Skip to content

digicert: support alternate chains for CertCentral issuer - #89

Merged
ftb-skry merged 1 commit into
mainfrom
digicert-alternate-chains
Oct 6, 2026
Merged

ftb-skry merged 1 commit into
mainfrom
digicert-alternate-chains

Conversation

@ftb-skry

@ftb-skry ftb-skry commented Oct 6, 2026

Copy link
Copy Markdown
Collaborator

Summary

  • Add DIGICERT_ALTERNATE_CHAINS for the CertCentral issuer (digicert-issuer): a mapping from authority name to a cross-signed certificate PEM that is appended to the chain of certificates issued by that authority. Mirrors the existing DIGICERT_CIS_ALTERNATE_CHAINS.
  • Applied in _download_certificate (pending-order resolution) and get_ordered_certificate.
  • The CIS issuer now uses the same helper (append_alternate_chain), which also strips the intermediate's trailing newline so the chain has no blank line between certificates.
  • Documented in docs/administration.rst.

Motivation: the dealer *.spotify.com certificate needs a chain that validates against both DigiCert G1 and G2 roots (ADR-047). Today this is done by hand on every renewal; with this change Lemur can produce the same chain automatically for a dedicated authority.

Testing

  • New unit tests: chain appended for a configured authority, unchanged for an unconfigured one, and get_ordered_certificate coverage.
  • Ran test_digicert.py locally (Python 3.14, no Postgres): the new tests pass, and the pre-existing failures that need the database or app config are the same with and without the change.
  • Checked that the generated chain for the current G2 intermediate is identical to the chain produced by the manual procedure in production, and that the leaf verifies to both G1 and G2.

🤖 Generated with Claude Code

Add DIGICERT_ALTERNATE_CHAINS, a mapping from authority name to a
cross-signed certificate PEM that is appended to the chain of
certificates issued by that authority. This mirrors the existing
DIGICERT_CIS_ALTERNATE_CHAINS for the CIS issuer and lets us issue
certificates that chain to both the DigiCert G1 and G2 roots.

The chain is extended in both _download_certificate (used when
resolving pending orders) and get_ordered_certificate. The CIS issuer
now uses the same helper, which also strips the trailing newline of
the intermediate so no blank line ends up between the certificates.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coveralls

Copy link
Copy Markdown

Coverage Report for CI Build 37471649651

Coverage remained the same at 59.879%

Details

  • Coverage remained the same as the base build.
  • Patch coverage: No coverable lines changed in this PR.
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 992
Covered Lines: 594
Line Coverage: 59.88%
Coverage Strength: 0.6 hits per line

💛 - Coveralls

@jonathanvdwatt jonathanvdwatt left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@ftb-skry
ftb-skry merged commit ea9095c into main Oct 6, 2026
11 checks passed
@ftb-skry
ftb-skry deleted the digicert-alternate-chains branch October 6, 2026 13:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants