Skip to content

Merge 3.0.0 to main - #79

Merged
indrora merged 31 commits into
mainfrom
release-3.0
Sep 23, 2026
Merged

indrora merged 31 commits into
mainfrom
release-3.0

Conversation

@indrora

@indrora indrora commented Sep 23, 2026

Copy link
Copy Markdown
Member

Merge release-3.0 to main - Automated PR

dgaley and others added 30 commits October 8, 2025 11:29
change default start sync date for first incremental sync
removing caching of product type list
change default incremental sync range
shorten incremental sync if it is too long
* add duplicate support

* Update generated docs

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
* add duplicate support

* Update generated docs

* treat needs_approval the same as pending on enrollments and don't return failure code

* Update generated docs

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
* improve BouncyCastle parsing

* add duplicate support

* Update generated docs

* Merge 2.2.0 to main

* fix for smime profile type

* template parameter to include client auth eku

* Update generated docs

* changelog and logging

* check for duplicate PEMs

* change default start sync date for first incremental sync

* removing caching of product type list

* change default incremental sync range

* version

* changelog

* shorten incremental sync if it is too long

* feat: release v2.2.0

* add duplicate support

* Update generated docs

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>

---------

Co-authored-by: David Galey <dgaley@keyfactor.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: Dave Galey <89407235+dgaley@users.noreply.github.com>
Co-authored-by: Sean <1661003+spbsoluble@users.noreply.github.com>

* treat needs_approval the same as pending on enrollments and don't return failure code

* Update generated docs

* Merge 2.2.1 to main (#49)

* fix for smime profile type

* template parameter to include client auth eku

* Update generated docs

* changelog and logging

* check for duplicate PEMs

* change default start sync date for first incremental sync

* removing caching of product type list

* change default incremental sync range

* version

* changelog

* shorten incremental sync if it is too long

* feat: release v2.2.0

* add duplicate support

* Update generated docs

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>

* Dev 2.2 (#47)

* add duplicate support

* Update generated docs

* treat needs_approval the same as pending on enrollments and don't return failure code

* Update generated docs

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>

---------

Co-authored-by: David Galey <dgaley@keyfactor.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: Dave Galey <89407235+dgaley@users.noreply.github.com>
Co-authored-by: Sean <1661003+spbsoluble@users.noreply.github.com>

* Merge  to main (#48)

* fix for smime profile type

* template parameter to include client auth eku

* Update generated docs

* changelog and logging

* check for duplicate PEMs

* change default start sync date for first incremental sync

* removing caching of product type list

* change default incremental sync range

* version

* changelog

* shorten incremental sync if it is too long

* add duplicate support

* Update generated docs

* treat needs_approval the same as pending on enrollments and don't return failure code

* Update generated docs

---------

Co-authored-by: David Galey <dgaley@keyfactor.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: Dave Galey <89407235+dgaley@users.noreply.github.com>
Co-authored-by: Sean <1661003+spbsoluble@users.noreply.github.com>

* Update CHANGELOG.md (#50)

* add option for kdc/smartcardlogon eku, fix template validation

* Update generated docs

* changelog

---------

Co-authored-by: Sean <1661003+spbsoluble@users.noreply.github.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: Morgan Gangwere <470584+indrora@users.noreply.github.com>
* add product ID filter to sync

* Update generated docs

* add Intel vPro EKU support

* Update generated docs

* fix for renewal of smime certs

* validation for intel vpro eku

* fix for template validation

* changelog

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
* add product ID filter to sync

* Update generated docs

* add Intel vPro EKU support

* Update generated docs

* fix for renewal of smime certs

* validation for intel vpro eku

* fix for template validation

* changelog

* check for existance of template parameter fields

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
* add product ID filter to sync

* Update generated docs

* add Intel vPro EKU support

* Update generated docs

* fix for renewal of smime certs

* validation for intel vpro eku

* fix for template validation

* changelog

* check for existance of template parameter fields

* Merge 2.4.1 to main (#61)

* fix for smime profile type

* template parameter to include client auth eku

* Update generated docs

* changelog and logging

* check for duplicate PEMs

* change default start sync date for first incremental sync

* removing caching of product type list

* change default incremental sync range

* version

* changelog

* shorten incremental sync if it is too long

* feat: release v2.2.0

* add duplicate support

* Update generated docs

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>

* Dev 2.2 (#47)

* add duplicate support

* Update generated docs

* treat needs_approval the same as pending on enrollments and don't return failure code

* Update generated docs

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>

* Dev 2.3 (#54)

* improve BouncyCastle parsing

* add duplicate support

* Update generated docs

* Merge 2.2.0 to main

* fix for smime profile type

* template parameter to include client auth eku

* Update generated docs

* changelog and logging

* check for duplicate PEMs

* change default start sync date for first incremental sync

* removing caching of product type list

* change default incremental sync range

* version

* changelog

* shorten incremental sync if it is too long

* feat: release v2.2.0

* add duplicate support

* Update generated docs

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>

---------

Co-authored-by: David Galey <dgaley@keyfactor.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: Dave Galey <89407235+dgaley@users.noreply.github.com>
Co-authored-by: Sean <1661003+spbsoluble@users.noreply.github.com>

* treat needs_approval the same as pending on enrollments and don't return failure code

* Update generated docs

* Merge 2.2.1 to main (#49)

* fix for smime profile type

* template parameter to include client auth eku

* Update generated docs

* changelog and logging

* check for duplicate PEMs

* change default start sync date for first incremental sync

* removing caching of product type list

* change default incremental sync range

* version

* changelog

* shorten incremental sync if it is too long

* feat: release v2.2.0

* add duplicate support

* Update generated docs

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>

* Dev 2.2 (#47)

* add duplicate support

* Update generated docs

* treat needs_approval the same as pending on enrollments and don't return failure code

* Update generated docs

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>

---------

Co-authored-by: David Galey <dgaley@keyfactor.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: Dave Galey <89407235+dgaley@users.noreply.github.com>
Co-authored-by: Sean <1661003+spbsoluble@users.noreply.github.com>

* Merge  to main (#48)

* fix for smime profile type

* template parameter to include client auth eku

* Update generated docs

* changelog and logging

* check for duplicate PEMs

* change default start sync date for first incremental sync

* removing caching of product type list

* change default incremental sync range

* version

* changelog

* shorten incremental sync if it is too long

* add duplicate support

* Update generated docs

* treat needs_approval the same as pending on enrollments and don't return failure code

* Update generated docs

---------

Co-authored-by: David Galey <dgaley@keyfactor.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: Dave Galey <89407235+dgaley@users.noreply.github.com>
Co-authored-by: Sean <1661003+spbsoluble@users.noreply.github.com>

* Update CHANGELOG.md (#50)

* add option for kdc/smartcardlogon eku, fix template validation

* Update generated docs

* changelog

---------

Co-authored-by: Sean <1661003+spbsoluble@users.noreply.github.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: Morgan Gangwere <470584+indrora@users.noreply.github.com>

* Dev 2.4 (#57)

* add product ID filter to sync

* Update generated docs

* add Intel vPro EKU support

* Update generated docs

* fix for renewal of smime certs

* validation for intel vpro eku

* fix for template validation

* changelog

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>

* Dev 2.4 (#60)

* add product ID filter to sync

* Update generated docs

* add Intel vPro EKU support

* Update generated docs

* fix for renewal of smime certs

* validation for intel vpro eku

* fix for template validation

* changelog

* check for existance of template parameter fields

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>

---------

Co-authored-by: David Galey <dgaley@keyfactor.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: Dave Galey <89407235+dgaley@users.noreply.github.com>
Co-authored-by: Sean <1661003+spbsoluble@users.noreply.github.com>

* Update digicert-certcentral-caplugin.csproj

* automated domain validation functionality

* update integration manifest

* update gateway framework required version

* fix release dir

* Update digicert-certcentral-caplugin.csproj

* Update generated docs

* Update keyfactor-bootstrap-workflow.yml

* docs: auto-generate README and documentation [skip ci]

* properly check if cert is DV to ignore org check

* avoid duplicate API calls on sync

* error handling on sync to catch bad certs

* rate limit handling

* improved API error handling

* add ToString to Error class

* sync filter fixes

* incremental sync fix

* doc update

* docs: auto-generate README and documentation [skip ci]

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: Morgan Gangwere <470584+indrora@users.noreply.github.com>
Co-authored-by: Sean <1661003+spbsoluble@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings September 23, 2026 22:16

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The DNS validation flow can create orders before rejecting unsupported methods, and additional moderate correctness issues remain.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity · 3 Medium severity · 4 Low severity

Open (8)
What changed in this PR

Merges release 3.0.0 into main, upgrading Gateway compatibility and adding automated DNS validation.

Changes:

  • Adds configurable TXT/CNAME DNS validation.
  • Updates frameworks, dependencies, metadata, and documentation.
  • Improves API error handling, retries, and synchronization.
File Changes and review notes
README.md Documents compatibility and DNS validation. Nit: describe configured TXT or CNAME validation accurately.
integration-manifest.json Updates metadata and configuration fields. Nit: correct the TXT-only description.
docsource/​configuration.md Documents automated DNS validation.
digicert-certcentral-caplugin/​Models/​Error.cs Improves error formatting.
digicert-certcentral-caplugin/​digicert-certcentral-caplugin.csproj Updates target frameworks and dependencies.
digicert-certcentral-caplugin/​Constants.cs Adds DNS configuration constants.
digicert-certcentral-caplugin/​Client/​CertCentralClient.cs Adds error parsing and retry handling. Moderate: retry behavior permits only two retries despite three-retry wording.
digicert-certcentral-caplugin/​CertCentralConfig.cs Adds DNS validation settings.
digicert-certcentral-caplugin/​CertCentralCAPlugin.cs Implements DNS validation and enrollment changes. Critical: validate unsupported or email methods before order creation. Moderate: propagate product lookup errors, verify DCV completion before download, handle missing DNS names, and avoid duplicate product lookups. Nits: correct diagnostic formatting and spelling.
CHANGELOG.md Records release changes.
.github/​workflows/​keyfactor-bootstrap-workflow.yml Updates the starter workflow version.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +1277 to +1280
if (!_config.DnsValidationEnabled)
{
_logger.LogTrace($"Automated DNS validation not enabled. Returning DCV token in enrollment context");
context.Add(dcvMethod, orderResponse.DCVRandomValue);
Comment on lines +190 to +193
CertificateTypeDetailsResponse details = client.GetCertificateTypeDetails(detailsRequest);

// Only do org check if the product type is NOT the group dv_ssl_certificate (https://dev.digicert.com/certcentral-apis/services-api/glossary.html#product-identifiers)
if (!string.Equals(details.GroupName, CertCentralConstants.ProductTypes.DV_SSL_CERT, StringComparison.OrdinalIgnoreCase))
Comment on lines +1297 to +1299
List<string> domains = new List<string>();
domains.Add(certificateOrderResponse.certificate.common_name);
domains.AddRange(certificateOrderResponse.certificate.dns_names);
}

private static int RequestIDCounter = 1;
private const int MaxRateLimitRetries = 3;
Comment thread README.md
* **FilterExpiredOrders** - If set to 'true', syncing will apply a filter to not return orders that are expired for longer than specified in SyncExpirationDays.
* **SyncExpirationDays** - If FilterExpiredOrders is set to true, this setting determines how many days in the past to still return expired orders. For example, a value of 30 means the sync will return any certs that expired within the past 30 days. A value of 0 means the sync will not return any certs that expired before the current day. This value is ignored if FilterExpiredOrders is false.
* **DnsValidationMethod** - The DNS validation method to use. Default value is 'email'. Other valid values are 'txt' and 'cname' If using automated DNS validation, 'txt' is the preferred method.
* **DnsValidationEnabled** - Enable automated DNS (TXT or CNAME) domain control validation. When enabled, the plugin requests TXT-based validation from DigiCert and publishes the returned record via the DNS provider plugin resolved by the AnyCA Gateway. Requires a DNS provider plugin (e.g. Azure, Cloudflare, etc) to be deployed and configured on the gateway. When disabled, requests that require validation will be flagged as External Validation, and the validation token, if needed depending on the DNS Validation method, will be returned.
}
else
{
_logger.LogWarning($"Unexpeted DCV method '{_config.DnsValidationMethod}'. Falling back to default of 'email'");
}
catch (Exception ex)
{
errors.Add($"Failed to resolve DNS provider plugin for '{dom}' (validation type '{validType}'\nError: {ex.Message}");
Comment thread integration-manifest.json
},
{
"name": "DnsValidationEnabled",
"description": "Enable automated DNS (TXT or CNAME) domain control validation. When enabled, the plugin requests TXT-based validation from DigiCert and publishes the returned record via the DNS provider plugin resolved by the AnyCA Gateway. Requires a DNS provider plugin (e.g. Azure, Cloudflare, etc) to be deployed and configured on the gateway. When disabled, requests that require validation will be flagged as External Validation, and the validation token, if needed depending on the DNS Validation method, will be returned."
@indrora
indrora merged commit 3e9f3a0 into main Sep 23, 2026
26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants