@nordicsemiconductor/asset-tracker-cloud-aws
Version:
A reference implementation of a serverless backend for an IoT product developed using AWS CDK in TypeScript.
259 lines (258 loc) • 8.71 kB
JavaScript
function asyncGeneratorStep(gen, resolve, reject, _next, _throw, key, arg) {
try {
var info = gen[key](arg);
var value = info.value;
} catch (error) {
reject(error);
return;
}
if (info.done) {
resolve(value);
} else {
Promise.resolve(value).then(_next, _throw);
}
}
function _async_to_generator(fn) {
return function() {
var self = this, args = arguments;
return new Promise(function(resolve, reject) {
var gen = fn.apply(self, args);
function _next(value) {
asyncGeneratorStep(gen, resolve, reject, _next, _throw, "next", value);
}
function _throw(err) {
asyncGeneratorStep(gen, resolve, reject, _next, _throw, "throw", err);
}
_next(undefined);
});
};
}
function _ts_generator(thisArg, body) {
var f, y, t, g, _ = {
label: 0,
sent: function() {
if (t[0] & 1) throw t[1];
return t[1];
},
trys: [],
ops: []
};
return g = {
next: verb(0),
"throw": verb(1),
"return": verb(2)
}, typeof Symbol === "function" && (g[Symbol.iterator] = function() {
return this;
}), g;
function verb(n) {
return function(v) {
return step([
n,
v
]);
};
}
function step(op) {
if (f) throw new TypeError("Generator is already executing.");
while(_)try {
if (f = 1, y && (t = op[0] & 2 ? y["return"] : op[0] ? y["throw"] || ((t = y["return"]) && t.call(y), 0) : y.next) && !(t = t.call(y, op[1])).done) return t;
if (y = 0, t) op = [
op[0] & 2,
t.value
];
switch(op[0]){
case 0:
case 1:
t = op;
break;
case 4:
_.label++;
return {
value: op[1],
done: false
};
case 5:
_.label++;
y = op[1];
op = [
0
];
continue;
case 7:
op = _.ops.pop();
_.trys.pop();
continue;
default:
if (!(t = _.trys, t = t.length > 0 && t[t.length - 1]) && (op[0] === 6 || op[0] === 2)) {
_ = 0;
continue;
}
if (op[0] === 3 && (!t || op[1] > t[0] && op[1] < t[3])) {
_.label = op[1];
break;
}
if (op[0] === 6 && _.label < t[1]) {
_.label = t[1];
t = op;
break;
}
if (t && _.label < t[2]) {
_.label = t[2];
_.ops.push(op);
break;
}
if (t[2]) _.ops.pop();
_.trys.pop();
continue;
}
op = body.call(thisArg, _);
} catch (e) {
op = [
6,
e
];
y = 0;
} finally{
f = t = 0;
}
if (op[0] & 5) throw op[1];
return {
value: op[0] ? op[1] : void 0,
done: true
};
}
}
import { randomUUID } from 'crypto';
import { mkdir, stat, unlink } from 'fs/promises';
import run from '@bifravst/run';
import { caFileLocations } from './caFileLocations.js';
import { registerCA } from './registerCA.js';
export var defaultCAValidityInDays = 356;
/**
* Creates a CA certificate and registers it for Just-in-time provisioning
* @see https://docs.aws.amazon.com/iot/latest/developerguide/device-certs-your-own.html
*/ export var createCA = function() {
var _ref = _async_to_generator(function(args) {
var certsDir, log, debug, iot, cf, e, caFiles, _args_daysValid, _args_subject, certificateId;
return _ts_generator(this, function(_state) {
switch(_state.label){
case 0:
certsDir = args.certsDir, log = args.log, debug = args.debug, iot = args.iot, cf = args.cf;
_state.label = 1;
case 1:
_state.trys.push([
1,
3,
,
5
]);
return [
4,
stat(certsDir)
];
case 2:
_state.sent();
return [
3,
5
];
case 3:
e = _state.sent();
return [
4,
mkdir(certsDir)
];
case 4:
_state.sent();
log("Created ".concat(certsDir));
return [
3,
5
];
case 5:
caFiles = caFileLocations({
id: randomUUID(),
certsDir: certsDir
});
return [
4,
run({
command: 'openssl',
args: [
'genrsa',
'-out',
caFiles.key,
'2048'
],
log: {
debug: debug
}
})
];
case 6:
_state.sent();
return [
4,
run({
command: 'openssl',
args: [
'req',
'-x509',
'-new',
'-nodes',
'-key',
caFiles.key,
'-sha256',
'-days',
"".concat((_args_daysValid = args.daysValid) !== null && _args_daysValid !== void 0 ? _args_daysValid : defaultCAValidityInDays),
'-out',
caFiles.cert,
'-subj',
"/OU=".concat((_args_subject = args.subject) !== null && _args_subject !== void 0 ? _args_subject : args.stack)
],
log: {
debug: debug
}
})
];
case 7:
_state.sent();
return [
4,
registerCA({
iot: iot,
cf: cf,
certsDir: certsDir,
stack: args.stack,
caCertificateFile: caFiles.cert,
caCertificateKeyFile: caFiles.key,
attributes: args.attributes,
tags: args.tags,
log: log,
debug: debug
})
];
case 8:
certificateId = _state.sent().certificateId;
return [
4,
Promise.all([
unlink(caFiles.cert),
unlink(caFiles.key)
])
];
case 9:
_state.sent();
return [
2,
{
certificateId: certificateId
}
];
}
});
});
return function createCA(args) {
return _ref.apply(this, arguments);
};
}();