certauth

package
v0.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 0 Imported by: 0

Documentation

Overview

Package certauth provides shared certificate signing request helpers for session-bound mTLS credentials issued by the platform API and adapter CLI.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func BuildSessionCSR

func BuildSessionCSR(trustDomain, namespace, sessionName string) (keyPEM, csrPEM []byte, spiffeID string, err error)

BuildSessionCSR generates a fresh P-256 key and a CSR whose only SAN is the session SPIFFE URI. It returns PKCS#8 key PEM, CSR PEM, and the SPIFFE ID string.

func ValidateCSRPEM

func ValidateCSRPEM(raw, expectedSPIFFEID string) ([]byte, error)

ValidateCSRPEM parses and validates a PEM CSR. The CSR must be signed, carry exactly one URI SAN equal to expectedSPIFFEID, and must not include DNS, email, or IP subject alternative names. It returns the CSR DER on success.

func ValidateIssuedCertificatePEM

func ValidateIssuedCertificatePEM(certPEM string, csrDER []byte, expectedSPIFFEID string, maxTTL time.Duration, now time.Time) error

ValidateIssuedCertificatePEM verifies a certificate returned by the workload issuer against the CSR the platform submitted. It is a defense-in-depth check that does not depend on the issuer's approval policy: the leaf must carry exactly the expected SPIFFE URI and no other SAN, be a non-CA client-auth-only certificate bound to the CSR's public key, and not outlive maxTTL (plus a small skew allowance for issuers that backdate NotBefore).

func WritePrivateFile

func WritePrivateFile(dir, name string, data []byte, mode os.FileMode) error

WritePrivateFile writes data to dir/name with mode, rejecting path traversal.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL