Skip to content

fix asn1 issue - #16

Merged
indrora merged 1 commit into
release-2.0from
fix/renewal-asn1-corrupted-data-2.0
Sep 30, 2026
Merged

indrora merged 1 commit into
release-2.0from
fix/renewal-asn1-corrupted-data-2.0

Conversation

@bhillkeyfactor

Copy link
Copy Markdown
Collaborator

Fixes the renewal/reissue enrollment failure: Encoding.ASCII.GetBytes was used on the stored base64 DER certificate string instead of Convert.FromBase64String, causing X509Certificate2 to throw 'ASN1 corrupted data' on every renewal or reissue attempt. Same fix as PR #15 against release-1.0, ported to the 2.0 line.

@indrora
indrora merged commit 8a59c93 into release-2.0 Sep 30, 2026
39 checks passed
indrora added a commit that referenced this pull request Sep 30, 2026
* Feature/84076 enrollment parameter defaults (#11)

* ADO 84076: Apply template parameter defaults when Command omits them

Enrollment against a template that was added but never saved arrives with the
plugin's declared template parameters absent from ProductParameters, because
Command does not populate a template's parameter collection with the annotation
defaults until the template is saved. Previously this failed enrollment
(ValidityPeriod/ValidityUnits threw ArgumentException; RenewalDays returned a
failure result), matching the "given key was not present in the dictionary"
class of bug reported in 81803.

Add RequestManager.ResolveTemplateParameter, which returns the value supplied by
Command or falls back to the DefaultValue declared in
GetTemplateParameterAnnotations(). Use it for ValidityPeriod, ValidityUnits, and
RenewalDays so enrollment succeeds against an unsaved template using the same
defaults the annotations advertise. Only a parameter with neither a supplied
value nor a declared default remains an error.

* Target 26.2 gateway framework and align IAnyCAPlugin to 3.3.0

Update gateway_framework to 26.2 in integration-manifest.json and bump
Keyfactor.AnyGateway.IAnyCAPlugin from 3.0.0 to 3.3.0, matching the versions
used by the cscglobal and sslstore plugins on the 26.2 framework.

* Update generated docs

* Upgrade starter workflow to starter.yml@v5

Bump the Keyfactor bootstrap workflow from starter.yml@v3 to @v5, matching the
cscglobal and sslstore plugins. Adds the Command connection inputs
(command_token_url, command_hostname, command_base_api_path) and the entra /
command client secrets required by v5, and drops the obsolete
APPROVE_README_PUSH secret.

* docs: auto-generate README and documentation [skip ci]

* Add unit test project with coverage for RequestManager

Add HydrantCAProxy.Tests (xUnit) and wire it into the solution. Covers the
ADO 84076 template-parameter-default fix (ResolveTemplateParameter and its
wiring through GetEnrollmentRequest) plus the previously untested RequestManager
surface: revocation-reason mapping (including reason 0), status mapping,
renewal/enrollment request building, SAN construction, certificate list
requests, and enrollment result mapping. 38 tests.

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

* fix asn1 issue (#16)

---------

Co-authored-by: Brian Hill <76450501+bhillkeyfactor@users.noreply.github.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants