diff --git a/Cargo.lock b/Cargo.lock index b733775..dd3192d 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -1,6 +1,6 @@ # This file is automatically @generated by Cargo. # It is not intended for manual editing. -version = 3 +version = 4 [[package]] name = "aho-corasick" @@ -99,6 +99,22 @@ version = "1.5.0" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "c08606f8c3cbf4ce6ec8e28fb0014a2c086708fe954eaa885384a6165172e7e8" +[[package]] +name = "base64" +version = "0.13.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "9e1b586273c5702936fe7b7d6896644d8be71e6314cfe09d3167c95f712589e8" + +[[package]] +name = "bcder" +version = "0.7.6" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "1f7c42c9913f68cf9390a225e81ad56a5c515347287eb98baa710090ca1de86d" +dependencies = [ + "bytes", + "smallvec", +] + [[package]] name = "bitflags" version = "2.10.0" @@ -119,9 +135,9 @@ checksum = "b35204fbdc0b3f4446b89fc1ac2cf84a8a68971995d0bf2e925ec7cd960f9cb3" [[package]] name = "cc" -version = "1.2.46" +version = "1.2.47" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "b97463e1064cb1b1c1384ad0a0b9c8abd0988e2a91f52606c80ef14aadb63e36" +checksum = "cd405d82c84ff7f35739f175f67d8b9fb7687a0e84ccdc78bd3568839827cf07" dependencies = [ "find-msvc-tools", "shlex", @@ -148,9 +164,9 @@ dependencies = [ [[package]] name = "clap" -version = "4.5.52" +version = "4.5.53" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "aa8120877db0e5c011242f96806ce3c94e0737ab8108532a76a3300a01db2ab8" +checksum = "c9e340e012a1bf4935f5282ed1436d1489548e8f72308207ea5df0e23d2d03f8" dependencies = [ "clap_builder", "clap_derive", @@ -158,9 +174,9 @@ dependencies = [ [[package]] name = "clap_builder" -version = "4.5.52" +version = "4.5.53" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "02576b399397b659c26064fbc92a75fede9d18ffd5f80ca1cd74ddab167016e1" +checksum = "d76b5d13eaa18c901fd2f7fca939fefe3a0727a953561fefdf3b2922b8569d00" dependencies = [ "anstream", "anstyle", @@ -178,7 +194,7 @@ dependencies = [ "heck", "proc-macro2", "quote", - "syn", + "syn 2.0.111", ] [[package]] @@ -291,7 +307,7 @@ checksum = "97369cbbc041bc366949bc74d34658d6cda5621039731c6310521892a3a20ae0" dependencies = [ "proc-macro2", "quote", - "syn", + "syn 2.0.111", ] [[package]] @@ -303,6 +319,7 @@ dependencies = [ "clap", "const_format", "domain", + "domain-kmip", "futures", "indenter", "jiff", @@ -328,7 +345,7 @@ dependencies = [ [[package]] name = "domain" version = "0.11.1" -source = "git+https://github.com/NLnetLabs/domain.git?branch=crypto-and-keyset-fixes#bd06f8b0d81f262059c4f8bd2b232c31405edc41" +source = "git+https://github.com/NLnetLabs/domain.git?branch=main#6c4eb26caaae72347113fc5f9e7375ef7e820867" dependencies = [ "arc-swap", "bumpalo", @@ -358,14 +375,27 @@ dependencies = [ "tracing-subscriber", ] +[[package]] +name = "domain-kmip" +version = "0.0.1" +source = "git+https://github.com/NLnetLabs/domain-kmip.git?branch=initial-impl#cd231ed9f4264180dc0016ee7ba741784f5314e1" +dependencies = [ + "bcder", + "domain", + "kmip-protocol", + "tracing", + "url", + "uuid", +] + [[package]] name = "domain-macros" version = "0.11.1" -source = "git+https://github.com/NLnetLabs/domain.git?branch=crypto-and-keyset-fixes#bd06f8b0d81f262059c4f8bd2b232c31405edc41" +source = "git+https://github.com/NLnetLabs/domain.git?branch=main#6c4eb26caaae72347113fc5f9e7375ef7e820867" dependencies = [ "proc-macro2", "quote", - "syn", + "syn 2.0.111", ] [[package]] @@ -374,6 +404,28 @@ version = "1.15.0" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "48c757948c5ede0e46177b7add2e67155f70e33c07fea8284df6576da70b3719" +[[package]] +name = "enum-display-derive" +version = "0.1.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "f16ef37b2a9b242295d61a154ee91ae884afff6b8b933b486b12481cc58310ca" +dependencies = [ + "proc-macro2", + "quote", + "syn 1.0.109", +] + +[[package]] +name = "enum-flags" +version = "0.1.8" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3682d2328e61f5529088a02cd20bb0a9aeaeeeb2f26597436dd7d75d1340f8f5" +dependencies = [ + "proc-macro2", + "quote", + "syn 1.0.109", +] + [[package]] name = "equivalent" version = "1.0.2" @@ -503,7 +555,7 @@ checksum = "162ee34ebcb7c64a8abebc059ce0fee27c2262618d7b60ed8faf72fef13c3650" dependencies = [ "proc-macro2", "quote", - "syn", + "syn 2.0.111", ] [[package]] @@ -561,9 +613,9 @@ dependencies = [ [[package]] name = "hashbrown" -version = "0.16.0" +version = "0.16.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "5419bdc4f6a9207fbeba6d11b604d481addf78ecd10c11ad51e76c2f6482748d" +checksum = "841d1cc9bed7f9236f321df977030373f4a4163ae1a7dbfe1a51a2c1a51d9100" dependencies = [ "allocator-api2", ] @@ -574,6 +626,12 @@ version = "0.5.0" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "2304e00983f87ffb38b55b444b5e3b60a884b5d30c0fca7d82fe33449bbe55ea" +[[package]] +name = "hex" +version = "0.4.3" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "7f24254aa9a54b5c858eaee2f5bccdb46aaf0e486a595ed5fd8f86ba55232a70" + [[package]] name = "iana-time-zone" version = "0.1.64" @@ -739,7 +797,7 @@ checksum = "980af8b43c3ad5d8d349ace167ec8170839f753a42d233ba19e08afe1850fa69" dependencies = [ "proc-macro2", "quote", - "syn", + "syn 2.0.111", ] [[package]] @@ -752,6 +810,44 @@ dependencies = [ "wasm-bindgen", ] +[[package]] +name = "kmip-protocol" +version = "0.5.0" +source = "git+https://github.com/NLnetLabs/kmip-protocol.git?branch=next#f632fb135d75ce6fe6de8428d68c78739f345b15" +dependencies = [ + "cfg-if", + "enum-display-derive", + "enum-flags", + "hex", + "kmip-ttlv", + "log", + "maybe-async", + "r2d2", + "rustc_version", + "rustls", + "rustls-pemfile", + "serde", + "serde_bytes", + "serde_derive", + "tracing", + "trait-set", + "webpki-roots", +] + +[[package]] +name = "kmip-ttlv" +version = "0.4.0" +source = "git+https://github.com/NLnetLabs/kmip-ttlv?branch=next#4ca144e19e69375a6ccd63cf40b0e61f89462f97" +dependencies = [ + "cfg-if", + "hex", + "maybe-async", + "rustc_version", + "serde", + "tracing", + "trait-set", +] + [[package]] name = "lazy_static" version = "1.5.0" @@ -806,6 +902,17 @@ dependencies = [ "regex-automata", ] +[[package]] +name = "maybe-async" +version = "0.2.10" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "5cf92c10c7e361d6b99666ec1c6f9805b0bea2c3bd8c78dc6fe98ac5bd78db11" +dependencies = [ + "proc-macro2", + "quote", + "syn 2.0.111", +] + [[package]] name = "memchr" version = "2.7.6" @@ -914,7 +1021,7 @@ checksum = "a948666b637a0f465e8564c73e89d4dde00d72d4d473cc972f390fc3dcee7d9c" dependencies = [ "proc-macro2", "quote", - "syn", + "syn 2.0.111", ] [[package]] @@ -1065,6 +1172,17 @@ version = "5.3.0" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "69cdb34c158ceb288df11e18b4bd39de994f6657d83847bdffdbd7f346754b0f" +[[package]] +name = "r2d2" +version = "0.8.10" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "51de85fb3fb6524929c8a2eb85e6b6d363de4e8c48f9e2c2eac4944abc181c93" +dependencies = [ + "log", + "parking_lot", + "scheduled-thread-pool", +] + [[package]] name = "rand" version = "0.8.5" @@ -1218,6 +1336,50 @@ dependencies = [ "windows-sys 0.61.2", ] +[[package]] +name = "rustls" +version = "0.23.35" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "533f54bc6a7d4f647e46ad909549eda97bf5afc1585190ef692b4286b198bd8f" +dependencies = [ + "log", + "once_cell", + "ring", + "rustls-pki-types", + "rustls-webpki", + "subtle", + "zeroize", +] + +[[package]] +name = "rustls-pemfile" +version = "0.2.1" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "5eebeaeb360c87bfb72e84abdb3447159c0eaececf1bef2aecd65a8be949d1c9" +dependencies = [ + "base64", +] + +[[package]] +name = "rustls-pki-types" +version = "1.13.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "94182ad936a0c91c324cd46c6511b9510ed16af436d7b5bab34beab0afd55f7a" +dependencies = [ + "zeroize", +] + +[[package]] +name = "rustls-webpki" +version = "0.103.8" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "2ffdfa2f5286e2247234e03f680868ac2815974dc39e00ea15adc445d0aafe52" +dependencies = [ + "ring", + "rustls-pki-types", + "untrusted", +] + [[package]] name = "rustversion" version = "1.0.22" @@ -1230,6 +1392,15 @@ version = "1.0.20" source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "28d3b2b1366ec20994f1fd18c3c594f05c5dd4bc44d8bb0c1c632c8d6829481f" +[[package]] +name = "scheduled-thread-pool" +version = "0.2.7" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "3cbc66816425a074528352f5789333ecff06ca41b36b0b0efdfbb29edc391a19" +dependencies = [ + "parking_lot", +] + [[package]] name = "scopeguard" version = "1.2.0" @@ -1261,6 +1432,16 @@ dependencies = [ "serde_derive", ] +[[package]] +name = "serde_bytes" +version = "0.11.19" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "a5d440709e79d88e51ac01c4b72fc6cb7314017bb7da9eeff678aa94c10e3ea8" +dependencies = [ + "serde", + "serde_core", +] + [[package]] name = "serde_core" version = "1.0.228" @@ -1278,7 +1459,7 @@ checksum = "d540f220d3187173da220f885ab66608367b6574e925011a9353e4badda91d79" dependencies = [ "proc-macro2", "quote", - "syn", + "syn 2.0.111", ] [[package]] @@ -1350,10 +1531,27 @@ source = "registry+https://github.com/rust-lang/crates.io-index" checksum = "7da8b5736845d9f2fcb837ea5d9e2628564b3b043a70948a3f0b778838c5fb4f" [[package]] -name = "syn" -version = "2.0.110" +name = "subtle" +version = "2.6.1" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "a99801b5bd34ede4cf3fc688c5919368fea4e4814a4664359503e6015b280aea" +checksum = "13c2bddecc57b384dee18652358fb23172facb8a2c51ccc10d74c157bdea3292" + +[[package]] +name = "syn" +version = "1.0.109" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "72b64191b275b66ffe2469e8af2c1cfe3bafa67b529ead792a6d0160888b4237" +dependencies = [ + "proc-macro2", + "quote", + "unicode-ident", +] + +[[package]] +name = "syn" +version = "2.0.111" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "390cc9a294ab71bdb1aa2e99d13be9c753cd2d7bd6560c77118597410c4d2e87" dependencies = [ "proc-macro2", "quote", @@ -1368,7 +1566,7 @@ checksum = "728a70f3dbaf5bab7f0c4b1ac8d7ae5ea60a4b5549c8a5914361c99147a709d2" dependencies = [ "proc-macro2", "quote", - "syn", + "syn 2.0.111", ] [[package]] @@ -1479,7 +1677,7 @@ checksum = "af407857209536a95c8e56f8231ef2c2e2aff839b22e07a1ffcbc617e9db9fa5" dependencies = [ "proc-macro2", "quote", - "syn", + "syn 2.0.111", ] [[package]] @@ -1513,7 +1711,7 @@ checksum = "81383ab64e72a7a8b8e13130c49e3dab29def6d0c7d76a03087b3cf71c5c6903" dependencies = [ "proc-macro2", "quote", - "syn", + "syn 2.0.111", ] [[package]] @@ -1555,6 +1753,17 @@ dependencies = [ "tracing-log", ] +[[package]] +name = "trait-set" +version = "0.2.0" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "875c4c873cc824e362fa9a9419ffa59807244824275a44ad06fec9684fff08f2" +dependencies = [ + "proc-macro2", + "quote", + "syn 1.0.109", +] + [[package]] name = "unicode-ident" version = "1.0.22" @@ -1667,7 +1876,7 @@ dependencies = [ "bumpalo", "proc-macro2", "quote", - "syn", + "syn 2.0.111", "wasm-bindgen-shared", ] @@ -1680,6 +1889,15 @@ dependencies = [ "unicode-ident", ] +[[package]] +name = "webpki-roots" +version = "1.0.4" +source = "registry+https://github.com/rust-lang/crates.io-index" +checksum = "b2878ef029c47c6e8cf779119f20fcf52bde7ad42a731b2a304bc221df17571e" +dependencies = [ + "rustls-pki-types", +] + [[package]] name = "windows-core" version = "0.62.2" @@ -1701,7 +1919,7 @@ checksum = "053e2e040ab57b9dc951b72c264860db7eb3b0200ba345b4e4c3b14f67855ddf" dependencies = [ "proc-macro2", "quote", - "syn", + "syn 2.0.111", ] [[package]] @@ -1712,7 +1930,7 @@ checksum = "3f316c4a2570ba26bbec722032c4099d8c8bc095efccdc15688708623367e358" dependencies = [ "proc-macro2", "quote", - "syn", + "syn 2.0.111", ] [[package]] @@ -1932,28 +2150,28 @@ checksum = "b659052874eb698efe5b9e8cf382204678a0086ebf46982b79d6ca3182927e5d" dependencies = [ "proc-macro2", "quote", - "syn", + "syn 2.0.111", "synstructure", ] [[package]] name = "zerocopy" -version = "0.8.27" +version = "0.8.30" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "0894878a5fa3edfd6da3f88c4805f4c8558e2b996227a3d864f47fe11e38282c" +checksum = "4ea879c944afe8a2b25fef16bb4ba234f47c694565e97383b36f3a878219065c" dependencies = [ "zerocopy-derive", ] [[package]] name = "zerocopy-derive" -version = "0.8.27" +version = "0.8.30" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "88d2b8d9c68ad2b9e4340d7832716a4d21a22a1154777ad56ea55c51a9cf3831" +checksum = "cf955aa904d6040f70dc8e9384444cb1030aed272ba3cb09bbc4ab9e7c1f34f5" dependencies = [ "proc-macro2", "quote", - "syn", + "syn 2.0.111", ] [[package]] @@ -1973,7 +2191,7 @@ checksum = "d71e5d6e06ab090c67b5e44993ec16b72dcbaabc526db883a360057678b48502" dependencies = [ "proc-macro2", "quote", - "syn", + "syn 2.0.111", "synstructure", ] @@ -2013,5 +2231,5 @@ checksum = "eadce39539ca5cb3985590102671f2567e659fca9666581ad3411d59207951f3" dependencies = [ "proc-macro2", "quote", - "syn", + "syn 2.0.111", ] diff --git a/Cargo.toml b/Cargo.toml index 6b0193e..59d7fa7 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -17,12 +17,11 @@ name = "ldns" path = "src/bin/ldns.rs" [features] -#default = ["kmip", "openssl", "ring"] -default = ["openssl", "ring"] +default = ["kmip", "openssl", "ring"] # Cryptographic backends #kmip = ["domain/kmip", "dep:indenter", "dep:rand"] -kmip = ["dep:indenter", "dep:rand"] +kmip = ["domain-kmip", "dep:indenter", "dep:rand"] openssl = ["domain/openssl"] ring = ["domain/ring"] @@ -34,7 +33,7 @@ static-openssl = ["openssl/vendored"] bytes = "1.8.0" chrono = "0.4.38" clap = { version = "4.3.4", features = ["cargo", "derive", "wrap_help"] } -domain = { git = "https://github.com/NLnetLabs/domain.git", branch = "crypto-and-keyset-fixes", features = [ +domain = { git = "https://github.com/NLnetLabs/domain.git", branch = "main", features = [ "bytes", "net", "resolv", @@ -45,6 +44,8 @@ domain = { git = "https://github.com/NLnetLabs/domain.git", branch = "crypto-and "unstable-validator", "unstable-zonetree" ] } +domain-kmip = { git = "https://github.com/NLnetLabs/domain-kmip.git", branch = "initial-impl", optional = true, features = [ +] } indenter = { version = "0.3.4", optional = true } lexopt = "0.3.0" rayon = "1.10.0" @@ -74,7 +75,7 @@ const_format = " 0.2.33" test_bin = "0.4.0" tempfile = "3.20.0" regex = "1.11.1" -domain = { git = "https://github.com/NLnetLabs/domain.git", branch = "crypto-and-keyset-fixes", features = [ +domain = { git = "https://github.com/NLnetLabs/domain.git", branch = "main", features = [ "unstable-stelline", ] } pretty_assertions = "1.4.1" diff --git a/src/commands/keyset/cmd.rs b/src/commands/keyset/cmd.rs index ad3536e..2b1eb65 100644 --- a/src/commands/keyset/cmd.rs +++ b/src/commands/keyset/cmd.rs @@ -28,11 +28,9 @@ use domain::base::zonefile_fmt::{DisplayKind, ZonefileFmt}; use domain::base::{ MessageBuilder, Name, ParseRecordData, ParsedName, Record, Rtype, Serial, ToName, Ttl, }; +#[cfg(feature = "kmip")] +use domain::crypto::sign::SignRaw; use domain::crypto::sign::{GenerateParams, KeyPair, SecretKeyBytes}; -#[cfg(feature = "kmip")] -use domain::crypto::{kmip, kmip::KeyUrl, sign::SignRaw}; -#[cfg(feature = "kmip")] -use domain::dep::kmip::client::pool::SyncConnPool; use domain::dep::octseq::{FromBuilder, OctetsFrom}; use domain::dnssec::common::{display_as_bind, parse_from_bind}; use domain::dnssec::sign::keys::keyset::{ @@ -55,6 +53,12 @@ use domain::resolv::StubResolver; #[cfg(feature = "kmip")] use domain::utils::base32::encode_string_hex; use domain::zonefile::inplace::{Entry, Zonefile}; +#[cfg(feature = "kmip")] +use domain_kmip as kmip; +#[cfg(feature = "kmip")] +use domain_kmip::dep::kmip::client::pool::SyncConnPool; +#[cfg(feature = "kmip")] +use domain_kmip::KeyUrl; use futures::future::join_all; use jiff::{Span, SpanRelativeTo}; use serde::{Deserialize, Serialize}; @@ -2358,11 +2362,8 @@ impl WorkSpace { .state .kmip .get_pool(&mut self.pools, kmip_key_url.server_id())?; - let key = - domain::crypto::kmip::PublicKey::for_key_url(kmip_key_url, kmip_conn_pool) - .map_err(|err| { - format!("Failed to fetch public key for KMIP key URL: {err}") - })?; + let key = kmip::PublicKey::for_key_url(kmip_key_url, kmip_conn_pool) + .map_err(|err| format!("Failed to fetch public key for KMIP key URL: {err}"))?; let owner: Name = self .state .keyset @@ -2501,7 +2502,7 @@ impl WorkSpace { rand::fill(&mut random_bytes[..]); let private_key_random_label = encode_string_hex(&random_bytes); - let key_pair = domain::crypto::kmip::sign::generate( + let key_pair = kmip::sign::generate( public_key_random_label, private_key_random_label, algorithm.clone(), @@ -2800,7 +2801,7 @@ impl WorkSpace { let privref = v.privref().ok_or("missing private key")?; let priv_url = Url::parse(privref).expect("valid URL expected"); let pub_url = Url::parse(k).expect("valid URL expected"); - let signing_key = match (priv_url.scheme(), pub_url.scheme()) { + match (priv_url.scheme(), pub_url.scheme()) { ("file", "file") => { let private_data = std::fs::read_to_string(priv_url.path()).map_err(|e| { @@ -2819,11 +2820,19 @@ impl WorkSpace { "private key {privref} and public key {k} do not match: {e}" ) })?; - SigningKey::new( + let signing_key = SigningKey::new( public_key.owner().clone(), public_key.data().flags(), key_pair, - ) + ); + let sig = sign_rrset(&signing_key, &rrset, inception, expiration).map_err( + |e| { + format!( + "error signing DNSKEY RRset with private key {privref}: {e}" + ) + }, + )?; + sigs.push(sig); } #[cfg(feature = "kmip")] @@ -2836,27 +2845,31 @@ impl WorkSpace { .state .kmip .get_pool(&mut self.pools, priv_key_url.server_id())?; - let key_pair = domain::crypto::kmip::sign::KeyPair::from_urls( + let key_pair = kmip::sign::KeyPair::from_urls( priv_key_url, pub_key_url, kmip_conn_pool, ) .map_err(|err| format!("Failed to retrieve KMIP key by URL: {err}"))?; - let key_pair = KeyPair::Kmip(key_pair); - SigningKey::new(owner, flags, key_pair) + //let key_pair = KeyPair::Kmip(key_pair); + let signing_key = SigningKey::new(owner, flags, key_pair); + + // TODO: Should there be a key not found error we can detect here so that we can retry if + // we believe that the key is simply not registered fully yet in the HSM? + let sig = sign_rrset(&signing_key, &rrset, inception, expiration).map_err( + |e| { + format!( + "error signing DNSKEY RRset with private key {privref}: {e}" + ) + }, + )?; + sigs.push(sig); } (priv_scheme, pub_scheme) => { panic!("unsupported URL scheme combination: {priv_scheme} & {pub_scheme}"); } }; - - // TODO: Should there be a key not found error we can detect here so that we can retry if - // we believe that the key is simply not registered fully yet in the HSM? - let sig = sign_rrset(&signing_key, &rrset, inception, expiration).map_err(|e| { - format!("error signing DNSKEY RRset with private key {privref}: {e}") - })?; - sigs.push(sig); } } @@ -2935,7 +2948,7 @@ impl WorkSpace { let privref = v.privref().ok_or("missing private key")?; let priv_url = Url::parse(privref).expect("valid URL expected"); let pub_url = Url::parse(k).expect("valid URL expected"); - let signing_key = match (priv_url.scheme(), pub_url.scheme()) { + match (priv_url.scheme(), pub_url.scheme()) { ("file", "file") => { let path = priv_url.path(); let filename = env.in_cwd(&path); @@ -2960,11 +2973,26 @@ impl WorkSpace { "private key {privref} and public key {k} do not match: {e}" ) })?; - SigningKey::new( + let signing_key = SigningKey::new( public_key.owner().clone(), public_key.data().flags(), key_pair, + ); + let sig = sign_rrset(&signing_key, &cds_rrset, inception, expiration) + .map_err(|e| { + format!("error signing CDS RRset with private key {privref}: {e}") + })?; + cds_sigs.push(sig); + let sig = sign_rrset::<_, _, Bytes, _>( + &signing_key, + &cdnskey_rrset, + inception, + expiration, ) + .map_err(|e| { + format!("error signing CDNSKEY RRset with private key {privref}: {e}") + })?; + cdnskey_sigs.push(sig); } #[cfg(feature = "kmip")] @@ -2977,35 +3005,34 @@ impl WorkSpace { .state .kmip .get_pool(&mut self.pools, priv_key_url.server_id())?; - let key_pair = domain::crypto::kmip::sign::KeyPair::from_urls( + let key_pair = kmip::sign::KeyPair::from_urls( priv_key_url, pub_key_url, kmip_conn_pool, ) .map_err(|err| format!("Failed to retrieve KMIP key by URL: {err}"))?; - let key_pair = KeyPair::Kmip(key_pair); - SigningKey::new(owner, flags, key_pair) + let signing_key = SigningKey::new(owner, flags, key_pair); + let sig = sign_rrset(&signing_key, &cds_rrset, inception, expiration) + .map_err(|e| { + format!("error signing CDS RRset with private key {privref}: {e}") + })?; + cds_sigs.push(sig); + let sig = sign_rrset::<_, _, Bytes, _>( + &signing_key, + &cdnskey_rrset, + inception, + expiration, + ) + .map_err(|e| { + format!("error signing CDNSKEY RRset with private key {privref}: {e}") + })?; + cdnskey_sigs.push(sig); } (priv_scheme, pub_scheme) => { panic!("unsupported URL scheme combination: {priv_scheme} & {pub_scheme}"); } }; - let sig = - sign_rrset(&signing_key, &cds_rrset, inception, expiration).map_err(|e| { - format!("error signing CDS RRset with private key {privref}: {e}") - })?; - cds_sigs.push(sig); - let sig = sign_rrset::<_, _, Bytes, _>( - &signing_key, - &cdnskey_rrset, - inception, - expiration, - ) - .map_err(|e| { - format!("error signing CDNSKEY RRset with private key {privref}: {e}") - })?; - cdnskey_sigs.push(sig); } } diff --git a/src/commands/keyset/kmip.rs b/src/commands/keyset/kmip.rs index 4b39bd5..aa3a9e1 100644 --- a/src/commands/keyset/kmip.rs +++ b/src/commands/keyset/kmip.rs @@ -30,11 +30,9 @@ use std::{ }; use clap::Subcommand; -use domain::{ - base::{name::ToLabelIter, Name, NameBuilder}, - crypto::kmip::{ClientCertificate, ConnectionSettings, KeyUrl}, - dep::kmip::client::pool::{ConnectionManager, KmipConnError, SyncConnPool}, -}; +use domain::base::{name::ToLabelIter, Name, NameBuilder}; +use domain_kmip::dep::kmip::client::pool::{ConnectionManager, KmipConnError, SyncConnPool}; +use domain_kmip::{ClientCertificate, ConnectionSettings, KeyUrl}; use serde::{Deserialize, Serialize}; use url::Url;