Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
71 commits
Select commit Hold shift + click to select a range
3e3d581
feat(enroll): synchronous certificate pickup (Sectigo parity) — v1.0.1
spbsoluble Jul 31, 2026
77fe123
chore(enroll): log RequestFormat on the enrollment-start line
spbsoluble Jul 31, 2026
49616cc
fix(client): don't retry non-idempotent order/CSR submits on a networ…
spbsoluble Jul 31, 2026
e8e4739
fix(client): enrich orphaned-order warnings + SubmitCSR transient gui…
spbsoluble Jul 31, 2026
6ae12b7
fix(enroll): harden synchronous pickup — DCV gating, wait ceiling, au…
spbsoluble Jul 31, 2026
f499f65
fix(enroll): UCC SANs never reached CERTInext — additionalDomains sen…
spbsoluble Aug 13, 2026
947ae68
docs: refresh docsource against current code
spbsoluble Aug 13, 2026
5d2d154
docs: auto-generate README and documentation [skip ci]
github-actions[bot] Aug 13, 2026
a890a7d
fix(enroll): renewal product code, AutoApprove UI text, config log vi…
spbsoluble Aug 13, 2026
00ccdbd
docs(changelog): add PR #28's renewal product-code, AutoApprove, and …
spbsoluble Aug 13, 2026
59aa2b2
fix(logging): add trace-level payload dumps for enrollment request/re…
spbsoluble Sep 14, 2026
1447a5c
feat(enroll): port ValidityYears from release-1.1 (PR #22)
spbsoluble Sep 14, 2026
6d056df
fix(enroll): send V1 GenerateOrderSSL fields where CERTInext reads them
spbsoluble Oct 2, 2026
7abcd52
test(enroll): pin V1 order shape for enroll and renewal
spbsoluble Oct 2, 2026
dc59d6c
docs(config): name the GenerateOrderSSL fields CERTInext actually reads
spbsoluble Oct 2, 2026
338d4ef
chore(scripts): send the corrected V1 order body from dev scripts
spbsoluble Oct 2, 2026
0556505
docs(changelog): note V1 order-body field fixes and upgrade impact in…
spbsoluble Oct 2, 2026
bfde454
fix(logging): redact authKey and requestor PII from V1 payload and er…
spbsoluble Oct 2, 2026
39f0264
test(logging): regression coverage for LogSensitiveRequestData redact…
spbsoluble Oct 2, 2026
7cdac90
fix(config): dispose transient CERTInextClient in Validate* methods
spbsoluble Oct 2, 2026
3e82232
test(config): regression test for ValidateProductInfo client allocati…
spbsoluble Oct 2, 2026
a15c89e
fix(enroll): re-throw OperationCanceledException in PickUpEnrolledCer…
spbsoluble Sep 22, 2026
8799e7b
test(enroll): regression test for pickup loop not swallowing Operatio…
spbsoluble Oct 2, 2026
2bffb57
test(integration): keep opt-in flags env-only and dispose Cloudflare …
spbsoluble Oct 2, 2026
84e792d
fix(logging): redact renamed technicalPointOfContact poc* keys when L…
spbsoluble Oct 2, 2026
a0df1df
test(logging): assert poc* redaction (flag off/on) and migrate tests …
spbsoluble Oct 2, 2026
7a6cbf7
fix(logging): strip CR/LF from RequesterName/RequesterEmail on enroll…
spbsoluble Oct 2, 2026
a77d5c4
test(logging): regression tests for CR/LF stripped from requester val…
spbsoluble Oct 2, 2026
0deb829
fix(enroll): omit technicalPointOfContact when the resolved contact n…
spbsoluble Oct 2, 2026
674b70a
test(enroll): technicalPointOfContact omitted for blank name on enrol…
spbsoluble Oct 2, 2026
ec5aef9
docs(config): describe GroupNumber default-group behavior per CERTIne…
spbsoluble Oct 2, 2026
02ceb4f
test(integration): live proof of V1 group placement and no-www SAN fo…
spbsoluble Oct 2, 2026
25ec9e6
docs(config): describe OrganizationNumber pre-vetting per CERTInext spec
spbsoluble Oct 2, 2026
8cca70c
docs(config): correct DefaultProductCode behavior (template code firs…
spbsoluble Oct 2, 2026
95e7e29
chore(make): replace hard-coded developer-home script paths with CURD…
spbsoluble Oct 2, 2026
50637b4
fix(enroll): fall back to defaults when product code and signer value…
spbsoluble Oct 2, 2026
729e834
test(enroll): blank product code and signer name/place fall back to d…
spbsoluble Oct 2, 2026
f1a588a
fix(logging): include HTTP status and log redacted body for V1 non-2x…
spbsoluble Oct 2, 2026
6267c6c
test(logging): cover V1 non-2xx error body logging and redaction (0073)
spbsoluble Oct 2, 2026
797f784
fix(enroll): honor SignerName/SignerPlace/SignerIp template parameter…
spbsoluble Oct 2, 2026
414a115
test(enroll): signer template/connector/default precedence on enroll …
spbsoluble Oct 2, 2026
0fb6c0f
docs(changelog): add 1.0.1 validation-leak fix and upgrade notes for …
spbsoluble Oct 2, 2026
afd13ec
test(integration): opt-in live probe for blank RequestorName/Technica…
spbsoluble Oct 2, 2026
8847142
test(enroll): pin and live-capture blank RequestorName/TechnicalConta…
spbsoluble Oct 2, 2026
69276ac
docs: auto-generate README and documentation [skip ci]
github-actions[bot] Oct 2, 2026
d16c67b
fix(enroll): warn when SignerIp is not an IP address, still send it u…
spbsoluble Oct 2, 2026
f1360b1
test(enroll): SignerIp warning for invalid values on enroll and renew…
spbsoluble Oct 2, 2026
e0caa5c
fix(logging): make redaction regexes escape-aware so escaped quotes d…
spbsoluble Oct 2, 2026
50c8e19
test(logging): cover escaped quotes and backslashes in PII and creden…
spbsoluble Oct 2, 2026
013731b
test(integration): scrub CA-echoed emails from GroupAndWww live-test …
spbsoluble Oct 2, 2026
8c6499c
fix(enroll): warn when SignerName/SignerPlace fall back to placeholde…
spbsoluble Oct 2, 2026
18af44a
test(enroll): pin SignerName/SignerPlace fallback warnings and unchan…
spbsoluble Oct 2, 2026
9662882
fix(logging): mask emails in CA-supplied error text unless LogSensiti…
spbsoluble Oct 2, 2026
6364e4b
test(logging): CA error text email masking in log lines and exception…
spbsoluble Oct 2, 2026
6baa5d3
fix(enroll): do not fail enroll or renewal when TrackOrder or DCV fai…
spbsoluble Oct 2, 2026
d951a1d
test(enroll): TrackOrder and DCV failure after order placement return…
spbsoluble Oct 2, 2026
3799fb7
docs: fix misplaced DcvPropagationDelaySeconds XML doc; clarify CSR S…
spbsoluble Oct 2, 2026
55d6f7b
docs(manifest): add SubmitNonDnsSans, PickupRetries and PickupDelay t…
spbsoluble Oct 2, 2026
01f1733
docs(manifest): correct AutoApprove description and ApiUrl example URLs
spbsoluble Oct 2, 2026
08132d4
fix(logging): mask mailto addresses and userinfo in URI SAN log value…
spbsoluble Oct 2, 2026
89a48fe
test(logging): URI SAN masking for mailto and userinfo, verbatim for …
spbsoluble Oct 2, 2026
51cfbb0
perf(logging): guard Trace payload redaction behind IsEnabled in the …
spbsoluble Oct 2, 2026
1d69bef
test(logging): payload redaction skipped when Trace disabled, unchang…
spbsoluble Oct 2, 2026
32caf31
fix(dcv): skip post-DCV issuance wait when any domain was skipped
spbsoluble Oct 2, 2026
69b5cdb
test(dcv): partial-skip skips issuance wait; all-staged still waits
spbsoluble Oct 2, 2026
87ab070
test: serialize all global-logger-state tests in one non-parallel col…
spbsoluble Oct 2, 2026
46cd930
test: move TracePayloadGuardTests into the shared logging-state colle…
spbsoluble Oct 2, 2026
89d6db6
fix(renew): skip the pickup wait for a renewal pending DNS-01 validat…
spbsoluble Oct 2, 2026
8dc1ebe
test(renew): renewal pickup is skipped only when DNS-01 DCV is pendin…
spbsoluble Oct 2, 2026
392e5ae
test: move RenewalPickupDcvTests into the shared logging-state collec…
spbsoluble Oct 2, 2026
8529825
docs: auto-generate README and documentation [skip ci]
github-actions[bot] Oct 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
351 changes: 351 additions & 0 deletions CERTInext.IntegrationTests/BlankRequestorLiveTests.cs

Large diffs are not rendered by default.

10 changes: 7 additions & 3 deletions CERTInext.IntegrationTests/CloudflareDomainValidator.cs
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ namespace Keyfactor.Extensions.CAPlugin.CERTInext.IntegrationTests
/// Credentials are read from the <see cref="IntegrationTestFixture"/>:
/// <c>CERTINEXT_CF_API_TOKEN</c> and <c>CERTINEXT_CF_ZONE_ID</c>.
/// </summary>
internal sealed class CloudflareDomainValidator : IDomainValidator
internal sealed class CloudflareDomainValidator : IDomainValidator, IDisposable
{
private const string CfApiBase = "https://api.cloudflare.com/client/v4";

Expand Down Expand Up @@ -113,17 +113,21 @@ public async Task<DomainValidationResult> CleanupValidation(string key, Cancella
public Task ValidateConfiguration(Dictionary<string, object> configuration) => Task.CompletedTask;
public Dictionary<string, Keyfactor.AnyGateway.Extensions.PropertyConfigInfo> GetDomainValidatorAnnotations() => new();
public string GetValidationType() => "dns-01";

public void Dispose() => _http.Dispose();
}

internal sealed class CloudflareDomainValidatorFactory : IDomainValidatorFactory
internal sealed class CloudflareDomainValidatorFactory : IDomainValidatorFactory, IDisposable
{
private readonly IDomainValidator _validator;
private readonly CloudflareDomainValidator _validator;

public CloudflareDomainValidatorFactory(string apiToken, string zoneId)
{
_validator = new CloudflareDomainValidator(apiToken, zoneId);
}

public IDomainValidator ResolveDomainValidator(string domain, string validationType) => _validator;

public void Dispose() => _validator.Dispose();
}
}
26 changes: 20 additions & 6 deletions CERTInext.IntegrationTests/DcvLifecycleTests.cs
Original file line number Diff line number Diff line change
Expand Up @@ -40,17 +40,25 @@ namespace Keyfactor.Extensions.CAPlugin.CERTInext.IntegrationTests
/// CERTINEXT_DCV_DOMAIN=&lt;subdomain to use, e.g. dcv-test.example.com&gt;
/// </code>
/// </summary>
public class DcvLifecycleTests : IClassFixture<IntegrationTestFixture>
public class DcvLifecycleTests : IClassFixture<IntegrationTestFixture>, IDisposable
{
private readonly IntegrationTestFixture _fixture;
private readonly ITestOutputHelper _output;
private readonly List<IDisposable> _toDispose = new List<IDisposable>();

public DcvLifecycleTests(IntegrationTestFixture fixture, ITestOutputHelper output)
{
_fixture = fixture;
_output = output;
}

public void Dispose()
{
foreach (var d in _toDispose)
d.Dispose();
_toDispose.Clear();
}

// ---------------------------------------------------------------------------
// Helpers
// ---------------------------------------------------------------------------
Expand All @@ -69,11 +77,17 @@ private static string GenerateCsrPem(string commonName)
+ "\n-----END CERTIFICATE REQUEST-----";
}

private IDomainValidatorFactory BuildDnsFactory() =>
_fixture.IsCloudflareConfigured
? (IDomainValidatorFactory)new CloudflareDomainValidatorFactory(
_fixture.CloudflareApiToken, _fixture.CloudflareZoneId)
: new StubDomainValidatorFactory();
private IDomainValidatorFactory BuildDnsFactory()
{
if (_fixture.IsCloudflareConfigured)
{
var factory = new CloudflareDomainValidatorFactory(
_fixture.CloudflareApiToken, _fixture.CloudflareZoneId);
_toDispose.Add(factory);
return factory;
}
return new StubDomainValidatorFactory();
}

/// <summary>
/// Runs <c>plugin.Synchronize</c> and returns every record that came out of the
Expand Down
Loading