Merge pull request #3877 from irbekrm/move_crypto_fork

Use upstream golang/crypto for ACME EAB + move crypto fork to cert-manager org
This commit is contained in:
jetstack-bot
2021-04-13 13:28:15 +01:00
committed by GitHub
17 changed files with 216 additions and 56 deletions
+35
View File
@@ -14131,6 +14131,41 @@ OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
================================================================================
================================================================================
= vendor/golang.org/x/term licensed under: =
Copyright (c) 2009 The Go Authors. All rights reserved.
Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions are
met:
* Redistributions of source code must retain the above copyright
notice, this list of conditions and the following disclaimer.
* Redistributions in binary form must reproduce the above
copyright notice, this list of conditions and the following disclaimer
in the documentation and/or other materials provided with the
distribution.
* Neither the name of Google Inc. nor the names of its
contributors may be used to endorse or promote products derived from
this software without specific prior written permission.
THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
= vendor/golang.org/x/term/LICENSE 5d4950ecb7b26d2c5e4e7b4e0dd74707
================================================================================
================================================================================
= vendor/golang.org/x/text licensed under: =
+4 -8
View File
@@ -84,12 +84,11 @@ spec:
description: ExternalAccountBinding is a reference to a CA external account of the ACME server. If set, upon registration cert-manager will attempt to associate the given external account credentials with the registered ACME account.
type: object
required:
- keyAlgorithm
- keyID
- keySecretRef
properties:
keyAlgorithm:
description: keyAlgorithm is the MAC key algorithm that the key is used for. Valid values are "HS256", "HS384" and "HS512".
description: 'Deprecated: keyAlgorithm field exists for historical compatibility reasons and should not be used. The algorithm is now hardcoded to HS256 in golang/x/crypto/acme.'
type: string
enum:
- HS256
@@ -1122,12 +1121,11 @@ spec:
description: ExternalAccountBinding is a reference to a CA external account of the ACME server. If set, upon registration cert-manager will attempt to associate the given external account credentials with the registered ACME account.
type: object
required:
- keyAlgorithm
- keyID
- keySecretRef
properties:
keyAlgorithm:
description: keyAlgorithm is the MAC key algorithm that the key is used for. Valid values are "HS256", "HS384" and "HS512".
description: 'Deprecated: keyAlgorithm field exists for historical compatibility reasons and should not be used. The algorithm is now hardcoded to HS256 in golang/x/crypto/acme.'
type: string
enum:
- HS256
@@ -2162,12 +2160,11 @@ spec:
description: ExternalAccountBinding is a reference to a CA external account of the ACME server. If set, upon registration cert-manager will attempt to associate the given external account credentials with the registered ACME account.
type: object
required:
- keyAlgorithm
- keyID
- keySecretRef
properties:
keyAlgorithm:
description: keyAlgorithm is the MAC key algorithm that the key is used for. Valid values are "HS256", "HS384" and "HS512".
description: 'Deprecated: keyAlgorithm field exists for historical compatibility reasons and should not be used. The algorithm is now hardcoded to HS256 in golang/x/crypto/acme.'
type: string
enum:
- HS256
@@ -3202,12 +3199,11 @@ spec:
description: ExternalAccountBinding is a reference to a CA external account of the ACME server. If set, upon registration cert-manager will attempt to associate the given external account credentials with the registered ACME account.
type: object
required:
- keyAlgorithm
- keyID
- keySecretRef
properties:
keyAlgorithm:
description: keyAlgorithm is the MAC key algorithm that the key is used for. Valid values are "HS256", "HS384" and "HS512".
description: 'Deprecated: keyAlgorithm field exists for historical compatibility reasons and should not be used. The algorithm is now hardcoded to HS256 in golang/x/crypto/acme.'
type: string
enum:
- HS256
+4 -8
View File
@@ -84,12 +84,11 @@ spec:
description: ExternalAccountBinding is a reference to a CA external account of the ACME server. If set, upon registration cert-manager will attempt to associate the given external account credentials with the registered ACME account.
type: object
required:
- keyAlgorithm
- keyID
- keySecretRef
properties:
keyAlgorithm:
description: keyAlgorithm is the MAC key algorithm that the key is used for. Valid values are "HS256", "HS384" and "HS512".
description: 'Deprecated: keyAlgorithm field exists for historical compatibility reasons and should not be used. The algorithm is now hardcoded to HS256 in golang/x/crypto/acme.'
type: string
enum:
- HS256
@@ -1122,12 +1121,11 @@ spec:
description: ExternalAccountBinding is a reference to a CA external account of the ACME server. If set, upon registration cert-manager will attempt to associate the given external account credentials with the registered ACME account.
type: object
required:
- keyAlgorithm
- keyID
- keySecretRef
properties:
keyAlgorithm:
description: keyAlgorithm is the MAC key algorithm that the key is used for. Valid values are "HS256", "HS384" and "HS512".
description: 'Deprecated: keyAlgorithm field exists for historical compatibility reasons and should not be used. The algorithm is now hardcoded to HS256 in golang/x/crypto/acme.'
type: string
enum:
- HS256
@@ -2162,12 +2160,11 @@ spec:
description: ExternalAccountBinding is a reference to a CA external account of the ACME server. If set, upon registration cert-manager will attempt to associate the given external account credentials with the registered ACME account.
type: object
required:
- keyAlgorithm
- keyID
- keySecretRef
properties:
keyAlgorithm:
description: keyAlgorithm is the MAC key algorithm that the key is used for. Valid values are "HS256", "HS384" and "HS512".
description: 'Deprecated: keyAlgorithm field exists for historical compatibility reasons and should not be used. The algorithm is now hardcoded to HS256 in golang/x/crypto/acme.'
type: string
enum:
- HS256
@@ -3202,12 +3199,11 @@ spec:
description: ExternalAccountBinding is a reference to a CA external account of the ACME server. If set, upon registration cert-manager will attempt to associate the given external account credentials with the registered ACME account.
type: object
required:
- keyAlgorithm
- keyID
- keySecretRef
properties:
keyAlgorithm:
description: keyAlgorithm is the MAC key algorithm that the key is used for. Valid values are "HS256", "HS384" and "HS512".
description: 'Deprecated: keyAlgorithm field exists for historical compatibility reasons and should not be used. The algorithm is now hardcoded to HS256 in golang/x/crypto/acme.'
type: string
enum:
- HS256
+3 -3
View File
@@ -3,8 +3,8 @@ module github.com/jetstack/cert-manager
go 1.16
// this if a fork to add EAB and alternative chains in ACME
// to be replaced after https://github.com/golang/crypto/pull/109 merges
replace golang.org/x/crypto => github.com/meyskens/crypto v0.0.0-20200821143559-6ca9aec645f0
// to be replaced after https://go-review.googlesource.com/c/crypto/+/277294/ merges
replace golang.org/x/crypto => github.com/cert-manager/crypto v0.0.0-20210409161129-d4c19753215a
require (
github.com/Azure/azure-sdk-for-go v46.3.0+incompatible
@@ -40,7 +40,7 @@ require (
github.com/spf13/pflag v1.0.5
github.com/stretchr/testify v1.6.1
golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9
golang.org/x/net v0.0.0-20200822124328-c89045814202
golang.org/x/net v0.0.0-20210226172049-e18ecbb05110
golang.org/x/oauth2 v0.0.0-20200107190931-bf48bf16ab8d
golang.org/x/sync v0.0.0-20190911185100-cd5d95a43a6e
google.golang.org/api v0.15.0
+8 -4
View File
@@ -106,6 +106,8 @@ github.com/blang/semver v3.5.0+incompatible h1:CGxCgetQ64DKk7rdZ++Vfnb1+ogGNnB17
github.com/blang/semver v3.5.0+incompatible/go.mod h1:kRBLl5iJ+tD4TcOOxsy/0fnwebNt5EWlYSAyrTnjyyk=
github.com/census-instrumentation/opencensus-proto v0.2.1 h1:glEXhBS5PSLLv4IXzLA5yPRVX4bilULVyxxbrfOtDAk=
github.com/census-instrumentation/opencensus-proto v0.2.1/go.mod h1:f6KPmirojxKA12rnyqOA5BBL4O983OfeGPqjHWSTneU=
github.com/cert-manager/crypto v0.0.0-20210409161129-d4c19753215a h1:HXp46OGPFPV7He+NPxUbCgEDCBL56R7BkQRGWEkznVQ=
github.com/cert-manager/crypto v0.0.0-20210409161129-d4c19753215a/go.mod h1:T9bdIzuCu7OtxOm1hfPfRQxPLYneinmdGuTeoZ9dtd4=
github.com/cespare/xxhash v1.1.0 h1:a6HrQnmkObjyL+Gs60czilIUGqrzKutQD6XZog3p+ko=
github.com/cespare/xxhash v1.1.0/go.mod h1:XrSqR1VqqWfGrhpAt58auRo0WTKS1nRRg3ghfAqPWnc=
github.com/cespare/xxhash/v2 v2.1.1 h1:6MnRN8NT7+YBpUIWxHtefFZOKTAPgGjpQSxqLNn0+qY=
@@ -512,8 +514,6 @@ github.com/mattn/go-runewidth v0.0.7/go.mod h1:H031xJmbD/WCDINGzjvQ9THkh0rPKHF+m
github.com/matttproud/golang_protobuf_extensions v1.0.1/go.mod h1:D8He9yQNgCq6Z5Ld7szi9bcBfOoFv/3dc6xSMkL2PC0=
github.com/matttproud/golang_protobuf_extensions v1.0.2-0.20181231171920-c182affec369 h1:I0XW9+e1XWDxdcEniV4rQAIOPUGDq67JSCiRCgGCZLI=
github.com/matttproud/golang_protobuf_extensions v1.0.2-0.20181231171920-c182affec369/go.mod h1:BSXmuO+STAnVfrANrmjBb36TMTDstsz7MSK+HVaYKv4=
github.com/meyskens/crypto v0.0.0-20200821143559-6ca9aec645f0 h1:09XQpCKCNW3zrjz4zvD/cYU3hqUEWW+bZrBwK8NwFW0=
github.com/meyskens/crypto v0.0.0-20200821143559-6ca9aec645f0/go.mod h1:ihkquczjM7M0cZsn7H1TJ3ACXW1rCuAMKX9lZEWNU3U=
github.com/miekg/dns v1.0.14/go.mod h1:W1PPwlIAgtquWBMBEV9nkV9Cazfe8ScdGz/Lj7v3Nrg=
github.com/miekg/dns v1.1.31 h1:sJFOl9BgwbYAWOGEwr61FU28pqsBNdpRBnhGXtO06Oo=
github.com/miekg/dns v1.1.31/go.mod h1:KNUDUusw/aVsxyTYZM1oqvCicbwhgbNgztCETuNZ7xM=
@@ -796,8 +796,9 @@ golang.org/x/net v0.0.0-20200226121028-0de0cce0169b/go.mod h1:z5CRVTTTmAJ677TzLL
golang.org/x/net v0.0.0-20200324143707-d3edc9973b7e/go.mod h1:qpuaurCH72eLCgpAm/N6yyVIVM9cpaDIP3A8BGJEC5A=
golang.org/x/net v0.0.0-20200520004742-59133d7f0dd7/go.mod h1:qpuaurCH72eLCgpAm/N6yyVIVM9cpaDIP3A8BGJEC5A=
golang.org/x/net v0.0.0-20200707034311-ab3426394381/go.mod h1:/O7V0waA8r7cgGh81Ro3o1hOxt32SMVPicZroKQ2sZA=
golang.org/x/net v0.0.0-20200822124328-c89045814202 h1:VvcQYSHwXgi7W+TpUR6A9g6Up98WAHf3f/ulnJ62IyA=
golang.org/x/net v0.0.0-20200822124328-c89045814202/go.mod h1:/O7V0waA8r7cgGh81Ro3o1hOxt32SMVPicZroKQ2sZA=
golang.org/x/net v0.0.0-20210226172049-e18ecbb05110 h1:qWPm9rbaAMKs8Bq/9LRpbMqxWRVUAQwMI9fVrssnTfw=
golang.org/x/net v0.0.0-20210226172049-e18ecbb05110/go.mod h1:m0MpNAwzfU5UDzcl9v0D8zg8gWTRqZa9RBIspLL5mdg=
golang.org/x/oauth2 v0.0.0-20180821212333-d2e6202438be/go.mod h1:N/0e6XlmueqKjAGxoOufVs8QHGRruUQn6yWY3a++T0U=
golang.org/x/oauth2 v0.0.0-20190226205417-e64efc72b421/go.mod h1:gOpvHmFTYa4IltrdGE7lF6nIHvwfUNPOp7c8zoXwtLw=
golang.org/x/oauth2 v0.0.0-20190604053449-0f29369cfe45/go.mod h1:gOpvHmFTYa4IltrdGE7lF6nIHvwfUNPOp7c8zoXwtLw=
@@ -848,8 +849,11 @@ golang.org/x/sys v0.0.0-20200202164722-d101bd2416d5/go.mod h1:h1NjWce9XRLGQEsW7w
golang.org/x/sys v0.0.0-20200302150141-5c8b2ff67527/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20200323222414-85ca7c5b95cd/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20200615200032-f1bc736245b1/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20200622214017-ed371f2e16b4 h1:5/PjkGUjvEU5Gl6BxmvKRPpqo2uNMv4rcHBMwzk/st8=
golang.org/x/sys v0.0.0-20200622214017-ed371f2e16b4/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20201119102817-f84b799fce68 h1:nxC68pudNYkKU6jWhgrqdreuFiOQWj1Fs7T3VrH4Pjw=
golang.org/x/sys v0.0.0-20201119102817-f84b799fce68/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1 h1:v+OssWQX+hTHEmOBgwxdZxK4zHq3yOs8F9J7mk0PY8E=
golang.org/x/term v0.0.0-20201126162022-7de9c90e9dd1/go.mod h1:bj7SfCRtBDWHUb9snDiAeCFNEtKQo2Wmx5Cou7ajbmo=
golang.org/x/text v0.0.0-20160726164857-2910a502d2bf/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
golang.org/x/text v0.3.1-0.20171227012246-e19ae1496984/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
+16 -7
View File
@@ -3380,9 +3380,9 @@ def go_repositories():
build_file_generation = "on",
build_file_proto_mode = "disable",
importpath = "golang.org/x/crypto",
replace = "github.com/meyskens/crypto",
sum = "h1:09XQpCKCNW3zrjz4zvD/cYU3hqUEWW+bZrBwK8NwFW0=",
version = "v0.0.0-20200821143559-6ca9aec645f0",
replace = "github.com/cert-manager/crypto",
sum = "h1:HXp46OGPFPV7He+NPxUbCgEDCBL56R7BkQRGWEkznVQ=",
version = "v0.0.0-20210409161129-d4c19753215a",
)
go_repository(
name = "org_golang_x_exp",
@@ -3430,8 +3430,8 @@ def go_repositories():
build_file_generation = "on",
build_file_proto_mode = "disable",
importpath = "golang.org/x/net",
sum = "h1:VvcQYSHwXgi7W+TpUR6A9g6Up98WAHf3f/ulnJ62IyA=",
version = "v0.0.0-20200822124328-c89045814202",
sum = "h1:qWPm9rbaAMKs8Bq/9LRpbMqxWRVUAQwMI9fVrssnTfw=",
version = "v0.0.0-20210226172049-e18ecbb05110",
)
go_repository(
name = "org_golang_x_oauth2",
@@ -3454,9 +3454,18 @@ def go_repositories():
build_file_generation = "on",
build_file_proto_mode = "disable",
importpath = "golang.org/x/sys",
sum = "h1:5/PjkGUjvEU5Gl6BxmvKRPpqo2uNMv4rcHBMwzk/st8=",
version = "v0.0.0-20200622214017-ed371f2e16b4",
sum = "h1:nxC68pudNYkKU6jWhgrqdreuFiOQWj1Fs7T3VrH4Pjw=",
version = "v0.0.0-20201119102817-f84b799fce68",
)
go_repository(
name = "org_golang_x_term",
build_file_generation = "on",
build_file_proto_mode = "disable",
importpath = "golang.org/x/term",
sum = "h1:v+OssWQX+hTHEmOBgwxdZxK4zHq3yOs8F9J7mk0PY8E=",
version = "v0.0.0-20201126162022-7de9c90e9dd1",
)
go_repository(
name = "org_golang_x_text",
build_file_generation = "on",
+5 -3
View File
@@ -118,9 +118,11 @@ type ACMEExternalAccountBinding struct {
// encoded data.
Key cmmeta.SecretKeySelector `json:"keySecretRef"`
// keyAlgorithm is the MAC key algorithm that the key is used for.
// Valid values are "HS256", "HS384" and "HS512".
KeyAlgorithm HMACKeyAlgorithm `json:"keyAlgorithm"`
// Deprecated: keyAlgorithm field exists for historical compatibility
// reasons and should not be used. The algorithm is now hardcoded to HS256
// in golang/x/crypto/acme.
// +optional
KeyAlgorithm HMACKeyAlgorithm `json:"keyAlgorithm,omitempty"`
}
// HMACKeyAlgorithm is the name of a key algorithm used for HMAC encryption
+5 -3
View File
@@ -118,9 +118,11 @@ type ACMEExternalAccountBinding struct {
// encoded data.
Key cmmeta.SecretKeySelector `json:"keySecretRef"`
// keyAlgorithm is the MAC key algorithm that the key is used for.
// Valid values are "HS256", "HS384" and "HS512".
KeyAlgorithm HMACKeyAlgorithm `json:"keyAlgorithm"`
// Deprecated: keyAlgorithm field exists for historical compatibility
// reasons and should not be used. The algorithm is now hardcoded to HS256
// in golang/x/crypto/acme.
// +optional
KeyAlgorithm HMACKeyAlgorithm `json:"keyAlgorithm,omitempty"`
}
// HMACKeyAlgorithm is the name of a key algorithm used for HMAC encryption
+5 -3
View File
@@ -118,9 +118,11 @@ type ACMEExternalAccountBinding struct {
// encoded data.
Key cmmeta.SecretKeySelector `json:"keySecretRef"`
// keyAlgorithm is the MAC key algorithm that the key is used for.
// Valid values are "HS256", "HS384" and "HS512".
KeyAlgorithm HMACKeyAlgorithm `json:"keyAlgorithm"`
// Deprecated: keyAlgorithm field exists for historical compatibility
// reasons and should not be used. The algorithm is now hardcoded to HS256
// in golang/x/crypto/acme.
// +optional
KeyAlgorithm HMACKeyAlgorithm `json:"keyAlgorithm,omitempty"`
}
// HMACKeyAlgorithm is the name of a key algorithm used for HMAC encryption
+5 -3
View File
@@ -118,9 +118,11 @@ type ACMEExternalAccountBinding struct {
// encoded data.
Key cmmeta.SecretKeySelector `json:"keySecretRef"`
// keyAlgorithm is the MAC key algorithm that the key is used for.
// Valid values are "HS256", "HS384" and "HS512".
KeyAlgorithm HMACKeyAlgorithm `json:"keyAlgorithm"`
// Deprecated: keyAlgorithm field exists for historical compatibility
// reasons and should not be used. The algorithm is now hardcoded to HS256
// in golang/x/crypto/acme.
// +optional
KeyAlgorithm HMACKeyAlgorithm `json:"keyAlgorithm,omitempty"`
}
// HMACKeyAlgorithm is the name of a key algorithm used for HMAC encryption
+4 -2
View File
@@ -108,8 +108,10 @@ type ACMEExternalAccountBinding struct {
// encoded data.
Key cmmeta.SecretKeySelector
// keyAlgorithm is the MAC key algorithm that the key is used for.
// Valid values are "HS256", "HS384" and "HS512".
// Deprecated: keyAlgorithm exists for historical compatibility reasons and
// should not be used. golang/x/crypto/acme hardcodes the algorithm to HS256
// so setting this field will have no effect.
// See https://github.com/jetstack/cert-manager/issues/3220#issuecomment-809438314
KeyAlgorithm HMACKeyAlgorithm
}
@@ -32,7 +32,7 @@ import (
cmmeta "github.com/jetstack/cert-manager/pkg/internal/apis/meta"
)
// Validation functions for cert-manager v1alpha2 Issuer types
// Validation functions for cert-manager Issuer types.
func ValidateIssuer(_ *admissionv1.AdmissionRequest, obj runtime.Object) field.ErrorList {
iss := obj.(*certmanager.Issuer)
@@ -116,10 +116,6 @@ func ValidateACMEIssuerConfig(iss *cmacme.ACMEIssuer, fldPath *field.Path) field
}
el = append(el, ValidateSecretKeySelector(&eab.Key, eabFldPath.Child("keySecretRef"))...)
if len(eab.KeyAlgorithm) == 0 {
el = append(el, field.Required(eabFldPath.Child("keyAlgorithm"), "the keyAlgorithm field is required when using externalAccountBinding"))
}
}
for i, sol := range iss.Solvers {
@@ -146,7 +146,7 @@ func TestValidateACMEIssuerConfig(t *testing.T) {
},
},
},
"acme solver with empty external account binding fields": {
"acme solver with external account binding missing required fields": {
spec: &cmacme.ACMEIssuer{
Email: "valid-email",
Server: "valid-server",
@@ -164,7 +164,43 @@ func TestValidateACMEIssuerConfig(t *testing.T) {
field.Required(fldPath.Child("externalAccountBinding.keyID"), "the keyID field is required when using externalAccountBinding"),
field.Required(fldPath.Child("externalAccountBinding.keySecretRef.name"), "secret name is required"),
field.Required(fldPath.Child("externalAccountBinding.keySecretRef.key"), "secret key is required"),
field.Required(fldPath.Child("externalAccountBinding.keyAlgorithm"), "the keyAlgorithm field is required when using externalAccountBinding"),
},
},
"acme solver with a valid external account binding and keyAlgorithm not set": {
spec: &cmacme.ACMEIssuer{
Email: "valid-email",
Server: "valid-server",
PrivateKey: validSecretKeyRef,
ExternalAccountBinding: &cmacme.ACMEExternalAccountBinding{
KeyID: "test",
Key: validSecretKeyRef,
},
Solvers: []cmacme.ACMEChallengeSolver{
{
DNS01: &cmacme.ACMEChallengeSolverDNS01{
CloudDNS: &validCloudDNSProvider,
},
},
},
},
},
"acme solver with a valid external account binding and keyAlgorithm set": {
spec: &cmacme.ACMEIssuer{
Email: "valid-email",
Server: "valid-server",
PrivateKey: validSecretKeyRef,
ExternalAccountBinding: &cmacme.ACMEExternalAccountBinding{
KeyID: "test",
Key: validSecretKeyRef,
KeyAlgorithm: cmacme.HS384,
},
Solvers: []cmacme.ACMEChallengeSolver{
{
DNS01: &cmacme.ACMEChallengeSolverDNS01{
CloudDNS: &validCloudDNSProvider,
},
},
},
},
},
"acme solver with missing http01 config type": {
+2 -3
View File
@@ -204,9 +204,8 @@ func (a *Acme) Setup(ctx context.Context) error {
// set the external account binding
eabAccount = &acmeapi.ExternalAccountBinding{
KID: eabObj.KeyID,
Key: eabKey,
KeyAlgorithm: string(eabObj.KeyAlgorithm),
KID: eabObj.KeyID,
Key: eabKey,
}
}
@@ -39,8 +39,7 @@ var _ = framework.ConformanceDescribe("Certificates", func() {
})
var _ = framework.ConformanceDescribe("Certificates with External Account Binding", func() {
runACMEIssuerTests(&cmacme.ACMEExternalAccountBinding{
KeyID: "kid-1",
KeyAlgorithm: "HS256",
KeyID: "kid-1",
})
})
+3
View File
@@ -10,6 +10,8 @@ go_library(
tags = ["manual"],
visibility = ["//visibility:public"],
deps = [
"//pkg/api/util:go_default_library",
"//pkg/apis/acme/v1:go_default_library",
"//pkg/apis/certmanager/v1:go_default_library",
"//pkg/apis/meta/v1:go_default_library",
"//test/e2e/framework:go_default_library",
@@ -20,6 +22,7 @@ go_library(
"@com_github_onsi_ginkgo//:go_default_library",
"@com_github_onsi_gomega//:go_default_library",
"@io_k8s_apimachinery//pkg/apis/meta/v1:go_default_library",
"@io_k8s_apimachinery//pkg/util/wait:go_default_library",
],
)
+77
View File
@@ -18,12 +18,18 @@ package acme
import (
"context"
"encoding/base64"
"errors"
"fmt"
"time"
. "github.com/onsi/ginkgo"
. "github.com/onsi/gomega"
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
"k8s.io/apimachinery/pkg/util/wait"
apiutil "github.com/jetstack/cert-manager/pkg/api/util"
cmacme "github.com/jetstack/cert-manager/pkg/apis/acme/v1"
v1 "github.com/jetstack/cert-manager/pkg/apis/certmanager/v1"
cmmeta "github.com/jetstack/cert-manager/pkg/apis/meta/v1"
"github.com/jetstack/cert-manager/test/e2e/framework"
@@ -267,4 +273,75 @@ var _ = framework.CertManagerDescribe("ACME Issuer", func() {
})
Expect(err).NotTo(HaveOccurred())
})
It("ACME account with External Account Binding", func() {
By("providing the legacy keyAlgorithm value")
var (
secretName = "test-secret"
keyID = "kid-1"
key = "kid-secret-1"
)
keyBytes := []byte(base64.RawURLEncoding.EncodeToString([]byte(key)))
s := gen.Secret(secretName,
gen.SetSecretNamespace(f.Namespace.Name),
gen.SetSecretData(map[string][]byte{
"key": keyBytes,
}))
_, err := f.KubeClientSet.CoreV1().Secrets(f.Namespace.Name).Create(context.TODO(), s, metav1.CreateOptions{})
Expect(err).NotTo(HaveOccurred())
acmeIssuer := gen.Issuer(issuerName,
gen.SetIssuerNamespace(f.Namespace.Name),
gen.SetIssuerACMEEmail(testingACMEEmail),
gen.SetIssuerACMEURL(f.Config.Addons.ACMEServer.URL),
gen.SetIssuerACMESkipTLSVerify(true),
gen.SetIssuerACMEPrivKeyRef(testingACMEPrivateKey),
gen.SetIssuerACMEEABWithKeyAlgorithm(keyID, secretName, cmacme.HS256))
acmeIssuer, err = f.CertManagerClientSet.CertmanagerV1().Issuers(f.Namespace.Name).Create(
context.TODO(), acmeIssuer, metav1.CreateOptions{})
Expect(err).NotTo(HaveOccurred())
err = util.WaitForIssuerCondition(f.CertManagerClientSet.CertmanagerV1().Issuers(f.Namespace.Name),
acmeIssuer.Name,
v1.IssuerCondition{
Type: v1.IssuerConditionReady,
Status: cmmeta.ConditionTrue,
})
Expect(err).NotTo(HaveOccurred())
By("removing the legacy keyAlgorithm value")
acmeIssuer, err = f.CertManagerClientSet.CertmanagerV1().Issuers(f.Namespace.Name).Get(context.TODO(), acmeIssuer.Name, metav1.GetOptions{})
Expect(err).NotTo(HaveOccurred())
acmeIssuer = gen.IssuerFrom(acmeIssuer,
gen.SetIssuerACMEEAB(keyID, secretName))
_, err = f.CertManagerClientSet.CertmanagerV1().Issuers(f.Namespace.Name).Update(context.TODO(), acmeIssuer, metav1.UpdateOptions{})
Expect(err).NotTo(HaveOccurred())
// TODO: we should use observedGeneration here, but currently it won't
// be incremented correctly in this scenario.
// Verify that Issuer's Ready condition remains True for 5 seconds.
err = wait.Poll(time.Millisecond*200, time.Second*5, func() (bool, error) {
iss, err := f.CertManagerClientSet.CertmanagerV1().Issuers(f.Namespace.Name).Get(
context.TODO(), issuerName, metav1.GetOptions{})
if err != nil {
return false, err
}
if !apiutil.IssuerHasCondition(iss, v1.IssuerCondition{
Type: v1.IssuerConditionReady,
Status: cmmeta.ConditionTrue,
}) {
return false, errors.New("expected Ready condition to be true, got false")
}
// keep polling
return false, nil
})
Expect(err).To(HaveOccurred())
Expect(err).To(MatchError(wait.ErrWaitTimeout))
})
})