diff --git a/pkg/core/deployer/providers/1panel/1panel.go b/pkg/core/deployer/providers/1panel/1panel.go index 84119f8d9..5f04adb06 100644 --- a/pkg/core/deployer/providers/1panel/1panel.go +++ b/pkg/core/deployer/providers/1panel/1panel.go @@ -14,7 +14,7 @@ import ( "github.com/certimate-go/certimate/pkg/core/deployer" onepanelsdk "github.com/certimate-go/certimate/pkg/sdk3rd/1panel" onepanelsdk2 "github.com/certimate-go/certimate/pkg/sdk3rd/1panel/v2" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" + xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" xwait "github.com/certimate-go/certimate/pkg/utils/wait" ) @@ -196,11 +196,6 @@ func (d *Deployer) deployToCertificate(ctx context.Context, certPEM, privkeyPEM func (d *Deployer) getMatchedWebsiteIdsByCertificate(ctx context.Context, certPEM string) ([]int64, error) { var websiteIds []int64 - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - switch sdkClient := d.sdkClient.(type) { case *onepanelsdk.Client: { @@ -229,7 +224,7 @@ func (d *Deployer) getMatchedWebsiteIdsByCertificate(ctx context.Context, certPE } for _, websiteItem := range websiteSearchResp.Data.Items { - if certX509.VerifyHostname(websiteItem.PrimaryDomain) != nil { + if !xcerthostname.IsMatchByCertificatePEM(certPEM, websiteItem.PrimaryDomain) { continue } @@ -240,7 +235,7 @@ func (d *Deployer) getMatchedWebsiteIdsByCertificate(ctx context.Context, certPE } for _, domainInfo := range websiteGetResp.Data.Domains { - if domainInfo.SSL || certX509.VerifyHostname(domainInfo.Domain) == nil { + if domainInfo.SSL || xcerthostname.IsMatchByCertificatePEM(certPEM, domainInfo.Domain) { websiteIds = append(websiteIds, websiteItem.ID) break } @@ -283,7 +278,7 @@ func (d *Deployer) getMatchedWebsiteIdsByCertificate(ctx context.Context, certPE } for _, websiteItem := range websiteSearchResp.Data.Items { - if certX509.VerifyHostname(websiteItem.PrimaryDomain) != nil { + if !xcerthostname.IsMatchByCertificatePEM(certPEM, websiteItem.PrimaryDomain) { continue } @@ -294,7 +289,7 @@ func (d *Deployer) getMatchedWebsiteIdsByCertificate(ctx context.Context, certPE } for _, domainInfo := range websiteGetResp.Data.Domains { - if domainInfo.SSL || certX509.VerifyHostname(domainInfo.Domain) == nil { + if domainInfo.SSL || xcerthostname.IsMatchByCertificatePEM(certPEM, domainInfo.Domain) { websiteIds = append(websiteIds, websiteItem.ID) break } diff --git a/pkg/core/deployer/providers/aliyun-apigw/aliyun_apigw.go b/pkg/core/deployer/providers/aliyun-apigw/aliyun_apigw.go index 3b3abfb57..5f83f3bcc 100644 --- a/pkg/core/deployer/providers/aliyun-apigw/aliyun_apigw.go +++ b/pkg/core/deployer/providers/aliyun-apigw/aliyun_apigw.go @@ -19,7 +19,6 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aliyun-cas" "github.com/certimate-go/certimate/pkg/core/deployer" "github.com/certimate-go/certimate/pkg/core/deployer/providers/aliyun-apigw/internal" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -160,18 +159,13 @@ func (d *Deployer) deployToTraditional(ctx context.Context, certPEM, privkeyPEM case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return err - } - domainCandidates, err := d.getTraditionalAllDomainsByGroupId(ctx, d.config.GroupId) if err != nil { return err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return errors.New("could not find any domains matched by certificate") @@ -258,18 +252,13 @@ func (d *Deployer) deployToCloudNative(ctx context.Context, certPEM, privkeyPEM case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return err - } - domainCandidates, err := d.getCloudNativeAllDomainsByGatewayId(ctx, d.config.GatewayId) if err != nil { return err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/aliyun-cdn/aliyun_cdn.go b/pkg/core/deployer/providers/aliyun-cdn/aliyun_cdn.go index f8bdb2935..a2a2383f1 100644 --- a/pkg/core/deployer/providers/aliyun-cdn/aliyun_cdn.go +++ b/pkg/core/deployer/providers/aliyun-cdn/aliyun_cdn.go @@ -18,7 +18,6 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aliyun-cas" "github.com/certimate-go/certimate/pkg/core/deployer" "github.com/certimate-go/certimate/pkg/core/deployer/providers/aliyun-cdn/internal" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -121,8 +120,7 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return xcerthostname.IsMatch(d.config.Domain, domain) || - strings.TrimPrefix(d.config.Domain, "*") == strings.TrimPrefix(domain, "*") + return xcerthostname.IsMatch(d.config.Domain, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by wildcard") @@ -134,19 +132,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil || - strings.TrimPrefix(d.config.Domain, "*") == strings.TrimPrefix(domain, "*") + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/aliyun-dcdn/aliyun_dcdn.go b/pkg/core/deployer/providers/aliyun-dcdn/aliyun_dcdn.go index 9b482e975..7985d080e 100644 --- a/pkg/core/deployer/providers/aliyun-dcdn/aliyun_dcdn.go +++ b/pkg/core/deployer/providers/aliyun-dcdn/aliyun_dcdn.go @@ -18,7 +18,6 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aliyun-cas" "github.com/certimate-go/certimate/pkg/core/deployer" "github.com/certimate-go/certimate/pkg/core/deployer/providers/aliyun-dcdn/internal" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -121,8 +120,7 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return xcerthostname.IsMatch(d.config.Domain, domain) || - strings.TrimPrefix(d.config.Domain, "*") == strings.TrimPrefix(domain, "*") + return xcerthostname.IsMatch(d.config.Domain, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by wildcard") @@ -134,19 +132,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil || - strings.TrimPrefix(d.config.Domain, "*") == strings.TrimPrefix(domain, "*") + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/aliyun-ddospro/aliyun_ddospro.go b/pkg/core/deployer/providers/aliyun-ddospro/aliyun_ddospro.go index 6c3ff66ba..010617e0f 100644 --- a/pkg/core/deployer/providers/aliyun-ddospro/aliyun_ddospro.go +++ b/pkg/core/deployer/providers/aliyun-ddospro/aliyun_ddospro.go @@ -17,7 +17,6 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aliyun-cas" "github.com/certimate-go/certimate/pkg/core/deployer" "github.com/certimate-go/certimate/pkg/core/deployer/providers/aliyun-ddospro/internal" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -132,18 +131,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/aliyun-esa-saas/aliyun_esasaas.go b/pkg/core/deployer/providers/aliyun-esa-saas/aliyun_esasaas.go index 861751bcc..23b5d1125 100644 --- a/pkg/core/deployer/providers/aliyun-esa-saas/aliyun_esasaas.go +++ b/pkg/core/deployer/providers/aliyun-esa-saas/aliyun_esasaas.go @@ -18,7 +18,6 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aliyun-cas" "github.com/certimate-go/certimate/pkg/core/deployer" "github.com/certimate-go/certimate/pkg/core/deployer/providers/aliyun-esa-saas/internal" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -155,18 +154,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - hostnameCandidates, err := d.getAllHostnames(ctx) if err != nil { return nil, err } hostnames := lo.Filter(hostnameCandidates, func(hostname *aliesa.ListCustomHostnamesResponseBodyHostnames, _ int) bool { - return certX509.VerifyHostname(tea.StringValue(hostname.Hostname)) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, tea.StringValue(hostname.Hostname)) }) if len(hostnames) == 0 { return nil, errors.New("could not find any hostnames matched by certificate") diff --git a/pkg/core/deployer/providers/aliyun-fc/aliyun_fc.go b/pkg/core/deployer/providers/aliyun-fc/aliyun_fc.go index b35d6628a..09933d16d 100644 --- a/pkg/core/deployer/providers/aliyun-fc/aliyun_fc.go +++ b/pkg/core/deployer/providers/aliyun-fc/aliyun_fc.go @@ -17,7 +17,6 @@ import ( "github.com/certimate-go/certimate/pkg/core/deployer" "github.com/certimate-go/certimate/pkg/core/deployer/providers/aliyun-fc/internal" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -135,18 +134,13 @@ func (d *Deployer) deployToFC3(ctx context.Context, certPEM, privkeyPEM string) case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return err - } - domainCandidates, err := d.getFC3AllDomains(ctx) if err != nil { return err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return errors.New("could not find any domains matched by certificate") @@ -221,18 +215,13 @@ func (d *Deployer) deployToFC2(ctx context.Context, certPEM, privkeyPEM string) case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return err - } - domainCandidates, err := d.getFC2AllDomains(ctx) if err != nil { return err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/aliyun-live/aliyun_live.go b/pkg/core/deployer/providers/aliyun-live/aliyun_live.go index db0b9193e..e0adfb569 100644 --- a/pkg/core/deployer/providers/aliyun-live/aliyun_live.go +++ b/pkg/core/deployer/providers/aliyun-live/aliyun_live.go @@ -16,7 +16,6 @@ import ( "github.com/certimate-go/certimate/pkg/core/deployer" "github.com/certimate-go/certimate/pkg/core/deployer/providers/aliyun-live/internal" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -97,8 +96,7 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return xcerthostname.IsMatch(d.config.Domain, domain) || - strings.TrimPrefix(d.config.Domain, "*") == strings.TrimPrefix(domain, "*") + return xcerthostname.IsMatch(d.config.Domain, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by wildcard") @@ -110,19 +108,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil || - strings.TrimPrefix(d.config.Domain, "*") == strings.TrimPrefix(domain, "*") + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/aliyun-vod/aliyun_vod.go b/pkg/core/deployer/providers/aliyun-vod/aliyun_vod.go index dd0c8e20e..271a5c770 100644 --- a/pkg/core/deployer/providers/aliyun-vod/aliyun_vod.go +++ b/pkg/core/deployer/providers/aliyun-vod/aliyun_vod.go @@ -18,7 +18,6 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aliyun-cas" "github.com/certimate-go/certimate/pkg/core/deployer" "github.com/certimate-go/certimate/pkg/core/deployer/providers/aliyun-vod/internal" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -131,18 +130,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/baiducloud-cdn/baiducloud_cdn.go b/pkg/core/deployer/providers/baiducloud-cdn/baiducloud_cdn.go index 24379e594..895a360ef 100644 --- a/pkg/core/deployer/providers/baiducloud-cdn/baiducloud_cdn.go +++ b/pkg/core/deployer/providers/baiducloud-cdn/baiducloud_cdn.go @@ -13,7 +13,6 @@ import ( "github.com/certimate-go/certimate/pkg/core/deployer" "github.com/samber/lo" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -100,18 +99,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/ctcccloud-ao/ctcccloud_ao.go b/pkg/core/deployer/providers/ctcccloud-ao/ctcccloud_ao.go index 2f89cdb94..94ab4ad5c 100644 --- a/pkg/core/deployer/providers/ctcccloud-ao/ctcccloud_ao.go +++ b/pkg/core/deployer/providers/ctcccloud-ao/ctcccloud_ao.go @@ -14,7 +14,6 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/ctcccloud-ao" "github.com/certimate-go/certimate/pkg/core/deployer" ctyunao "github.com/certimate-go/certimate/pkg/sdk3rd/ctyun/ao" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -119,18 +118,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/ctcccloud-cdn/ctcccloud_cdn.go b/pkg/core/deployer/providers/ctcccloud-cdn/ctcccloud_cdn.go index 09560b70a..c08933008 100644 --- a/pkg/core/deployer/providers/ctcccloud-cdn/ctcccloud_cdn.go +++ b/pkg/core/deployer/providers/ctcccloud-cdn/ctcccloud_cdn.go @@ -13,7 +13,6 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/ctcccloud-cdn" "github.com/certimate-go/certimate/pkg/core/deployer" ctyuncdn "github.com/certimate-go/certimate/pkg/sdk3rd/ctyun/cdn" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -118,18 +117,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/ctcccloud-icdn/ctcccloud_icdn.go b/pkg/core/deployer/providers/ctcccloud-icdn/ctcccloud_icdn.go index 20bfb5519..e504cf8fb 100644 --- a/pkg/core/deployer/providers/ctcccloud-icdn/ctcccloud_icdn.go +++ b/pkg/core/deployer/providers/ctcccloud-icdn/ctcccloud_icdn.go @@ -13,7 +13,6 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/ctcccloud-icdn" "github.com/certimate-go/certimate/pkg/core/deployer" ctyunicdn "github.com/certimate-go/certimate/pkg/sdk3rd/ctyun/icdn" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -118,18 +117,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/ctcccloud-lvdn/ctcccloud_lvdn.go b/pkg/core/deployer/providers/ctcccloud-lvdn/ctcccloud_lvdn.go index b9bd29e42..370ed4c47 100644 --- a/pkg/core/deployer/providers/ctcccloud-lvdn/ctcccloud_lvdn.go +++ b/pkg/core/deployer/providers/ctcccloud-lvdn/ctcccloud_lvdn.go @@ -12,7 +12,7 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/ctcccloud-lvdn" "github.com/certimate-go/certimate/pkg/core/deployer" ctyunlvdn "github.com/certimate-go/certimate/pkg/sdk3rd/ctyun/lvdn" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" + xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) type DeployerConfig struct { @@ -93,18 +93,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/dogecloud-cdn/dogecloud_cdn.go b/pkg/core/deployer/providers/dogecloud-cdn/dogecloud_cdn.go index 629bc6612..3f668a792 100644 --- a/pkg/core/deployer/providers/dogecloud-cdn/dogecloud_cdn.go +++ b/pkg/core/deployer/providers/dogecloud-cdn/dogecloud_cdn.go @@ -13,7 +13,7 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/dogecloud" "github.com/certimate-go/certimate/pkg/core/deployer" dogesdk "github.com/certimate-go/certimate/pkg/sdk3rd/dogecloud" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" + xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) type DeployerConfig struct { @@ -96,18 +96,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/huaweicloud-aad/huaweicloud_aad.go b/pkg/core/deployer/providers/huaweicloud-aad/huaweicloud_aad.go index 8d17f927b..84be505f0 100644 --- a/pkg/core/deployer/providers/huaweicloud-aad/huaweicloud_aad.go +++ b/pkg/core/deployer/providers/huaweicloud-aad/huaweicloud_aad.go @@ -5,7 +5,6 @@ import ( "errors" "fmt" "log/slog" - "strings" "time" "github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/global" @@ -17,7 +16,6 @@ import ( "github.com/certimate-go/certimate/pkg/core/deployer" "github.com/certimate-go/certimate/pkg/core/deployer/providers/huaweicloud-aad/internal" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -115,8 +113,7 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep } domains := lo.Filter(domainCandidates, func(domainItem *hcaadmodelv2.InstanceDomainItem, _ int) bool { - return xcerthostname.IsMatch(d.config.Domain, lo.FromPtr(domainItem.DomainName)) || - strings.TrimPrefix(d.config.Domain, "*") == strings.TrimPrefix(lo.FromPtr(domainItem.DomainName), "*") + return xcerthostname.IsMatch(d.config.Domain, lo.FromPtr(domainItem.DomainName)) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by wildcard") @@ -129,19 +126,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomainsByInstanceId(ctx, d.config.InstanceId) if err != nil { return nil, err } domains := lo.Filter(domainCandidates, func(domainItem *hcaadmodelv2.InstanceDomainItem, _ int) bool { - return certX509.VerifyHostname(lo.FromPtr(domainItem.DomainName)) == nil || - strings.TrimPrefix(d.config.Domain, "*") == strings.TrimPrefix(lo.FromPtr(domainItem.DomainName), "*") + return xcerthostname.IsMatchByCertificatePEM(certPEM, lo.FromPtr(domainItem.DomainName)) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/huaweicloud-cdn/huaweicloud_cdn.go b/pkg/core/deployer/providers/huaweicloud-cdn/huaweicloud_cdn.go index 8a62a583c..5b67cd13b 100644 --- a/pkg/core/deployer/providers/huaweicloud-cdn/huaweicloud_cdn.go +++ b/pkg/core/deployer/providers/huaweicloud-cdn/huaweicloud_cdn.go @@ -17,7 +17,6 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/huaweicloud-scm" "github.com/certimate-go/certimate/pkg/core/deployer" "github.com/certimate-go/certimate/pkg/core/deployer/providers/huaweicloud-cdn/internal" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -133,18 +132,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/huaweicloud-live/huaweicloud_live.go b/pkg/core/deployer/providers/huaweicloud-live/huaweicloud_live.go index 12e2fdff9..de394f9bf 100644 --- a/pkg/core/deployer/providers/huaweicloud-live/huaweicloud_live.go +++ b/pkg/core/deployer/providers/huaweicloud-live/huaweicloud_live.go @@ -20,7 +20,7 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/huaweicloud-scm" "github.com/certimate-go/certimate/pkg/core/deployer" "github.com/certimate-go/certimate/pkg/core/deployer/providers/huaweicloud-live/internal" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" + xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) type DeployerConfig struct { @@ -112,18 +112,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/jdcloud-cdn/jdcloud_cdn.go b/pkg/core/deployer/providers/jdcloud-cdn/jdcloud_cdn.go index 4a9daabfa..625171c4a 100644 --- a/pkg/core/deployer/providers/jdcloud-cdn/jdcloud_cdn.go +++ b/pkg/core/deployer/providers/jdcloud-cdn/jdcloud_cdn.go @@ -15,7 +15,6 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/jdcloud-ssl" "github.com/certimate-go/certimate/pkg/core/deployer" "github.com/certimate-go/certimate/pkg/core/deployer/providers/jdcloud-cdn/internal" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -122,18 +121,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/jdcloud-live/jdcloud_live.go b/pkg/core/deployer/providers/jdcloud-live/jdcloud_live.go index f7f67dc70..459406549 100644 --- a/pkg/core/deployer/providers/jdcloud-live/jdcloud_live.go +++ b/pkg/core/deployer/providers/jdcloud-live/jdcloud_live.go @@ -12,7 +12,7 @@ import ( "github.com/certimate-go/certimate/pkg/core/deployer" "github.com/certimate-go/certimate/pkg/core/deployer/providers/jdcloud-live/internal" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" + xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) type DeployerConfig struct { @@ -75,18 +75,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/jdcloud-vod/jdcloud_vod.go b/pkg/core/deployer/providers/jdcloud-vod/jdcloud_vod.go index 26e88e193..9283d0a85 100644 --- a/pkg/core/deployer/providers/jdcloud-vod/jdcloud_vod.go +++ b/pkg/core/deployer/providers/jdcloud-vod/jdcloud_vod.go @@ -14,7 +14,7 @@ import ( "github.com/certimate-go/certimate/pkg/core/deployer" "github.com/certimate-go/certimate/pkg/core/deployer/providers/jdcloud-vod/internal" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" + xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) type DeployerConfig struct { @@ -77,18 +77,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/ksyun-cdn/ksyun_cdn.go b/pkg/core/deployer/providers/ksyun-cdn/ksyun_cdn.go index b2c010d20..ddcb6f8af 100644 --- a/pkg/core/deployer/providers/ksyun-cdn/ksyun_cdn.go +++ b/pkg/core/deployer/providers/ksyun-cdn/ksyun_cdn.go @@ -14,7 +14,6 @@ import ( "github.com/samber/lo" "github.com/certimate-go/certimate/pkg/core/deployer" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -126,18 +125,13 @@ func (d *Deployer) deployToDomain(ctx context.Context, certPEM, privkeyPEM strin case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/qiniu-cdn/qiniu_cdn.go b/pkg/core/deployer/providers/qiniu-cdn/qiniu_cdn.go index 8f3e7949f..b692e37b9 100644 --- a/pkg/core/deployer/providers/qiniu-cdn/qiniu_cdn.go +++ b/pkg/core/deployer/providers/qiniu-cdn/qiniu_cdn.go @@ -14,7 +14,6 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/qiniu-sslcert" "github.com/certimate-go/certimate/pkg/core/deployer" qiniusdk "github.com/certimate-go/certimate/pkg/sdk3rd/qiniu" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -108,8 +107,7 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return xcerthostname.IsMatch(d.config.Domain, domain) || - strings.TrimPrefix(d.config.Domain, "*") == strings.TrimPrefix(domain, "*") + return xcerthostname.IsMatch(d.config.Domain, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by wildcard") @@ -121,19 +119,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil || - strings.TrimPrefix(d.config.Domain, "*") == strings.TrimPrefix(domain, "*") + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/qiniu-pili/qiniu_pili.go b/pkg/core/deployer/providers/qiniu-pili/qiniu_pili.go index 52141e73a..64a81081f 100644 --- a/pkg/core/deployer/providers/qiniu-pili/qiniu_pili.go +++ b/pkg/core/deployer/providers/qiniu-pili/qiniu_pili.go @@ -12,7 +12,7 @@ import ( "github.com/certimate-go/certimate/pkg/core/certmgr" mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/qiniu-sslcert" "github.com/certimate-go/certimate/pkg/core/deployer" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" + xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) type DeployerConfig struct { @@ -98,18 +98,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomainsByHub(ctx, d.config.Hub) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/tencentcloud-css/tencentcloud_css.go b/pkg/core/deployer/providers/tencentcloud-css/tencentcloud_css.go index 0f149a510..8bf9dc14d 100644 --- a/pkg/core/deployer/providers/tencentcloud-css/tencentcloud_css.go +++ b/pkg/core/deployer/providers/tencentcloud-css/tencentcloud_css.go @@ -16,7 +16,7 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/tencentcloud-ssl" "github.com/certimate-go/certimate/pkg/core/deployer" "github.com/certimate-go/certimate/pkg/core/deployer/providers/tencentcloud-css/internal" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" + xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) type DeployerConfig struct { @@ -104,18 +104,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/tencentcloud-eo/tencentcloud_eo.go b/pkg/core/deployer/providers/tencentcloud-eo/tencentcloud_eo.go index 575879704..d79b2521a 100644 --- a/pkg/core/deployer/providers/tencentcloud-eo/tencentcloud_eo.go +++ b/pkg/core/deployer/providers/tencentcloud-eo/tencentcloud_eo.go @@ -144,16 +144,11 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates := lo.Map(domainsInZone, func(domainInfo *tcteo.AccelerationDomain, _ int) string { return lo.FromPtr(domainInfo.DomainName) }) domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/tencentcloud-scf/tencentcloud_scf.go b/pkg/core/deployer/providers/tencentcloud-scf/tencentcloud_scf.go index b80e9ed19..da1641eba 100644 --- a/pkg/core/deployer/providers/tencentcloud-scf/tencentcloud_scf.go +++ b/pkg/core/deployer/providers/tencentcloud-scf/tencentcloud_scf.go @@ -16,7 +16,7 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/tencentcloud-ssl" "github.com/certimate-go/certimate/pkg/core/deployer" "github.com/certimate-go/certimate/pkg/core/deployer/providers/tencentcloud-scf/internal" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" + xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) type DeployerConfig struct { @@ -106,18 +106,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/upyun-cdn/upyun_cdn.go b/pkg/core/deployer/providers/upyun-cdn/upyun_cdn.go index 382ede820..39df3ae97 100644 --- a/pkg/core/deployer/providers/upyun-cdn/upyun_cdn.go +++ b/pkg/core/deployer/providers/upyun-cdn/upyun_cdn.go @@ -13,7 +13,6 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/upyun-ssl" "github.com/certimate-go/certimate/pkg/core/deployer" upyunsdk "github.com/certimate-go/certimate/pkg/sdk3rd/upyun/console" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -120,18 +119,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/volcengine-apig/volcengine_apig.go b/pkg/core/deployer/providers/volcengine-apig/volcengine_apig.go index 3e9811389..46920c28a 100644 --- a/pkg/core/deployer/providers/volcengine-apig/volcengine_apig.go +++ b/pkg/core/deployer/providers/volcengine-apig/volcengine_apig.go @@ -5,7 +5,6 @@ import ( "errors" "fmt" "log/slog" - "strings" "github.com/samber/lo" veapig "github.com/volcengine/volcengine-go-sdk/service/apig" @@ -16,7 +15,6 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/volcengine-certcenter" "github.com/certimate-go/certimate/pkg/core/deployer" "github.com/certimate-go/certimate/pkg/core/deployer/providers/volcengine-apig/internal" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -126,8 +124,7 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep } domains := lo.Filter(domainCandidates, func(domainItem *veapig.ItemForListCustomDomainsOutput, _ int) bool { - return xcerthostname.IsMatch(d.config.Domain, lo.FromPtr(domainItem.Domain)) || - strings.TrimPrefix(d.config.Domain, "*") == strings.TrimPrefix(lo.FromPtr(domainItem.Domain), "*") + return xcerthostname.IsMatch(d.config.Domain, lo.FromPtr(domainItem.Domain)) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by wildcard") @@ -140,19 +137,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains := lo.Filter(domainCandidates, func(domainItem *veapig.ItemForListCustomDomainsOutput, _ int) bool { - return certX509.VerifyHostname(lo.FromPtr(domainItem.Domain)) == nil || - strings.TrimPrefix(d.config.Domain, "*") == strings.TrimPrefix(lo.FromPtr(domainItem.Domain), "*") + return xcerthostname.IsMatchByCertificatePEM(certPEM, lo.FromPtr(domainItem.Domain)) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/volcengine-dcdn/volcengine_dcdn.go b/pkg/core/deployer/providers/volcengine-dcdn/volcengine_dcdn.go index a55657b4a..1de3ed40d 100644 --- a/pkg/core/deployer/providers/volcengine-dcdn/volcengine_dcdn.go +++ b/pkg/core/deployer/providers/volcengine-dcdn/volcengine_dcdn.go @@ -16,7 +16,6 @@ import ( mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/volcengine-certcenter" "github.com/certimate-go/certimate/pkg/core/deployer" "github.com/certimate-go/certimate/pkg/core/deployer/providers/volcengine-dcdn/internal" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -116,8 +115,7 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return xcerthostname.IsMatch(d.config.Domain, domain) || - strings.TrimPrefix(d.config.Domain, "*") == strings.TrimPrefix(domain, "*") + return xcerthostname.IsMatch(d.config.Domain, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by wildcard") @@ -129,19 +127,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil || - strings.TrimPrefix(d.config.Domain, "*") == strings.TrimPrefix(domain, "*") + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/volcengine-live/volcengine_live.go b/pkg/core/deployer/providers/volcengine-live/volcengine_live.go index b3756d899..3e860f4e7 100644 --- a/pkg/core/deployer/providers/volcengine-live/volcengine_live.go +++ b/pkg/core/deployer/providers/volcengine-live/volcengine_live.go @@ -14,7 +14,6 @@ import ( "github.com/certimate-go/certimate/pkg/core/certmgr" mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/volcengine-live" "github.com/certimate-go/certimate/pkg/core/deployer" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -120,18 +119,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/core/deployer/providers/volcengine-vod/volcengine_vod.go b/pkg/core/deployer/providers/volcengine-vod/volcengine_vod.go index f29a4630b..24acc8f21 100644 --- a/pkg/core/deployer/providers/volcengine-vod/volcengine_vod.go +++ b/pkg/core/deployer/providers/volcengine-vod/volcengine_vod.go @@ -16,7 +16,6 @@ import ( "github.com/certimate-go/certimate/pkg/core/certmgr" mcertmgr "github.com/certimate-go/certimate/pkg/core/certmgr/providers/volcengine-certcenter" "github.com/certimate-go/certimate/pkg/core/deployer" - xcert "github.com/certimate-go/certimate/pkg/utils/cert" xcerthostname "github.com/certimate-go/certimate/pkg/utils/cert/hostname" ) @@ -126,18 +125,13 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*dep case DOMAIN_MATCH_PATTERN_CERTSAN: { - certX509, err := xcert.ParseCertificateFromPEM(certPEM) - if err != nil { - return nil, err - } - domainCandidates, err := d.getAllDomains(ctx) if err != nil { return nil, err } domains = lo.Filter(domainCandidates, func(domain string, _ int) bool { - return certX509.VerifyHostname(domain) == nil + return xcerthostname.IsMatchByCertificatePEM(certPEM, domain) }) if len(domains) == 0 { return nil, errors.New("could not find any domains matched by certificate") diff --git a/pkg/utils/cert/hostname/hostname.go b/pkg/utils/cert/hostname/hostname.go index 1acc1944f..9cc872517 100644 --- a/pkg/utils/cert/hostname/hostname.go +++ b/pkg/utils/cert/hostname/hostname.go @@ -4,29 +4,79 @@ import ( "crypto/x509" "net" "strings" + + xcert "github.com/certimate-go/certimate/pkg/utils/cert" ) // 检查目标主机名是否匹配待匹配主机名。 +// 兼容目标主机名开头是 "." 的情况(视为泛域名)。 // // 入参: -// - match: 待匹配主机名。可以是泛域名,如 "*.example.com"。 -// - candidate: 目标主机名。如 "sub.example.com"。 +// - pattern: 待匹配主机名,可以是泛域名。如 "*.example.com"。 +// - hostname: 目标主机名。如 "sub.example.com"。 // // 出参: // - 是否匹配。 -func IsMatch(match, candidate string) bool { - if match == "" || candidate == "" { +func IsMatch(pattern, hostname string) bool { + if pattern == "" || hostname == "" { return false } mockCert := &x509.Certificate{} - if ip := net.ParseIP(match); ip != nil { + if ip := net.ParseIP(pattern); ip != nil { mockCert.IPAddresses = []net.IP{ip} } else { - if strings.EqualFold(match, candidate) { + if strings.EqualFold(pattern, hostname) { return true } - mockCert.DNSNames = []string{match} + mockCert.DNSNames = []string{pattern} } - return mockCert.VerifyHostname(candidate) == nil + return IsMatchByCertificate(mockCert, hostname) +} + +// 检查目标主机名是否匹配证书。 +// 兼容目标主机名开头是 "." 的情况(视为泛域名)。 +// +// 入参: +// - certPEM: 证书 PEM 内容。 +// - hostname: 目标主机名。如 "sub.example.com"。 +// +// 出参: +// - 是否匹配。 +func IsMatchByCertificatePEM(certPEM string, hostname string) bool { + if certPEM == "" || hostname == "" { + return false + } + + certX509, err := xcert.ParseCertificateFromPEM(certPEM) + if err != nil { + return false + } + + return IsMatchByCertificate(certX509, hostname) +} + +// 检查目标主机名是否匹配证书。 +// 兼容目标主机名开头是 "." 的情况(视为泛域名)。 +// +// 入参: +// - certX509: 证书 X509 对象。 +// - hostname: 目标主机名。如 "sub.example.com"。 +// +// 出参: +// - 是否匹配。 +func IsMatchByCertificate(certX509 *x509.Certificate, hostname string) bool { + if certX509 == nil || hostname == "" { + return false + } + + if strings.HasPrefix(hostname, "*.") || strings.HasPrefix(hostname, ".") { + for _, dn := range certX509.DNSNames { + if strings.EqualFold(strings.TrimPrefix(dn, "*"), strings.TrimPrefix(hostname, "*")) { + return true + } + } + } + + return certX509.VerifyHostname(hostname) == nil } diff --git a/pkg/utils/cert/hostname/hostname_test.go b/pkg/utils/cert/hostname/hostname_test.go index 33d06f471..28d055ca0 100644 --- a/pkg/utils/cert/hostname/hostname_test.go +++ b/pkg/utils/cert/hostname/hostname_test.go @@ -9,12 +9,14 @@ import ( func TestCertHostnameUtil_IsMatch(t *testing.T) { t.Run("IsMatch", func(t *testing.T) { testCases := []struct { - wildcard string - target string + pattern string + hostname string expected bool }{ {"*.example.com", "sub.example.com", true}, {"*.example.com", "sub.sub.example.com", false}, + {"*.example.com", "*.example.com", true}, + {"*.example.com", ".example.com", true}, {"*.example.com", "example.com", false}, {"*.*.example.com", "a.b.example.com", false}, @@ -36,7 +38,7 @@ func TestCertHostnameUtil_IsMatch(t *testing.T) { } for _, tc := range testCases { - result := xcerthostname.IsMatch(tc.wildcard, tc.target) + result := xcerthostname.IsMatch(tc.pattern, tc.hostname) status := "✓" pf := t.Logf if result != tc.expected { @@ -44,7 +46,52 @@ func TestCertHostnameUtil_IsMatch(t *testing.T) { pf = t.Errorf } - pf("%s Wildcard: %-20s Target: %-20s Expected: %-5v Got: %-5v\n", status, tc.wildcard, tc.target, tc.expected, result) + pf("%s Pattern: %-20s Hostname: %-20s Expected: %-5v Got: %-5v\n", status, tc.pattern, tc.hostname, tc.expected, result) + } + }) +} + +func TestCertHostnameUtil_IsMatch(t *testing.T) { + t.Run("IsMatch", func(t *testing.T) { + testCases := []struct { + pattern string + hostname string + expected bool + }{ + {"*.example.com", "sub.example.com", true}, + {"*.example.com", "sub.sub.example.com", false}, + {"*.example.com", "*.example.com", true}, + {"*.example.com", ".example.com", true}, + {"*.example.com", "example.com", false}, + + {"*.*.example.com", "a.b.example.com", false}, + {"*.*.example.com", "a.example.com", false}, + {"*.*.example.com", "a.b.c.example.com", false}, + + {"example.com", "example.com", true}, + {"example.com", "wrong.com", false}, + + {"", "example.com", false}, + {"*.example.com", "", false}, + + {"*.sub.example.com", "a.sub.example.com", true}, + {"*.sub.example.com", "a.b.sub.example.com", false}, + {"*.sub.example.com", "sub.example.com", false}, + + {"*.Example.COM", "sub.example.com", true}, + {"*.EXAMPLE.COM", "SUB.EXAMPLE.COM", true}, + } + + for _, tc := range testCases { + result := xcerthostname.IsMatch(tc.pattern, tc.hostname) + status := "✓" + pf := t.Logf + if result != tc.expected { + status = "✗" + pf = t.Errorf + } + + pf("%s Pattern: %-20s Hostname: %-20s Expected: %-5v Got: %-5v\n", status, tc.pattern, tc.hostname, tc.expected, result) } }) }