Skip to content

Commit e093f56

Browse files
committed
#535 VID scoped x509 certificates
- Minor refactoring Signed-off-by: Abdulbois <abdulbois.tursunov@dsr-corporation.com> Signed-off-by: Abdulbois <abdulbois123@gmail.com>
1 parent b98e4d1 commit e093f56

File tree

4 files changed

+121
-121
lines changed

4 files changed

+121
-121
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,119 @@
1+
set -euo pipefail
2+
source integration_tests/cli/common.sh
3+
4+
root_cert_with_vid_65521_subject="MIGYMQswCQYDVQQGEwJVUzERMA8GA1UECAwITmV3IFlvcmsxETAPBgNVBAcMCE5ldyBZb3JrMRgwFgYDVQQKDA9FeGFtcGxlIENvbXBhbnkxGTAXBgNVBAsMEFRlc3RpbmcgRGl2aXNpb24xGDAWBgNVBAMMD3d3dy5leGFtcGxlLmNvbTEUMBIGCisGAQQBgqJ8AgEMBEZGRjE="
5+
root_cert_with_vid_65521_subject_key_id="CE:A8:92:66:EA:E0:80:BD:2B:B5:68:E4:0B:07:C4:FA:2C:34:6D:31"
6+
root_cert_with_vid_65521_path="integration_tests/constants/root_cert_with_vid"
7+
root_cert_with_vid_65521_vid=65521
8+
intermediate_cert_with_vid_subject="MIGuMQswCQYDVQQGEwJVUzERMA8GA1UECAwITmV3IFlvcmsxETAPBgNVBAcMCE5ldyBZb3JrMRgwFgYDVQQKDA9FeGFtcGxlIENvbXBhbnkxGTAXBgNVBAsMEFRlc3RpbmcgRGl2aXNpb24xGDAWBgNVBAMMD3d3dy5leGFtcGxlLmNvbTEUMBIGCisGAQQBgqJ8AgEMBEZGRjExFDASBgorBgEEAYKifAICDARGRkYx"
9+
intermediate_cert_with_vid_subject_key_id="0E:8C:E8:C8:B8:AA:50:BC:25:85:56:B9:B1:9C:C2:C7:D9:C5:2F:17"
10+
intermediate_cert_with_vid_65521_path="integration_tests/constants/intermediate_cert_with_vid_1"
11+
intermediate_cert_with_vid_65522_path="integration_tests/constants/intermediate_cert_with_vid_2"
12+
intermediate_cert_with_vid_65521_serial_number="3"
13+
intermediate_cert_with_vid_65522_serial_number="4"
14+
intermediate_cert_with_vid_65521_vid=65521
15+
intermediate_cert_with_vid_65522_vid=65522
16+
17+
root_cert_with_no_vid_path="integration_tests/constants/paa_cert_no_vid"
18+
root_cert_with_no_vid_subject="MBoxGDAWBgNVBAMMD01hdHRlciBUZXN0IFBBQQ=="
19+
root_cert_with_no_vid_subject_key_id="78:5C:E7:05:B8:6B:8F:4E:6F:C7:93:AA:60:CB:43:EA:69:68:82:D5"
20+
intermediate_cert_with_vid_65522_path="integration_tests/constants/pai_cert_numeric_vid"
21+
intermediate_cert_with_vid_65522_subject="MDAxGDAWBgNVBAMMD01hdHRlciBUZXN0IFBBSTEUMBIGCisGAQQBgqJ8AgEMBEZGRjI="
22+
intermediate_cert_with_vid_65522_subject_key_id="61:3D:D0:87:35:5E:F0:8B:AE:01:E4:C6:9A:8F:C7:3D:AC:8C:7D:FD"
23+
intermediate_cert_with_vid_65522_vid=65522
24+
intermediate_cert_with_vid_65522_serial_number="4428370313154203676"
25+
26+
trustee_account="jack"
27+
second_trustee_account="alice"
28+
29+
test_divider
30+
31+
echo "ADD VID SCOPED X509 CERTIFICATES"
32+
33+
vendor_vid_65521=$root_cert_with_vid_65521_vid
34+
vendor_account_65521=vendor_account_$vendor_vid_65521
35+
echo "Create Vendor account - $vendor_account_65521"
36+
create_new_vendor_account $vendor_account_65521 $vendor_vid_65521
37+
38+
echo "Propose and approve root certificate with vid=$root_cert_with_vid_65521_vid"
39+
result=$(echo "$passphrase" | dcld tx pki propose-add-x509-root-cert --certificate="$root_cert_with_vid_65521_path" --vid "$root_cert_with_vid_65521_vid" --from $trustee_account --yes)
40+
check_response "$result" "\"code\": 0"
41+
result=$(echo "$passphrase" | dcld tx pki approve-add-x509-root-cert --subject="$root_cert_with_vid_65521_subject" --subject-key-id="$root_cert_with_vid_65521_subject_key_id" --from $second_trustee_account --yes)
42+
check_response "$result" "\"code\": 0"
43+
44+
echo "Add an intermediate certificate with vid=$intermediate_cert_with_vid_65521_vid by $vendor_account_65521 with vid=$vendor_vid_65521"
45+
result=$(echo "$passphrase" | dcld tx pki add-x509-cert --certificate="$intermediate_cert_with_vid_65521_path" --from $vendor_account_65521 --yes)
46+
check_response "$result" "\"code\": 0"
47+
48+
echo "Request all approved root certificates."
49+
result=$(dcld query pki all-x509-certs)
50+
echo $result | jq
51+
check_response "$result" "\"subject\": \"$root_cert_with_vid_65521_subject\""
52+
check_response "$result" "\"subjectKeyId\": \"$root_cert_with_vid_65521_subject_key_id\""
53+
check_response "$result" "\"subject\": \"$intermediate_cert_with_vid_subject\""
54+
check_response "$result" "\"subjectKeyId\": \"$intermediate_cert_with_vid_subject_key_id\""
55+
check_response "$result" "\"serialNumber\": \"$intermediate_cert_with_vid_65521_serial_number\""
56+
57+
echo "Try to add an intermediate certificate with vid=$intermediate_cert_with_vid_65522_vid by $vendor_account_65521 with vid=$vendor_vid_65521"
58+
result=$(echo "$passphrase" | dcld tx pki add-x509-cert --certificate="$intermediate_cert_with_vid_65522_path" --from $vendor_account_65521 --yes)
59+
check_response "$result" "\"code\": 440"
60+
61+
echo "Request all approved root certificates should not contain intermediate cert with serialNumber=$intermediate_cert_with_vid_65522_serial_number"
62+
result=$(dcld query pki all-x509-certs)
63+
echo $result | jq
64+
check_response "$result" "\"subject\": \"$root_cert_with_vid_65521_subject\""
65+
check_response "$result" "\"subject\": \"$intermediate_cert_with_vid_subject\""
66+
check_response "$result" "\"subjectKeyId\": \"$root_cert_with_vid_65521_subject_key_id\""
67+
check_response "$result" "\"subjectKeyId\": \"$intermediate_cert_with_vid_subject_key_id\""
68+
check_response "$result" "\"serialNumber\": \"$intermediate_cert_with_vid_65521_serial_number\""
69+
response_does_not_contain "$result" "\"serialNumber\": \"$intermediate_cert_with_vid_65522_serial_number\""
70+
71+
echo "Propose and approve non-vid root certificate"
72+
result=$(echo "$passphrase" | dcld tx pki propose-add-x509-root-cert --certificate="$root_cert_with_no_vid_path" --vid "65522" --from $trustee_account --yes)
73+
check_response "$result" "\"code\": 0"
74+
result=$(echo "$passphrase" | dcld tx pki approve-add-x509-root-cert --subject="$root_cert_with_no_vid_subject" --subject-key-id="$root_cert_with_no_vid_subject_key_id" --from $second_trustee_account --yes)
75+
check_response "$result" "\"code\": 0"
76+
77+
vendor_vid_65523=65523
78+
vendor_account_65523=vendor_account_$vendor_vid_65523
79+
echo "Create Vendor account - $vendor_account_65523"
80+
create_new_vendor_account $vendor_account_65523 $vendor_vid_65523
81+
82+
echo "Add an intermediate certificate with vid=$intermediate_cert_with_vid_65522_vid by $vendor_account_65523 with vid=$vendor_vid_65523"
83+
result=$(echo "$passphrase" | dcld tx pki add-x509-cert --certificate="$intermediate_cert_with_vid_65522_path" --from $vendor_account_65523 --yes)
84+
check_response "$result" "\"code\": 439"
85+
86+
echo "Request all approved root certificates should not contain intermediate cert with serialNumber=$intermediate_cert_with_vid_65522_serial_number"
87+
result=$(dcld query pki all-x509-certs)
88+
echo $result | jq
89+
check_response "$result" "\"subject\": \"$root_cert_with_vid_65521_subject\""
90+
check_response "$result" "\"subject\": \"$intermediate_cert_with_vid_subject\""
91+
check_response "$result" "\"subjectKeyId\": \"$root_cert_with_vid_65521_subject_key_id\""
92+
check_response "$result" "\"subjectKeyId\": \"$intermediate_cert_with_vid_subject_key_id\""
93+
check_response "$result" "\"serialNumber\": \"$intermediate_cert_with_vid_65521_serial_number\""
94+
response_does_not_contain "$result" "\"subject\": \"$intermediate_cert_with_vid_65522_subject\""
95+
response_does_not_contain "$result" "\"subjectKeyId\": \"$intermediate_cert_with_vid_65522_subject_key_id"
96+
response_does_not_contain "$result" "\"serialNumber\": \"$intermediate_cert_with_vid_65522_serial_number\""
97+
98+
vendor_vid_65522=65522
99+
vendor_account_65522=vendor_account_$vendor_vid_65522
100+
echo "Create Vendor account - $vendor_account_65522"
101+
create_new_vendor_account $vendor_account_65522 $vendor_vid_65522
102+
103+
echo "Add an intermediate certificate with vid=$intermediate_cert_with_vid_65522_vid by $vendor_account_65522 with vid=$vendor_vid_65522"
104+
result=$(echo "$passphrase" | dcld tx pki add-x509-cert --certificate="$intermediate_cert_with_vid_65522_path" --from $vendor_account_65522 --yes)
105+
check_response "$result" "\"code\": 0"
106+
107+
echo "Request all approved root certificates should contain intermediate cert with serialNumber=$intermediate_cert_with_vid_65522_serial_number"
108+
result=$(dcld query pki all-x509-certs)
109+
echo $result | jq
110+
check_response "$result" "\"subject\": \"$root_cert_with_vid_65521_subject\""
111+
check_response "$result" "\"subject\": \"$intermediate_cert_with_vid_subject\""
112+
check_response "$result" "\"subjectKeyId\": \"$root_cert_with_vid_65521_subject_key_id\""
113+
check_response "$result" "\"subjectKeyId\": \"$intermediate_cert_with_vid_subject_key_id\""
114+
check_response "$result" "\"serialNumber\": \"$intermediate_cert_with_vid_65521_serial_number\""
115+
check_response "$result" "\"subject\": \"$intermediate_cert_with_vid_65522_subject\""
116+
check_response "$result" "\"subjectKeyId\": \"$intermediate_cert_with_vid_65522_subject_key_id"
117+
check_response "$result" "\"serialNumber\": \"$intermediate_cert_with_vid_65522_serial_number\""
118+
119+
test_divider

integration_tests/cli/pki-add-vid-scoped-x509-certificates.sh

-119
This file was deleted.

integration_tests/grpc_rest/pki/helpers.go

+1-1
Original file line numberDiff line numberDiff line change
@@ -1984,7 +1984,7 @@ func Demo(suite *utils.TestSuite) {
19841984
_, err = GetX509Cert(suite, testconstants.LeafCertWithSameSubjectAndSKIDSubject, testconstants.LeafCertWithSameSubjectAndSKIDSubjectKeyID)
19851985
suite.AssertNotFound(err)
19861986

1987-
// Add VID scoped X509 certificate
1987+
// Add X509 certificates by Vendor Account
19881988

19891989
// Check that if root cert is VID scoped and RootVID==CertVID==AccountVID then adding x509 should succeed
19901990
// Add root certificate

types/pki/errors.go

+1-1
Original file line numberDiff line numberDiff line change
@@ -224,7 +224,7 @@ func NewErrRootCertVidNotEqualToAccountVidOrCertVid(rootVID int32, accountVID in
224224

225225
func NewErrAccountVidNotEqualToCertVid(accountVID int32, certVID int32) error {
226226
return sdkerrors.Wrapf(ErrCertVidNotEqualAccountVid,
227-
"Intermediate certificate is VID scoped: Only a Vendor associated with this VID can add an intermediate certificate: "+
227+
"Certificate is VID scoped: Only a Vendor associated with this VID can add an intermediate certificate: "+
228228
"Account VID = %v, Certificate's VID = %v",
229229
accountVID, certVID)
230230
}

0 commit comments

Comments
 (0)