Files
orchard/internal/config/context.go
T
Nikolay Edigaryev dcc954631b TLS improvements (#90)
* Fix typo when passing arguments to tls.LoadX509KeyPair()

* Support TLS 1.2 too

* Do not require a controller to only present a single certificate

* No need to set ServerName since we use InsecureSkipVerify

* Use host's root CA set by default and support normal SNI scenarios
2023-06-07 15:31:55 +04:00

35 lines
866 B
Go

package config
import (
"crypto/x509"
"encoding/pem"
"fmt"
)
type Context struct {
URL string `yaml:"url,omitempty"`
Certificate Base64 `yaml:"certificate,omitempty"`
ServiceAccountName string `yaml:"serviceAccountName,omitempty"`
ServiceAccountToken string `yaml:"serviceAccountToken,omitempty"`
}
func (context *Context) TrustedCertificate() (*x509.Certificate, error) {
if len(context.Certificate) == 0 {
return nil, nil
}
block, _ := pem.Decode(context.Certificate)
if block == nil {
return nil, fmt.Errorf("%w: failed to load context's certificate: no PEM data found",
ErrConfigReadFailed)
}
trustedCertificate, err := x509.ParseCertificate(block.Bytes)
if err != nil {
return nil, fmt.Errorf("%w: failed to load context's certificate: %v",
ErrConfigReadFailed, err)
}
return trustedCertificate, nil
}