mirror of
https://github.com/certbot/certbot.git
synced 2026-08-01 19:02:52 +02:00
Merge branch 'use-cn-from-csr' into csr++
This commit is contained in:
+28
-4
@@ -258,15 +258,20 @@ def pyopenssl_load_certificate(data):
|
|||||||
str(error) for error in openssl_errors)))
|
str(error) for error in openssl_errors)))
|
||||||
|
|
||||||
|
|
||||||
def _get_sans_from_cert_or_req(cert_or_req_str, load_func,
|
def _load_cert_or_req(cert_or_req_str, load_func,
|
||||||
typ=OpenSSL.crypto.FILETYPE_PEM):
|
typ=OpenSSL.crypto.FILETYPE_PEM):
|
||||||
try:
|
try:
|
||||||
cert_or_req = load_func(typ, cert_or_req_str)
|
return load_func(typ, cert_or_req_str)
|
||||||
except OpenSSL.crypto.Error as error:
|
except OpenSSL.crypto.Error as error:
|
||||||
logger.exception(error)
|
logger.exception(error)
|
||||||
raise
|
raise
|
||||||
|
|
||||||
|
|
||||||
|
def _get_sans_from_cert_or_req(cert_or_req_str, load_func,
|
||||||
|
typ=OpenSSL.crypto.FILETYPE_PEM):
|
||||||
# pylint: disable=protected-access
|
# pylint: disable=protected-access
|
||||||
return acme_crypto_util._pyopenssl_cert_or_req_san(cert_or_req)
|
return acme_crypto_util._pyopenssl_cert_or_req_san(_load_cert_or_req(
|
||||||
|
cert_or_req_str, load_func, typ))
|
||||||
|
|
||||||
|
|
||||||
def get_sans_from_cert(cert, typ=OpenSSL.crypto.FILETYPE_PEM):
|
def get_sans_from_cert(cert, typ=OpenSSL.crypto.FILETYPE_PEM):
|
||||||
@@ -297,6 +302,25 @@ def get_sans_from_csr(csr, typ=OpenSSL.crypto.FILETYPE_PEM):
|
|||||||
csr, OpenSSL.crypto.load_certificate_request, typ)
|
csr, OpenSSL.crypto.load_certificate_request, typ)
|
||||||
|
|
||||||
|
|
||||||
|
def get_names_from_csr(csr, typ=OpenSSL.crypto.FILETYPE_PEM):
|
||||||
|
"""Get a list of domains from a CSR, including the CN if it is set.
|
||||||
|
|
||||||
|
:param str csr: CSR (encoded).
|
||||||
|
:param typ: `OpenSSL.crypto.FILETYPE_PEM` or `OpenSSL.crypto.FILETYPE_ASN1`
|
||||||
|
|
||||||
|
:returns: A list of domain names.
|
||||||
|
:rtype: list
|
||||||
|
|
||||||
|
"""
|
||||||
|
loaded_csr = _load_cert_or_req(
|
||||||
|
csr, OpenSSL.crypto.load_certificate_request, typ)
|
||||||
|
# Use a set to avoid duplication with CN and Subject Alt Names
|
||||||
|
domains = set(d for d in (loaded_csr.get_subject().CN,) if d is not None)
|
||||||
|
# pylint: disable=protected-access
|
||||||
|
domains.update(acme_crypto_util._pyopenssl_cert_or_req_san(loaded_csr))
|
||||||
|
return list(domains)
|
||||||
|
|
||||||
|
|
||||||
def dump_pyopenssl_chain(chain, filetype=OpenSSL.crypto.FILETYPE_PEM):
|
def dump_pyopenssl_chain(chain, filetype=OpenSSL.crypto.FILETYPE_PEM):
|
||||||
"""Dump certificate chain into a bundle.
|
"""Dump certificate chain into a bundle.
|
||||||
|
|
||||||
|
|||||||
@@ -234,6 +234,36 @@ class GetSANsFromCSRTest(unittest.TestCase):
|
|||||||
[], self._call(test_util.load_vector('csr-nosans.pem')))
|
[], self._call(test_util.load_vector('csr-nosans.pem')))
|
||||||
|
|
||||||
|
|
||||||
|
class GetNamesFromCSRTest(unittest.TestCase):
|
||||||
|
"""Tests for certbot.crypto_util.get_names_from_csr."""
|
||||||
|
@classmethod
|
||||||
|
def _call(cls, *args, **kwargs):
|
||||||
|
from certbot.crypto_util import get_names_from_csr
|
||||||
|
return get_names_from_csr(*args, **kwargs)
|
||||||
|
|
||||||
|
def test_extract_one_san(self):
|
||||||
|
self.assertEqual(['example.com'], self._call(
|
||||||
|
test_util.load_vector('csr.pem')))
|
||||||
|
|
||||||
|
def test_extract_two_sans(self):
|
||||||
|
self.assertEqual(set(('example.com', 'www.example.com',)), set(
|
||||||
|
self._call(test_util.load_vector('csr-san.pem'))))
|
||||||
|
|
||||||
|
def test_extract_six_sans(self):
|
||||||
|
self.assertEqual(
|
||||||
|
set(self._call(test_util.load_vector('csr-6sans.pem'))),
|
||||||
|
set(("example.com", "example.org", "example.net",
|
||||||
|
"example.info", "subdomain.example.com",
|
||||||
|
"other.subdomain.example.com",)))
|
||||||
|
|
||||||
|
def test_parse_non_csr(self):
|
||||||
|
self.assertRaises(OpenSSL.crypto.Error, self._call, "hello there")
|
||||||
|
|
||||||
|
def test_parse_no_sans(self):
|
||||||
|
self.assertEqual(["example.org"],
|
||||||
|
self._call(test_util.load_vector('csr-nosans.pem')))
|
||||||
|
|
||||||
|
|
||||||
class CertLoaderTest(unittest.TestCase):
|
class CertLoaderTest(unittest.TestCase):
|
||||||
"""Tests for certbot.crypto_util.pyopenssl_load_certificate"""
|
"""Tests for certbot.crypto_util.pyopenssl_load_certificate"""
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user