Skip to content

Commit ded1861

Browse files
authored
Allow input from stdin for 'certificate fingerprint' command (#1270)
1 parent 33edf23 commit ded1861

File tree

3 files changed

+123
-115
lines changed

3 files changed

+123
-115
lines changed

command/certificate/fingerprint.go

Lines changed: 22 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,9 @@ import (
88
//nolint:gosec // support for sha1 fingerprints
99
_ "crypto/sha1"
1010

11+
"github.com/pkg/errors"
1112
"github.com/smallstep/cli/flags"
13+
"github.com/smallstep/cli/utils"
1214
"github.com/urfave/cli"
1315
"go.step.sm/cli-utils/errs"
1416
"go.step.sm/crypto/fingerprint"
@@ -99,21 +101,26 @@ debugging invalid certificates remotely.`,
99101
}
100102

101103
func fingerprintAction(ctx *cli.Context) error {
102-
if err := errs.NumberOfArguments(ctx, 1); err != nil {
104+
if err := errs.MinMaxNumberOfArguments(ctx, 0, 1); err != nil {
103105
return err
104106
}
105107

106108
var (
109+
crtFile = ctx.Args().Get(0)
107110
certs []*x509.Certificate
108111
serverName = ctx.String("servername")
109112
roots = ctx.String("roots")
110113
bundle = ctx.Bool("bundle")
111114
insecure = ctx.Bool("insecure")
112-
crtFile = ctx.Args().First()
113115
format = ctx.String("format")
114116
useSHA1 = ctx.Bool("sha1")
115117
)
116118

119+
// Use stdin if no argument is used.
120+
if crtFile == "" {
121+
crtFile = "-"
122+
}
123+
117124
if useSHA1 && !insecure {
118125
return errs.RequiredInsecureFlag(ctx, "sha")
119126
}
@@ -132,17 +139,24 @@ func fingerprintAction(ctx *cli.Context) error {
132139
return err
133140
}
134141
default:
135-
certs, err = pemutil.ReadCertificateBundle(crtFile)
142+
b, err := utils.ReadFile(crtFile)
136143
if err != nil {
137-
// Fallback to parse a CSR
138-
csr, csrErr := pemutil.ReadCertificateRequest(crtFile)
139-
if csrErr != nil {
140-
return err
144+
return errors.Wrapf(err, "error reading file %s", crtFile)
145+
}
146+
147+
var pemError *pemutil.InvalidPEMError
148+
certs, err = pemutil.ParseCertificateBundle(b)
149+
switch {
150+
case errors.As(err, &pemError) && pemError.Type == pemutil.PEMTypeCertificate:
151+
csr, err := pemutil.ParseCertificateRequest(b)
152+
if err != nil {
153+
return errors.Errorf("file %s does not contain any valid CERTIFICATE or CERTIFICATE REQUEST blocks", crtFile)
141154
}
142-
// We will only need the raw DER bytes to generate a fingerprint.
143155
certs = []*x509.Certificate{
144156
{Raw: csr.Raw},
145157
}
158+
case err != nil:
159+
return fmt.Errorf("error parsing %s: %w", crtFile, err)
146160
}
147161
}
148162

go.mod

Lines changed: 33 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ require (
1616
github.com/pquerna/otp v1.4.0
1717
github.com/slackhq/nebula v1.9.3
1818
github.com/smallstep/assert v0.0.0-20200723003110-82e2b9b3b262
19-
github.com/smallstep/certificates v0.27.2
19+
github.com/smallstep/certificates v0.27.3-0.20240912083530-c118a2a15439
2020
github.com/smallstep/certinfo v1.12.2
2121
github.com/smallstep/go-attestation v0.4.4-0.20240109183208-413678f90935
2222
github.com/smallstep/truststore v0.13.0
@@ -37,12 +37,13 @@ require (
3737

3838
require (
3939
cloud.google.com/go v0.115.1 // indirect
40-
cloud.google.com/go/auth v0.9.1 // indirect
40+
cloud.google.com/go/auth v0.9.3 // indirect
4141
cloud.google.com/go/auth/oauth2adapt v0.2.4 // indirect
4242
cloud.google.com/go/compute/metadata v0.5.0 // indirect
43-
cloud.google.com/go/iam v1.1.13 // indirect
44-
cloud.google.com/go/longrunning v0.5.12 // indirect
45-
cloud.google.com/go/security v1.17.4 // indirect
43+
cloud.google.com/go/iam v1.2.0 // indirect
44+
cloud.google.com/go/longrunning v0.6.0 // indirect
45+
cloud.google.com/go/security v1.18.0 // indirect
46+
dario.cat/mergo v1.0.1 // indirect
4647
filippo.io/edwards25519 v1.1.0 // indirect
4748
github.com/AndreasBriese/bbloom v0.0.0-20190825152654-46b345b51c96 // indirect
4849
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.14.0 // indirect
@@ -52,14 +53,15 @@ require (
5253
github.com/Azure/azure-sdk-for-go/sdk/keyvault/internal v0.7.1 // indirect
5354
github.com/AzureAD/microsoft-authentication-library-for-go v1.2.2 // indirect
5455
github.com/Masterminds/goutils v1.1.1 // indirect
55-
github.com/Masterminds/semver/v3 v3.2.0 // indirect
56-
github.com/Masterminds/sprig/v3 v3.2.3 // indirect
56+
github.com/Masterminds/semver/v3 v3.3.0 // indirect
57+
github.com/Masterminds/sprig/v3 v3.3.0 // indirect
5758
github.com/asaskevich/govalidator v0.0.0-20210307081110-f21760c49a8d // indirect
5859
github.com/beorn7/perks v1.0.1 // indirect
5960
github.com/boombuler/barcode v1.0.1 // indirect
6061
github.com/cespare/xxhash v1.1.0 // indirect
6162
github.com/cespare/xxhash/v2 v2.3.0 // indirect
6263
github.com/chzyer/readline v1.5.1 // indirect
64+
github.com/coreos/go-oidc/v3 v3.11.0 // indirect
6365
github.com/corpix/uarand v0.2.0 // indirect
6466
github.com/cpuguy83/go-md2man/v2 v2.0.4 // indirect
6567
github.com/creack/pty v1.1.18 // indirect
@@ -71,6 +73,7 @@ require (
7173
github.com/dustin/go-humanize v1.0.1 // indirect
7274
github.com/felixge/httpsnoop v1.0.4 // indirect
7375
github.com/go-chi/chi/v5 v5.1.0 // indirect
76+
github.com/go-jose/go-jose/v4 v4.0.2 // indirect
7477
github.com/go-kit/kit v0.13.0 // indirect
7578
github.com/go-kit/log v0.2.1 // indirect
7679
github.com/go-logfmt/logfmt v0.6.0 // indirect
@@ -87,61 +90,61 @@ require (
8790
github.com/google/go-tpm-tools v0.4.4 // indirect
8891
github.com/google/go-tspi v0.3.0 // indirect
8992
github.com/google/s2a-go v0.1.8 // indirect
90-
github.com/googleapis/enterprise-certificate-proxy v0.3.2 // indirect
93+
github.com/googleapis/enterprise-certificate-proxy v0.3.3 // indirect
9194
github.com/googleapis/gax-go/v2 v2.13.0 // indirect
92-
github.com/huandu/xstrings v1.4.0 // indirect
93-
github.com/imdario/mergo v0.3.13 // indirect
95+
github.com/huandu/xstrings v1.5.0 // indirect
9496
github.com/jackc/pgpassfile v1.0.0 // indirect
9597
github.com/jackc/pgservicefile v0.0.0-20221227161230-091c0ba34f0a // indirect
9698
github.com/jackc/pgx/v5 v5.6.0 // indirect
9799
github.com/jackc/puddle/v2 v2.2.1 // indirect
98100
github.com/kballard/go-shellquote v0.0.0-20180428030007-95032a82bc51 // indirect
99-
github.com/klauspost/compress v1.16.3 // indirect
101+
github.com/klauspost/compress v1.17.9 // indirect
100102
github.com/kr/pty v1.1.8 // indirect
101103
github.com/kylelemons/godebug v1.1.0 // indirect
102104
github.com/mattn/go-colorable v0.1.13 // indirect
103105
github.com/mattn/go-isatty v0.0.20 // indirect
104106
github.com/mgutz/ansi v0.0.0-20200706080929-d51e80ef957d // indirect
105107
github.com/mitchellh/copystructure v1.2.0 // indirect
106108
github.com/mitchellh/reflectwalk v1.0.2 // indirect
107-
github.com/newrelic/go-agent/v3 v3.33.1 // indirect
109+
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
110+
github.com/newrelic/go-agent/v3 v3.34.0 // indirect
108111
github.com/peterbourgon/diskv/v3 v3.0.1 // indirect
109112
github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect
110113
github.com/pmezard/go-difflib v1.0.0 // indirect
111-
github.com/prometheus/client_golang v1.19.1 // indirect
112-
github.com/prometheus/client_model v0.5.0 // indirect
113-
github.com/prometheus/common v0.48.0 // indirect
114-
github.com/prometheus/procfs v0.12.0 // indirect
115-
github.com/rs/xid v1.5.0 // indirect
114+
github.com/prometheus/client_golang v1.20.3 // indirect
115+
github.com/prometheus/client_model v0.6.1 // indirect
116+
github.com/prometheus/common v0.55.0 // indirect
117+
github.com/prometheus/procfs v0.15.1 // indirect
118+
github.com/rs/xid v1.6.0 // indirect
116119
github.com/russross/blackfriday/v2 v2.1.0 // indirect
117120
github.com/schollz/jsonstore v1.1.0 // indirect
118-
github.com/shopspring/decimal v1.3.1 // indirect
121+
github.com/shopspring/decimal v1.4.0 // indirect
119122
github.com/shurcooL/sanitized_anchor_name v1.0.0 // indirect
120123
github.com/sirupsen/logrus v1.9.3 // indirect
121124
github.com/smallstep/nosql v0.7.0 // indirect
122125
github.com/smallstep/pkcs7 v0.0.0-20231024181729-3b98ecc1ca81 // indirect
123126
github.com/smallstep/scep v0.0.0-20231024192529-aee96d7ad34d // indirect
124-
github.com/spf13/cast v1.5.0 // indirect
127+
github.com/spf13/cast v1.7.0 // indirect
125128
github.com/weppos/publicsuffix-go v0.20.0 // indirect
126129
github.com/x448/float16 v0.8.4 // indirect
127130
go.etcd.io/bbolt v1.3.10 // indirect
128131
go.opencensus.io v0.24.0 // indirect
129-
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.52.0 // indirect
130-
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.53.0 // indirect
131-
go.opentelemetry.io/otel v1.28.0 // indirect
132-
go.opentelemetry.io/otel/metric v1.28.0 // indirect
133-
go.opentelemetry.io/otel/trace v1.28.0 // indirect
132+
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.54.0 // indirect
133+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.54.0 // indirect
134+
go.opentelemetry.io/otel v1.29.0 // indirect
135+
go.opentelemetry.io/otel/metric v1.29.0 // indirect
136+
go.opentelemetry.io/otel/trace v1.29.0 // indirect
134137
golang.org/x/exp v0.0.0-20240318143956-a85f2c67cd81 // indirect
135-
golang.org/x/net v0.28.0 // indirect
138+
golang.org/x/net v0.29.0 // indirect
136139
golang.org/x/oauth2 v0.22.0 // indirect
137140
golang.org/x/sync v0.8.0 // indirect
138141
golang.org/x/text v0.18.0 // indirect
139142
golang.org/x/time v0.6.0 // indirect
140-
google.golang.org/api v0.194.0 // indirect
141-
google.golang.org/genproto v0.0.0-20240814211410-ddb44dafa142 // indirect
142-
google.golang.org/genproto/googleapis/api v0.0.0-20240814211410-ddb44dafa142 // indirect
143-
google.golang.org/genproto/googleapis/rpc v0.0.0-20240814211410-ddb44dafa142 // indirect
144-
google.golang.org/grpc v1.65.0 // indirect
143+
google.golang.org/api v0.196.0 // indirect
144+
google.golang.org/genproto v0.0.0-20240903143218-8af14fe29dc1 // indirect
145+
google.golang.org/genproto/googleapis/api v0.0.0-20240827150818-7e3bb234dfed // indirect
146+
google.golang.org/genproto/googleapis/rpc v0.0.0-20240903143218-8af14fe29dc1 // indirect
147+
google.golang.org/grpc v1.66.0 // indirect
145148
gopkg.in/yaml.v3 v3.0.1 // indirect
146149
howett.net/plist v1.0.0 // indirect
147150
k8s.io/klog/v2 v2.100.1 // indirect

0 commit comments

Comments
 (0)