certificates/acme/api/order.go

333 lines
9.6 KiB
Go
Raw Normal View History

2019-05-27 00:41:10 +00:00
package api
import (
2021-03-05 07:10:46 +00:00
"context"
2019-05-27 00:41:10 +00:00
"crypto/x509"
"encoding/base64"
"encoding/json"
2022-04-07 12:11:53 +00:00
"fmt"
2021-06-03 20:02:13 +00:00
"net"
2019-05-27 00:41:10 +00:00
"net/http"
2021-03-05 07:10:46 +00:00
"strings"
2019-05-27 00:41:10 +00:00
"time"
"github.com/go-chi/chi"
"go.step.sm/crypto/randutil"
2019-05-27 00:41:10 +00:00
"github.com/smallstep/certificates/acme"
"github.com/smallstep/certificates/api/render"
"github.com/smallstep/certificates/authority/provisioner"
2019-05-27 00:41:10 +00:00
)
// NewOrderRequest represents the body for a NewOrder request.
type NewOrderRequest struct {
Identifiers []acme.Identifier `json:"identifiers"`
NotBefore time.Time `json:"notBefore,omitempty"`
NotAfter time.Time `json:"notAfter,omitempty"`
}
// Validate validates a new-order request body.
func (n *NewOrderRequest) Validate() error {
if len(n.Identifiers) == 0 {
2021-03-05 07:10:46 +00:00
return acme.NewError(acme.ErrorMalformedType, "identifiers list cannot be empty")
2019-05-27 00:41:10 +00:00
}
for _, id := range n.Identifiers {
if !(id.Type == acme.DNS || id.Type == acme.IP) {
2021-03-05 07:10:46 +00:00
return acme.NewError(acme.ErrorMalformedType, "identifier type unsupported: %s", id.Type)
2019-05-27 00:41:10 +00:00
}
if id.Type == acme.IP && net.ParseIP(id.Value) == nil {
2021-06-03 20:45:24 +00:00
return acme.NewError(acme.ErrorMalformedType, "invalid IP address: %s", id.Value)
2021-06-03 20:02:13 +00:00
}
// TODO(hs): add some validations for DNS domains?
// TODO(hs): combine the errors from this with allow/deny policy, like example error in https://datatracker.ietf.org/doc/html/rfc8555#section-6.7.1
2019-05-27 00:41:10 +00:00
}
return nil
}
// FinalizeRequest captures the body for a Finalize order request.
type FinalizeRequest struct {
CSR string `json:"csr"`
csr *x509.CertificateRequest
}
// Validate validates a finalize request body.
func (f *FinalizeRequest) Validate() error {
var err error
csrBytes, err := base64.RawURLEncoding.DecodeString(f.CSR)
if err != nil {
2021-03-05 07:10:46 +00:00
return acme.WrapError(acme.ErrorMalformedType, err, "error base64url decoding csr")
2019-05-27 00:41:10 +00:00
}
f.csr, err = x509.ParseCertificateRequest(csrBytes)
if err != nil {
2021-03-05 07:10:46 +00:00
return acme.WrapError(acme.ErrorMalformedType, err, "unable to parse csr")
2019-05-27 00:41:10 +00:00
}
if err = f.csr.CheckSignature(); err != nil {
2021-03-05 07:10:46 +00:00
return acme.WrapError(acme.ErrorMalformedType, err, "csr failed signature check")
2019-05-27 00:41:10 +00:00
}
return nil
}
2021-03-05 07:10:46 +00:00
var defaultOrderExpiry = time.Hour * 24
2021-03-25 07:23:57 +00:00
var defaultOrderBackdate = time.Minute
2021-03-05 07:10:46 +00:00
2019-05-27 00:41:10 +00:00
// NewOrder ACME api for creating a new order.
func (h *Handler) NewOrder(w http.ResponseWriter, r *http.Request) {
ctx := r.Context()
2021-03-05 07:10:46 +00:00
acc, err := accountFromContext(ctx)
if err != nil {
render.Error(w, err)
2021-03-05 07:10:46 +00:00
return
}
prov, err := provisionerFromContext(ctx)
2019-05-27 00:41:10 +00:00
if err != nil {
render.Error(w, err)
2019-05-27 00:41:10 +00:00
return
}
payload, err := payloadFromContext(ctx)
2019-05-27 00:41:10 +00:00
if err != nil {
render.Error(w, err)
2019-05-27 00:41:10 +00:00
return
}
2019-05-27 00:41:10 +00:00
var nor NewOrderRequest
if err := json.Unmarshal(payload.value, &nor); err != nil {
render.Error(w, acme.WrapError(acme.ErrorMalformedType, err,
2021-03-05 07:10:46 +00:00
"failed to unmarshal new-order request payload"))
2019-05-27 00:41:10 +00:00
return
}
2021-06-03 20:02:13 +00:00
2019-05-27 00:41:10 +00:00
if err := nor.Validate(); err != nil {
render.Error(w, err)
2019-05-27 00:41:10 +00:00
return
}
// TODO(hs): the policy evaluation below should also verify rules set in the Account (i.e. allowed/denied
// DNS and IPs). It's probably good to connect those to the EAB credentials and management? Or
// should we do it fully properly and connect them to the Account directly? The latter would allow
// management of allowed/denied names based on just the name, without having bound to EAB. Still,
// EAB is not illogical, because that's the way Accounts are connected to an external system and
// thus make sense to also set the allowed/denied names based on that info.
// TODO(hs): gather all errors, so that we can build one response with subproblems; include the nor.Validate()
// error here too, like in example?
2022-04-07 12:11:53 +00:00
eak, err := h.db.GetExternalAccountKeyByAccountID(ctx, prov.GetID(), acc.ID)
fmt.Println("EAK: ", eak, err)
for _, identifier := range nor.Identifiers {
// evaluate the provisioner level policy
orderIdentifier := provisioner.ACMEIdentifier{Type: provisioner.ACMEIdentifierType(identifier.Type), Value: identifier.Value}
err = prov.AuthorizeOrderIdentifier(ctx, orderIdentifier)
if err != nil {
render.Error(w, acme.WrapError(acme.ErrorRejectedIdentifierType, err, "not authorized"))
return
}
// evaluate the authority level policy
err = h.ca.AreSANsAllowed(ctx, []string{identifier.Value})
if err != nil {
render.Error(w, acme.WrapError(acme.ErrorRejectedIdentifierType, err, "not authorized"))
return
}
}
now := clock.Now()
2021-03-05 07:10:46 +00:00
// New order.
o := &acme.Order{
2021-03-25 07:23:57 +00:00
AccountID: acc.ID,
ProvisionerID: prov.GetID(),
Status: acme.StatusPending,
Identifiers: nor.Identifiers,
ExpiresAt: now.Add(defaultOrderExpiry),
AuthorizationIDs: make([]string, len(nor.Identifiers)),
NotBefore: nor.NotBefore,
NotAfter: nor.NotAfter,
}
2021-03-05 07:10:46 +00:00
for i, identifier := range o.Identifiers {
az := &acme.Authorization{
AccountID: acc.ID,
Identifier: identifier,
2021-03-25 07:23:57 +00:00
ExpiresAt: o.ExpiresAt,
Status: acme.StatusPending,
2021-03-05 07:10:46 +00:00
}
if err := h.newAuthorization(ctx, az); err != nil {
render.Error(w, err)
2021-03-05 07:10:46 +00:00
return
}
o.AuthorizationIDs[i] = az.ID
}
if o.NotBefore.IsZero() {
o.NotBefore = now
}
if o.NotAfter.IsZero() {
o.NotAfter = o.NotBefore.Add(prov.DefaultTLSCertDuration())
}
// If request NotBefore was empty then backdate the order.NotBefore (now)
// to avoid timing issues.
2021-03-25 07:23:57 +00:00
if nor.NotBefore.IsZero() {
o.NotBefore = o.NotBefore.Add(-defaultOrderBackdate)
2021-03-25 07:23:57 +00:00
}
2021-03-05 07:10:46 +00:00
if err := h.db.CreateOrder(ctx, o); err != nil {
render.Error(w, acme.WrapErrorISE(err, "error creating order"))
2019-05-27 00:41:10 +00:00
return
}
2021-03-05 07:14:56 +00:00
h.linker.LinkOrder(ctx, o)
2021-03-05 07:10:46 +00:00
w.Header().Set("Location", h.linker.GetLink(ctx, OrderLinkType, o.ID))
render.JSONStatus(w, o, http.StatusCreated)
2019-05-27 00:41:10 +00:00
}
2021-03-05 07:10:46 +00:00
func (h *Handler) newAuthorization(ctx context.Context, az *acme.Authorization) error {
if strings.HasPrefix(az.Identifier.Value, "*.") {
az.Wildcard = true
az.Identifier = acme.Identifier{
Value: strings.TrimPrefix(az.Identifier.Value, "*."),
Type: az.Identifier.Type,
}
}
chTypes := challengeTypes(az)
2021-03-05 07:10:46 +00:00
var err error
2021-03-05 07:10:46 +00:00
az.Token, err = randutil.Alphanumeric(32)
if err != nil {
return acme.WrapErrorISE(err, "error generating random alphanumeric ID")
}
az.Challenges = make([]*acme.Challenge, len(chTypes))
for i, typ := range chTypes {
ch := &acme.Challenge{
AccountID: az.AccountID,
Value: az.Identifier.Value,
Type: typ,
Token: az.Token,
Status: acme.StatusPending,
2021-03-05 07:10:46 +00:00
}
if err := h.db.CreateChallenge(ctx, ch); err != nil {
2021-03-25 07:23:57 +00:00
return acme.WrapErrorISE(err, "error creating challenge")
2021-03-05 07:10:46 +00:00
}
az.Challenges[i] = ch
}
if err = h.db.CreateAuthorization(ctx, az); err != nil {
return acme.WrapErrorISE(err, "error creating authorization")
}
return nil
}
2019-05-27 00:41:10 +00:00
// GetOrder ACME api for retrieving an order.
func (h *Handler) GetOrder(w http.ResponseWriter, r *http.Request) {
ctx := r.Context()
2021-03-05 07:10:46 +00:00
acc, err := accountFromContext(ctx)
2019-05-27 00:41:10 +00:00
if err != nil {
render.Error(w, err)
2019-05-27 00:41:10 +00:00
return
}
2021-03-05 07:10:46 +00:00
prov, err := provisionerFromContext(ctx)
2019-05-27 00:41:10 +00:00
if err != nil {
render.Error(w, err)
2019-05-27 00:41:10 +00:00
return
}
2021-03-05 07:10:46 +00:00
o, err := h.db.GetOrder(ctx, chi.URLParam(r, "ordID"))
if err != nil {
render.Error(w, acme.WrapErrorISE(err, "error retrieving order"))
2021-03-05 07:10:46 +00:00
return
}
if acc.ID != o.AccountID {
render.Error(w, acme.NewError(acme.ErrorUnauthorizedType,
2021-03-05 07:10:46 +00:00
"account '%s' does not own order '%s'", acc.ID, o.ID))
return
}
if prov.GetID() != o.ProvisionerID {
render.Error(w, acme.NewError(acme.ErrorUnauthorizedType,
2021-03-05 07:10:46 +00:00
"provisioner '%s' does not own order '%s'", prov.GetID(), o.ID))
return
}
if err = o.UpdateStatus(ctx, h.db); err != nil {
render.Error(w, acme.WrapErrorISE(err, "error updating order status"))
2021-03-05 07:10:46 +00:00
return
}
2019-05-27 00:41:10 +00:00
2021-03-05 07:10:46 +00:00
h.linker.LinkOrder(ctx, o)
w.Header().Set("Location", h.linker.GetLink(ctx, OrderLinkType, o.ID))
render.JSON(w, o)
2019-05-27 00:41:10 +00:00
}
// FinalizeOrder attemptst to finalize an order and create a certificate.
func (h *Handler) FinalizeOrder(w http.ResponseWriter, r *http.Request) {
ctx := r.Context()
2021-03-05 07:10:46 +00:00
acc, err := accountFromContext(ctx)
if err != nil {
render.Error(w, err)
2021-03-05 07:10:46 +00:00
return
}
prov, err := provisionerFromContext(ctx)
2019-05-27 00:41:10 +00:00
if err != nil {
render.Error(w, err)
2019-05-27 00:41:10 +00:00
return
}
payload, err := payloadFromContext(ctx)
2019-05-27 00:41:10 +00:00
if err != nil {
render.Error(w, err)
2019-05-27 00:41:10 +00:00
return
}
var fr FinalizeRequest
if err := json.Unmarshal(payload.value, &fr); err != nil {
render.Error(w, acme.WrapError(acme.ErrorMalformedType, err,
2021-03-05 07:10:46 +00:00
"failed to unmarshal finalize-order request payload"))
2019-05-27 00:41:10 +00:00
return
}
if err := fr.Validate(); err != nil {
render.Error(w, err)
2019-05-27 00:41:10 +00:00
return
}
2021-03-05 07:10:46 +00:00
o, err := h.db.GetOrder(ctx, chi.URLParam(r, "ordID"))
2019-05-27 00:41:10 +00:00
if err != nil {
render.Error(w, acme.WrapErrorISE(err, "error retrieving order"))
2019-05-27 00:41:10 +00:00
return
}
2021-03-05 07:10:46 +00:00
if acc.ID != o.AccountID {
render.Error(w, acme.NewError(acme.ErrorUnauthorizedType,
2021-03-05 07:10:46 +00:00
"account '%s' does not own order '%s'", acc.ID, o.ID))
return
}
if prov.GetID() != o.ProvisionerID {
render.Error(w, acme.NewError(acme.ErrorUnauthorizedType,
2021-03-05 07:10:46 +00:00
"provisioner '%s' does not own order '%s'", prov.GetID(), o.ID))
return
}
if err = o.Finalize(ctx, h.db, fr.csr, h.ca, prov); err != nil {
render.Error(w, acme.WrapErrorISE(err, "error finalizing order"))
2021-03-05 07:10:46 +00:00
return
}
h.linker.LinkOrder(ctx, o)
2019-05-27 00:41:10 +00:00
w.Header().Set("Location", h.linker.GetLink(ctx, OrderLinkType, o.ID))
render.JSON(w, o)
2019-05-27 00:41:10 +00:00
}
// challengeTypes determines the types of challenges that should be used
// for the ACME authorization request.
func challengeTypes(az *acme.Authorization) []acme.ChallengeType {
var chTypes []acme.ChallengeType
switch az.Identifier.Type {
case acme.IP:
chTypes = []acme.ChallengeType{acme.HTTP01, acme.TLSALPN01}
case acme.DNS:
chTypes = []acme.ChallengeType{acme.DNS01}
// HTTP and TLS challenges can only be used for identifiers without wildcards.
if !az.Wildcard {
chTypes = append(chTypes, []acme.ChallengeType{acme.HTTP01, acme.TLSALPN01}...)
}
default:
chTypes = []acme.ChallengeType{}
}
return chTypes
}