mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 13:28:27 +00:00
Handle external ca
# Conflicts: # backend/src/ee/services/pki-acme/pki-acme-service.ts # Conflicts: # backend/src/ee/services/pki-acme/pki-acme-service.ts
This commit is contained in:
@@ -29,7 +29,8 @@ import { TProjectDALFactory } from "@app/services/project/project-dal";
|
|||||||
import { getProjectKmsCertificateKeyId } from "@app/services/project/project-fns";
|
import { getProjectKmsCertificateKeyId } from "@app/services/project/project-fns";
|
||||||
|
|
||||||
import { getConfig } from "@app/lib/config/env";
|
import { getConfig } from "@app/lib/config/env";
|
||||||
import { TLicenseServiceFactory } from "../license/license-service";
|
import { TCertificateAuthorityDALFactory } from "@app/services/certificate-authority/certificate-authority-dal";
|
||||||
|
import { CaType } from "@app/services/certificate-authority/certificate-authority-enums";
|
||||||
import { TPkiAcmeAccountDALFactory } from "./pki-acme-account-dal";
|
import { TPkiAcmeAccountDALFactory } from "./pki-acme-account-dal";
|
||||||
import { TPkiAcmeAuthDALFactory } from "./pki-acme-auth-dal";
|
import { TPkiAcmeAuthDALFactory } from "./pki-acme-auth-dal";
|
||||||
import { TPkiAcmeChallengeDALFactory } from "./pki-acme-challenge-dal";
|
import { TPkiAcmeChallengeDALFactory } from "./pki-acme-challenge-dal";
|
||||||
@@ -80,6 +81,7 @@ import {
|
|||||||
|
|
||||||
type TPkiAcmeServiceFactoryDep = {
|
type TPkiAcmeServiceFactoryDep = {
|
||||||
projectDAL: Pick<TProjectDALFactory, "findOne" | "updateById" | "transaction">;
|
projectDAL: Pick<TProjectDALFactory, "findOne" | "updateById" | "transaction">;
|
||||||
|
certificateAuthorityDAL: Pick<TCertificateAuthorityDALFactory, "findByIdWithAssociatedCa">;
|
||||||
certificateProfileDAL: Pick<TCertificateProfileDALFactory, "findByIdWithOwnerOrgId" | "findByIdWithConfigs">;
|
certificateProfileDAL: Pick<TCertificateProfileDALFactory, "findByIdWithOwnerOrgId" | "findByIdWithConfigs">;
|
||||||
certificateBodyDAL: Pick<TCertificateBodyDALFactory, "findOne">;
|
certificateBodyDAL: Pick<TCertificateBodyDALFactory, "findOne">;
|
||||||
acmeAccountDAL: Pick<
|
acmeAccountDAL: Pick<
|
||||||
@@ -110,6 +112,7 @@ type TPkiAcmeServiceFactoryDep = {
|
|||||||
|
|
||||||
export const pkiAcmeServiceFactory = ({
|
export const pkiAcmeServiceFactory = ({
|
||||||
projectDAL,
|
projectDAL,
|
||||||
|
certificateAuthorityDAL,
|
||||||
certificateProfileDAL,
|
certificateProfileDAL,
|
||||||
certificateBodyDAL,
|
certificateBodyDAL,
|
||||||
acmeAccountDAL,
|
acmeAccountDAL,
|
||||||
@@ -622,6 +625,7 @@ export const pkiAcmeServiceFactory = ({
|
|||||||
orderId: string;
|
orderId: string;
|
||||||
payload: TFinalizeAcmeOrderPayload;
|
payload: TFinalizeAcmeOrderPayload;
|
||||||
}): Promise<TAcmeResponse<TAcmeOrderResource>> => {
|
}): Promise<TAcmeResponse<TAcmeOrderResource>> => {
|
||||||
|
const profile = (await certificateProfileDAL.findByIdWithConfigs(profileId))!;
|
||||||
let order = await acmeOrderDAL.findByAccountAndOrderIdWithAuthorizations(accountId, orderId);
|
let order = await acmeOrderDAL.findByAccountAndOrderIdWithAuthorizations(accountId, orderId);
|
||||||
if (!order) {
|
if (!order) {
|
||||||
throw new NotFoundError({ message: "ACME order not found" });
|
throw new NotFoundError({ message: "ACME order not found" });
|
||||||
@@ -638,28 +642,48 @@ export const pkiAcmeServiceFactory = ({
|
|||||||
throw new AcmeOrderNotReadyError({ message: "ACME order has expired" });
|
throw new AcmeOrderNotReadyError({ message: "ACME order has expired" });
|
||||||
}
|
}
|
||||||
const { csr } = payload;
|
const { csr } = payload;
|
||||||
|
const ca = await certificateAuthorityDAL.findByIdWithAssociatedCa(profile.caId);
|
||||||
|
if (!ca) {
|
||||||
|
throw new NotFoundError({ message: "Certificate Authority not found" });
|
||||||
|
}
|
||||||
|
const caType = (ca.externalCa?.type as CaType) ?? CaType.INTERNAL;
|
||||||
let errorToReturn: Error | undefined;
|
let errorToReturn: Error | undefined;
|
||||||
try {
|
try {
|
||||||
const { certificateId } = await certificateV3Service.signCertificateFromProfile({
|
const { certificateId } = await (async () => {
|
||||||
actor: ActorType.ACME_ACCOUNT,
|
if (caType === CaType.INTERNAL) {
|
||||||
actorId: accountId,
|
const result = await certificateV3Service.signCertificateFromProfile({
|
||||||
actorAuthMethod: null,
|
actor: ActorType.ACME_ACCOUNT,
|
||||||
actorOrgId,
|
actorId: accountId,
|
||||||
profileId,
|
actorAuthMethod: null,
|
||||||
csr,
|
actorOrgId,
|
||||||
notBefore: finalizingOrder.notBefore ? new Date(finalizingOrder.notBefore) : undefined,
|
profileId,
|
||||||
notAfter: finalizingOrder.notAfter ? new Date(finalizingOrder.notAfter) : undefined,
|
csr,
|
||||||
validity: !finalizingOrder.notAfter
|
notBefore: finalizingOrder.notBefore ? new Date(finalizingOrder.notBefore) : undefined,
|
||||||
? {
|
notAfter: finalizingOrder.notAfter ? new Date(finalizingOrder.notAfter) : undefined,
|
||||||
// 47 days, the default TTL comes with Let's Encrypt
|
validity: !finalizingOrder.notAfter
|
||||||
// TODO: read config from the profile to get the expiration time instead
|
? {
|
||||||
ttl: `${47}d`
|
// 47 days, the default TTL comes with Let's Encrypt
|
||||||
}
|
// TODO: read config from the profile to get the expiration time instead
|
||||||
: // ttl is not used if notAfter is provided
|
ttl: `${47}d`
|
||||||
({ ttl: "0d" } as const),
|
}
|
||||||
enrollmentType: EnrollmentType.ACME
|
: // ttl is not used if notAfter is provided
|
||||||
});
|
({ ttl: "0d" } as const),
|
||||||
// TODO: associate the certificate with the order
|
enrollmentType: EnrollmentType.ACME
|
||||||
|
});
|
||||||
|
return { certificateId: result.certificateId };
|
||||||
|
} else {
|
||||||
|
const orderWithAuthorizations = (await acmeOrderDAL.findByAccountAndOrderIdWithAuthorizations(
|
||||||
|
accountId,
|
||||||
|
orderId,
|
||||||
|
tx
|
||||||
|
))!;
|
||||||
|
const result = await orderCertificateForAcmeProfile(
|
||||||
|
profileId,
|
||||||
|
orderWithAuthorizations.authorizations[0].identifierValue
|
||||||
|
);
|
||||||
|
return { certificateId: result };
|
||||||
|
}
|
||||||
|
})();
|
||||||
await acmeOrderDAL.updateById(
|
await acmeOrderDAL.updateById(
|
||||||
orderId,
|
orderId,
|
||||||
{
|
{
|
||||||
|
|||||||
Reference in New Issue
Block a user