Always return CSR as part of Resource#1593
Open
relvira wants to merge 1 commit intogo-acme:masterfrom
Open
Conversation
Member
|
Hello, I think you already have all the information to re-create the CSR: certcrypto.GenerateCSR(privateKey, commonName, san, mustStaple)
The only case that I see for your PR is when you don't provide explicitly a private key. Am I missing something? 🤔 |
Author
|
thanks @ldez for your comment, I will definitely give that a try and report back. Wouldn't it make sense to have the CSR returned as part of the certificates struct anyway? a CSR is always generated and it was slightly confusing to have the attribute available in the struct but it was empty after all. Looking forward to hear your thoughts! |
b63378b to
c4ab057
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Return the generated CSR in the certificate
Resourceafter anObtainorObtainForCSR.There are cases where users of this library will like to perform some additional operations with the generated CSR after an obtain was run, for example: submitting the CSR to an external tool that monitors certificate-transparency logs, in order to make sure the certificate issued by the library is legitimate.
I am not very familiar with this codebase so I might've missed something. I updated existing tests to make sure the CSR in Resource exists.
@ldez Please let me know if there's anything else I can do to speed up this work (or if there's something terribly wrong with my approach).
Thank you.