Documentation
¶
Overview ¶
Package certauth provides shared certificate signing request helpers for session-bound mTLS credentials issued by the platform API and adapter CLI.
Index ¶
- func BuildSessionCSR(trustDomain, namespace, sessionName string) (keyPEM, csrPEM []byte, spiffeID string, err error)
- func ValidateCSRPEM(raw, expectedSPIFFEID string) ([]byte, error)
- func ValidateIssuedCertificatePEM(certPEM string, csrDER []byte, expectedSPIFFEID string, maxTTL time.Duration, ...) error
- func WritePrivateFile(dir, name string, data []byte, mode os.FileMode) error
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func BuildSessionCSR ¶
func BuildSessionCSR(trustDomain, namespace, sessionName string) (keyPEM, csrPEM []byte, spiffeID string, err error)
BuildSessionCSR generates a fresh P-256 key and a CSR whose only SAN is the session SPIFFE URI. It returns PKCS#8 key PEM, CSR PEM, and the SPIFFE ID string.
func ValidateCSRPEM ¶
ValidateCSRPEM parses and validates a PEM CSR. The CSR must be signed, carry exactly one URI SAN equal to expectedSPIFFEID, and must not include DNS, email, or IP subject alternative names. It returns the CSR DER on success.
func ValidateIssuedCertificatePEM ¶
func ValidateIssuedCertificatePEM(certPEM string, csrDER []byte, expectedSPIFFEID string, maxTTL time.Duration, now time.Time) error
ValidateIssuedCertificatePEM verifies a certificate returned by the workload issuer against the CSR the platform submitted. It is a defense-in-depth check that does not depend on the issuer's approval policy: the leaf must carry exactly the expected SPIFFE URI and no other SAN, be a non-CA client-auth-only certificate bound to the CSR's public key, and not outlive maxTTL (plus a small skew allowance for issuers that backdate NotBefore).
Types ¶
This section is empty.