Repository navigation
crypto: expose tls's x509 Certificate Object #29181
Description
Activity
- addedcryptoIssues and PRs related to the crypto subsystem.Issues and PRs related to the crypto subsystem.feature requestIssues requesting new Node.js features.Issues requesting new Node.js features.
on Aug 17, 2019 If anyone wants to take a crack at it, this would be reasonably straight-forward. The code to convert from an OpenSSL
X509exists already,, so it just needs a bit of a wrapper to use OpenSSL to parse out anLine 1904 in 02c74e7
static Local<Object> X509ToObject(Environment* env, X509* cert) { X509object from js string/buffer data before converting to a js object.We should have a unified way of accessing the key and its components for certificates and
KeyObjects.What if we took this idea a bit further and created an X509Store as well? Not only would we have a structured way of reading the properties of an X509, we could compose them into a store and then pass references to stores in the various parameters of the TLS module. e.g. pass an X509Store to
options.ca.Would provide a solid foundation for certificate handling in node.js going forward and also solve some of the performance issues relating to the parsing of string-formatted certificates on each request.
Hi - Any update on this ticket please? It would be really useful!
You can see that #30675 is a quick POC, but I make no promises about having the time to finish it.
@RalphBragg If you want to pick it up, feel free to take that code and finish it, there's not much there and you are welcome to call it your own.
- added a commit that references this issue
on Jan 12, 2021 - added a commit that references this issue
on May 22, 2026
Is your feature request related to a problem? Please describe.
Several use-cases for getting x509 certificate information need to be solved by requiring an asn.1 module, defining the structure and undergoing slow, inefficient and error prone parsing.
Describe the solution you'd like
Seeing how you can already get parsed certificate information from a
tlsSocketI wonder if an API like this could be exposed