Always check for existing keys when hsm feature is enabled.

This commit is contained in:
Tim Bruijnzeels
2022-07-21 10:08:15 +02:00
parent f35ffd7bd3
commit c5014b1928
+9 -3
View File
@@ -316,6 +316,15 @@ pub trait UpgradeStore {
/// knowing that no changes are added to the event history at this time. After this,
/// the migration will be finalised.
pub fn prepare_upgrade_data_migrations(mode: UpgradeMode, config: Arc<Config>) -> UpgradeResult<Option<UpgradeReport>> {
// First of all ALWAYS check the existing keys if the hsm feature is enabled.
// Remember that this feature - although enabled by default from 0.10.x - may be enabled by installing
// a new krill binary of the same Krill version as the the previous binary. In other words, we cannot
// rely on the KrillVersion to decide whether this is needed. On the other hand.. this is a fairly
// cheap operation that we can just do at startup. It is done here, because in effect it *is* a data
// migration.
#[cfg(feature = "hsm")]
record_preexisting_openssl_keys_in_signer_mapper(config.clone())?;
match upgrade_versions(config.as_ref()) {
None => Ok(None),
Some(versions) => {
@@ -353,9 +362,6 @@ pub fn prepare_upgrade_data_migrations(mode: UpgradeMode, config: Arc<Config>) -
// - pubd_objects for objects published in a repository server
// - ca_objects for published objects for a CA.
#[cfg(feature = "hsm")]
record_preexisting_openssl_keys_in_signer_mapper(config.clone())?;
// We need to prepare pubd first, because if there were any CAs using
// an embedded repository then they will need to be updated to use the
// RFC 8181 protocol (using localhost) instead, and this can only be