Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enable response wrapping of PKI secrets #649

Merged
merged 1 commit into from
Dec 14, 2020
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view
15 changes: 12 additions & 3 deletions hvac/api/secrets_engines/pki.py
Original file line number Diff line number Diff line change
Expand Up @@ -242,7 +242,7 @@ def rotate_crl(self, mount_point=DEFAULT_MOUNT_POINT):
url=api_path,
)

def generate_intermediate(self, type, common_name, extra_params=None, mount_point=DEFAULT_MOUNT_POINT):
def generate_intermediate(self, type, common_name, extra_params=None, mount_point=DEFAULT_MOUNT_POINT, wrap_ttl=None):
"""Generate Intermediate.

Generates a new private key and a CSR for signing.
Expand All @@ -258,6 +258,8 @@ def generate_intermediate(self, type, common_name, extra_params=None, mount_poin
:type extra_params: dict
:param mount_point: The "path" the method/backend was mounted on.
:type mount_point: str | unicode
:param wrap_ttl: Specifies response wrapping token creation with duration. IE: '15s', '20m', '25h'.
:type wrap_ttl: str | unicode
:return: The JSON response of the request.
:rtype: requests.Response
"""
Expand All @@ -275,6 +277,7 @@ def generate_intermediate(self, type, common_name, extra_params=None, mount_poin
return self._adapter.post(
url=api_path,
json=params,
wrap_ttl=wrap_ttl,
)

def set_signed_intermediate(self, certificate, mount_point=DEFAULT_MOUNT_POINT):
Expand Down Expand Up @@ -305,7 +308,7 @@ def set_signed_intermediate(self, certificate, mount_point=DEFAULT_MOUNT_POINT):
json=params,
)

def generate_certificate(self, name, common_name, extra_params=None, mount_point=DEFAULT_MOUNT_POINT):
def generate_certificate(self, name, common_name, extra_params=None, mount_point=DEFAULT_MOUNT_POINT, wrap_ttl=None):
"""Generate Certificate.

Generates a new set of credentials (private key and certificate) based on the role named in the endpoint.
Expand All @@ -321,6 +324,8 @@ def generate_certificate(self, name, common_name, extra_params=None, mount_point
:name extra_params: dict
:param mount_point: The "path" the method/backend was mounted on.
:name mount_point: str | unicode
:param wrap_ttl: Specifies response wrapping token creation with duration. IE: '15s', '20m', '25h'.
:type wrap_ttl: str | unicode
:return: The JSON response of the request.
:rtype: requests.Response
"""
Expand All @@ -338,6 +343,7 @@ def generate_certificate(self, name, common_name, extra_params=None, mount_point
return self._adapter.post(
url=api_path,
json=params,
wrap_ttl=wrap_ttl,
)

def revoke_certificate(self, serial_number, mount_point=DEFAULT_MOUNT_POINT):
Expand Down Expand Up @@ -465,7 +471,7 @@ def delete_role(self, name, mount_point=DEFAULT_MOUNT_POINT):
url=api_path,
)

def generate_root(self, type, common_name, extra_params=None, mount_point=DEFAULT_MOUNT_POINT):
def generate_root(self, type, common_name, extra_params=None, mount_point=DEFAULT_MOUNT_POINT, wrap_ttl=None):
"""Generate Root.

Generates a new self-signed CA certificate and private key.
Expand All @@ -481,6 +487,8 @@ def generate_root(self, type, common_name, extra_params=None, mount_point=DEFAUL
:type extra_params: dict
:param mount_point: The "path" the method/backend was mounted on.
:type mount_point: str | unicode
:param wrap_ttl: Specifies response wrapping token creation with duration. IE: '15s', '20m', '25h'.
:type wrap_ttl: str | unicode
:return: The JSON response of the request.
:rtype: requests.Response
"""
Expand All @@ -498,6 +506,7 @@ def generate_root(self, type, common_name, extra_params=None, mount_point=DEFAUL
return self._adapter.post(
url=api_path,
json=params,
wrap_ttl=wrap_ttl,
)

def delete_root(self, mount_point=DEFAULT_MOUNT_POINT):
Expand Down