2016-08-07 23:27:20 -05:00
|
|
|
#
|
|
|
|
# Copyright (C) 2016 FreeIPA Contributors see COPYING for license
|
|
|
|
#
|
2018-09-03 16:52:57 -05:00
|
|
|
import base64
|
2016-08-07 23:27:20 -05:00
|
|
|
|
|
|
|
from ipaclient.frontend import MethodOverride
|
2017-05-09 10:45:20 -05:00
|
|
|
from ipalib import errors, util, x509, Str
|
2016-08-07 23:27:20 -05:00
|
|
|
from ipalib.plugable import Registry
|
|
|
|
from ipalib.text import _
|
|
|
|
|
|
|
|
register = Registry()
|
|
|
|
|
|
|
|
|
|
|
|
class WithCertOutArgs(MethodOverride):
|
|
|
|
|
|
|
|
takes_options = (
|
|
|
|
Str(
|
|
|
|
'certificate_out?',
|
|
|
|
doc=_('Write certificate (chain if --chain used) to file'),
|
|
|
|
include='cli',
|
|
|
|
cli_metavar='FILE',
|
|
|
|
),
|
|
|
|
)
|
|
|
|
|
|
|
|
def forward(self, *keys, **options):
|
|
|
|
filename = None
|
|
|
|
if 'certificate_out' in options:
|
|
|
|
filename = options.pop('certificate_out')
|
2017-05-09 10:45:20 -05:00
|
|
|
try:
|
|
|
|
util.check_writable_file(filename)
|
|
|
|
except errors.FileError as e:
|
|
|
|
raise errors.ValidationError(name='certificate-out',
|
|
|
|
error=str(e))
|
2016-08-07 23:27:20 -05:00
|
|
|
|
|
|
|
result = super(WithCertOutArgs, self).forward(*keys, **options)
|
|
|
|
if filename:
|
|
|
|
if options.get('chain', False):
|
2018-09-03 16:52:57 -05:00
|
|
|
certs = result['result']['certificate_chain']
|
2016-08-07 23:27:20 -05:00
|
|
|
else:
|
2018-09-27 01:36:59 -05:00
|
|
|
certs = [base64.b64decode(result['result']['certificate'])]
|
|
|
|
certs = (x509.load_der_x509_certificate(cert) for cert in certs)
|
2017-06-16 03:18:07 -05:00
|
|
|
x509.write_certificate_list(certs, filename)
|
2016-08-07 23:27:20 -05:00
|
|
|
|
|
|
|
return result
|
|
|
|
|
|
|
|
|
|
|
|
@register(override=True, no_fail=True)
|
|
|
|
class ca_add(WithCertOutArgs):
|
|
|
|
pass
|
|
|
|
|
|
|
|
|
|
|
|
@register(override=True, no_fail=True)
|
|
|
|
class ca_show(WithCertOutArgs):
|
|
|
|
pass
|