From 0fd83d13ae1145c6dbf47f2b4e8653514a7aada4 Mon Sep 17 00:00:00 2001 From: Raul Benencia Date: Fri, 17 Jul 2020 10:35:54 -0700 Subject: [PATCH] Fix intermediate CA creation on cryptography plugin --- lemur/plugins/lemur_cryptography/plugin.py | 7 +++++- .../tests/test_cryptography.py | 25 +++++++++++++++++++ 2 files changed, 31 insertions(+), 1 deletion(-) diff --git a/lemur/plugins/lemur_cryptography/plugin.py b/lemur/plugins/lemur_cryptography/plugin.py index 005f36f9..1cf60fba 100644 --- a/lemur/plugins/lemur_cryptography/plugin.py +++ b/lemur/plugins/lemur_cryptography/plugin.py @@ -24,7 +24,12 @@ from lemur.certificates.service import create_csr def build_certificate_authority(options): options["certificate_authority"] = True csr, private_key = create_csr(**options) - cert_pem, chain_cert_pem = issue_certificate(csr, options, private_key) + + if options.get("parent"): + # Intermediate Cert Issuance + cert_pem, chain_cert_pem = issue_certificate(csr, options, None) + else: + cert_pem, chain_cert_pem = issue_certificate(csr, options, private_key) return cert_pem, private_key, chain_cert_pem diff --git a/lemur/plugins/lemur_cryptography/tests/test_cryptography.py b/lemur/plugins/lemur_cryptography/tests/test_cryptography.py index 7f1777fc..05012c03 100644 --- a/lemur/plugins/lemur_cryptography/tests/test_cryptography.py +++ b/lemur/plugins/lemur_cryptography/tests/test_cryptography.py @@ -25,6 +25,31 @@ def test_build_certificate_authority(): assert chain_cert_pem == "" +def test_build_intermediate_certificate_authority(authority): + from lemur.plugins.lemur_cryptography.plugin import build_certificate_authority + + options = { + "key_type": "RSA2048", + "country": "US", + "state": "CA", + "location": "Example place", + "organization": "Example, Inc.", + "organizational_unit": "Example Unit", + "common_name": "Example INTERMEDIATE", + "validity_start": arrow.get("2016-12-01").datetime, + "validity_end": arrow.get("2016-12-02").datetime, + "first_serial": 1, + "serial_number": 1, + "owner": "owner@example.com", + "parent": authority + } + cert_pem, private_key_pem, chain_cert_pem = build_certificate_authority(options) + + assert cert_pem + assert private_key_pem + assert chain_cert_pem == authority.authority_certificate.body + + def test_issue_certificate(authority): from lemur.tests.vectors import CSR_STR from lemur.plugins.lemur_cryptography.plugin import issue_certificate