fix(auth): accept PEM trust-chain preambles - #18555
dhairyajangir wants to merge 2 commits into
Conversation
Ensure trust chain data is processed correctly by skipping empty certificate blocks.
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
There was a problem hiding this comment.
Code Review
This pull request updates the _read_trust_chain method in identity_pool.py to correctly ignore any preamble text that appears before the first PEM certificate header (-----BEGIN CERTIFICATE-----). It also adds corresponding unit tests in test_identity_pool.py to cover various scenarios involving preambles, invalid trust chains, and empty trust chains. There are no review comments, so I have no feedback to provide.
An X.509 workload trust-chain file with comments or OpenSSL metadata before its first certificate currently raises
RefreshError: the loader adds a certificate header to that preamble and tries to parse it as a certificate. Skip the preamble when a certificate header is present, preserving certificate order and the existing handling of malformed, missing and empty certificate data.The parser continues to work with the declared cryptography 38.0.3 minimum. Tests cover comment and OpenSSL preambles, whitespace, chains with and without the leaf certificate, malformed PEM, files containing no certificate and empty files.
Validation on Python 3.12:
The supported Python/OS matrix and cloud system tests were not run. This change was developed with AI assistance and tested locally using fixture certificates.
Thank you for opening a Pull Request! Before submitting your PR, there are a few things you can do to make sure it goes smoothly:
The existing issue predates this patch. The user guide already describes a PEM-formatted trust-chain file, so no documentation correction is needed. Compared with unmodified base
3799568in the same environment, statement coverage increased from 97.2398% to 97.2406%, and branch coverage increased from 95.8998% to 95.9613%.Fixes #17623 🦕