Files
ExploreDNS/vendor/github.com/miekg/dns/dane.go
db806835aa
CI / test (pull_request) Failing after 3h2m8s
CI / docker (pull_request) Has been cancelled
fix: vendor deps and fix CI go-version, timeout, GOTOOLCHAIN (HAN-414)
- Run go mod vendor to eliminate proxy.golang.org network dependency
- Set GOFLAGS=-mod=vendor at job env level so all go commands use vendor/
- Fix go-version from 1.23 to 1.24.0 to match go.mod
- Move GOTOOLCHAIN=local to job-level env (not per-step inline)
- Set cache: false on setup-go (cache is irrelevant with vendoring)
- Add timeout-minutes: 15 so failures are caught quickly instead of 3h

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: multica-agent <github@multica.ai>
2026-06-11 09:08:51 +10:00

44 lines
997 B
Go

package dns
import (
"crypto/sha256"
"crypto/sha512"
"crypto/x509"
"encoding/hex"
"errors"
)
// CertificateToDANE converts a certificate to a hex string as used in the TLSA or SMIMEA records.
func CertificateToDANE(selector, matchingType uint8, cert *x509.Certificate) (string, error) {
switch matchingType {
case 0:
switch selector {
case 0:
return hex.EncodeToString(cert.Raw), nil
case 1:
return hex.EncodeToString(cert.RawSubjectPublicKeyInfo), nil
}
case 1:
h := sha256.New()
switch selector {
case 0:
h.Write(cert.Raw)
return hex.EncodeToString(h.Sum(nil)), nil
case 1:
h.Write(cert.RawSubjectPublicKeyInfo)
return hex.EncodeToString(h.Sum(nil)), nil
}
case 2:
h := sha512.New()
switch selector {
case 0:
h.Write(cert.Raw)
return hex.EncodeToString(h.Sum(nil)), nil
case 1:
h.Write(cert.RawSubjectPublicKeyInfo)
return hex.EncodeToString(h.Sum(nil)), nil
}
}
return "", errors.New("dns: bad MatchingType or Selector")
}