mirror of
https://github.com/certimate-go/certimate.git
synced 2026-09-24 23:10:13 +08:00
fix: custom private key validation
This commit is contained in:
@@ -237,20 +237,20 @@ func (s *CertificateService) ValidatePrivateKey(ctx context.Context, req *dtos.C
|
||||
return nil, err
|
||||
}
|
||||
|
||||
var keyAlgorithmString string
|
||||
keyAlgorithm, keySize, _ := xcryptokey.GetPrivateKeyAlgorithm(privkey)
|
||||
switch keyAlgorithm {
|
||||
var keyAlgorithm string
|
||||
privkeyAlg, privkeySize, _ := xcryptokey.GetPrivateKeyAlgorithm(privkey)
|
||||
switch privkeyAlg {
|
||||
case x509.RSA:
|
||||
keyAlgorithmString = fmt.Sprintf("RSA%d", keySize)
|
||||
keyAlgorithm = fmt.Sprintf("RSA%d", privkeySize)
|
||||
case x509.ECDSA:
|
||||
keyAlgorithmString = fmt.Sprintf("EC%d", keySize)
|
||||
keyAlgorithm = fmt.Sprintf("EC%d", privkeySize)
|
||||
case x509.Ed25519:
|
||||
keyAlgorithmString = "ED25519"
|
||||
keyAlgorithm = "ED25519"
|
||||
}
|
||||
|
||||
return &dtos.CertificateValidatePrivateKeyResp{
|
||||
IsValid: keyAlgorithmString != "",
|
||||
KeyAlgorithm: keyAlgorithmString,
|
||||
IsValid: true,
|
||||
KeyAlgorithm: keyAlgorithm,
|
||||
}, nil
|
||||
}
|
||||
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
package engine
|
||||
|
||||
import (
|
||||
"crypto/x509"
|
||||
"fmt"
|
||||
"log/slog"
|
||||
"maps"
|
||||
@@ -22,6 +23,7 @@ import (
|
||||
"github.com/certimate-go/certimate/internal/repository"
|
||||
"github.com/certimate-go/certimate/internal/tools/mproc"
|
||||
xcert "github.com/certimate-go/certimate/pkg/utils/cert"
|
||||
xcryptokey "github.com/certimate-go/certimate/pkg/utils/crypto/key"
|
||||
)
|
||||
|
||||
var useMultiProc = true
|
||||
@@ -215,8 +217,32 @@ func (ne *bizApplyNodeExecutor) executeObtain(execCtx *NodeExecutionContext, nod
|
||||
if err != nil {
|
||||
return nil, err
|
||||
} else {
|
||||
if nodeCfg.KeySource == BizApplyKeySourceReuse && lastCertificate != nil {
|
||||
legoKeyType, _ = lastCertificate.KeyAlgorithm.KeyType()
|
||||
switch nodeCfg.KeySource {
|
||||
case BizApplyKeySourceAuto:
|
||||
break
|
||||
case BizApplyKeySourceReuse:
|
||||
if lastCertificate != nil {
|
||||
legoKeyType, _ = lastCertificate.KeyAlgorithm.KeyType()
|
||||
}
|
||||
case BizApplyKeySourceCustom:
|
||||
privkey, err := xcert.ParsePrivateKeyFromPEM(nodeCfg.KeyContent)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("could not parse custom private key: %w", err)
|
||||
} else {
|
||||
privkeyAlg, privkeySize, _ := xcryptokey.GetPrivateKeyAlgorithm(privkey)
|
||||
switch privkeyAlg {
|
||||
case x509.RSA:
|
||||
if nodeCfg.KeyAlgorithm != fmt.Sprintf("RSA%d", privkeySize) {
|
||||
return nil, fmt.Errorf("could not parse custom private key: unsupported algorithm or key size")
|
||||
}
|
||||
case x509.ECDSA:
|
||||
if nodeCfg.KeyAlgorithm != fmt.Sprintf("EC%d", privkeySize) {
|
||||
return nil, fmt.Errorf("could not parse custom private key: unsupported algorithm or key size")
|
||||
}
|
||||
default:
|
||||
return nil, fmt.Errorf("could not parse custom private key: unsupported algorithm")
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user