aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorelijah <elijah@riseup.net>2013-07-24 13:03:02 -0700
committerelijah <elijah@riseup.net>2013-07-24 13:03:02 -0700
commit35de71be644343abc5f16a15e671fff8c94910ab (patch)
treec55b3bf5c0506d7da5004e29c3bf6ae358a27d3c
parentb2b537b0961a2f41b0da00ddedf904602ece81dc (diff)
downloadleap_cli-35de71be644343abc5f16a15e671fff8c94910ab.tar.gz
leap_cli-35de71be644343abc5f16a15e671fff8c94910ab.tar.bz2
allow provider to include country, state, and locality in the CSR.
-rw-r--r--lib/leap_cli/commands/ca.rb14
1 files changed, 10 insertions, 4 deletions
diff --git a/lib/leap_cli/commands/ca.rb b/lib/leap_cli/commands/ca.rb
index b5a8765..b3d0a9d 100644
--- a/lib/leap_cli/commands/ca.rb
+++ b/lib/leap_cli/commands/ca.rb
@@ -93,22 +93,28 @@ module LeapCli; module Commands
domain = options[:domain] || provider.domain
assert_files_missing! [:commercial_key, domain], [:commercial_csr, domain], :msg => 'If you really want to create a new key and CSR, remove these files first.'
+ server_certificates = provider.ca.server_certificates
+
# RSA key
keypair = CertificateAuthority::MemoryKeyMaterial.new
- log :generating, "%s bit RSA key" % provider.ca.server_certificates.bit_size do
- keypair.generate_key(provider.ca.server_certificates.bit_size)
+ log :generating, "%s bit RSA key" % server_certificates.bit_size do
+ keypair.generate_key(server_certificates.bit_size)
write_file! [:commercial_key, domain], keypair.private_key.to_pem
end
# CSR
dn = CertificateAuthority::DistinguishedName.new
csr = CertificateAuthority::SigningRequest.new
- dn.common_name = domain
+ dn.common_name = domain
dn.organization = provider.name[provider.default_language]
+ dn.country = server_certificates['country'] # optional
+ dn.state = server_certificates['state'] # optional
+ dn.locality = server_certificates['locality'] # optional
+
log :generating, "CSR with commonName => '%s', organization => '%s'" % [dn.common_name, dn.organization] do
csr.distinguished_name = dn
csr.key_material = keypair
- csr.digest = provider.ca.server_certificates.digest
+ csr.digest = server_certificates.digest
request = csr.to_x509_csr
write_file! [:commercial_csr, domain], csr.to_pem
end