feat(trust): add get_certificates() for Trust store certificate inventory
Reads certificates via POST /api/trust/cert/search, normalising each row
to {name, issuer, valid_from, valid_to, in_use_by}. Field mapping (Unix
timestamps for validity, %caref for the resolved issuer label) verified
against a live OPNsense 24.7 instance. Never surfaces crt_payload/
prv_payload/csr_payload -- those carry private key material.
This commit is contained in:
@@ -1059,6 +1059,38 @@ class OPNsenseDriver(FirewallDriver):
|
||||
})
|
||||
return sorted(result, key=lambda x: x["name"].lower())
|
||||
|
||||
def get_certificates(self) -> list[dict[str, Any]]:
|
||||
"""Return certificates from the OPNsense Trust store.
|
||||
|
||||
Calls ``POST /api/trust/cert/search`` and normalises each row to
|
||||
``{name, issuer, valid_from, valid_to, in_use_by}`` (Unix
|
||||
timestamps for the validity fields). Never includes
|
||||
crt_payload/prv_payload/csr_payload -- those rows carry private key
|
||||
material and must not leave the Trust store.
|
||||
"""
|
||||
try:
|
||||
data = self._post("/api/trust/cert/search")
|
||||
except Exception as exc:
|
||||
logger.warning("get_certificates() failed: %s", exc)
|
||||
return []
|
||||
|
||||
def _as_int(value: Any) -> int:
|
||||
try:
|
||||
return int(value or 0)
|
||||
except (TypeError, ValueError):
|
||||
return 0
|
||||
|
||||
result: list[dict[str, Any]] = []
|
||||
for row in data.get("rows", []):
|
||||
result.append({
|
||||
"name": row.get("commonname") or row.get("descr") or row.get("refid", ""),
|
||||
"issuer": row.get("%caref") or "",
|
||||
"valid_from": _as_int(row.get("valid_from")),
|
||||
"valid_to": _as_int(row.get("valid_to")),
|
||||
"in_use_by": _as_int(row.get("in_use")),
|
||||
})
|
||||
return result
|
||||
|
||||
def get_dhcp_leases(self) -> list[dict[str, Any]]:
|
||||
"""Return active DHCP leases from OPNsense.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user