feat(trust): add get_certificates() for Trust store certificate inventory
CI / test (3.10) (push) Failing after 8s
CI / test (3.11) (push) Failing after 7s
CI / test (3.12) (push) Failing after 8s
CI / test (3.9) (push) Failing after 7s

Reads certificates via POST /api/trust/cert/search, normalising each row
to {name, issuer, valid_from, valid_to, in_use_by}. Field mapping (Unix
timestamps for validity, %caref for the resolved issuer label) verified
against a live OPNsense 24.7 instance. Never surfaces crt_payload/
prv_payload/csr_payload -- those carry private key material.
This commit is contained in:
Christian Manivong
2026-07-15 12:26:36 +02:00
parent 62424cfd71
commit 26470676ce
2 changed files with 120 additions and 0 deletions
+32
View File
@@ -1059,6 +1059,38 @@ class OPNsenseDriver(FirewallDriver):
})
return sorted(result, key=lambda x: x["name"].lower())
def get_certificates(self) -> list[dict[str, Any]]:
"""Return certificates from the OPNsense Trust store.
Calls ``POST /api/trust/cert/search`` and normalises each row to
``{name, issuer, valid_from, valid_to, in_use_by}`` (Unix
timestamps for the validity fields). Never includes
crt_payload/prv_payload/csr_payload -- those rows carry private key
material and must not leave the Trust store.
"""
try:
data = self._post("/api/trust/cert/search")
except Exception as exc:
logger.warning("get_certificates() failed: %s", exc)
return []
def _as_int(value: Any) -> int:
try:
return int(value or 0)
except (TypeError, ValueError):
return 0
result: list[dict[str, Any]] = []
for row in data.get("rows", []):
result.append({
"name": row.get("commonname") or row.get("descr") or row.get("refid", ""),
"issuer": row.get("%caref") or "",
"valid_from": _as_int(row.get("valid_from")),
"valid_to": _as_int(row.get("valid_to")),
"in_use_by": _as_int(row.get("in_use")),
})
return result
def get_dhcp_leases(self) -> list[dict[str, Any]]:
"""Return active DHCP leases from OPNsense.