mirror of
https://github.com/storytold/irsa-manager.git
synced 2026-10-09 00:09:43 +00:00
create cert, key
This commit is contained in:
@@ -1 +0,0 @@
|
||||
package selfhosted
|
||||
@@ -0,0 +1,75 @@
|
||||
package certificate
|
||||
|
||||
import (
|
||||
"crypto/rand"
|
||||
"crypto/rsa"
|
||||
"crypto/x509"
|
||||
"crypto/x509/pkix"
|
||||
"encoding/base64"
|
||||
"encoding/pem"
|
||||
"math/big"
|
||||
"time"
|
||||
|
||||
"k8s.io/apimachinery/pkg/types"
|
||||
)
|
||||
|
||||
type TlsCredentials struct {
|
||||
privateKey []byte
|
||||
certificate []byte
|
||||
}
|
||||
|
||||
func (t *TlsCredentials) CaBundle() string {
|
||||
return base64.StdEncoding.EncodeToString(t.certificate)
|
||||
}
|
||||
|
||||
func (t *TlsCredentials) Certificate() []byte {
|
||||
return t.certificate
|
||||
}
|
||||
|
||||
func (t *TlsCredentials) PrivateKey() []byte {
|
||||
return t.privateKey
|
||||
}
|
||||
|
||||
func CreateTlsCredential(serviceNamespacedName types.NamespacedName) (TlsCredentials, error) {
|
||||
certificatePeriod := 365 // days
|
||||
|
||||
// Generate RSA private key
|
||||
privateKey, err := rsa.GenerateKey(rand.Reader, 2048)
|
||||
if err != nil {
|
||||
return TlsCredentials{}, err
|
||||
}
|
||||
|
||||
// Define certificate template
|
||||
template := x509.Certificate{
|
||||
SerialNumber: big.NewInt(1),
|
||||
Subject: pkix.Name{
|
||||
CommonName: serviceNamespacedName.Name + "." + serviceNamespacedName.Namespace + ".svc",
|
||||
},
|
||||
NotBefore: time.Now(),
|
||||
NotAfter: time.Now().AddDate(0, 0, certificatePeriod),
|
||||
KeyUsage: x509.KeyUsageKeyEncipherment | x509.KeyUsageDigitalSignature,
|
||||
ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth},
|
||||
BasicConstraintsValid: true,
|
||||
IsCA: true,
|
||||
}
|
||||
|
||||
// Create the certificate
|
||||
certBytes, err := x509.CreateCertificate(rand.Reader, &template, &template, &privateKey.PublicKey, privateKey)
|
||||
if err != nil {
|
||||
return TlsCredentials{}, err
|
||||
}
|
||||
|
||||
// Encode the private key to PEM format
|
||||
privPemBytes := pem.EncodeToMemory(&pem.Block{
|
||||
Type: "RSA PRIVATE KEY",
|
||||
Bytes: x509.MarshalPKCS1PrivateKey(privateKey),
|
||||
})
|
||||
|
||||
// Encode the certificate to PEM format
|
||||
certPemBytes := pem.EncodeToMemory(&pem.Block{
|
||||
Type: "CERTIFICATE",
|
||||
Bytes: certBytes,
|
||||
})
|
||||
|
||||
return TlsCredentials{privateKey: privPemBytes, certificate: certPemBytes}, nil
|
||||
}
|
||||
@@ -0,0 +1,54 @@
|
||||
package certificate
|
||||
|
||||
import (
|
||||
"crypto/rsa"
|
||||
"crypto/x509"
|
||||
"encoding/pem"
|
||||
"testing"
|
||||
|
||||
"k8s.io/apimachinery/pkg/types"
|
||||
)
|
||||
|
||||
func TestCreateTlsCredentials(t *testing.T) {
|
||||
creds, err := CreateTlsCredential(types.NamespacedName{
|
||||
Name: "pod-identity-webhook",
|
||||
Namespace: "kube-system",
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatalf("Failed to create TLS credentials: %v", err)
|
||||
}
|
||||
|
||||
certBlock, _ := pem.Decode(creds.certificate)
|
||||
if certBlock == nil {
|
||||
t.Fatal("Failed to decode PEM block containing the certificate")
|
||||
}
|
||||
cert, err := x509.ParseCertificate(certBlock.Bytes)
|
||||
if err != nil {
|
||||
t.Fatalf("Failed to parse certificate: %v", err)
|
||||
}
|
||||
|
||||
keyBlock, _ := pem.Decode(creds.privateKey)
|
||||
if keyBlock == nil {
|
||||
t.Fatal("Failed to decode PEM block containing the private key")
|
||||
}
|
||||
key, err := x509.ParsePKCS1PrivateKey(keyBlock.Bytes)
|
||||
if err != nil {
|
||||
t.Fatalf("Failed to parse private key: %v", err)
|
||||
}
|
||||
|
||||
// Verify public keys are equivalent
|
||||
if !publicKeysEqual(cert.PublicKey, &key.PublicKey) {
|
||||
t.Fatal("Public key in certificate does not match public key in private key")
|
||||
}
|
||||
}
|
||||
|
||||
// Helper function to compare public keys
|
||||
func publicKeysEqual(pub1, pub2 interface{}) bool {
|
||||
rsaPub1, ok1 := pub1.(*rsa.PublicKey)
|
||||
rsaPub2, ok2 := pub2.(*rsa.PublicKey)
|
||||
|
||||
if !ok1 || !ok2 {
|
||||
return false
|
||||
}
|
||||
return rsaPub1.N.Cmp(rsaPub2.N) == 0 && rsaPub1.E == rsaPub2.E
|
||||
}
|
||||
@@ -22,7 +22,7 @@ func TestJWK(t *testing.T) {
|
||||
expected: rsaKeyID,
|
||||
},
|
||||
{
|
||||
name: "rsa",
|
||||
name: "no rsa",
|
||||
filename: "testdata/ecdsa.pub",
|
||||
expectErr: true,
|
||||
},
|
||||
|
||||
@@ -2,11 +2,11 @@ package selfhosted
|
||||
|
||||
import "context"
|
||||
|
||||
func Execute(ctx context.Context, factory OIDCIdPFactory, forceUpdate bool) error {
|
||||
issuerMeta := factory.IssuerMeta()
|
||||
discovery := factory.IdPDiscovery()
|
||||
discoveryContents := factory.IdPDiscoveryContents(issuerMeta)
|
||||
idp, err := factory.IdP(issuerMeta)
|
||||
func Execute(ctx context.Context, idpComponentsFactory OIDCIdPFactory, forceUpdate bool) error {
|
||||
issuerMeta := idpComponentsFactory.IssuerMeta()
|
||||
discovery := idpComponentsFactory.IdPDiscovery()
|
||||
discoveryContents := idpComponentsFactory.IdPDiscoveryContents(issuerMeta)
|
||||
idp, err := idpComponentsFactory.IdP(issuerMeta)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user