Skip to content

Commit e896f1d

Browse files
author
GitLab Runner
committed
Merge branch 'main' of github.com:securosys-com/hcvault-ce-rest-integration
2 parents 846c559 + a6b20ca commit e896f1d

42 files changed

Lines changed: 35198 additions & 0 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 181 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,181 @@
1+
//go:build go1.11 || go1.12 || go1.13 || go1.14 || go1.15
2+
3+
package pkcs7
4+
5+
import (
6+
"crypto/x509"
7+
"encoding/pem"
8+
"io/ioutil"
9+
"os"
10+
"os/exec"
11+
"testing"
12+
)
13+
14+
func TestVerifyEC2(t *testing.T) {
15+
fixture := UnmarshalDSATestFixture(EC2IdentityDocumentFixture)
16+
p7, err := Parse(fixture.Input)
17+
if err != nil {
18+
t.Errorf("Parse encountered unexpected error: %v", err)
19+
}
20+
p7.Certificates = []*x509.Certificate{fixture.Certificate}
21+
if err := p7.Verify(); err != nil {
22+
t.Errorf("Verify failed with error: %v", err)
23+
}
24+
}
25+
26+
var EC2IdentityDocumentFixture = `
27+
-----BEGIN PKCS7-----
28+
MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAaCA
29+
JIAEggGmewogICJwcml2YXRlSXAiIDogIjE3Mi4zMC4wLjI1MiIsCiAgImRldnBh
30+
eVByb2R1Y3RDb2RlcyIgOiBudWxsLAogICJhdmFpbGFiaWxpdHlab25lIiA6ICJ1
31+
cy1lYXN0LTFhIiwKICAidmVyc2lvbiIgOiAiMjAxMC0wOC0zMSIsCiAgImluc3Rh
32+
bmNlSWQiIDogImktZjc5ZmU1NmMiLAogICJiaWxsaW5nUHJvZHVjdHMiIDogbnVs
33+
bCwKICAiaW5zdGFuY2VUeXBlIiA6ICJ0Mi5taWNybyIsCiAgImFjY291bnRJZCIg
34+
OiAiMTIxNjU5MDE0MzM0IiwKICAiaW1hZ2VJZCIgOiAiYW1pLWZjZTNjNjk2IiwK
35+
ICAicGVuZGluZ1RpbWUiIDogIjIwMTYtMDQtMDhUMDM6MDE6MzhaIiwKICAiYXJj
36+
aGl0ZWN0dXJlIiA6ICJ4ODZfNjQiLAogICJrZXJuZWxJZCIgOiBudWxsLAogICJy
37+
YW1kaXNrSWQiIDogbnVsbCwKICAicmVnaW9uIiA6ICJ1cy1lYXN0LTEiCn0AAAAA
38+
AAAxggEYMIIBFAIBATBpMFwxCzAJBgNVBAYTAlVTMRkwFwYDVQQIExBXYXNoaW5n
39+
dG9uIFN0YXRlMRAwDgYDVQQHEwdTZWF0dGxlMSAwHgYDVQQKExdBbWF6b24gV2Vi
40+
IFNlcnZpY2VzIExMQwIJAJa6SNnlXhpnMAkGBSsOAwIaBQCgXTAYBgkqhkiG9w0B
41+
CQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xNjA0MDgwMzAxNDRaMCMG
42+
CSqGSIb3DQEJBDEWBBTuUc28eBXmImAautC+wOjqcFCBVjAJBgcqhkjOOAQDBC8w
43+
LQIVAKA54NxGHWWCz5InboDmY/GHs33nAhQ6O/ZI86NwjA9Vz3RNMUJrUPU5tAAA
44+
AAAAAA==
45+
-----END PKCS7-----
46+
-----BEGIN CERTIFICATE-----
47+
MIIC7TCCAq0CCQCWukjZ5V4aZzAJBgcqhkjOOAQDMFwxCzAJBgNVBAYTAlVTMRkw
48+
FwYDVQQIExBXYXNoaW5ndG9uIFN0YXRlMRAwDgYDVQQHEwdTZWF0dGxlMSAwHgYD
49+
VQQKExdBbWF6b24gV2ViIFNlcnZpY2VzIExMQzAeFw0xMjAxMDUxMjU2MTJaFw0z
50+
ODAxMDUxMjU2MTJaMFwxCzAJBgNVBAYTAlVTMRkwFwYDVQQIExBXYXNoaW5ndG9u
51+
IFN0YXRlMRAwDgYDVQQHEwdTZWF0dGxlMSAwHgYDVQQKExdBbWF6b24gV2ViIFNl
52+
cnZpY2VzIExMQzCCAbcwggEsBgcqhkjOOAQBMIIBHwKBgQCjkvcS2bb1VQ4yt/5e
53+
ih5OO6kK/n1Lzllr7D8ZwtQP8fOEpp5E2ng+D6Ud1Z1gYipr58Kj3nssSNpI6bX3
54+
VyIQzK7wLclnd/YozqNNmgIyZecN7EglK9ITHJLP+x8FtUpt3QbyYXJdmVMegN6P
55+
hviYt5JH/nYl4hh3Pa1HJdskgQIVALVJ3ER11+Ko4tP6nwvHwh6+ERYRAoGBAI1j
56+
k+tkqMVHuAFcvAGKocTgsjJem6/5qomzJuKDmbJNu9Qxw3rAotXau8Qe+MBcJl/U
57+
hhy1KHVpCGl9fueQ2s6IL0CaO/buycU1CiYQk40KNHCcHfNiZbdlx1E9rpUp7bnF
58+
lRa2v1ntMX3caRVDdbtPEWmdxSCYsYFDk4mZrOLBA4GEAAKBgEbmeve5f8LIE/Gf
59+
MNmP9CM5eovQOGx5ho8WqD+aTebs+k2tn92BBPqeZqpWRa5P/+jrdKml1qx4llHW
60+
MXrs3IgIb6+hUIB+S8dz8/mmO0bpr76RoZVCXYab2CZedFut7qc3WUH9+EUAH5mw
61+
vSeDCOUMYQR7R9LINYwouHIziqQYMAkGByqGSM44BAMDLwAwLAIUWXBlk40xTwSw
62+
7HX32MxXYruse9ACFBNGmdX2ZBrVNGrN9N2f6ROk0k9K
63+
-----END CERTIFICATE-----`
64+
65+
func TestDSASignWithOpenSSLAndVerify(t *testing.T) {
66+
content := []byte(`
67+
A ship in port is safe,
68+
but that's not what ships are built for.
69+
-- Grace Hopper`)
70+
// write the content to a temp file
71+
tmpContentFile, err := ioutil.TempFile("", "TestDSASignWithOpenSSLAndVerify_content")
72+
if err != nil {
73+
t.Fatal(err)
74+
}
75+
ioutil.WriteFile(tmpContentFile.Name(), content, 0o755)
76+
77+
// write the signer cert to a temp file
78+
tmpSignerCertFile, err := ioutil.TempFile("", "TestDSASignWithOpenSSLAndVerify_signer")
79+
if err != nil {
80+
t.Fatal(err)
81+
}
82+
ioutil.WriteFile(tmpSignerCertFile.Name(), dsaPublicCert, 0o755)
83+
84+
// write the signer key to a temp file
85+
tmpSignerKeyFile, err := ioutil.TempFile("", "TestDSASignWithOpenSSLAndVerify_key")
86+
if err != nil {
87+
t.Fatal(err)
88+
}
89+
ioutil.WriteFile(tmpSignerKeyFile.Name(), dsaPrivateKey, 0o755)
90+
91+
tmpSignedFile, err := ioutil.TempFile("", "TestDSASignWithOpenSSLAndVerify_signature")
92+
if err != nil {
93+
t.Fatal(err)
94+
}
95+
// call openssl to sign the content
96+
opensslCMD := exec.Command("openssl", "smime", "-sign", "-nodetach", "-md", "sha1",
97+
"-in", tmpContentFile.Name(), "-out", tmpSignedFile.Name(),
98+
"-signer", tmpSignerCertFile.Name(), "-inkey", tmpSignerKeyFile.Name(),
99+
"-certfile", tmpSignerCertFile.Name(), "-outform", "PEM")
100+
out, err := opensslCMD.CombinedOutput()
101+
if err != nil {
102+
t.Fatalf("openssl command failed with %s: %s", err, out)
103+
}
104+
105+
// verify the signed content
106+
pemSignature, err := ioutil.ReadFile(tmpSignedFile.Name())
107+
if err != nil {
108+
t.Fatal(err)
109+
}
110+
t.Logf("%s\n", pemSignature)
111+
derBlock, _ := pem.Decode(pemSignature)
112+
if derBlock == nil {
113+
t.Fatalf("failed to read DER block from signature PEM %s", tmpSignedFile.Name())
114+
}
115+
p7, err := Parse(derBlock.Bytes)
116+
if err != nil {
117+
t.Fatalf("Parse encountered unexpected error: %v", err)
118+
}
119+
if err := p7.Verify(); err != nil {
120+
t.Fatalf("Verify failed with error: %v", err)
121+
}
122+
os.Remove(tmpSignerCertFile.Name()) // clean up
123+
os.Remove(tmpSignerKeyFile.Name()) // clean up
124+
os.Remove(tmpContentFile.Name()) // clean up
125+
}
126+
127+
var dsaPrivateKey = []byte(`-----BEGIN PRIVATE KEY-----
128+
MIIBSwIBADCCASwGByqGSM44BAEwggEfAoGBAP1/U4EddRIpUt9KnC7s5Of2EbdS
129+
PO9EAMMeP4C2USZpRV1AIlH7WT2NWPq/xfW6MPbLm1Vs14E7gB00b/JmYLdrmVCl
130+
pJ+f6AR7ECLCT7up1/63xhv4O1fnxqimFQ8E+4P208UewwI1VBNaFpEy9nXzrith
131+
1yrv8iIDGZ3RSAHHAhUAl2BQjxUjC8yykrmCouuEC/BYHPUCgYEA9+GghdabPd7L
132+
vKtcNrhXuXmUr7v6OuqC+VdMCz0HgmdRWVeOutRZT+ZxBxCBgLRJFnEj6EwoFhO3
133+
zwkyjMim4TwWeotUfI0o4KOuHiuzpnWRbqN/C/ohNWLx+2J6ASQ7zKTxvqhRkImo
134+
g9/hWuWfBpKLZl6Ae1UlZAFMO/7PSSoEFgIUfW4aPdQBn9gJZp2KuNpzgHzvfsE=
135+
-----END PRIVATE KEY-----`)
136+
137+
var dsaPublicCert = []byte(`-----BEGIN CERTIFICATE-----
138+
MIIDOjCCAvWgAwIBAgIEPCY/UDANBglghkgBZQMEAwIFADBsMRAwDgYDVQQGEwdV
139+
bmtub3duMRAwDgYDVQQIEwdVbmtub3duMRAwDgYDVQQHEwdVbmtub3duMRAwDgYD
140+
VQQKEwdVbmtub3duMRAwDgYDVQQLEwdVbmtub3duMRAwDgYDVQQDEwdVbmtub3du
141+
MB4XDTE4MTAyMjEzNDMwN1oXDTQ2MDMwOTEzNDMwN1owbDEQMA4GA1UEBhMHVW5r
142+
bm93bjEQMA4GA1UECBMHVW5rbm93bjEQMA4GA1UEBxMHVW5rbm93bjEQMA4GA1UE
143+
ChMHVW5rbm93bjEQMA4GA1UECxMHVW5rbm93bjEQMA4GA1UEAxMHVW5rbm93bjCC
144+
AbgwggEsBgcqhkjOOAQBMIIBHwKBgQD9f1OBHXUSKVLfSpwu7OTn9hG3UjzvRADD
145+
Hj+AtlEmaUVdQCJR+1k9jVj6v8X1ujD2y5tVbNeBO4AdNG/yZmC3a5lQpaSfn+gE
146+
exAiwk+7qdf+t8Yb+DtX58aophUPBPuD9tPFHsMCNVQTWhaRMvZ1864rYdcq7/Ii
147+
Axmd0UgBxwIVAJdgUI8VIwvMspK5gqLrhAvwWBz1AoGBAPfhoIXWmz3ey7yrXDa4
148+
V7l5lK+7+jrqgvlXTAs9B4JnUVlXjrrUWU/mcQcQgYC0SRZxI+hMKBYTt88JMozI
149+
puE8FnqLVHyNKOCjrh4rs6Z1kW6jfwv6ITVi8ftiegEkO8yk8b6oUZCJqIPf4Vrl
150+
nwaSi2ZegHtVJWQBTDv+z0kqA4GFAAKBgQDCriMPbEVBoRK4SOUeFwg7+VRf4TTp
151+
rcOQC9IVVoCjXzuWEGrp3ZI7YWJSpFnSch4lk29RH8O0HpI/NOzKnOBtnKr782pt
152+
1k/bJVMH9EaLd6MKnAVjrCDMYBB0MhebZ8QHY2elZZCWoqDYAcIDOsEx+m4NLErT
153+
ypPnjS5M0jm1PKMhMB8wHQYDVR0OBBYEFC0Yt5XdM0Kc95IX8NQ8XRssGPx7MA0G
154+
CWCGSAFlAwQDAgUAAzAAMC0CFQCIgQtrZZ9hdZG1ROhR5hc8nYEmbgIUAIlgC688
155+
qzy/7yePTlhlpj+ahMM=
156+
-----END CERTIFICATE-----`)
157+
158+
type DSATestFixture struct {
159+
Input []byte
160+
Certificate *x509.Certificate
161+
}
162+
163+
func UnmarshalDSATestFixture(testPEMBlock string) DSATestFixture {
164+
var result DSATestFixture
165+
var derBlock *pem.Block
166+
pemBlock := []byte(testPEMBlock)
167+
for {
168+
derBlock, pemBlock = pem.Decode(pemBlock)
169+
if derBlock == nil {
170+
break
171+
}
172+
switch derBlock.Type {
173+
case "PKCS7":
174+
result.Input = derBlock.Bytes
175+
case "CERTIFICATE":
176+
result.Certificate, _ = x509.ParseCertificate(derBlock.Bytes)
177+
}
178+
}
179+
180+
return result
181+
}
Lines changed: 56 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
# Copyright (c) HashiCorp, Inc.
2+
# SPDX-License-Identifier: BUSL-1.1
3+
4+
variable "cluster_id" {
5+
type = string
6+
}
7+
8+
variable "cluster_meta" {
9+
type = string
10+
default = null
11+
}
12+
13+
variable "common_tags" {
14+
type = map(string)
15+
default = null
16+
}
17+
18+
variable "other_resources" {
19+
type = list(string)
20+
default = []
21+
}
22+
23+
locals {
24+
cluster_name = var.cluster_meta == null ? var.cluster_id : "${var.cluster_id}-${var.cluster_meta}"
25+
}
26+
27+
resource "aws_kms_key" "key" {
28+
description = "auto-unseal-key-${local.cluster_name}"
29+
deletion_window_in_days = 7 // 7 is the shortest allowed window
30+
tags = var.common_tags
31+
}
32+
33+
resource "aws_kms_alias" "alias" {
34+
name = "alias/auto-unseal-key-${local.cluster_name}"
35+
target_key_id = aws_kms_key.key.key_id
36+
}
37+
38+
output "alias" {
39+
description = "The key alias name"
40+
value = aws_kms_alias.alias.name
41+
}
42+
43+
output "id" {
44+
description = "The key ID"
45+
value = aws_kms_key.key.key_id
46+
}
47+
48+
output "resource_name" {
49+
description = "The ARN"
50+
value = aws_kms_key.key.arn
51+
}
52+
53+
output "resource_names" {
54+
description = "The list of names"
55+
value = compact(concat([aws_kms_key.key.arn], var.other_resources))
56+
}
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
# Copyright (c) HashiCorp, Inc.
2+
# SPDX-License-Identifier: BUSL-1.1
3+
4+
# A shim unseal key module for shamir seal types
5+
6+
variable "cluster_id" { default = null }
7+
variable "cluster_meta" { default = null }
8+
variable "common_tags" { default = null }
9+
variable "names" {
10+
type = list(string)
11+
default = []
12+
}
13+
14+
output "alias" { value = null }
15+
output "id" { value = null }
16+
output "resource_name" { value = null }
17+
output "resource_names" { value = var.names }
Lines changed: 51 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
# Copyright (c) HashiCorp, Inc.
2+
# SPDX-License-Identifier: BUSL-1.1
3+
4+
locals {
5+
6+
// file name extensions for the install packages of vault for the various architectures, distributions and editions
7+
package_extensions = {
8+
amd64 = {
9+
ubuntu = "-1_amd64.deb"
10+
rhel = "-1.x86_64.rpm"
11+
}
12+
arm64 = {
13+
ubuntu = "-1_arm64.deb"
14+
rhel = "-1.aarch64.rpm"
15+
}
16+
}
17+
18+
// product_version --> artifact_version
19+
artifact_version = replace(var.product_version, var.edition, "ent")
20+
21+
// file name prefixes for the install packages of vault for the various distributions and artifact types (package or bundle)
22+
artifact_package_release_names = {
23+
ubuntu = {
24+
"ce" = "vault_"
25+
"ent" = "vault-enterprise_",
26+
"ent.fips1402" = "vault-enterprise-fips1402_",
27+
"ent.hsm" = "vault-enterprise-hsm_",
28+
"ent.hsm.fips1402" = "vault-enterprise-hsm-fips1402_",
29+
},
30+
rhel = {
31+
"ce" = "vault-"
32+
"ent" = "vault-enterprise-",
33+
"ent.fips1402" = "vault-enterprise-fips1402-",
34+
"ent.hsm" = "vault-enterprise-hsm-",
35+
"ent.hsm.fips1402" = "vault-enterprise-hsm-fips1402-",
36+
}
37+
}
38+
39+
// edition --> artifact name edition
40+
artifact_name_edition = {
41+
"ce" = ""
42+
"ent" = ""
43+
"ent.hsm" = ".hsm"
44+
"ent.fips1402" = ".fips1402"
45+
"ent.hsm.fips1402" = ".hsm.fips1402"
46+
}
47+
48+
artifact_name_prefix = var.artifact_type == "package" ? local.artifact_package_release_names[var.distro][var.edition] : "vault_"
49+
artifact_name_extension = var.artifact_type == "package" ? local.package_extensions[var.arch][var.distro] : "_linux_${var.arch}.zip"
50+
artifact_name = var.artifact_type == "package" ? "${local.artifact_name_prefix}${replace(local.artifact_version, "-", "~")}${local.artifact_name_extension}" : "${local.artifact_name_prefix}${var.product_version}${local.artifact_name_extension}"
51+
}
Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
# Copyright (c) HashiCorp, Inc.
2+
# SPDX-License-Identifier: BUSL-1.1
3+
4+
terraform {
5+
required_providers {
6+
enos = {
7+
source = "app.terraform.io/hashicorp-qti/enos"
8+
version = ">= 0.2.3"
9+
}
10+
}
11+
}
12+
13+
data "enos_artifactory_item" "vault" {
14+
username = var.artifactory_username
15+
token = var.artifactory_token
16+
name = local.artifact_name
17+
host = var.artifactory_host
18+
repo = var.artifactory_repo
19+
path = var.edition == "ce" ? "vault/*" : "vault-enterprise/*"
20+
properties = tomap({
21+
"commit" = var.revision
22+
"product-name" = var.edition == "ce" ? "vault" : "vault-enterprise"
23+
"product-version" = local.artifact_version
24+
})
25+
}
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
# Copyright (c) HashiCorp, Inc.
2+
# SPDX-License-Identifier: BUSL-1.1
3+
4+
5+
output "url" {
6+
value = data.enos_artifactory_item.vault.results[0].url
7+
description = "The artifactory download url for the artifact"
8+
}
9+
10+
output "sha256" {
11+
value = data.enos_artifactory_item.vault.results[0].sha256
12+
description = "The sha256 checksum for the artifact"
13+
}
14+
15+
output "size" {
16+
value = data.enos_artifactory_item.vault.results[0].size
17+
description = "The size in bytes of the artifact"
18+
}
19+
20+
output "name" {
21+
value = data.enos_artifactory_item.vault.results[0].name
22+
description = "The name of the artifact"
23+
}
24+
25+
output "vault_artifactory_release" {
26+
value = {
27+
url = data.enos_artifactory_item.vault.results[0].url
28+
sha256 = data.enos_artifactory_item.vault.results[0].sha256
29+
username = var.artifactory_username
30+
token = var.artifactory_token
31+
}
32+
}

0 commit comments

Comments
 (0)