Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 2 additions & 10 deletions .github/workflows/keyfactor-bootstrap-workflow.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,17 +11,9 @@ on:

jobs:
call-starter-workflow:
uses: keyfactor/actions/.github/workflows/starter.yml@v5
with:
command_token_url: ${{ vars.COMMAND_TOKEN_URL }}
command_hostname: ${{ vars.COMMAND_HOSTNAME }}
command_base_api_path: ${{ vars.COMMAND_API_PATH }}
uses: keyfactor/actions/.github/workflows/starter.yml@v3
secrets:
token: ${{ secrets.V2BUILDTOKEN}}
APPROVE_README_PUSH: ${{ secrets.APPROVE_README_PUSH}}
gpg_key: ${{ secrets.KF_GPG_PRIVATE_KEY }}
gpg_pass: ${{ secrets.KF_GPG_PASSPHRASE }}
scan_token: ${{ secrets.SAST_TOKEN }}
entra_username: ${{ secrets.DOCTOOL_ENTRA_USERNAME }}
entra_password: ${{ secrets.DOCTOOL_ENTRA_PASSWD }}
command_client_id: ${{ secrets.COMMAND_CLIENT_ID }}
command_client_secret: ${{ secrets.COMMAND_CLIENT_SECRET }}
30 changes: 0 additions & 30 deletions AcmeCaPlugin.sln
Original file line number Diff line number Diff line change
Expand Up @@ -10,52 +10,22 @@ EndProject
Global
GlobalSection(SolutionConfigurationPlatforms) = preSolution
Debug|Any CPU = Debug|Any CPU
Debug|x64 = Debug|x64
Debug|x86 = Debug|x86
Prerelease|Any CPU = Prerelease|Any CPU
Prerelease|x64 = Prerelease|x64
Prerelease|x86 = Prerelease|x86
Release|Any CPU = Release|Any CPU
Release|x64 = Release|x64
Release|x86 = Release|x86
EndGlobalSection
GlobalSection(ProjectConfigurationPlatforms) = postSolution
{011DC646-BEF9-4D3B-9D20-CA444A26B355}.Debug|Any CPU.ActiveCfg = Debug|Any CPU
{011DC646-BEF9-4D3B-9D20-CA444A26B355}.Debug|Any CPU.Build.0 = Debug|Any CPU
{011DC646-BEF9-4D3B-9D20-CA444A26B355}.Debug|x64.ActiveCfg = Debug|Any CPU
{011DC646-BEF9-4D3B-9D20-CA444A26B355}.Debug|x64.Build.0 = Debug|Any CPU
{011DC646-BEF9-4D3B-9D20-CA444A26B355}.Debug|x86.ActiveCfg = Debug|Any CPU
{011DC646-BEF9-4D3B-9D20-CA444A26B355}.Debug|x86.Build.0 = Debug|Any CPU
{011DC646-BEF9-4D3B-9D20-CA444A26B355}.Prerelease|Any CPU.ActiveCfg = Release|Any CPU
{011DC646-BEF9-4D3B-9D20-CA444A26B355}.Prerelease|Any CPU.Build.0 = Release|Any CPU
{011DC646-BEF9-4D3B-9D20-CA444A26B355}.Prerelease|x64.ActiveCfg = Prerelease|Any CPU
{011DC646-BEF9-4D3B-9D20-CA444A26B355}.Prerelease|x64.Build.0 = Prerelease|Any CPU
{011DC646-BEF9-4D3B-9D20-CA444A26B355}.Prerelease|x86.ActiveCfg = Prerelease|Any CPU
{011DC646-BEF9-4D3B-9D20-CA444A26B355}.Prerelease|x86.Build.0 = Prerelease|Any CPU
{011DC646-BEF9-4D3B-9D20-CA444A26B355}.Release|Any CPU.ActiveCfg = Release|Any CPU
{011DC646-BEF9-4D3B-9D20-CA444A26B355}.Release|Any CPU.Build.0 = Release|Any CPU
{011DC646-BEF9-4D3B-9D20-CA444A26B355}.Release|x64.ActiveCfg = Release|Any CPU
{011DC646-BEF9-4D3B-9D20-CA444A26B355}.Release|x64.Build.0 = Release|Any CPU
{011DC646-BEF9-4D3B-9D20-CA444A26B355}.Release|x86.ActiveCfg = Release|Any CPU
{011DC646-BEF9-4D3B-9D20-CA444A26B355}.Release|x86.Build.0 = Release|Any CPU
{F45D27E5-26B8-435B-AC49-5A119094BFD3}.Debug|Any CPU.ActiveCfg = Debug|Any CPU
{F45D27E5-26B8-435B-AC49-5A119094BFD3}.Debug|Any CPU.Build.0 = Debug|Any CPU
{F45D27E5-26B8-435B-AC49-5A119094BFD3}.Debug|x64.ActiveCfg = Debug|Any CPU
{F45D27E5-26B8-435B-AC49-5A119094BFD3}.Debug|x64.Build.0 = Debug|Any CPU
{F45D27E5-26B8-435B-AC49-5A119094BFD3}.Debug|x86.ActiveCfg = Debug|Any CPU
{F45D27E5-26B8-435B-AC49-5A119094BFD3}.Debug|x86.Build.0 = Debug|Any CPU
{F45D27E5-26B8-435B-AC49-5A119094BFD3}.Prerelease|Any CPU.ActiveCfg = Debug|Any CPU
{F45D27E5-26B8-435B-AC49-5A119094BFD3}.Prerelease|Any CPU.Build.0 = Debug|Any CPU
{F45D27E5-26B8-435B-AC49-5A119094BFD3}.Prerelease|x64.ActiveCfg = Prerelease|Any CPU
{F45D27E5-26B8-435B-AC49-5A119094BFD3}.Prerelease|x64.Build.0 = Prerelease|Any CPU
{F45D27E5-26B8-435B-AC49-5A119094BFD3}.Prerelease|x86.ActiveCfg = Prerelease|Any CPU
{F45D27E5-26B8-435B-AC49-5A119094BFD3}.Prerelease|x86.Build.0 = Prerelease|Any CPU
{F45D27E5-26B8-435B-AC49-5A119094BFD3}.Release|Any CPU.ActiveCfg = Release|Any CPU
{F45D27E5-26B8-435B-AC49-5A119094BFD3}.Release|Any CPU.Build.0 = Release|Any CPU
{F45D27E5-26B8-435B-AC49-5A119094BFD3}.Release|x64.ActiveCfg = Release|Any CPU
{F45D27E5-26B8-435B-AC49-5A119094BFD3}.Release|x64.Build.0 = Release|Any CPU
{F45D27E5-26B8-435B-AC49-5A119094BFD3}.Release|x86.ActiveCfg = Release|Any CPU
{F45D27E5-26B8-435B-AC49-5A119094BFD3}.Release|x86.Build.0 = Release|Any CPU
EndGlobalSection
GlobalSection(SolutionProperties) = preSolution
HideSolutionNode = FALSE
Expand Down
489 changes: 114 additions & 375 deletions AcmeCaPlugin/AcmeCaPlugin.cs

Large diffs are not rendered by default.

19 changes: 12 additions & 7 deletions AcmeCaPlugin/AcmeCaPlugin.csproj
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
<Project Sdk="Microsoft.NET.Sdk">
<PropertyGroup>
<TargetFrameworks>net10.0</TargetFrameworks>
<TargetFrameworks>net6.0;net8.0;net10.0</TargetFrameworks>
<ImplicitUsings>disable</ImplicitUsings>
<Nullable>disable</Nullable>
<CopyLocalLockFileAssemblies>true</CopyLocalLockFileAssemblies>
Expand All @@ -9,21 +9,26 @@
<AssemblyName>AcmeCaPlugin</AssemblyName>
</PropertyGroup>
<ItemGroup>
<!-- Core ACME and CA Plugin dependencies -->
<PackageReference Include="ACMESharpCore" Version="2.2.0.148" />
<PackageReference Include="Autofac" Version="8.3.0" />
<PackageReference Include="AWSSDK.Core" Version="4.0.3.10" />
<PackageReference Include="AWSSDK.Route53" Version="4.0.8.8" />
<PackageReference Include="Azure.Identity" Version="1.17.1" />
<PackageReference Include="Azure.ResourceManager.Cdn" Version="1.4.0" />
<PackageReference Include="Azure.ResourceManager.Dns" Version="1.1.1" />
<PackageReference Include="BouncyCastle.Cryptography" Version="2.6.2" />
<PackageReference Include="DnsClient" Version="1.8.0" />
<PackageReference Include="Keyfactor.AnyGateway.IAnyCAPlugin" Version="3.3.0" />
<PackageReference Include="Keyfactor.Logging" Version="1.3.0" />
<PackageReference Include="Keyfactor.PKI" Version="8.3.1" />
<PackageReference Include="ARSoft.Tools.Net" Version="3.6.0" />
<PackageReference Include="Google.Apis.Dns.v1" Version="1.69.0.3753" />
<PackageReference Include="Keyfactor.AnyGateway.IAnyCAPlugin" Version="3.1.0" />
<PackageReference Include="Keyfactor.Logging" Version="1.1.1" />
<PackageReference Include="Keyfactor.PKI" Version="5.5.0" />
<PackageReference Include="Microsoft.Extensions.Http" Version="9.0.5" />
<PackageReference Include="Nager.PublicSuffix" Version="3.5.0" />
<PackageReference Include="Newtonsoft.Json" Version="13.0.3" />
<PackageReference Include="System.Drawing.Common" Version="10.0.2" />
<PackageReference Include="System.Net.Http.WinHttpHandler" Version="9.0.5" />
<PackageReference Include="System.Security.Cryptography.ProtectedData" Version="9.0.5" />
<!-- DnsClient (above) is used for CNAME delegation resolution and TXT propagation checks.
DNS provider SDKs now live in their own externalized DNS provider plugins. -->
</ItemGroup>
<ItemGroup>
<None Update="manifest.json">
Expand Down
186 changes: 181 additions & 5 deletions AcmeCaPlugin/AcmeCaPluginConfig.cs
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
using Keyfactor.AnyGateway.Extensions;
using Keyfactor.AnyGateway.Extensions;
using System.Collections.Generic;

namespace Keyfactor.Extensions.CAPlugin.Acme
Expand Down Expand Up @@ -51,6 +51,37 @@ public static Dictionary<string, PropertyConfigInfo> GetPluginAnnotations()
DefaultValue = "",
Type = "Secret"
},
["DnsProvider"] = new PropertyConfigInfo()
{
Comments = "DNS Provider to use for ACME DNS-01 challenges (options: Google, Cloudflare, AwsRoute53, Azure, Ns1, Rfc2136, Infoblox)",
Hidden = false,
DefaultValue = "Google",
Type = "String"
},

// Google DNS
["Google_ServiceAccountKeyPath"] = new PropertyConfigInfo()
{
Comments = "Google Cloud DNS: Path to service account JSON key file only if using Google DNS (Optional)",
Hidden = false,
DefaultValue = "",
Type = "String"
},
["Google_ServiceAccountKeyJson"] = new PropertyConfigInfo()
{
Comments = "Google Cloud DNS: Service account JSON key content (alternative to file path for containerized deployments)",
Hidden = true,
DefaultValue = "",
Type = "Secret"
},
["Google_ProjectId"] = new PropertyConfigInfo()
{
Comments = "Google Cloud DNS: Project ID only if using Google DNS (Optional)",
Hidden = false,
DefaultValue = "",
Type = "String"
},

// Container Deployment
["AccountStoragePath"] = new PropertyConfigInfo()
{
Expand All @@ -60,14 +91,111 @@ public static Dictionary<string, PropertyConfigInfo> GetPluginAnnotations()
Type = "String"
},

// DNS Propagation Settings
["DnsPropagationDelaySeconds"] = new PropertyConfigInfo()
// Cloudflare DNS
["Cloudflare_ApiToken"] = new PropertyConfigInfo()
{
Comments = "Cloudflare DNS: API Token only if using Cloudflare DNS (Optional)",
Hidden = true,
DefaultValue = "",
Type = "Secret"
},

// Azure DNS
["Azure_ClientId"] = new PropertyConfigInfo()
{
Comments = "Azure DNS: ClientId only if using Azure DNS and Not Managed Itentity in Azure (Optional)",
Hidden = false,
DefaultValue = "",
Type = "Secret"
},
["Azure_ClientSecret"] = new PropertyConfigInfo()
{
Comments = "Azure DNS: ClientSecret only if using Azure DNS and Not Managed Itentity in Azure (Optional)",
Hidden = true,
DefaultValue = "",
Type = "Secret"
},
["Azure_SubscriptionId"] = new PropertyConfigInfo()
{
Comments = "Azure DNS: SubscriptionId only if using Azure DNS and Not Managed Itentity in Azure (Optional)",
Hidden = false,
DefaultValue = "",
Type = "String"
},
["Azure_TenantId"] = new PropertyConfigInfo()
{
Comments = "Azure DNS: TenantId only if using Azure DNS and Not Managed Itentity in Azure (Optional)",
Hidden = false,
DefaultValue = "",
Type = "String"
},
["AwsRoute53_AccessKey"] = new PropertyConfigInfo()
{
Comments = "Time in seconds to wait after creating DNS records before checking propagation. Set to 0 to skip the delay.",
Comments = "Aws DNS: Access Key only if not using AWS DNS and default AWS Chain Creds on AWS (Optional)",
Hidden = false,
DefaultValue = "60",
DefaultValue = "",
Type = "String"
},
["AwsRoute53_SecretKey"] = new PropertyConfigInfo()
{
Comments = "Aws DNS: Secret Key only if using AWS DNS and not using default AWS Chain Creds on AWS (Optional)",
Hidden = true,
DefaultValue = "",
Type = "Secret"
}
//IBM NS1 DNS
,
["Ns1_ApiKey"] = new PropertyConfigInfo()
{
Comments = "Ns1 DNS: Api Key only if Using Ns1 DNS (Optional)",
Hidden = true,
DefaultValue = "",
Type = "String"
},

// RFC 2136 Dynamic DNS (BIND/Microsoft DNS)
["Rfc2136_Server"] = new PropertyConfigInfo()
{
Comments = "RFC 2136 DNS: Server hostname or IP address (Optional)",
Hidden = false,
DefaultValue = "",
Type = "String"
},
["Rfc2136_Port"] = new PropertyConfigInfo()
{
Comments = "RFC 2136 DNS: Server port (default 53) (Optional)",
Hidden = false,
DefaultValue = "53",
Type = "Number"
},
["Rfc2136_Zone"] = new PropertyConfigInfo()
{
Comments = "RFC 2136 DNS: Zone name (e.g., example.com) (Optional)",
Hidden = false,
DefaultValue = "",
Type = "String"
},
["Rfc2136_TsigKeyName"] = new PropertyConfigInfo()
{
Comments = "RFC 2136 DNS: TSIG key name for authentication (Optional)",
Hidden = false,
DefaultValue = "",
Type = "String"
},
["Rfc2136_TsigKey"] = new PropertyConfigInfo()
{
Comments = "RFC 2136 DNS: TSIG key (base64 encoded) for authentication (Optional)",
Hidden = true,
DefaultValue = "",
Type = "Secret"
},
["Rfc2136_TsigAlgorithm"] = new PropertyConfigInfo()
{
Comments = "RFC 2136 DNS: TSIG algorithm (default hmac-sha256) (Optional)",
Hidden = false,
DefaultValue = "hmac-sha256",
Type = "String"
},

// DNS Verification Settings
["DnsVerificationServer"] = new PropertyConfigInfo()
Expand All @@ -78,6 +206,54 @@ public static Dictionary<string, PropertyConfigInfo> GetPluginAnnotations()
Type = "String"
}

//Infoblox DNS
,
["Infoblox_Host"] = new PropertyConfigInfo()
{
Comments = "Infoblox DNS: API URL (e.g., https://infoblox.example.com/wapi/v2.12) only if using Infoblox DNS (Optional)",
Hidden = false,
DefaultValue = "",
Type = "String"
},
["Infoblox_Username"] = new PropertyConfigInfo()
{
Comments = "Infoblox DNS: Username for authentication only if using Infoblox DNS (Optional)",
Hidden = false,
DefaultValue = "",
Type = "String"
},
["Infoblox_Password"] = new PropertyConfigInfo()
{
Comments = "Infoblox DNS: Password for authentication only if using Infoblox DNS (Optional)",
Hidden = true,
DefaultValue = "",
Type = "Secret"
}

//Infoblox DNS
,
["Infoblox_Host"] = new PropertyConfigInfo()
{
Comments = "Infoblox DNS: API URL (e.g., https://infoblox.example.com/wapi/v2.12) only if using Infoblox DNS (Optional)",
Hidden = false,
DefaultValue = "",
Type = "String"
},
["Infoblox_Username"] = new PropertyConfigInfo()
{
Comments = "Infoblox DNS: Username for authentication only if using Infoblox DNS (Optional)",
Hidden = false,
DefaultValue = "",
Type = "String"
},
["Infoblox_Password"] = new PropertyConfigInfo()
{
Comments = "Infoblox DNS: Password for authentication only if using Infoblox DNS (Optional)",
Hidden = true,
DefaultValue = "",
Type = "Secret"
}

};
}

Expand Down
46 changes: 42 additions & 4 deletions AcmeCaPlugin/AcmeClientConfig.cs
Original file line number Diff line number Diff line change
@@ -1,4 +1,6 @@
namespace Keyfactor.Extensions.CAPlugin.Acme
using Amazon;

namespace Keyfactor.Extensions.CAPlugin.Acme
{
public class AcmeClientConfig
{
Expand All @@ -9,13 +11,49 @@ public class AcmeClientConfig
public string EabHmacKey { get; set; } = null;
public string SignerEncryptionPhrase{ get; set; } = null;

// Chosen DNS Provider
public string DnsProvider { get; set; } = null;

// Google Cloud DNS
public string Google_ServiceAccountKeyPath { get; set; } = null;
public string Google_ServiceAccountKeyJson { get; set; } = null;
public string Google_ProjectId { get; set; } = null;

// Cloudflare DNS
public string Cloudflare_ApiToken { get; set; } = null;


// Azure DNS
public string Azure_ClientId { get; set; } = null;
public string Azure_ClientSecret { get; set; } = null;
public string Azure_SubscriptionId { get; set; } = null;
public string Azure_TenantId { get; set; } = null;

// AWS Route53
public string AwsRoute53_AccessKey { get; set; } = null;
public string AwsRoute53_SecretKey { get; set; } = null;

//IBM NS1 DNS Ns1_ApiKey
public string Ns1_ApiKey { get; set; } = null;

// Container Deployment Support
public string AccountStoragePath { get; set; } = null;
// RFC 2136 Dynamic DNS (BIND)
public string Rfc2136_Server { get; set; } = null;
public int Rfc2136_Port { get; set; } = 53;
public string Rfc2136_Zone { get; set; } = null;
public string Rfc2136_TsigKeyName { get; set; } = null;
public string Rfc2136_TsigKey { get; set; } = null;
public string Rfc2136_TsigAlgorithm { get; set; } = "hmac-sha256";

// DNS Propagation Delay (in seconds) - wait this long after creating DNS records before checking propagation
public int DnsPropagationDelaySeconds { get; set; } = 60;
// Infoblox DNS
public string Infoblox_Host { get; set; } = null;
public string Infoblox_Username { get; set; } = null;
public string Infoblox_Password { get; set; } = null;
public string Infoblox_WapiVersion { get; set; } = "2.12";
public bool Infoblox_IgnoreSslErrors { get; set; } = false;

// DNS Verification Settings - DNS server IP for verification (for private zones)
// DNS Verification Settings
public string DnsVerificationServer { get; set; } = null;

}
Expand Down
Loading
Loading