OpenXPKI自定义SearchCertificate工作流:Curl批量获取证书列表遇阻
OpenXPKI RPC API 证书查询工作流问题解决
问题场景
想要通过OpenXPKI RPC Server API批量获取即将过期的证书列表,无需逐个传入主机名。尝试在/etc/openxpki/config.d/realm.tpl/workflow/def下自定义工作流未生效,于是修改了基础的SearchCertificate工作流,但遇到以下问题:
- 无法通过
*.mydomain.com这类通配符匹配获取多主机证书结果 - 不传
common_name参数时无任何输出 - 尝试自定义
notafter参数筛选即将过期证书无果
当前使用的工作流配置
action: initialize: class: OpenXPKI::Server::Workflow::Activity::Tools::SearchCertificates param: _map_cert_subject: "CN=[% context.common_name %],*" order: notbefore desc include_revoked: 0 include_expired: 1 limit: 50 input: - common_name validator: - common_name get_certificate_data: class: OpenXPKI::Server::Workflow::Activity::Tools::SetContext param: _map_notbefore: "[% USE Certificate %][% Certificate.notbefore(context.cert_identifier) %]" _map_notafter: "[% USE Certificate %][% Certificate.notafter(context.cert_identifier) %]" _map_status: "[% USE Certificate %][% Certificate.status(context.cert_identifier) %]" condition: has_result: class: Workflow::Condition::Evaluate param: test: $context->{cert_identifier} validator: common_name: class: OpenXPKI::Server::Workflow::Validator::Regex arg: - $common_name param: regex: "\A [a-zA-Z0-9-\.\:]+" modifier: xi field: common_name: name: common_name required: 0 type: server
Curl调用示例及输出
curl -F "method=SearchCertificate" -F "common_name=hostname1" http://localhost:80/rpc
{"result":{"pid":8045,"id":0,"data":{"cert_identifier":"ZzWtdso_jTxpnDcb_cckUn5X6A0","status":"ISSUED","notafter":"2025-07-20T08:11:05","notbefore":"2022-07-20T08:11:05"},"proc_state":"finished","state":"SUCCESS"}}
问题分析与解决方案
1. 问题根源
- 原
common_name验证正则禁止*字符,导致通配符输入被拦截 _map_cert_subject在common_name为空时生成无效匹配规则CN=,*,无法命中任何证书- 原工作流仅支持单证书结果输出,未处理批量查询场景
- 未正确配置
notafter过滤规则筛选即将过期证书
2. 调整后的完整工作流配置
action: initialize: class: OpenXPKI::Server::Workflow::Activity::Tools::SearchCertificates param: # 空参数时匹配所有CN,支持通配符输入 _map_cert_subject: "CN=[% context.common_name || '*' %],*" # 按过期时间升序,即将过期的证书排在前面 order: notafter asc include_revoked: 0 include_expired: 0 limit: 50 # 筛选未来30天内过期的证书,可修改30调整天数 _notafter: "[% USE Date %][% Date.format(Date.now() + 30*86400, '%Y-%m-%dT%H:%M:%S') %]" _status: ISSUED input: - common_name validator: - common_name # 遍历搜索结果,批量收集证书详情 collect_cert_details: class: OpenXPKI::Server::Workflow::Activity::Tools::Iterator::Array param: _array: "[% context.search_result %]" _target_key: cert_item _loop_context: cert_loop on_true: - get_single_cert_data on_false: - finish_workflow get_single_cert_data: class: OpenXPKI::Server::Workflow::Activity::Tools::SetContext param: _map_cert_identifier: "[% cert_loop.cert_identifier %]" _map_notbefore: "[% USE Certificate %][% Certificate.notbefore(cert_loop.cert_identifier) %]" _map_notafter: "[% USE Certificate %][% Certificate.notafter(cert_loop.cert_identifier) %]" _map_status: "[% USE Certificate %][% Certificate.status(cert_loop.cert_identifier) %]" _map_subject: "[% cert_loop.subject %]" # 将单条证书信息追加到结果列表 post_actions: - name: push_to_context param: key: expired_cert_list value: "[% context.hash({cert_identifier => cert_identifier, notbefore => notbefore, notafter => notafter, status => status, subject => subject}) %]" on_success: - collect_cert_details finish_workflow: class: OpenXPKI::Server::Workflow::Activity::Tools::Noop condition: has_result: class: Workflow::Condition::Evaluate param: test: $context->{search_result} && $context->{search_result}->@* > 0 validator: common_name: class: OpenXPKI::Server::Workflow::Validator::Regex arg: - $common_name param: # 允许*字符用于通配符匹配 regex: "\A [a-zA-Z0-9-\.\:\*]+" modifier: xi # 允许common_name为空 allow_blank: 1 field: common_name: name: common_name required: 0 type: server # 新增输出字段,返回批量证书列表 expired_cert_list: name: expired_cert_list type: server required: 0
3. 关键修改说明
- 通配符与空参数支持:修改验证正则允许
*,并开启allow_blank:1;_map_cert_subject设置默认值*,空参数时匹配所有CN证书 - 过期筛选:通过TT2的Date工具计算未来30天的时间,作为
_notafter过滤条件 - 批量结果处理:新增迭代步骤遍历搜索结果,将所有证书详情收集到
expired_cert_list字段返回
4. 生效注意事项
- 修改配置后需重启OpenXPKI服务
- 自定义工作流需放在对应realm的
workflow/def目录下(而非模板tpl目录),文件后缀为.yaml
内容的提问来源于stack exchange,提问作者Aguirre23
相关产品推荐
相关产品推荐

