fix(deploy): recognize failed edge certificate shape
This commit is contained in:
@@ -2370,9 +2370,9 @@ def device_edge_channel_invalid_identity_is_exact_recoverable():
|
|||||||
return False
|
return False
|
||||||
text = device_edge_channel_certificate_text(certificate)
|
text = device_edge_channel_certificate_text(certificate)
|
||||||
if (
|
if (
|
||||||
text.count("X509v3 Basic Constraints: critical") != 2
|
text.count("X509v3 Basic Constraints:") != 2
|
||||||
or "CA:TRUE" not in text
|
or text.count("CA:TRUE") != 1
|
||||||
or "CA:FALSE" not in text
|
or text.count("CA:FALSE") != 1
|
||||||
):
|
):
|
||||||
return False
|
return False
|
||||||
if (
|
if (
|
||||||
|
|||||||
@@ -140,6 +140,135 @@ keyUsage = critical,keyCertSign,cRLSign
|
|||||||
):
|
):
|
||||||
RUNNER.recover_invalid_device_edge_channel_core_identity()
|
RUNNER.recover_invalid_device_edge_channel_core_identity()
|
||||||
|
|
||||||
|
def test_failed_016_recovery_accepts_actual_synology_constraint_shape(self):
|
||||||
|
with tempfile.TemporaryDirectory(
|
||||||
|
prefix="nodedc-device-edge-failed-016-",
|
||||||
|
) as directory:
|
||||||
|
root = Path(directory)
|
||||||
|
private_key = root / "core-private-key.pem"
|
||||||
|
certificate = root / "core-certificate.pem"
|
||||||
|
peers = root / "peers"
|
||||||
|
private_key.write_text("private-placeholder\n", encoding="ascii")
|
||||||
|
certificate.write_text("certificate-placeholder\n", encoding="ascii")
|
||||||
|
peers.mkdir()
|
||||||
|
with (
|
||||||
|
mock.patch.object(
|
||||||
|
RUNNER,
|
||||||
|
"DEVICE_PLANE_EDGE_CHANNEL_CORE_PRIVATE_KEY_FILE",
|
||||||
|
private_key,
|
||||||
|
),
|
||||||
|
mock.patch.object(
|
||||||
|
RUNNER,
|
||||||
|
"DEVICE_PLANE_EDGE_CHANNEL_CORE_CERTIFICATE_FILE",
|
||||||
|
certificate,
|
||||||
|
),
|
||||||
|
mock.patch.object(
|
||||||
|
RUNNER,
|
||||||
|
"DEVICE_PLANE_EDGE_CHANNEL_PEER_TRUST_DIR",
|
||||||
|
peers,
|
||||||
|
),
|
||||||
|
mock.patch.object(
|
||||||
|
RUNNER,
|
||||||
|
"DEVICE_PLANE_EDGE_CHANNEL_EXPORTED_CORE_CERTIFICATE_FILE",
|
||||||
|
root / "exported-certificate.pem",
|
||||||
|
),
|
||||||
|
mock.patch.object(
|
||||||
|
RUNNER,
|
||||||
|
"DEVICE_PLANE_EDGE_CHANNEL_EXPORTED_CORE_FINGERPRINT_FILE",
|
||||||
|
root / "exported-fingerprint.txt",
|
||||||
|
),
|
||||||
|
mock.patch.object(
|
||||||
|
RUNNER,
|
||||||
|
"device_edge_channel_certificate_fingerprint",
|
||||||
|
return_value=(
|
||||||
|
RUNNER.DEVICE_PLANE_EDGE_CORE_CHANNEL_INVALID_CERTIFICATE_FINGERPRINT
|
||||||
|
),
|
||||||
|
),
|
||||||
|
mock.patch.object(
|
||||||
|
RUNNER,
|
||||||
|
"device_edge_channel_certificate_text",
|
||||||
|
return_value="""
|
||||||
|
X509v3 Basic Constraints:
|
||||||
|
CA:TRUE
|
||||||
|
X509v3 Basic Constraints: critical
|
||||||
|
CA:FALSE
|
||||||
|
X509v3 Key Usage: critical
|
||||||
|
Digital Signature
|
||||||
|
X509v3 Extended Key Usage:
|
||||||
|
TLS Web Client Authentication
|
||||||
|
""",
|
||||||
|
),
|
||||||
|
mock.patch.object(
|
||||||
|
RUNNER,
|
||||||
|
"capture_openssl",
|
||||||
|
side_effect=[b"same-public-key", b"same-public-key"],
|
||||||
|
),
|
||||||
|
):
|
||||||
|
self.assertTrue(
|
||||||
|
RUNNER.device_edge_channel_invalid_identity_is_exact_recoverable()
|
||||||
|
)
|
||||||
|
|
||||||
|
def test_failed_016_recovery_rejects_ambiguous_constraint_shape(self):
|
||||||
|
with tempfile.TemporaryDirectory(
|
||||||
|
prefix="nodedc-device-edge-ambiguous-",
|
||||||
|
) as directory:
|
||||||
|
root = Path(directory)
|
||||||
|
private_key = root / "core-private-key.pem"
|
||||||
|
certificate = root / "core-certificate.pem"
|
||||||
|
peers = root / "peers"
|
||||||
|
private_key.write_text("private-placeholder\n", encoding="ascii")
|
||||||
|
certificate.write_text("certificate-placeholder\n", encoding="ascii")
|
||||||
|
peers.mkdir()
|
||||||
|
with (
|
||||||
|
mock.patch.object(
|
||||||
|
RUNNER,
|
||||||
|
"DEVICE_PLANE_EDGE_CHANNEL_CORE_PRIVATE_KEY_FILE",
|
||||||
|
private_key,
|
||||||
|
),
|
||||||
|
mock.patch.object(
|
||||||
|
RUNNER,
|
||||||
|
"DEVICE_PLANE_EDGE_CHANNEL_CORE_CERTIFICATE_FILE",
|
||||||
|
certificate,
|
||||||
|
),
|
||||||
|
mock.patch.object(
|
||||||
|
RUNNER,
|
||||||
|
"DEVICE_PLANE_EDGE_CHANNEL_PEER_TRUST_DIR",
|
||||||
|
peers,
|
||||||
|
),
|
||||||
|
mock.patch.object(
|
||||||
|
RUNNER,
|
||||||
|
"DEVICE_PLANE_EDGE_CHANNEL_EXPORTED_CORE_CERTIFICATE_FILE",
|
||||||
|
root / "exported-certificate.pem",
|
||||||
|
),
|
||||||
|
mock.patch.object(
|
||||||
|
RUNNER,
|
||||||
|
"DEVICE_PLANE_EDGE_CHANNEL_EXPORTED_CORE_FINGERPRINT_FILE",
|
||||||
|
root / "exported-fingerprint.txt",
|
||||||
|
),
|
||||||
|
mock.patch.object(
|
||||||
|
RUNNER,
|
||||||
|
"device_edge_channel_certificate_fingerprint",
|
||||||
|
return_value=(
|
||||||
|
RUNNER.DEVICE_PLANE_EDGE_CORE_CHANNEL_INVALID_CERTIFICATE_FINGERPRINT
|
||||||
|
),
|
||||||
|
),
|
||||||
|
mock.patch.object(
|
||||||
|
RUNNER,
|
||||||
|
"device_edge_channel_certificate_text",
|
||||||
|
return_value="""
|
||||||
|
X509v3 Basic Constraints:
|
||||||
|
CA:TRUE
|
||||||
|
X509v3 Basic Constraints: critical
|
||||||
|
CA:FALSE
|
||||||
|
X509v3 Basic Constraints: critical
|
||||||
|
CA:FALSE
|
||||||
|
""",
|
||||||
|
),
|
||||||
|
):
|
||||||
|
self.assertFalse(
|
||||||
|
RUNNER.device_edge_channel_invalid_identity_is_exact_recoverable()
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
if __name__ == "__main__":
|
||||||
unittest.main()
|
unittest.main()
|
||||||
|
|||||||
Reference in New Issue
Block a user