Skip to content

Fix import pem - #248

Merged
7ritn merged 2 commits into
mainfrom
fix-import-pem
Sep 2, 2026
Merged

7ritn merged 2 commits into
mainfrom
fix-import-pem

Conversation

@7ritn

@7ritn 7ritn commented Sep 1, 2026

Copy link
Copy Markdown
Owner

Importing a (PEM encoded) CA currently has two issues. It does not check if provided CRL string is empty (is the case if no CRL is specified in frontend) and does not decode PEM-encoded private key to DER, meaning PEM-encoded imported CAs can not be used.

Emily Ehlert added 2 commits September 1, 2026 18:07
The frontend sends the API during CA import never a NULL as CRL, but if
no CRL is specified an empty string. During import VaulTLS only checks
if the CRL field is set at all and not if string is empty. It then tries
to extract a CRL number which fails and logs warning. Otherwise import
works and does not cause issues.

Add check for empty string to stop wasting cycles and print unnessary
warning.
VaulTLS does not decode a PEM-encoded private key to DER when storing as
a CA object. When trying to use the imported CA to create a certificate
it fails, because rcgen can not read the private key.

Add decoding of PEM private key to DER, same approach used for cert
file.

Fixes: #239
@7ritn 7ritn linked an issue Sep 1, 2026 that may be closed by this pull request
@7ritn 7ritn added this to the v1.4.1 milestone Sep 1, 2026
@7ritn 7ritn added bug Something isn't working rust Pull requests that update rust code labels Sep 1, 2026
@7ritn 7ritn self-assigned this Sep 1, 2026
@7ritn

7ritn commented Sep 2, 2026

Copy link
Copy Markdown
Owner Author

Verified fix thanks to tester

@7ritn
7ritn merged commit f3f3029 into main Sep 2, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working rust Pull requests that update rust code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Unable to create client certificate from Cloudflare managed CA

1 participant