Skip to content

Merge 2.4.1 to main#61

Merged
indrora merged 28 commits into
mainfrom
release-2.4
Jul 22, 2026
Merged

Merge 2.4.1 to main#61
indrora merged 28 commits into
mainfrom
release-2.4

Conversation

@indrora

@indrora indrora commented Jul 22, 2026

Copy link
Copy Markdown
Member

Merge release-2.4 to main - Automated PR

dgaley and others added 27 commits October 8, 2025 11:29
change default start sync date for first incremental sync
removing caching of product type list
change default incremental sync range
shorten incremental sync if it is too long
* add duplicate support

* Update generated docs

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
* add duplicate support

* Update generated docs

* treat needs_approval the same as pending on enrollments and don't return failure code

* Update generated docs

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
* improve BouncyCastle parsing

* add duplicate support

* Update generated docs

* Merge 2.2.0 to main

* fix for smime profile type

* template parameter to include client auth eku

* Update generated docs

* changelog and logging

* check for duplicate PEMs

* change default start sync date for first incremental sync

* removing caching of product type list

* change default incremental sync range

* version

* changelog

* shorten incremental sync if it is too long

* feat: release v2.2.0

* add duplicate support

* Update generated docs

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>

---------

Co-authored-by: David Galey <dgaley@keyfactor.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: Dave Galey <89407235+dgaley@users.noreply.github.com>
Co-authored-by: Sean <1661003+spbsoluble@users.noreply.github.com>

* treat needs_approval the same as pending on enrollments and don't return failure code

* Update generated docs

* Merge 2.2.1 to main (#49)

* fix for smime profile type

* template parameter to include client auth eku

* Update generated docs

* changelog and logging

* check for duplicate PEMs

* change default start sync date for first incremental sync

* removing caching of product type list

* change default incremental sync range

* version

* changelog

* shorten incremental sync if it is too long

* feat: release v2.2.0

* add duplicate support

* Update generated docs

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>

* Dev 2.2 (#47)

* add duplicate support

* Update generated docs

* treat needs_approval the same as pending on enrollments and don't return failure code

* Update generated docs

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>

---------

Co-authored-by: David Galey <dgaley@keyfactor.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: Dave Galey <89407235+dgaley@users.noreply.github.com>
Co-authored-by: Sean <1661003+spbsoluble@users.noreply.github.com>

* Merge  to main (#48)

* fix for smime profile type

* template parameter to include client auth eku

* Update generated docs

* changelog and logging

* check for duplicate PEMs

* change default start sync date for first incremental sync

* removing caching of product type list

* change default incremental sync range

* version

* changelog

* shorten incremental sync if it is too long

* add duplicate support

* Update generated docs

* treat needs_approval the same as pending on enrollments and don't return failure code

* Update generated docs

---------

Co-authored-by: David Galey <dgaley@keyfactor.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: Dave Galey <89407235+dgaley@users.noreply.github.com>
Co-authored-by: Sean <1661003+spbsoluble@users.noreply.github.com>

* Update CHANGELOG.md (#50)

* add option for kdc/smartcardlogon eku, fix template validation

* Update generated docs

* changelog

---------

Co-authored-by: Sean <1661003+spbsoluble@users.noreply.github.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: Morgan Gangwere <470584+indrora@users.noreply.github.com>
* add product ID filter to sync

* Update generated docs

* add Intel vPro EKU support

* Update generated docs

* fix for renewal of smime certs

* validation for intel vpro eku

* fix for template validation

* changelog

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
* add product ID filter to sync

* Update generated docs

* add Intel vPro EKU support

* Update generated docs

* fix for renewal of smime certs

* validation for intel vpro eku

* fix for template validation

* changelog

* check for existance of template parameter fields

---------

Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Copilot AI review requested due to automatic review settings July 22, 2026 20:51

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR merges the release-2.4 changes into main, introducing sync-time filtering by DigiCert product ID and expanding SSL template EKU options (including Intel vPro), along with a couple of behavioral fixes noted in the changelog.

Changes:

  • Add SyncProductFilter configuration and pass product/division filters through to the DigiCert “list orders” API request.
  • Enforce “only one EKU option” for SSL enrollments and add IncludeIntelvProEKU.
  • Update documentation/manifest/changelog to reflect new parameters and behaviors.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated 6 comments.

Show a summary per file
File Description
README.md Documents SyncProductFilter and the new/updated EKU template parameters.
integration-manifest.json Adds SyncProductFilter and IncludeIntelvProEKU, and clarifies EKU mutual exclusivity.
digicert-certcentral-caplugin/Constants.cs Adds new config keys for product sync filtering and Intel vPro EKU.
digicert-certcentral-caplugin/Client/CertCentralClient.cs Updates ListAllCertificateOrders to accept division/product filter lists.
digicert-certcentral-caplugin/CertCentralConfig.cs Adds SyncProductFilter and parses it into a list for sync usage.
digicert-certcentral-caplugin/CertCentralCAPlugin.cs Implements EKU mutual exclusion + Intel vPro option, adds product filtering to sync flow, and updates SMIME renewal handling.
digicert-certcentral-caplugin/API/ListCertificateOrders.cs Adds support for multiple division/product filters in request query parameters.
CHANGELOG.md Adds entries for 2.4.0 and 2.4.1 describing the new features/fixes.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +1699 to +1702
if (productIds != null && productIds.Count > 0 && !productIds.Contains(orderResponse.product.name_id.ToString()))
{
_logger.LogTrace($"Found order ID {orderId} that does not match Product filter. Product ID: {orderResponse.product.name_id.ToString()} Skipping...");
}
_logger.LogTrace($"Sync CAs: {syncCAstring}");
List<string> caList = _config.SyncCAs;

caList.ForEach(c => c.ToUpper());
Comment on lines +41 to +49
if (!string.IsNullOrEmpty(SyncProductFilter))
{
return SyncProductFilter.Split(",").ToList();
}
else
{
return new List<string>();
}
}
Comment on lines +42 to +45
foreach (string divID in this.divIDs)
{
sbParamters.Append("&filters[container_id]=").Append(this.divID);
sbParamters.Append("&filters[container_id]=").Append(divID);
}
Comment on lines +46 to 49
foreach (string productID in productIDs)
{
sbParamters.Append("&filters[product_name_id]=").Append(productID);
}
Comment on lines +2104 to 2105
priorCertSnString = productInfo.ProductParameters["PriorCertSN"];
priorCertReqID = _certificateDataReader.GetRequestIDBySerialNumber(priorCertSnString).Result;
@indrora
indrora merged commit 368a70f into main Jul 22, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants