mirror of
https://github.com/NLnetLabs/krill.git
synced 2026-10-01 05:44:52 +02:00
Always check for existing keys when hsm feature is enabled.
This commit is contained in:
+9
-3
@@ -316,6 +316,15 @@ pub trait UpgradeStore {
|
||||
/// knowing that no changes are added to the event history at this time. After this,
|
||||
/// the migration will be finalised.
|
||||
pub fn prepare_upgrade_data_migrations(mode: UpgradeMode, config: Arc<Config>) -> UpgradeResult<Option<UpgradeReport>> {
|
||||
// First of all ALWAYS check the existing keys if the hsm feature is enabled.
|
||||
// Remember that this feature - although enabled by default from 0.10.x - may be enabled by installing
|
||||
// a new krill binary of the same Krill version as the the previous binary. In other words, we cannot
|
||||
// rely on the KrillVersion to decide whether this is needed. On the other hand.. this is a fairly
|
||||
// cheap operation that we can just do at startup. It is done here, because in effect it *is* a data
|
||||
// migration.
|
||||
#[cfg(feature = "hsm")]
|
||||
record_preexisting_openssl_keys_in_signer_mapper(config.clone())?;
|
||||
|
||||
match upgrade_versions(config.as_ref()) {
|
||||
None => Ok(None),
|
||||
Some(versions) => {
|
||||
@@ -353,9 +362,6 @@ pub fn prepare_upgrade_data_migrations(mode: UpgradeMode, config: Arc<Config>) -
|
||||
// - pubd_objects for objects published in a repository server
|
||||
// - ca_objects for published objects for a CA.
|
||||
|
||||
#[cfg(feature = "hsm")]
|
||||
record_preexisting_openssl_keys_in_signer_mapper(config.clone())?;
|
||||
|
||||
// We need to prepare pubd first, because if there were any CAs using
|
||||
// an embedded repository then they will need to be updated to use the
|
||||
// RFC 8181 protocol (using localhost) instead, and this can only be
|
||||
|
||||
Reference in New Issue
Block a user