From e9f50554814c41b8f9e1a38c2120293d99deffb3 Mon Sep 17 00:00:00 2001 From: Julius Mieliauskas Date: Tue, 5 Aug 2025 20:19:17 +0300 Subject: [PATCH] fixed SAN extension field in certificate issuance --- .../internal-certificate-authority-service.ts | 20 +++++++++++++++++-- 1 file changed, 18 insertions(+), 2 deletions(-) diff --git a/backend/src/services/certificate-authority/internal/internal-certificate-authority-service.ts b/backend/src/services/certificate-authority/internal/internal-certificate-authority-service.ts index dd30cc62e..4d54f79bf 100644 --- a/backend/src/services/certificate-authority/internal/internal-certificate-authority-service.ts +++ b/backend/src/services/certificate-authority/internal/internal-certificate-authority-service.ts @@ -1365,7 +1365,7 @@ export const internalCertificateAuthorityServiceFactory = ({ } let altNamesArray: { - type: "email" | "dns"; + type: "email" | "dns" | "url" | "ip"; value: string; }[] = []; @@ -1390,6 +1390,14 @@ export const internalCertificateAuthorityServiceFactory = ({ }; } + if (z.string().url().safeParse(altName).success) { + return { type: "url", value: altName }; + } + + if (z.string().ip().safeParse(altName).success) { + return { type: "ip", value: altName }; + } + // If altName is neither a valid email nor a valid hostname, throw an error or handle it accordingly throw new Error(`Invalid altName: ${altName}`); }); @@ -1767,7 +1775,7 @@ export const internalCertificateAuthorityServiceFactory = ({ let altNamesFromCsr: string = ""; let altNamesArray: { - type: "email" | "dns"; + type: "email" | "dns" | "url" | "ip"; value: string; }[] = []; if (altNames) { @@ -1791,6 +1799,14 @@ export const internalCertificateAuthorityServiceFactory = ({ }; } + if (z.string().url().safeParse(altName).success) { + return { type: "url", value: altName }; + } + + if (z.string().ip().safeParse(altName).success) { + return { type: "ip", value: altName }; + } + // If altName is neither a valid email nor a valid hostname, throw an error or handle it accordingly throw new Error(`Invalid altName: ${altName}`); });