Switch to domain-kmip. (#142)

* Switch to domain-kmip.

* Use https URL for domain-kmip.

* Update for domain-kmip change.
This commit is contained in:
Philip-NLnetLabs
2025-11-26 12:17:13 +01:00
committed by GitHub
parent 07d5bfec55
commit ef60307dc3
4 changed files with 332 additions and 88 deletions
Generated
+253 -35
View File
@@ -1,6 +1,6 @@
# This file is automatically @generated by Cargo.
# It is not intended for manual editing.
version = 3
version = 4
[[package]]
name = "aho-corasick"
@@ -99,6 +99,22 @@ version = "1.5.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "c08606f8c3cbf4ce6ec8e28fb0014a2c086708fe954eaa885384a6165172e7e8"
[[package]]
name = "base64"
version = "0.13.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "9e1b586273c5702936fe7b7d6896644d8be71e6314cfe09d3167c95f712589e8"
[[package]]
name = "bcder"
version = "0.7.6"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "1f7c42c9913f68cf9390a225e81ad56a5c515347287eb98baa710090ca1de86d"
dependencies = [
"bytes",
"smallvec",
]
[[package]]
name = "bitflags"
version = "2.10.0"
@@ -119,9 +135,9 @@ checksum = "b35204fbdc0b3f4446b89fc1ac2cf84a8a68971995d0bf2e925ec7cd960f9cb3"
[[package]]
name = "cc"
version = "1.2.46"
version = "1.2.47"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "b97463e1064cb1b1c1384ad0a0b9c8abd0988e2a91f52606c80ef14aadb63e36"
checksum = "cd405d82c84ff7f35739f175f67d8b9fb7687a0e84ccdc78bd3568839827cf07"
dependencies = [
"find-msvc-tools",
"shlex",
@@ -148,9 +164,9 @@ dependencies = [
[[package]]
name = "clap"
version = "4.5.52"
version = "4.5.53"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "aa8120877db0e5c011242f96806ce3c94e0737ab8108532a76a3300a01db2ab8"
checksum = "c9e340e012a1bf4935f5282ed1436d1489548e8f72308207ea5df0e23d2d03f8"
dependencies = [
"clap_builder",
"clap_derive",
@@ -158,9 +174,9 @@ dependencies = [
[[package]]
name = "clap_builder"
version = "4.5.52"
version = "4.5.53"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "02576b399397b659c26064fbc92a75fede9d18ffd5f80ca1cd74ddab167016e1"
checksum = "d76b5d13eaa18c901fd2f7fca939fefe3a0727a953561fefdf3b2922b8569d00"
dependencies = [
"anstream",
"anstyle",
@@ -178,7 +194,7 @@ dependencies = [
"heck",
"proc-macro2",
"quote",
"syn",
"syn 2.0.111",
]
[[package]]
@@ -291,7 +307,7 @@ checksum = "97369cbbc041bc366949bc74d34658d6cda5621039731c6310521892a3a20ae0"
dependencies = [
"proc-macro2",
"quote",
"syn",
"syn 2.0.111",
]
[[package]]
@@ -303,6 +319,7 @@ dependencies = [
"clap",
"const_format",
"domain",
"domain-kmip",
"futures",
"indenter",
"jiff",
@@ -328,7 +345,7 @@ dependencies = [
[[package]]
name = "domain"
version = "0.11.1"
source = "git+https://github.com/NLnetLabs/domain.git?branch=crypto-and-keyset-fixes#bd06f8b0d81f262059c4f8bd2b232c31405edc41"
source = "git+https://github.com/NLnetLabs/domain.git?branch=main#6c4eb26caaae72347113fc5f9e7375ef7e820867"
dependencies = [
"arc-swap",
"bumpalo",
@@ -358,14 +375,27 @@ dependencies = [
"tracing-subscriber",
]
[[package]]
name = "domain-kmip"
version = "0.0.1"
source = "git+https://github.com/NLnetLabs/domain-kmip.git?branch=initial-impl#cd231ed9f4264180dc0016ee7ba741784f5314e1"
dependencies = [
"bcder",
"domain",
"kmip-protocol",
"tracing",
"url",
"uuid",
]
[[package]]
name = "domain-macros"
version = "0.11.1"
source = "git+https://github.com/NLnetLabs/domain.git?branch=crypto-and-keyset-fixes#bd06f8b0d81f262059c4f8bd2b232c31405edc41"
source = "git+https://github.com/NLnetLabs/domain.git?branch=main#6c4eb26caaae72347113fc5f9e7375ef7e820867"
dependencies = [
"proc-macro2",
"quote",
"syn",
"syn 2.0.111",
]
[[package]]
@@ -374,6 +404,28 @@ version = "1.15.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "48c757948c5ede0e46177b7add2e67155f70e33c07fea8284df6576da70b3719"
[[package]]
name = "enum-display-derive"
version = "0.1.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "f16ef37b2a9b242295d61a154ee91ae884afff6b8b933b486b12481cc58310ca"
dependencies = [
"proc-macro2",
"quote",
"syn 1.0.109",
]
[[package]]
name = "enum-flags"
version = "0.1.8"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "3682d2328e61f5529088a02cd20bb0a9aeaeeeb2f26597436dd7d75d1340f8f5"
dependencies = [
"proc-macro2",
"quote",
"syn 1.0.109",
]
[[package]]
name = "equivalent"
version = "1.0.2"
@@ -503,7 +555,7 @@ checksum = "162ee34ebcb7c64a8abebc059ce0fee27c2262618d7b60ed8faf72fef13c3650"
dependencies = [
"proc-macro2",
"quote",
"syn",
"syn 2.0.111",
]
[[package]]
@@ -561,9 +613,9 @@ dependencies = [
[[package]]
name = "hashbrown"
version = "0.16.0"
version = "0.16.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "5419bdc4f6a9207fbeba6d11b604d481addf78ecd10c11ad51e76c2f6482748d"
checksum = "841d1cc9bed7f9236f321df977030373f4a4163ae1a7dbfe1a51a2c1a51d9100"
dependencies = [
"allocator-api2",
]
@@ -574,6 +626,12 @@ version = "0.5.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "2304e00983f87ffb38b55b444b5e3b60a884b5d30c0fca7d82fe33449bbe55ea"
[[package]]
name = "hex"
version = "0.4.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "7f24254aa9a54b5c858eaee2f5bccdb46aaf0e486a595ed5fd8f86ba55232a70"
[[package]]
name = "iana-time-zone"
version = "0.1.64"
@@ -739,7 +797,7 @@ checksum = "980af8b43c3ad5d8d349ace167ec8170839f753a42d233ba19e08afe1850fa69"
dependencies = [
"proc-macro2",
"quote",
"syn",
"syn 2.0.111",
]
[[package]]
@@ -752,6 +810,44 @@ dependencies = [
"wasm-bindgen",
]
[[package]]
name = "kmip-protocol"
version = "0.5.0"
source = "git+https://github.com/NLnetLabs/kmip-protocol.git?branch=next#f632fb135d75ce6fe6de8428d68c78739f345b15"
dependencies = [
"cfg-if",
"enum-display-derive",
"enum-flags",
"hex",
"kmip-ttlv",
"log",
"maybe-async",
"r2d2",
"rustc_version",
"rustls",
"rustls-pemfile",
"serde",
"serde_bytes",
"serde_derive",
"tracing",
"trait-set",
"webpki-roots",
]
[[package]]
name = "kmip-ttlv"
version = "0.4.0"
source = "git+https://github.com/NLnetLabs/kmip-ttlv?branch=next#4ca144e19e69375a6ccd63cf40b0e61f89462f97"
dependencies = [
"cfg-if",
"hex",
"maybe-async",
"rustc_version",
"serde",
"tracing",
"trait-set",
]
[[package]]
name = "lazy_static"
version = "1.5.0"
@@ -806,6 +902,17 @@ dependencies = [
"regex-automata",
]
[[package]]
name = "maybe-async"
version = "0.2.10"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "5cf92c10c7e361d6b99666ec1c6f9805b0bea2c3bd8c78dc6fe98ac5bd78db11"
dependencies = [
"proc-macro2",
"quote",
"syn 2.0.111",
]
[[package]]
name = "memchr"
version = "2.7.6"
@@ -914,7 +1021,7 @@ checksum = "a948666b637a0f465e8564c73e89d4dde00d72d4d473cc972f390fc3dcee7d9c"
dependencies = [
"proc-macro2",
"quote",
"syn",
"syn 2.0.111",
]
[[package]]
@@ -1065,6 +1172,17 @@ version = "5.3.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "69cdb34c158ceb288df11e18b4bd39de994f6657d83847bdffdbd7f346754b0f"
[[package]]
name = "r2d2"
version = "0.8.10"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "51de85fb3fb6524929c8a2eb85e6b6d363de4e8c48f9e2c2eac4944abc181c93"
dependencies = [
"log",
"parking_lot",
"scheduled-thread-pool",
]
[[package]]
name = "rand"
version = "0.8.5"
@@ -1218,6 +1336,50 @@ dependencies = [
"windows-sys 0.61.2",
]
[[package]]
name = "rustls"
version = "0.23.35"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "533f54bc6a7d4f647e46ad909549eda97bf5afc1585190ef692b4286b198bd8f"
dependencies = [
"log",
"once_cell",
"ring",
"rustls-pki-types",
"rustls-webpki",
"subtle",
"zeroize",
]
[[package]]
name = "rustls-pemfile"
version = "0.2.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "5eebeaeb360c87bfb72e84abdb3447159c0eaececf1bef2aecd65a8be949d1c9"
dependencies = [
"base64",
]
[[package]]
name = "rustls-pki-types"
version = "1.13.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "94182ad936a0c91c324cd46c6511b9510ed16af436d7b5bab34beab0afd55f7a"
dependencies = [
"zeroize",
]
[[package]]
name = "rustls-webpki"
version = "0.103.8"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "2ffdfa2f5286e2247234e03f680868ac2815974dc39e00ea15adc445d0aafe52"
dependencies = [
"ring",
"rustls-pki-types",
"untrusted",
]
[[package]]
name = "rustversion"
version = "1.0.22"
@@ -1230,6 +1392,15 @@ version = "1.0.20"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "28d3b2b1366ec20994f1fd18c3c594f05c5dd4bc44d8bb0c1c632c8d6829481f"
[[package]]
name = "scheduled-thread-pool"
version = "0.2.7"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "3cbc66816425a074528352f5789333ecff06ca41b36b0b0efdfbb29edc391a19"
dependencies = [
"parking_lot",
]
[[package]]
name = "scopeguard"
version = "1.2.0"
@@ -1261,6 +1432,16 @@ dependencies = [
"serde_derive",
]
[[package]]
name = "serde_bytes"
version = "0.11.19"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "a5d440709e79d88e51ac01c4b72fc6cb7314017bb7da9eeff678aa94c10e3ea8"
dependencies = [
"serde",
"serde_core",
]
[[package]]
name = "serde_core"
version = "1.0.228"
@@ -1278,7 +1459,7 @@ checksum = "d540f220d3187173da220f885ab66608367b6574e925011a9353e4badda91d79"
dependencies = [
"proc-macro2",
"quote",
"syn",
"syn 2.0.111",
]
[[package]]
@@ -1350,10 +1531,27 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "7da8b5736845d9f2fcb837ea5d9e2628564b3b043a70948a3f0b778838c5fb4f"
[[package]]
name = "syn"
version = "2.0.110"
name = "subtle"
version = "2.6.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "a99801b5bd34ede4cf3fc688c5919368fea4e4814a4664359503e6015b280aea"
checksum = "13c2bddecc57b384dee18652358fb23172facb8a2c51ccc10d74c157bdea3292"
[[package]]
name = "syn"
version = "1.0.109"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "72b64191b275b66ffe2469e8af2c1cfe3bafa67b529ead792a6d0160888b4237"
dependencies = [
"proc-macro2",
"quote",
"unicode-ident",
]
[[package]]
name = "syn"
version = "2.0.111"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "390cc9a294ab71bdb1aa2e99d13be9c753cd2d7bd6560c77118597410c4d2e87"
dependencies = [
"proc-macro2",
"quote",
@@ -1368,7 +1566,7 @@ checksum = "728a70f3dbaf5bab7f0c4b1ac8d7ae5ea60a4b5549c8a5914361c99147a709d2"
dependencies = [
"proc-macro2",
"quote",
"syn",
"syn 2.0.111",
]
[[package]]
@@ -1479,7 +1677,7 @@ checksum = "af407857209536a95c8e56f8231ef2c2e2aff839b22e07a1ffcbc617e9db9fa5"
dependencies = [
"proc-macro2",
"quote",
"syn",
"syn 2.0.111",
]
[[package]]
@@ -1513,7 +1711,7 @@ checksum = "81383ab64e72a7a8b8e13130c49e3dab29def6d0c7d76a03087b3cf71c5c6903"
dependencies = [
"proc-macro2",
"quote",
"syn",
"syn 2.0.111",
]
[[package]]
@@ -1555,6 +1753,17 @@ dependencies = [
"tracing-log",
]
[[package]]
name = "trait-set"
version = "0.2.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "875c4c873cc824e362fa9a9419ffa59807244824275a44ad06fec9684fff08f2"
dependencies = [
"proc-macro2",
"quote",
"syn 1.0.109",
]
[[package]]
name = "unicode-ident"
version = "1.0.22"
@@ -1667,7 +1876,7 @@ dependencies = [
"bumpalo",
"proc-macro2",
"quote",
"syn",
"syn 2.0.111",
"wasm-bindgen-shared",
]
@@ -1680,6 +1889,15 @@ dependencies = [
"unicode-ident",
]
[[package]]
name = "webpki-roots"
version = "1.0.4"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "b2878ef029c47c6e8cf779119f20fcf52bde7ad42a731b2a304bc221df17571e"
dependencies = [
"rustls-pki-types",
]
[[package]]
name = "windows-core"
version = "0.62.2"
@@ -1701,7 +1919,7 @@ checksum = "053e2e040ab57b9dc951b72c264860db7eb3b0200ba345b4e4c3b14f67855ddf"
dependencies = [
"proc-macro2",
"quote",
"syn",
"syn 2.0.111",
]
[[package]]
@@ -1712,7 +1930,7 @@ checksum = "3f316c4a2570ba26bbec722032c4099d8c8bc095efccdc15688708623367e358"
dependencies = [
"proc-macro2",
"quote",
"syn",
"syn 2.0.111",
]
[[package]]
@@ -1932,28 +2150,28 @@ checksum = "b659052874eb698efe5b9e8cf382204678a0086ebf46982b79d6ca3182927e5d"
dependencies = [
"proc-macro2",
"quote",
"syn",
"syn 2.0.111",
"synstructure",
]
[[package]]
name = "zerocopy"
version = "0.8.27"
version = "0.8.30"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "0894878a5fa3edfd6da3f88c4805f4c8558e2b996227a3d864f47fe11e38282c"
checksum = "4ea879c944afe8a2b25fef16bb4ba234f47c694565e97383b36f3a878219065c"
dependencies = [
"zerocopy-derive",
]
[[package]]
name = "zerocopy-derive"
version = "0.8.27"
version = "0.8.30"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "88d2b8d9c68ad2b9e4340d7832716a4d21a22a1154777ad56ea55c51a9cf3831"
checksum = "cf955aa904d6040f70dc8e9384444cb1030aed272ba3cb09bbc4ab9e7c1f34f5"
dependencies = [
"proc-macro2",
"quote",
"syn",
"syn 2.0.111",
]
[[package]]
@@ -1973,7 +2191,7 @@ checksum = "d71e5d6e06ab090c67b5e44993ec16b72dcbaabc526db883a360057678b48502"
dependencies = [
"proc-macro2",
"quote",
"syn",
"syn 2.0.111",
"synstructure",
]
@@ -2013,5 +2231,5 @@ checksum = "eadce39539ca5cb3985590102671f2567e659fca9666581ad3411d59207951f3"
dependencies = [
"proc-macro2",
"quote",
"syn",
"syn 2.0.111",
]
+6 -5
View File
@@ -17,12 +17,11 @@ name = "ldns"
path = "src/bin/ldns.rs"
[features]
#default = ["kmip", "openssl", "ring"]
default = ["openssl", "ring"]
default = ["kmip", "openssl", "ring"]
# Cryptographic backends
#kmip = ["domain/kmip", "dep:indenter", "dep:rand"]
kmip = ["dep:indenter", "dep:rand"]
kmip = ["domain-kmip", "dep:indenter", "dep:rand"]
openssl = ["domain/openssl"]
ring = ["domain/ring"]
@@ -34,7 +33,7 @@ static-openssl = ["openssl/vendored"]
bytes = "1.8.0"
chrono = "0.4.38"
clap = { version = "4.3.4", features = ["cargo", "derive", "wrap_help"] }
domain = { git = "https://github.com/NLnetLabs/domain.git", branch = "crypto-and-keyset-fixes", features = [
domain = { git = "https://github.com/NLnetLabs/domain.git", branch = "main", features = [
"bytes",
"net",
"resolv",
@@ -45,6 +44,8 @@ domain = { git = "https://github.com/NLnetLabs/domain.git", branch = "crypto-and
"unstable-validator",
"unstable-zonetree"
] }
domain-kmip = { git = "https://github.com/NLnetLabs/domain-kmip.git", branch = "initial-impl", optional = true, features = [
] }
indenter = { version = "0.3.4", optional = true }
lexopt = "0.3.0"
rayon = "1.10.0"
@@ -74,7 +75,7 @@ const_format = " 0.2.33"
test_bin = "0.4.0"
tempfile = "3.20.0"
regex = "1.11.1"
domain = { git = "https://github.com/NLnetLabs/domain.git", branch = "crypto-and-keyset-fixes", features = [
domain = { git = "https://github.com/NLnetLabs/domain.git", branch = "main", features = [
"unstable-stelline",
] }
pretty_assertions = "1.4.1"
+70 -43
View File
@@ -28,11 +28,9 @@ use domain::base::zonefile_fmt::{DisplayKind, ZonefileFmt};
use domain::base::{
MessageBuilder, Name, ParseRecordData, ParsedName, Record, Rtype, Serial, ToName, Ttl,
};
#[cfg(feature = "kmip")]
use domain::crypto::sign::SignRaw;
use domain::crypto::sign::{GenerateParams, KeyPair, SecretKeyBytes};
#[cfg(feature = "kmip")]
use domain::crypto::{kmip, kmip::KeyUrl, sign::SignRaw};
#[cfg(feature = "kmip")]
use domain::dep::kmip::client::pool::SyncConnPool;
use domain::dep::octseq::{FromBuilder, OctetsFrom};
use domain::dnssec::common::{display_as_bind, parse_from_bind};
use domain::dnssec::sign::keys::keyset::{
@@ -55,6 +53,12 @@ use domain::resolv::StubResolver;
#[cfg(feature = "kmip")]
use domain::utils::base32::encode_string_hex;
use domain::zonefile::inplace::{Entry, Zonefile};
#[cfg(feature = "kmip")]
use domain_kmip as kmip;
#[cfg(feature = "kmip")]
use domain_kmip::dep::kmip::client::pool::SyncConnPool;
#[cfg(feature = "kmip")]
use domain_kmip::KeyUrl;
use futures::future::join_all;
use jiff::{Span, SpanRelativeTo};
use serde::{Deserialize, Serialize};
@@ -2358,11 +2362,8 @@ impl WorkSpace {
.state
.kmip
.get_pool(&mut self.pools, kmip_key_url.server_id())?;
let key =
domain::crypto::kmip::PublicKey::for_key_url(kmip_key_url, kmip_conn_pool)
.map_err(|err| {
format!("Failed to fetch public key for KMIP key URL: {err}")
})?;
let key = kmip::PublicKey::for_key_url(kmip_key_url, kmip_conn_pool)
.map_err(|err| format!("Failed to fetch public key for KMIP key URL: {err}"))?;
let owner: Name<Octs> = self
.state
.keyset
@@ -2501,7 +2502,7 @@ impl WorkSpace {
rand::fill(&mut random_bytes[..]);
let private_key_random_label = encode_string_hex(&random_bytes);
let key_pair = domain::crypto::kmip::sign::generate(
let key_pair = kmip::sign::generate(
public_key_random_label,
private_key_random_label,
algorithm.clone(),
@@ -2800,7 +2801,7 @@ impl WorkSpace {
let privref = v.privref().ok_or("missing private key")?;
let priv_url = Url::parse(privref).expect("valid URL expected");
let pub_url = Url::parse(k).expect("valid URL expected");
let signing_key = match (priv_url.scheme(), pub_url.scheme()) {
match (priv_url.scheme(), pub_url.scheme()) {
("file", "file") => {
let private_data =
std::fs::read_to_string(priv_url.path()).map_err(|e| {
@@ -2819,11 +2820,19 @@ impl WorkSpace {
"private key {privref} and public key {k} do not match: {e}"
)
})?;
SigningKey::new(
let signing_key = SigningKey::new(
public_key.owner().clone(),
public_key.data().flags(),
key_pair,
)
);
let sig = sign_rrset(&signing_key, &rrset, inception, expiration).map_err(
|e| {
format!(
"error signing DNSKEY RRset with private key {privref}: {e}"
)
},
)?;
sigs.push(sig);
}
#[cfg(feature = "kmip")]
@@ -2836,27 +2845,31 @@ impl WorkSpace {
.state
.kmip
.get_pool(&mut self.pools, priv_key_url.server_id())?;
let key_pair = domain::crypto::kmip::sign::KeyPair::from_urls(
let key_pair = kmip::sign::KeyPair::from_urls(
priv_key_url,
pub_key_url,
kmip_conn_pool,
)
.map_err(|err| format!("Failed to retrieve KMIP key by URL: {err}"))?;
let key_pair = KeyPair::Kmip(key_pair);
SigningKey::new(owner, flags, key_pair)
//let key_pair = KeyPair::Kmip(key_pair);
let signing_key = SigningKey::new(owner, flags, key_pair);
// TODO: Should there be a key not found error we can detect here so that we can retry if
// we believe that the key is simply not registered fully yet in the HSM?
let sig = sign_rrset(&signing_key, &rrset, inception, expiration).map_err(
|e| {
format!(
"error signing DNSKEY RRset with private key {privref}: {e}"
)
},
)?;
sigs.push(sig);
}
(priv_scheme, pub_scheme) => {
panic!("unsupported URL scheme combination: {priv_scheme} & {pub_scheme}");
}
};
// TODO: Should there be a key not found error we can detect here so that we can retry if
// we believe that the key is simply not registered fully yet in the HSM?
let sig = sign_rrset(&signing_key, &rrset, inception, expiration).map_err(|e| {
format!("error signing DNSKEY RRset with private key {privref}: {e}")
})?;
sigs.push(sig);
}
}
@@ -2935,7 +2948,7 @@ impl WorkSpace {
let privref = v.privref().ok_or("missing private key")?;
let priv_url = Url::parse(privref).expect("valid URL expected");
let pub_url = Url::parse(k).expect("valid URL expected");
let signing_key = match (priv_url.scheme(), pub_url.scheme()) {
match (priv_url.scheme(), pub_url.scheme()) {
("file", "file") => {
let path = priv_url.path();
let filename = env.in_cwd(&path);
@@ -2960,11 +2973,26 @@ impl WorkSpace {
"private key {privref} and public key {k} do not match: {e}"
)
})?;
SigningKey::new(
let signing_key = SigningKey::new(
public_key.owner().clone(),
public_key.data().flags(),
key_pair,
);
let sig = sign_rrset(&signing_key, &cds_rrset, inception, expiration)
.map_err(|e| {
format!("error signing CDS RRset with private key {privref}: {e}")
})?;
cds_sigs.push(sig);
let sig = sign_rrset::<_, _, Bytes, _>(
&signing_key,
&cdnskey_rrset,
inception,
expiration,
)
.map_err(|e| {
format!("error signing CDNSKEY RRset with private key {privref}: {e}")
})?;
cdnskey_sigs.push(sig);
}
#[cfg(feature = "kmip")]
@@ -2977,35 +3005,34 @@ impl WorkSpace {
.state
.kmip
.get_pool(&mut self.pools, priv_key_url.server_id())?;
let key_pair = domain::crypto::kmip::sign::KeyPair::from_urls(
let key_pair = kmip::sign::KeyPair::from_urls(
priv_key_url,
pub_key_url,
kmip_conn_pool,
)
.map_err(|err| format!("Failed to retrieve KMIP key by URL: {err}"))?;
let key_pair = KeyPair::Kmip(key_pair);
SigningKey::new(owner, flags, key_pair)
let signing_key = SigningKey::new(owner, flags, key_pair);
let sig = sign_rrset(&signing_key, &cds_rrset, inception, expiration)
.map_err(|e| {
format!("error signing CDS RRset with private key {privref}: {e}")
})?;
cds_sigs.push(sig);
let sig = sign_rrset::<_, _, Bytes, _>(
&signing_key,
&cdnskey_rrset,
inception,
expiration,
)
.map_err(|e| {
format!("error signing CDNSKEY RRset with private key {privref}: {e}")
})?;
cdnskey_sigs.push(sig);
}
(priv_scheme, pub_scheme) => {
panic!("unsupported URL scheme combination: {priv_scheme} & {pub_scheme}");
}
};
let sig =
sign_rrset(&signing_key, &cds_rrset, inception, expiration).map_err(|e| {
format!("error signing CDS RRset with private key {privref}: {e}")
})?;
cds_sigs.push(sig);
let sig = sign_rrset::<_, _, Bytes, _>(
&signing_key,
&cdnskey_rrset,
inception,
expiration,
)
.map_err(|e| {
format!("error signing CDNSKEY RRset with private key {privref}: {e}")
})?;
cdnskey_sigs.push(sig);
}
}
+3 -5
View File
@@ -30,11 +30,9 @@ use std::{
};
use clap::Subcommand;
use domain::{
base::{name::ToLabelIter, Name, NameBuilder},
crypto::kmip::{ClientCertificate, ConnectionSettings, KeyUrl},
dep::kmip::client::pool::{ConnectionManager, KmipConnError, SyncConnPool},
};
use domain::base::{name::ToLabelIter, Name, NameBuilder};
use domain_kmip::dep::kmip::client::pool::{ConnectionManager, KmipConnError, SyncConnPool};
use domain_kmip::{ClientCertificate, ConnectionSettings, KeyUrl};
use serde::{Deserialize, Serialize};
use url::Url;