.ts

# Conflicts:
#	backend/src/ee/services/pki-acme/pki-acme-service.ts
This commit is contained in:
Fang-Pen Lin
2025-11-13 09:21:30 -08:00
parent 731a0d5cd0
commit d559d48e7e
@@ -29,7 +29,8 @@ import { TProjectDALFactory } from "@app/services/project/project-dal";
import { getProjectKmsCertificateKeyId } from "@app/services/project/project-fns"; import { getProjectKmsCertificateKeyId } from "@app/services/project/project-fns";
import { getConfig } from "@app/lib/config/env"; import { getConfig } from "@app/lib/config/env";
import { TLicenseServiceFactory } from "../license/license-service"; import { TCertificateAuthorityDALFactory } from "@app/services/certificate-authority/certificate-authority-dal";
import { CaType } from "@app/services/certificate-authority/certificate-authority-enums";
import { TPkiAcmeAccountDALFactory } from "./pki-acme-account-dal"; import { TPkiAcmeAccountDALFactory } from "./pki-acme-account-dal";
import { TPkiAcmeAuthDALFactory } from "./pki-acme-auth-dal"; import { TPkiAcmeAuthDALFactory } from "./pki-acme-auth-dal";
import { TPkiAcmeChallengeDALFactory } from "./pki-acme-challenge-dal"; import { TPkiAcmeChallengeDALFactory } from "./pki-acme-challenge-dal";
@@ -80,6 +81,7 @@ import {
type TPkiAcmeServiceFactoryDep = { type TPkiAcmeServiceFactoryDep = {
projectDAL: Pick<TProjectDALFactory, "findOne" | "updateById" | "transaction">; projectDAL: Pick<TProjectDALFactory, "findOne" | "updateById" | "transaction">;
certificateAuthorityDAL: Pick<TCertificateAuthorityDALFactory, "findByIdWithAssociatedCa">;
certificateProfileDAL: Pick<TCertificateProfileDALFactory, "findByIdWithOwnerOrgId" | "findByIdWithConfigs">; certificateProfileDAL: Pick<TCertificateProfileDALFactory, "findByIdWithOwnerOrgId" | "findByIdWithConfigs">;
certificateBodyDAL: Pick<TCertificateBodyDALFactory, "findOne">; certificateBodyDAL: Pick<TCertificateBodyDALFactory, "findOne">;
acmeAccountDAL: Pick< acmeAccountDAL: Pick<
@@ -110,6 +112,7 @@ type TPkiAcmeServiceFactoryDep = {
export const pkiAcmeServiceFactory = ({ export const pkiAcmeServiceFactory = ({
projectDAL, projectDAL,
certificateAuthorityDAL,
certificateProfileDAL, certificateProfileDAL,
certificateBodyDAL, certificateBodyDAL,
acmeAccountDAL, acmeAccountDAL,
@@ -622,6 +625,7 @@ export const pkiAcmeServiceFactory = ({
orderId: string; orderId: string;
payload: TFinalizeAcmeOrderPayload; payload: TFinalizeAcmeOrderPayload;
}): Promise<TAcmeResponse<TAcmeOrderResource>> => { }): Promise<TAcmeResponse<TAcmeOrderResource>> => {
const profile = (await certificateProfileDAL.findByIdWithConfigs(profileId))!;
let order = await acmeOrderDAL.findByAccountAndOrderIdWithAuthorizations(accountId, orderId); let order = await acmeOrderDAL.findByAccountAndOrderIdWithAuthorizations(accountId, orderId);
if (!order) { if (!order) {
throw new NotFoundError({ message: "ACME order not found" }); throw new NotFoundError({ message: "ACME order not found" });
@@ -638,9 +642,16 @@ export const pkiAcmeServiceFactory = ({
throw new AcmeOrderNotReadyError({ message: "ACME order has expired" }); throw new AcmeOrderNotReadyError({ message: "ACME order has expired" });
} }
const { csr } = payload; const { csr } = payload;
const ca = await certificateAuthorityDAL.findByIdWithAssociatedCa(profile.caId);
if (!ca) {
throw new NotFoundError({ message: "Certificate Authority not found" });
}
const caType = (ca.externalCa?.type as CaType) ?? CaType.INTERNAL;
let errorToReturn: Error | undefined; let errorToReturn: Error | undefined;
try { try {
const { certificateId } = await certificateV3Service.signCertificateFromProfile({ const { certificateId } = await (async () => {
if (caType === CaType.INTERNAL) {
const result = await certificateV3Service.signCertificateFromProfile({
actor: ActorType.ACME_ACCOUNT, actor: ActorType.ACME_ACCOUNT,
actorId: accountId, actorId: accountId,
actorAuthMethod: null, actorAuthMethod: null,
@@ -659,7 +670,20 @@ export const pkiAcmeServiceFactory = ({
({ ttl: "0d" } as const), ({ ttl: "0d" } as const),
enrollmentType: EnrollmentType.ACME enrollmentType: EnrollmentType.ACME
}); });
// TODO: associate the certificate with the order return { certificateId: result.certificateId };
} else {
const orderWithAuthorizations = (await acmeOrderDAL.findByAccountAndOrderIdWithAuthorizations(
accountId,
orderId,
tx
))!;
const result = await orderCertificateForAcmeProfile(
profileId,
orderWithAuthorizations.authorizations[0].identifierValue
);
return { certificateId: result };
}
})();
await acmeOrderDAL.updateById( await acmeOrderDAL.updateById(
orderId, orderId,
{ {