mirror of
https://github.com/open-cluster-management-io/ocm.git
synced 2026-08-23 22:26:49 +00:00
Retrigger CSR when subject org and ou doesn't match. (#377)
Signed-off-by: GitHub <noreply@github.com>
This commit is contained in:
@@ -2,9 +2,11 @@ package clientcert
|
||||
|
||||
import (
|
||||
"context"
|
||||
"crypto/x509"
|
||||
"crypto/x509/pkix"
|
||||
"errors"
|
||||
"fmt"
|
||||
"reflect"
|
||||
"time"
|
||||
|
||||
"github.com/openshift/library-go/pkg/operator/events"
|
||||
@@ -92,17 +94,37 @@ func IsCertificateValid(logger klog.Logger, certData []byte, subject *pkix.Name)
|
||||
}
|
||||
|
||||
// check subject of certificates
|
||||
// if the subject is specified, make sure at least one cert in the certificate chain matches the subject
|
||||
for _, cert := range certs {
|
||||
if cert.Subject.CommonName != subject.CommonName {
|
||||
continue
|
||||
if certMatchSubject(cert, subject) {
|
||||
return true, nil
|
||||
}
|
||||
return true, nil
|
||||
}
|
||||
|
||||
logger.V(4).Info("Certificate is not issued for subject", "commonName", subject.CommonName)
|
||||
logger.V(4).Info("Certificate is not issued for subject", "commonName", subject.CommonName, "organization",
|
||||
subject.Organization, "organizationalUnit", subject.OrganizationalUnit)
|
||||
return false, nil
|
||||
}
|
||||
|
||||
func certMatchSubject(cert *x509.Certificate, subject *pkix.Name) bool {
|
||||
// check commonName
|
||||
if cert.Subject.CommonName != subject.CommonName {
|
||||
return false
|
||||
}
|
||||
|
||||
// check groups(origanization)
|
||||
if !reflect.DeepEqual(cert.Subject.Organization, subject.Organization) {
|
||||
return false
|
||||
}
|
||||
|
||||
// check originzation unit
|
||||
if !reflect.DeepEqual(cert.Subject.OrganizationalUnit, subject.OrganizationalUnit) {
|
||||
return false
|
||||
}
|
||||
|
||||
return true
|
||||
}
|
||||
|
||||
// getCertValidityPeriod returns the validity period of the client certificate in the secret
|
||||
func getCertValidityPeriod(secret *corev1.Secret) (*time.Time, *time.Time, error) {
|
||||
if secret.Data == nil {
|
||||
|
||||
@@ -162,12 +162,42 @@ func TestIsCertificateValid(t *testing.T) {
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "valid cert",
|
||||
name: "invalid organization",
|
||||
testCert: testinghelpers.NewTestCertWithSubject(pkix.Name{
|
||||
CommonName: "test",
|
||||
CommonName: "test",
|
||||
Organization: []string{"org_foo"},
|
||||
}, 60*time.Second),
|
||||
subject: &pkix.Name{
|
||||
CommonName: "test",
|
||||
CommonName: "test",
|
||||
Organization: []string{"org_bar"},
|
||||
},
|
||||
isValid: false,
|
||||
},
|
||||
{
|
||||
name: "invalid organization unit",
|
||||
testCert: testinghelpers.NewTestCertWithSubject(pkix.Name{
|
||||
CommonName: "test",
|
||||
Organization: []string{"org"},
|
||||
OrganizationalUnit: []string{"ou_foo"},
|
||||
}, 60*time.Second),
|
||||
subject: &pkix.Name{
|
||||
CommonName: "test",
|
||||
Organization: []string{"org"},
|
||||
OrganizationalUnit: []string{"ou_bar"},
|
||||
},
|
||||
isValid: false,
|
||||
},
|
||||
{
|
||||
name: "valid cert",
|
||||
testCert: testinghelpers.NewTestCertWithSubject(pkix.Name{
|
||||
CommonName: "test",
|
||||
Organization: []string{"org"},
|
||||
OrganizationalUnit: []string{"ou"},
|
||||
}, 60*time.Second),
|
||||
subject: &pkix.Name{
|
||||
CommonName: "test",
|
||||
Organization: []string{"org"},
|
||||
OrganizationalUnit: []string{"ou"},
|
||||
},
|
||||
isValid: true,
|
||||
},
|
||||
|
||||
@@ -44,20 +44,24 @@ var _ = ginkgo.Describe("Cluster Auto Approval", func() {
|
||||
defer cancel()
|
||||
|
||||
// after bootstrap the spokecluster should be accepted and its csr should be auto approved
|
||||
gomega.Eventually(func() bool {
|
||||
gomega.Eventually(func() error {
|
||||
cluster, err := util.GetManagedCluster(clusterClient, managedClusterName)
|
||||
if err != nil {
|
||||
return false
|
||||
return err
|
||||
}
|
||||
|
||||
return cluster.Spec.HubAcceptsClient
|
||||
}, eventuallyTimeout, eventuallyInterval).Should(gomega.BeTrue())
|
||||
if !cluster.Spec.HubAcceptsClient {
|
||||
return fmt.Errorf("cluster should be accepted")
|
||||
}
|
||||
|
||||
return nil
|
||||
}, eventuallyTimeout, eventuallyInterval).Should(gomega.Succeed())
|
||||
|
||||
var approvedCSR *certificates.CertificateSigningRequest
|
||||
gomega.Eventually(func() bool {
|
||||
gomega.Eventually(func() error {
|
||||
approvedCSR, err = util.FindAutoApprovedSpokeCSR(kubeClient, managedClusterName)
|
||||
return err == nil
|
||||
}, eventuallyTimeout, eventuallyInterval).Should(gomega.BeTrue())
|
||||
return err
|
||||
}, eventuallyTimeout, eventuallyInterval).Should(gomega.Succeed())
|
||||
|
||||
// simulate hub cluster to fill a certificate
|
||||
now := time.Now()
|
||||
|
||||
Reference in New Issue
Block a user