@salesforce/b2c-tooling-sdk / operations/mtls
operations/mtls
mTLS code upload certificate operations for B2C Commerce.
Two-factor (mTLS) code upload to staging via eCDN works with a private certificate authority (CA):
- Generate a CA certificate and key (generateCaCertificate).
- Upload the CA to eCDN (createCodeUploadCertificate). The response includes the code upload hostname associated with the staging zone.
- Issue one or more client certificates signed by the CA, bundled as PKCS12 (
.p12) files (issueClientCertificate). Each user (named after their Business Manager username) or CI pipeline (named after its API client ID) gets its own client certificate for WebDAV uploads; the CA itself is never used as a client certificate.
The CA certificate may be valid for at most MAX_CODE_UPLOAD_CA_VALIDITY_DAYS days. To rotate, upload a new CA before the old one expires, re-issue client certificates from it, then delete the old CA.
Usage
typescript
import {createCdnZonesClient} from '@salesforce/b2c-tooling-sdk/clients';
import {
createCodeUploadCertificate,
generateCaCertificate,
issueClientCertificate,
} from '@salesforce/b2c-tooling-sdk/operations/mtls';
const ca = generateCaCertificate({commonName: 'My Code Upload CA'});
const client = createCdnZonesClient({shortCode, tenantId}, auth, {readWrite: true});
const uploaded = await createCodeUploadCertificate(client, organizationId, {
name: 'code-upload',
certificatePem: ca.certificatePem,
privateKeyPem: ca.privateKeyPem,
});
const clientCert = issueClientCertificate({ca, commonName: 'build-server'});
await fs.writeFile('build-server.p12', clientCert.pkcs12);
// clientCert.passphrase protects the .p12; uploaded.mtlsAssociatedCodeUploadHostname
// is the WebDAV hostname to use with it.Interfaces
- CertificateKeyPair
- CreateCodeUploadCertificateOptions
- GenerateCaCertificateOptions
- GeneratedCertificate
- IssueClientCertificateOptions
- IssuedClientCertificate
Type Aliases
Variables
- DEFAULT_CA_VALIDITY_DAYS
- DEFAULT_CLIENT_VALIDITY_DAYS
- DEFAULT_KEY_SIZE
- MAX_CODE_UPLOAD_CA_VALIDITY_DAYS