You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenXPKI自定义SearchCertificate工作流:Curl批量获取证书列表遇阻

OpenXPKI RPC API 证书查询工作流问题解决

问题场景

想要通过OpenXPKI RPC Server API批量获取即将过期的证书列表,无需逐个传入主机名。尝试在/etc/openxpki/config.d/realm.tpl/workflow/def下自定义工作流未生效,于是修改了基础的SearchCertificate工作流,但遇到以下问题:

  • 无法通过*.mydomain.com这类通配符匹配获取多主机证书结果
  • 不传common_name参数时无任何输出
  • 尝试自定义notafter参数筛选即将过期证书无果

当前使用的工作流配置

action:
    initialize:
        class: OpenXPKI::Server::Workflow::Activity::Tools::SearchCertificates
        param:
            _map_cert_subject: "CN=[% context.common_name %],*"
            order: notbefore desc
            include_revoked: 0
            include_expired: 1
            limit: 50

        input:
          - common_name

        validator:
          - common_name

    get_certificate_data:
        class: OpenXPKI::Server::Workflow::Activity::Tools::SetContext
        param:
            _map_notbefore: "[% USE Certificate %][% Certificate.notbefore(context.cert_identifier) %]"
            _map_notafter: "[% USE Certificate %][% Certificate.notafter(context.cert_identifier) %]"
            _map_status: "[% USE Certificate %][% Certificate.status(context.cert_identifier) %]"

condition:
    has_result:
         class: Workflow::Condition::Evaluate
         param:
             test: $context->{cert_identifier}

validator:
    common_name:
        class: OpenXPKI::Server::Workflow::Validator::Regex
        arg:
          - $common_name
        param:
            regex: "\A [a-zA-Z0-9-\.\:]+"
            modifier: xi

field:
    common_name:
        name: common_name
        required: 0
        type: server

Curl调用示例及输出

curl -F "method=SearchCertificate" -F "common_name=hostname1"  http://localhost:80/rpc
{"result":{"pid":8045,"id":0,"data":{"cert_identifier":"ZzWtdso_jTxpnDcb_cckUn5X6A0","status":"ISSUED","notafter":"2025-07-20T08:11:05","notbefore":"2022-07-20T08:11:05"},"proc_state":"finished","state":"SUCCESS"}}

问题分析与解决方案

1. 问题根源

  • 原common_name验证正则禁止*字符,导致通配符输入被拦截
  • _map_cert_subject在common_name为空时生成无效匹配规则CN=,*,无法命中任何证书
  • 原工作流仅支持单证书结果输出,未处理批量查询场景
  • 未正确配置notafter过滤规则筛选即将过期证书

2. 调整后的完整工作流配置

action:
    initialize:
        class: OpenXPKI::Server::Workflow::Activity::Tools::SearchCertificates
        param:
            # 空参数时匹配所有CN,支持通配符输入
            _map_cert_subject: "CN=[% context.common_name || '*' %],*"
            # 按过期时间升序,即将过期的证书排在前面
            order: notafter asc
            include_revoked: 0
            include_expired: 0
            limit: 50
            # 筛选未来30天内过期的证书,可修改30调整天数
            _notafter: "[% USE Date %][% Date.format(Date.now() + 30*86400, '%Y-%m-%dT%H:%M:%S') %]"
            _status: ISSUED

        input:
          - common_name

        validator:
          - common_name

    # 遍历搜索结果,批量收集证书详情
    collect_cert_details:
        class: OpenXPKI::Server::Workflow::Activity::Tools::Iterator::Array
        param:
            _array: "[% context.search_result %]"
            _target_key: cert_item
            _loop_context: cert_loop
        on_true:
            - get_single_cert_data
        on_false:
            - finish_workflow

    get_single_cert_data:
        class: OpenXPKI::Server::Workflow::Activity::Tools::SetContext
        param:
            _map_cert_identifier: "[% cert_loop.cert_identifier %]"
            _map_notbefore: "[% USE Certificate %][% Certificate.notbefore(cert_loop.cert_identifier) %]"
            _map_notafter: "[% USE Certificate %][% Certificate.notafter(cert_loop.cert_identifier) %]"
            _map_status: "[% USE Certificate %][% Certificate.status(cert_loop.cert_identifier) %]"
            _map_subject: "[% cert_loop.subject %]"
        # 将单条证书信息追加到结果列表
        post_actions:
            - name: push_to_context
              param:
                  key: expired_cert_list
                  value: "[% context.hash({cert_identifier => cert_identifier, notbefore => notbefore, notafter => notafter, status => status, subject => subject}) %]"
        on_success:
            - collect_cert_details

    finish_workflow:
        class: OpenXPKI::Server::Workflow::Activity::Tools::Noop

condition:
    has_result:
         class: Workflow::Condition::Evaluate
         param:
             test: $context->{search_result} && $context->{search_result}->@* > 0

validator:
    common_name:
        class: OpenXPKI::Server::Workflow::Validator::Regex
        arg:
          - $common_name
        param:
            # 允许*字符用于通配符匹配
            regex: "\A [a-zA-Z0-9-\.\:\*]+"
            modifier: xi
            # 允许common_name为空
            allow_blank: 1

field:
    common_name:
        name: common_name
        required: 0
        type: server
    # 新增输出字段,返回批量证书列表
    expired_cert_list:
        name: expired_cert_list
        type: server
        required: 0

3. 关键修改说明

  • 通配符与空参数支持:修改验证正则允许*,并开启allow_blank:1;_map_cert_subject设置默认值*,空参数时匹配所有CN证书
  • 过期筛选:通过TT2的Date工具计算未来30天的时间,作为_notafter过滤条件
  • 批量结果处理:新增迭代步骤遍历搜索结果,将所有证书详情收集到expired_cert_list字段返回

4. 生效注意事项

  • 修改配置后需重启OpenXPKI服务
  • 自定义工作流需放在对应realm的workflow/def目录下(而非模板tpl目录),文件后缀为.yaml

内容的提问来源于stack exchange,提问作者Aguirre23

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.24 09:54:20