This file is indexed.

/usr/lib/python2.7/dist-packages/magnumclient/v1/certificates_shell.py is in python-magnumclient 2.8.0-0ubuntu1.

This file is owned by root:root, with mode 0o644.

The actual contents of the file can be viewed below.

  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
# Copyright 2015 NEC Corporation.  All rights reserved.
#
#    Licensed under the Apache License, Version 2.0 (the "License"); you may
#    not use this file except in compliance with the License. You may obtain
#    a copy of the License at
#
#         http://www.apache.org/licenses/LICENSE-2.0
#
#    Unless required by applicable law or agreed to in writing, software
#    distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
#    WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
#    License for the specific language governing permissions and limitations
#    under the License.

import os.path

from magnumclient.common import cliutils as utils
from magnumclient.i18n import _


DEPRECATION_MESSAGE = (
    'WARNING: The bay parameter is deprecated and will be removed in a future '
    'release.\nUse the cluster parameter to avoid seeing this message.')


def _show_cert(certificate):
    print(certificate.pem)


def _get_target_uuid(cs, args):
    target = None
    if args.cluster:
        target = cs.clusters.get(args.cluster)
    elif args.bay:
        print(DEPRECATION_MESSAGE)
        target = cs.bays.get(args.bay)
    else:
        raise utils.MissingArgs(['--cluster or --bay'])
    return target.uuid


@utils.arg('--bay',
           required=False,
           metavar='<bay>',
           help=_('ID or name of the bay.'))
@utils.arg('postional_cluster',
           metavar='<cluster>',
           nargs='?',
           default=None,
           help=_('ID or name of the cluster.'))
@utils.arg('--cluster',
           metavar='<cluster>',
           default=None,
           help=(_('ID or name of the cluster. %s') %
                 utils.CLUSTER_DEPRECATION_HELP))
def do_ca_show(cs, args):
    """Show details about the CA certificate for a bay or cluster."""
    utils.validate_cluster_args(args.postional_cluster, args.cluster)
    args.cluster = args.postional_cluster or args.cluster
    opts = {
        'cluster_uuid': _get_target_uuid(cs, args)
    }

    cert = cs.certificates.get(**opts)
    _show_cert(cert)


@utils.arg('--csr',
           metavar='<csr>',
           help=_('File path of the csr file to send to Magnum'
                  ' to get signed.'))
@utils.arg('--bay',
           required=False,
           metavar='<bay>',
           help=_('ID or name of the bay.'))
@utils.arg('--cluster',
           required=False,
           metavar='<cluster>',
           help=_('ID or name of the cluster.'))
def do_ca_sign(cs, args):
    """Generate the CA certificate for a bay or cluster."""
    opts = {
        'cluster_uuid': _get_target_uuid(cs, args)
    }

    if args.csr is None or not os.path.isfile(args.csr):
        print('A CSR must be provided.')
        return

    with open(args.csr, 'r') as f:
        opts['csr'] = f.read()

    cert = cs.certificates.create(**opts)
    _show_cert(cert)


@utils.arg('--cluster',
           required=True,
           metavar='<cluster>',
           help=_('ID or name of the cluster.'))
def do_ca_rotate(cs, args):
    """Rotate the CA certificate for a bay or cluster to revoke access."""
    cluster = cs.clusters.get(args.cluster)
    opts = {
        'cluster_uuid': cluster.uuid
    }

    cs.certificates.rotate_ca(**opts)