Ashley Davis
|
68f5ceb3b4
|
Fix manually specified Certificate and CertificateRequest versions
Basically all modern X.509 certs are version 3, but confusingly to
specify "version 3" in an encoded cert, the version number is actually
2.
For PKCS#10 CSRs, the only valid version is 1, which again
confusingly has the value "0" when encoded.
This was incorrect in many places, including one place in which the
version number on a CSR was used as a certificate's version number,
when the two are entirely unrelated.
Go ignores these values, so there's no functional changes here; still,
it's better to be accurate.
Go ignoring CSR version and specifying 0:
https://cs.opensource.google/go/go/+/refs/tags/go1.17:src/crypto/x509/x509.go;l=1958
Go ignoring Certificate version and specifying 2:
https://cs.opensource.google/go/go/+/refs/tags/go1.17:src/crypto/x509/x509.go;l=1534
PKCS#10 CSR specification in RFC 2986 section 4.1:
https://datatracker.ietf.org/doc/html/rfc2986#section-4
X.509 Cert specification in RFC 5280 section 4.1.2.1:
https://datatracker.ietf.org/doc/html/rfc5280#section-4.1.2.1
Signed-off-by: Ashley Davis <ashley.davis@jetstack.io>
|
2021-08-19 14:48:12 +01:00 |
|
irbekrm
|
ddf7e130b7
|
Allow users to specify which annotations should be copied from Certificate to CertificateRequest
Default to all being copied except for kubectl, fluxcd, argocd annotations
Signed-off-by: irbekrm <irbekrm@gmail.com>
|
2021-07-26 20:00:10 +01:00 |
|
joshvanl
|
1678d0833e
|
Reverts ACME issuer from forming a chain bundle and populating the
ca.crt
Signed-off-by: joshvanl <vleeuwenjoshua@gmail.com>
|
2021-06-02 12:21:50 +01:00 |
|
 jetstack-botandGitHub
|
efd8b7a076
|
Merge pull request #3866 from jandersen-plaid/jandersen-plaid-make-orders-unique-to-controlling-cr
Hash orders with the issuing certificate request to ensure unique hash
|
2021-05-21 17:34:25 +01:00 |
|
 
|
b5fe7ecdca
|
Update pkg/controller/certificaterequests/acme/acme.go
Co-authored-by: Ashley Davis <SgtCoDFish@users.noreply.github.com>
Signed-off-by: Jack Andersen <jandersen@plaid.com>
|
2021-05-21 12:08:22 -04:00 |
|
 
|
cd1d8a2788
|
Update pkg/controller/certificaterequests/acme/acme_test.go
Co-authored-by: Ashley Davis <SgtCoDFish@users.noreply.github.com>
Signed-off-by: Jack Andersen <jandersen@plaid.com>
|
2021-05-21 12:08:07 -04:00 |
|
 
|
ed88ce6030
|
Update pkg/controller/certificaterequests/acme/acme_test.go
Co-authored-by: Ashley Davis <SgtCoDFish@users.noreply.github.com>
Signed-off-by: Jack Andersen <jandersen@plaid.com>
|
2021-05-21 12:07:40 -04:00 |
|
irbekrm
|
881fb2ddea
|
Make tests fail if controller registration fail
Part of work towards fixing errors discovered by static analysis tools
Signed-off-by: irbekrm <irbekrm@gmail.com>
|
2021-05-19 10:16:59 +01:00 |
|
Jack Andersen
|
b48e9664a6
|
Only use the new hash on certificate request names > 52 chars
Signed-off-by: Jack Andersen <jandersen@plaid.com>
|
2021-05-18 09:08:30 -04:00 |
|
 jetstack-botandGitHub
|
22ff380f39
|
Merge pull request #3984 from JoshVanL/parse-certificate-chain-acme
Parse certificate chain acme
|
2021-05-13 13:50:14 +01:00 |
|
joshvanl
|
58a25314f7
|
Changes CR CA controller to use ECDSA keys
Signed-off-by: joshvanl <vleeuwenjoshua@gmail.com>
|
2021-05-12 15:07:25 +01:00 |
|
joshvanl
|
ea2cfdc3c9
|
Updates CA issuer to updates SignCSRTemplate and propagate CA
certificate down
Signed-off-by: joshvanl <vleeuwenjoshua@gmail.com>
|
2021-05-12 14:22:59 +01:00 |
|
joshvanl
|
e4d3d3f725
|
Change ParseCertificateChain to ParseSingleCertificateChain
Signed-off-by: joshvanl <vleeuwenjoshua@gmail.com>
|
2021-05-12 14:17:41 +01:00 |
|
joshvanl
|
33fcf0d082
|
Uses ParseCertificateChainPEM for ACME Order Response
Signed-off-by: joshvanl <vleeuwenjoshua@gmail.com>
|
2021-05-12 14:17:02 +01:00 |
|
Jake Sanders
|
196e42c221
|
Tidy godoc comments
Signed-off-by: Jake Sanders <i@am.so-aweso.me>
|
2021-05-05 16:21:24 +01:00 |
|
Jake Sanders
|
f194d9b732
|
Add godoc comments
Signed-off-by: Jake Sanders <i@am.so-aweso.me>
|
2021-05-05 15:59:02 +01:00 |
|
joshvanl
|
e05adbf06b
|
Remove expected events when Ready Denied condition set
Signed-off-by: joshvanl <vleeuwenjoshua@gmail.com>
|
2021-04-09 18:20:07 +01:00 |
|
joshvanl
|
50a84eaf1d
|
Sets the Ready condition to False when a request is Denied
Signed-off-by: joshvanl <vleeuwenjoshua@gmail.com>
|
2021-04-09 15:34:32 +01:00 |
|
Jack Andersen
|
ceab5f1b15
|
Adjust comment to reflect what the hash applies to
Signed-off-by: Jack Andersen <jandersen@plaid.com>
|
2021-04-07 10:37:11 -04:00 |
|
Jack Andersen
|
6fc20a7055
|
Hash orders with the issuing certificate request to ensure unique hash
Signed-off-by: Jack Andersen <jandersen@plaid.com>
|
2021-04-07 10:27:47 -04:00 |
|
joshvanl
|
18ae2295f9
|
Pass context through to client calls in controllers and acme issuer
Signed-off-by: joshvanl <vleeuwenjoshua@gmail.com>
|
2021-03-31 20:34:12 +01:00 |
|
joshvanl
|
32d0c5af4e
|
Updates Approved/Denied tests for new reasons
Signed-off-by: joshvanl <vleeuwenjoshua@gmail.com>
|
2021-03-17 13:10:39 +00:00 |
|
joshvanl
|
a3e63b1787
|
Update CertificateRequest controllers to use new Denied type, and add
tests for when a CertificateRequest is denied
Signed-off-by: joshvanl <vleeuwenjoshua@gmail.com>
|
2021-03-17 13:10:39 +00:00 |
|
joshvanl
|
e62e8c517b
|
Updates CertificateRequest signer tests to check Approved behaviour
Signed-off-by: joshvanl <vleeuwenjoshua@gmail.com>
|
2021-03-17 13:10:39 +00:00 |
|
 jetstack-botandGitHub
|
70c66e02a0
|
Merge pull request #3641 from JoshVanL/certificate-request-identity
CertificateRequest UserInfo fields
|
2021-03-15 14:26:15 +00:00 |
|
Lars Lehtonen
|
0270377f6c
|
pkg/controller/certificaterequests/acme: fix dropped test error
Signed-off-by: Lars Lehtonen <lars.lehtonen@gmail.com>
|
2021-02-23 18:13:37 -08:00 |
|
joshvanl
|
235adea826
|
Remove CertificateRequest validation in CertificateRequest controllers
as this happens at admission time.
Signed-off-by: joshvanl <vleeuwenjoshua@gmail.com>
|
2021-02-08 19:20:57 +00:00 |
|
Richard Wall
|
27d0f011be
|
Delete Order if its certificate data is bad or unexpected
Signed-off-by: Richard Wall <richard.wall@jetstack.io>
|
2020-12-15 13:46:52 +00:00 |
|
Richard Wall
|
fb01c3b3c2
|
Tests for handling of Orders with bad certificates
* Badly formed certificates, and
* certificates with an unexpected public key.
Signed-off-by: Richard Wall <richard.wall@jetstack.io>
|
2020-12-15 13:44:59 +00:00 |
|
Richard Wall
|
98e2f1c8f3
|
Wait for order-controller to add certificate data to the Order
Signed-off-by: Richard Wall <richard.wall@jetstack.io>
|
2020-12-15 10:22:38 +00:00 |
|
Richard Wall
|
02883417ee
|
Re-organise the handling of non-failed but not-yet-valid Orders
Exit early in this case and move the happy case to the end of the function.
Signed-off-by: Richard Wall <richard.wall@jetstack.io>
|
2020-12-15 10:22:38 +00:00 |
|
Maartje Eyskens
|
ab0cd57dc5
|
Use The cert-manager Authors.
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
|
2020-12-11 19:04:13 +01:00 |
|
Maartje Eyskens
|
1788a9d758
|
Update copyright to cert-manager project
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
|
2020-12-08 19:04:49 +01:00 |
|
Maartje Eyskens
|
d705838e83
|
Implement feedback
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
|
2020-11-20 09:46:49 +01:00 |
|
Maartje Eyskens
|
66f787ef33
|
Fix a lost EnableNotAfterDate
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
|
2020-11-20 09:46:49 +01:00 |
|
Maartje Eyskens
|
04d88479e4
|
Pass duration on until ACME order creation
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
|
2020-11-20 09:46:49 +01:00 |
|
Maartje Eyskens
|
1b33e8029a
|
Fix unit tests
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
|
2020-11-20 09:46:08 +01:00 |
|
Maartje Eyskens
|
7b6573aa35
|
Add duration into ACME
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
|
2020-11-20 09:45:32 +01:00 |
|
Maartje Eyskens
|
d8023a79d0
|
Fix error format
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
|
2020-10-08 15:24:56 +02:00 |
|
Maartje Eyskens
|
542b329914
|
Implement feedback
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
|
2020-10-08 15:24:56 +02:00 |
|
Maartje Eyskens
|
1cbfe49938
|
Fix CN check for IPs as well as add tests
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
|
2020-10-08 15:24:56 +02:00 |
|
Maartje Eyskens
|
58b462eef9
|
Fix nil in spec
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
|
2020-10-08 15:24:56 +02:00 |
|
Maartje Eyskens
|
39de7f3b99
|
Fix IP type
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
|
2020-10-08 15:24:56 +02:00 |
|
Maartje Eyskens
|
b3e25815a5
|
Add support for IPs in ACME
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
|
2020-10-08 15:24:56 +02:00 |
|
 
|
9d0a1b136e
|
Update pkg/controller/certificaterequests/acme/acme.go
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
Co-authored-by: Richard Wall <wallrj@users.noreply.github.com>
|
2020-09-01 15:05:48 +02:00 |
|
Maartje Eyskens
|
6756856e82
|
Nil out request in spec again for order
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
|
2020-08-31 10:08:54 +02:00 |
|
Maartje Eyskens
|
f1c6c93df5
|
Fix CR and make a general function
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
|
2020-08-28 15:06:54 +02:00 |
|
Maartje Eyskens
|
69186afbdd
|
Move logic to utils
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
|
2020-08-28 09:59:48 +02:00 |
|
Maartje Eyskens
|
bb89b50c8f
|
Fix invalid DNS-1123 on ACME computed names
Signed-off-by: Maartje Eyskens <maartje@eyskens.me>
|
2020-08-28 09:54:18 +02:00 |
|
Richard Wall
|
821d824cc2
|
Revert renaming of CSR > Request in comments and in error messages
Signed-off-by: Richard Wall <richard.wall@jetstack.io>
|
2020-08-20 14:28:07 +01:00 |
|