fix: custom private key validation

This commit is contained in:
Fu Diwei
2025-11-04 10:53:59 +08:00
parent fc9c52f722
commit 781deac79f
2 changed files with 36 additions and 10 deletions
+8 -8
View File
@@ -237,20 +237,20 @@ func (s *CertificateService) ValidatePrivateKey(ctx context.Context, req *dtos.C
return nil, err
}
var keyAlgorithmString string
keyAlgorithm, keySize, _ := xcryptokey.GetPrivateKeyAlgorithm(privkey)
switch keyAlgorithm {
var keyAlgorithm string
privkeyAlg, privkeySize, _ := xcryptokey.GetPrivateKeyAlgorithm(privkey)
switch privkeyAlg {
case x509.RSA:
keyAlgorithmString = fmt.Sprintf("RSA%d", keySize)
keyAlgorithm = fmt.Sprintf("RSA%d", privkeySize)
case x509.ECDSA:
keyAlgorithmString = fmt.Sprintf("EC%d", keySize)
keyAlgorithm = fmt.Sprintf("EC%d", privkeySize)
case x509.Ed25519:
keyAlgorithmString = "ED25519"
keyAlgorithm = "ED25519"
}
return &dtos.CertificateValidatePrivateKeyResp{
IsValid: keyAlgorithmString != "",
KeyAlgorithm: keyAlgorithmString,
IsValid: true,
KeyAlgorithm: keyAlgorithm,
}, nil
}
+28 -2
View File
@@ -1,6 +1,7 @@
package engine
import (
"crypto/x509"
"fmt"
"log/slog"
"maps"
@@ -22,6 +23,7 @@ import (
"github.com/certimate-go/certimate/internal/repository"
"github.com/certimate-go/certimate/internal/tools/mproc"
xcert "github.com/certimate-go/certimate/pkg/utils/cert"
xcryptokey "github.com/certimate-go/certimate/pkg/utils/crypto/key"
)
var useMultiProc = true
@@ -215,8 +217,32 @@ func (ne *bizApplyNodeExecutor) executeObtain(execCtx *NodeExecutionContext, nod
if err != nil {
return nil, err
} else {
if nodeCfg.KeySource == BizApplyKeySourceReuse && lastCertificate != nil {
legoKeyType, _ = lastCertificate.KeyAlgorithm.KeyType()
switch nodeCfg.KeySource {
case BizApplyKeySourceAuto:
break
case BizApplyKeySourceReuse:
if lastCertificate != nil {
legoKeyType, _ = lastCertificate.KeyAlgorithm.KeyType()
}
case BizApplyKeySourceCustom:
privkey, err := xcert.ParsePrivateKeyFromPEM(nodeCfg.KeyContent)
if err != nil {
return nil, fmt.Errorf("could not parse custom private key: %w", err)
} else {
privkeyAlg, privkeySize, _ := xcryptokey.GetPrivateKeyAlgorithm(privkey)
switch privkeyAlg {
case x509.RSA:
if nodeCfg.KeyAlgorithm != fmt.Sprintf("RSA%d", privkeySize) {
return nil, fmt.Errorf("could not parse custom private key: unsupported algorithm or key size")
}
case x509.ECDSA:
if nodeCfg.KeyAlgorithm != fmt.Sprintf("EC%d", privkeySize) {
return nil, fmt.Errorf("could not parse custom private key: unsupported algorithm or key size")
}
default:
return nil, fmt.Errorf("could not parse custom private key: unsupported algorithm")
}
}
}
}