diff --git a/internal/certificate/service.go b/internal/certificate/service.go index bdd14080d..54e52ba53 100644 --- a/internal/certificate/service.go +++ b/internal/certificate/service.go @@ -237,20 +237,20 @@ func (s *CertificateService) ValidatePrivateKey(ctx context.Context, req *dtos.C return nil, err } - var keyAlgorithmString string - keyAlgorithm, keySize, _ := xcryptokey.GetPrivateKeyAlgorithm(privkey) - switch keyAlgorithm { + var keyAlgorithm string + privkeyAlg, privkeySize, _ := xcryptokey.GetPrivateKeyAlgorithm(privkey) + switch privkeyAlg { case x509.RSA: - keyAlgorithmString = fmt.Sprintf("RSA%d", keySize) + keyAlgorithm = fmt.Sprintf("RSA%d", privkeySize) case x509.ECDSA: - keyAlgorithmString = fmt.Sprintf("EC%d", keySize) + keyAlgorithm = fmt.Sprintf("EC%d", privkeySize) case x509.Ed25519: - keyAlgorithmString = "ED25519" + keyAlgorithm = "ED25519" } return &dtos.CertificateValidatePrivateKeyResp{ - IsValid: keyAlgorithmString != "", - KeyAlgorithm: keyAlgorithmString, + IsValid: true, + KeyAlgorithm: keyAlgorithm, }, nil } diff --git a/internal/workflow/engine/executor_bizapply.go b/internal/workflow/engine/executor_bizapply.go index 297f8505e..89a260f1d 100644 --- a/internal/workflow/engine/executor_bizapply.go +++ b/internal/workflow/engine/executor_bizapply.go @@ -1,6 +1,7 @@ package engine import ( + "crypto/x509" "fmt" "log/slog" "maps" @@ -22,6 +23,7 @@ import ( "github.com/certimate-go/certimate/internal/repository" "github.com/certimate-go/certimate/internal/tools/mproc" xcert "github.com/certimate-go/certimate/pkg/utils/cert" + xcryptokey "github.com/certimate-go/certimate/pkg/utils/crypto/key" ) var useMultiProc = true @@ -215,8 +217,32 @@ func (ne *bizApplyNodeExecutor) executeObtain(execCtx *NodeExecutionContext, nod if err != nil { return nil, err } else { - if nodeCfg.KeySource == BizApplyKeySourceReuse && lastCertificate != nil { - legoKeyType, _ = lastCertificate.KeyAlgorithm.KeyType() + switch nodeCfg.KeySource { + case BizApplyKeySourceAuto: + break + case BizApplyKeySourceReuse: + if lastCertificate != nil { + legoKeyType, _ = lastCertificate.KeyAlgorithm.KeyType() + } + case BizApplyKeySourceCustom: + privkey, err := xcert.ParsePrivateKeyFromPEM(nodeCfg.KeyContent) + if err != nil { + return nil, fmt.Errorf("could not parse custom private key: %w", err) + } else { + privkeyAlg, privkeySize, _ := xcryptokey.GetPrivateKeyAlgorithm(privkey) + switch privkeyAlg { + case x509.RSA: + if nodeCfg.KeyAlgorithm != fmt.Sprintf("RSA%d", privkeySize) { + return nil, fmt.Errorf("could not parse custom private key: unsupported algorithm or key size") + } + case x509.ECDSA: + if nodeCfg.KeyAlgorithm != fmt.Sprintf("EC%d", privkeySize) { + return nil, fmt.Errorf("could not parse custom private key: unsupported algorithm or key size") + } + default: + return nil, fmt.Errorf("could not parse custom private key: unsupported algorithm") + } + } } }