-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathcert.go
58 lines (51 loc) · 1.94 KB
/
cert.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
// Copyright 2012, 2013 Canonical Ltd.
// Licensed under the AGPLv3, see LICENCE file for details.
package cert
import (
"crypto/x509"
"fmt"
"time"
"github.com/juju/errors"
utilscert "github.com/juju/utils/cert"
)
// Verify verifies that the given server certificate is valid with
// respect to the given CA certificate at the given time.
func Verify(srvCertPEM, caCertPEM string, when time.Time) error {
caCert, err := utilscert.ParseCert(caCertPEM)
if err != nil {
return errors.Annotate(err, "cannot parse CA certificate")
}
srvCert, err := utilscert.ParseCert(srvCertPEM)
if err != nil {
return errors.Annotate(err, "cannot parse server certificate")
}
pool := x509.NewCertPool()
pool.AddCert(caCert)
opts := x509.VerifyOptions{
DNSName: "anyServer",
Roots: pool,
CurrentTime: when,
}
_, err = srvCert.Verify(opts)
return err
}
// NewDefaultServer generates a certificate/key pair suitable for use by a server, with an
// expiry time of 10 years.
func NewDefaultServer(caCertPEM, caKeyPEM string, hostnames []string) (certPEM, keyPEM string, err error) {
// TODO(perrito666) 2016-05-02 lp:1558657
expiry := time.Now().UTC().AddDate(10, 0, 0)
return utilscert.NewLeaf("*", caCertPEM, caKeyPEM, expiry, hostnames, []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth})
}
// NewServer generates a certificate/key pair suitable for use by a server.
func NewServer(caCertPEM, caKeyPEM string, expiry time.Time, hostnames []string) (certPEM, keyPEM string, err error) {
return utilscert.NewLeaf("*", caCertPEM, caKeyPEM, expiry, hostnames, []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth})
}
// NewCA generates a CA certificate/key pair suitable for signing server
// keys for an environment with the given name.
// wrapper arount utils/cert#NewCA
func NewCA(commonName, UUID string, expiry time.Time) (certPEM, keyPEM string, err error) {
return utilscert.NewCA(
fmt.Sprintf("juju-generated CA for model %q", commonName),
UUID, expiry,
)
}