Skip to content

Commit

Permalink
Add helper method for retrieving serial number of certificate.
Browse files Browse the repository at this point in the history
  • Loading branch information
felixfontein committed Apr 13, 2020
1 parent 1bdfbaa commit 02b536b
Show file tree
Hide file tree
Showing 4 changed files with 20 additions and 9 deletions.
12 changes: 12 additions & 0 deletions plugins/module_utils/crypto/cryptography_support.py
Original file line number Diff line number Diff line change
Expand Up @@ -288,3 +288,15 @@ def cryptography_compare_public_keys(key1, key2):
b = key2.public_bytes(serialization.Encoding.Raw, serialization.PublicFormat.Raw)
return a == b
return key1.public_numbers() == key2.public_numbers()


def cryptography_serial_number_of_cert(cert):
'''Returns cert.serial_number.
Also works for old versions of cryptography.
'''
try:
return cert.serial_number
except AttributeError:
# The property was called "serial" before cryptography 1.4
return cert.serial
7 changes: 4 additions & 3 deletions plugins/modules/x509_certificate.py
Original file line number Diff line number Diff line change
Expand Up @@ -890,6 +890,7 @@
cryptography_name_to_oid,
cryptography_key_needs_digest_for_signing,
cryptography_parse_key_usage_params,
cryptography_serial_number_of_cert,
)

MINIMAL_CRYPTOGRAPHY_VERSION = '1.6'
Expand Down Expand Up @@ -1241,7 +1242,7 @@ def dump(self, check_mode=False):
result.update({
'notBefore': self.cert.not_valid_before.strftime("%Y%m%d%H%M%SZ"),
'notAfter': self.cert.not_valid_after.strftime("%Y%m%d%H%M%SZ"),
'serial_number': self.cert.serial_number,
'serial_number': cryptography_serial_number_of_cert(self.cert),
})

return result
Expand Down Expand Up @@ -1538,7 +1539,7 @@ def dump(self, check_mode=False):
result.update({
'notBefore': self.cert.not_valid_before.strftime("%Y%m%d%H%M%SZ"),
'notAfter': self.cert.not_valid_after.strftime("%Y%m%d%H%M%SZ"),
'serial_number': self.cert.serial_number,
'serial_number': cryptography_serial_number_of_cert(self.cert),
})

return result
Expand Down Expand Up @@ -2402,7 +2403,7 @@ def _get_cert_details(self):
time_string = to_native(self.cert.get_notAfter())
expiry = datetime.datetime.strptime(time_string, "%Y%m%d%H%M%SZ")
elif self.backend == 'cryptography':
serial_number = "{0:X}".format(self.cert.serial_number)
serial_number = "{0:X}".format(cryptography_serial_number_of_cert(self.cert))
expiry = self.cert.not_valid_after

# get some information about the expiry of this certificate
Expand Down
3 changes: 2 additions & 1 deletion plugins/modules/x509_certificate_info.py
Original file line number Diff line number Diff line change
Expand Up @@ -330,6 +330,7 @@
cryptography_decode_name,
cryptography_get_extensions_from_cert,
cryptography_oid_to_name,
cryptography_serial_number_of_cert,
)

from ansible_collections.community.crypto.plugins.module_utils.crypto.pyopenssl_support import (
Expand Down Expand Up @@ -671,7 +672,7 @@ def _get_authority_key_identifier(self):
return None, None, None

def _get_serial_number(self):
return self.cert.serial_number
return cryptography_serial_number_of_cert(self.cert)

def _get_all_extensions(self):
return cryptography_get_extensions_from_cert(self.cert)
Expand Down
7 changes: 2 additions & 5 deletions plugins/modules/x509_crl.py
Original file line number Diff line number Diff line change
Expand Up @@ -376,6 +376,7 @@
cryptography_get_name,
cryptography_name_to_oid,
cryptography_oid_to_name,
cryptography_serial_number_of_cert,
)

from ansible_collections.community.crypto.plugins.module_utils.crypto.cryptography_crl import (
Expand Down Expand Up @@ -462,11 +463,7 @@ def __init__(self, module):
if rc['content'] is not None:
rc['content'] = rc['content'].encode('utf-8')
cert = load_certificate(rc['path'], content=rc['content'], backend='cryptography')
try:
result['serial_number'] = cert.serial_number
except AttributeError:
# The property was called "serial" before cryptography 1.4
result['serial_number'] = cert.serial
result['serial_number'] = cryptography_serial_number_of_cert(cert)
except OpenSSLObjectError as e:
if rc['content'] is not None:
module.fail_json(
Expand Down

0 comments on commit 02b536b

Please sign in to comment.