29 lines
888 B
Go
29 lines
888 B
Go
package config
|
|
|
|
import (
|
|
"encoding/hex"
|
|
"fmt"
|
|
"strings"
|
|
)
|
|
|
|
// ParseCertificateFingerprints parses a deployment-owned comma-separated SHA-256
|
|
// leaf fingerprint allowlist. Colons are accepted for operator convenience but
|
|
// normalized away before comparison.
|
|
func ParseCertificateFingerprints(raw string) (map[string]struct{}, error) {
|
|
result := make(map[string]struct{})
|
|
for _, item := range strings.Split(raw, ",") {
|
|
fingerprint := strings.ToLower(strings.ReplaceAll(strings.TrimSpace(item), ":", ""))
|
|
if fingerprint == "" {
|
|
continue
|
|
}
|
|
if len(fingerprint) != 64 {
|
|
return nil, fmt.Errorf("mTLS peer certificate fingerprint must be 32 bytes: %q", item)
|
|
}
|
|
if _, err := hex.DecodeString(fingerprint); err != nil {
|
|
return nil, fmt.Errorf("invalid mTLS peer certificate fingerprint %q: %w", item, err)
|
|
}
|
|
result[fingerprint] = struct{}{}
|
|
}
|
|
return result, nil
|
|
}
|