Show RFC8183 XML in CLI (#868)

This commit is contained in:
Tim Bruijnzeels
2022-08-29 16:51:39 +02:00
parent 0468106522
commit d34a7f2fdb
8 changed files with 57 additions and 56 deletions
+1
View File
@@ -37,6 +37,7 @@ in RC1 and RC2:
- Manifest of 0.10.0-rc1 includes CRL, but nothing else #853
- Security fixes in KMIP dependencies (HSM support).
- Handle more PKCS#11 transient failure scenarios (HSM support).
- Show RFC8183 XML in the CLI output #868
In this release we introduce the following major features:
- BGPSec Router Certificate Signing
+4 -4
View File
@@ -191,8 +191,8 @@ impl KrillClient {
CaCommand::ParentResponse(handle, child) => {
let uri = format!("api/v1/cas/{}/children/{}/contact", handle, child);
let info: ParentCaContact = get_json(&self.server, &self.token, &uri).await?;
Ok(ApiResponse::ParentCaContact(info))
let response: idexchange::ParentResponse = get_json(&self.server, &self.token, &uri).await?;
Ok(ApiResponse::Rfc8183ParentResponse(response))
}
CaCommand::ChildRequest(handle) => {
@@ -263,8 +263,8 @@ impl KrillClient {
CaCommand::ChildAdd(handle, req) => {
let uri = format!("api/v1/cas/{}/children", handle);
let info: ParentCaContact = post_json_with_response(&self.server, &self.token, &uri, req).await?;
Ok(ApiResponse::ParentCaContact(info))
let response = post_json_with_response(&self.server, &self.token, &uri, req).await?;
Ok(ApiResponse::Rfc8183ParentResponse(response))
}
CaCommand::ChildUpdate(handle, child, req) => {
let uri = format!("api/v1/cas/{}/children/{}", handle, child);
+25 -3
View File
@@ -55,6 +55,7 @@ pub enum ApiResponse {
PublisherList(PublisherList),
RepoStats(RepoStats),
Rfc8183ParentResponse(idexchange::ParentResponse),
Rfc8183RepositoryResponse(idexchange::RepositoryResponse),
Rfc8183ChildRequest(idexchange::ChildRequest),
Rfc8183PublisherRequest(idexchange::PublisherRequest),
@@ -100,6 +101,7 @@ impl ApiResponse {
ApiResponse::PublisherList(list) => Ok(Some(list.report(fmt)?)),
ApiResponse::PublisherDetails(details) => Ok(Some(details.report(fmt)?)),
ApiResponse::RepoStats(stats) => Ok(Some(stats.report(fmt)?)),
ApiResponse::Rfc8183ParentResponse(res) => Ok(Some(res.report(fmt)?)),
ApiResponse::Rfc8183ChildRequest(req) => Ok(Some(req.report(fmt)?)),
ApiResponse::Rfc8183PublisherRequest(req) => Ok(Some(req.report(fmt)?)),
ApiResponse::Rfc8183RepositoryResponse(res) => Ok(Some(res.report(fmt)?)),
@@ -196,9 +198,29 @@ impl Report for ChildrenConnectionStats {}
impl Report for PublisherDetails {}
impl Report for idexchange::RepositoryResponse {}
impl Report for idexchange::ChildRequest {}
impl Report for idexchange::PublisherRequest {}
impl Report for idexchange::RepositoryResponse {
fn text(&self) -> Result<String, ReportError> {
Ok(self.to_xml_string())
}
}
impl Report for idexchange::ParentResponse {
fn text(&self) -> Result<String, ReportError> {
Ok(self.to_xml_string())
}
}
impl Report for idexchange::ChildRequest {
fn text(&self) -> Result<String, ReportError> {
Ok(self.to_xml_string())
}
}
impl Report for idexchange::PublisherRequest {
fn text(&self) -> Result<String, ReportError> {
Ok(self.to_xml_string())
}
}
impl Report for RoaDefinitions {}
+4 -6
View File
@@ -450,24 +450,22 @@ impl CaManager {
/// # CAs as parents
///
impl CaManager {
/// Adds a child under a CA. The 'service_uri' is used here so that
/// the appropriate `ParentCaContact` can be returned. If the `AddChildRequest`
/// contains resources not held by this CA, then an `Error::CaChildExtraResources`
/// is returned.
/// Adds a child under a CA. If the `AddChildRequest` contains resources not held
/// by this CA, then an `Error::CaChildExtraResources` is returned.
pub async fn ca_add_child(
&self,
ca: &CaHandle,
req: AddChildRequest,
service_uri: &uri::Https,
actor: &Actor,
) -> KrillResult<ParentCaContact> {
) -> KrillResult<idexchange::ParentResponse> {
info!("CA '{}' process add child request: {}", &ca, &req);
let (child_handle, child_res, id_cert) = req.unpack();
let add_child = CmdDet::child_add(ca, child_handle.clone(), id_cert.into(), child_res, actor);
self.send_command(add_child).await?;
self.ca_parent_contact(ca, child_handle, service_uri).await
self.ca_parent_response(ca, child_handle, service_uri).await
}
/// Show details for a child under the CA.
+1 -11
View File
@@ -1404,15 +1404,6 @@ async fn api_ca_stats_child_connections(req: Request, ca: CaHandle) -> RoutingRe
)
}
async fn api_ca_parent_contact(req: Request, ca: CaHandle, child: ChildHandle) -> RoutingResult {
aa!(
req,
Permission::CA_READ,
Handle::from(&ca),
render_json_res(req.state().ca_parent_contact(&ca, child.clone()).await)
)
}
async fn api_ca_parent_res_json(req: Request, ca: CaHandle, child: ChildHandle) -> RoutingResult {
aa!(
req,
@@ -1597,8 +1588,7 @@ async fn api_ca_children(req: Request, path: &mut RequestPath, ca: CaHandle) ->
Method::DELETE => api_ca_child_remove(req, ca, child).await,
_ => render_unknown_method(),
},
Some("contact") => api_ca_parent_contact(req, ca, child).await,
Some("parent_response.json") => api_ca_parent_res_json(req, ca, child).await,
Some("contact") | Some("parent_response.json") => api_ca_parent_res_json(req, ca, child).await,
Some("parent_response.xml") => api_ca_parent_res_xml(req, ca, child).await,
_ => render_unknown_method(),
},
+15 -11
View File
@@ -216,10 +216,14 @@ impl KrillServer {
let child_req =
AddChildRequest::new(testbed_ca_handle.convert(), testbed_ca_resources, child_id_cert);
let parent_ca_contact = ca_manager
let parent_response = ca_manager
.ca_add_child(&ta_handle, child_req, &service_uri, &system_actor)
.await?;
let parent_ca_contact =
ParentCaContact::for_rfc8183_parent_response(parent_response).map_err(Error::rfc8183)?;
let parent_req = ParentCaReq::new(ta_handle.convert(), parent_ca_contact);
ca_manager
.ca_parent_add_or_update(testbed_ca_handle.clone(), parent_req, &system_actor)
.await?;
@@ -408,9 +412,13 @@ impl KrillServer {
let child_id_cert = ca.child_request().validate().map_err(Error::rfc8183)?;
let child_req = AddChildRequest::new(ca_handle.convert(), resources, child_id_cert);
let parent_ca_contact = ca_manager
let parent_response = ca_manager
.ca_add_child(&parent_handle.convert(), child_req, &service_uri, &system_actor)
.await?;
let parent_ca_contact =
ParentCaContact::for_rfc8183_parent_response(parent_response).map_err(Error::rfc8183)?;
let parent_req = ParentCaReq::new(parent_handle.clone(), parent_ca_contact);
ca_manager
.ca_parent_add_or_update(ca_handle.clone(), parent_req, &system_actor)
@@ -549,15 +557,13 @@ impl KrillServer {
ca: &CaHandle,
req: AddChildRequest,
actor: &Actor,
) -> KrillResult<ParentCaContact> {
let contact = self.ca_manager.ca_add_child(ca, req, &self.service_uri, actor).await?;
Ok(contact)
) -> KrillResult<idexchange::ParentResponse> {
self.ca_manager.ca_add_child(ca, req, &self.service_uri, actor).await
}
/// Shows the parent contact for a child.
pub async fn ca_parent_contact(&self, ca: &CaHandle, child: ChildHandle) -> KrillResult<ParentCaContact> {
let contact = self.ca_manager.ca_parent_contact(ca, child, &self.service_uri).await?;
Ok(contact)
self.ca_manager.ca_parent_contact(ca, child, &self.service_uri).await
}
/// Shows the parent contact for a child.
@@ -566,8 +572,7 @@ impl KrillServer {
ca: &CaHandle,
child: ChildHandle,
) -> KrillResult<idexchange::ParentResponse> {
let contact = self.ca_manager.ca_parent_response(ca, child, &self.service_uri).await?;
Ok(contact)
self.ca_manager.ca_parent_response(ca, child, &self.service_uri).await
}
/// Update IdCert or resources of a child.
@@ -578,8 +583,7 @@ impl KrillServer {
req: UpdateChildRequest,
actor: &Actor,
) -> KrillEmptyResult {
self.ca_manager.ca_child_update(ca, child, req, actor).await?;
Ok(())
self.ca_manager.ca_child_update(ca, child, req, actor).await
}
/// Update IdCert or resources of a child.
+1 -16
View File
@@ -289,21 +289,6 @@ pub async fn request(ca: &CaHandle) -> idexchange::ChildRequest {
}
}
pub async fn add_child_to_ta_rfc6492(
child: &ChildHandle,
child_request: idexchange::ChildRequest,
resources: ResourceSet,
) -> ParentCaContact {
let id_cert = child_request.validate().unwrap();
let req = AddChildRequest::new(child.clone(), resources, id_cert);
let res = krill_admin(Command::CertAuth(CaCommand::ChildAdd(ta_handle(), req))).await;
match res {
ApiResponse::ParentCaContact(info) => info,
_ => panic!("Expected ParentCaInfo response"),
}
}
pub async fn add_child_rfc6492(
ca: CaHandle,
child: ChildHandle,
@@ -315,7 +300,7 @@ pub async fn add_child_rfc6492(
let add_child_request = AddChildRequest::new(child, resources, id_cert);
match krill_admin(Command::CertAuth(CaCommand::ChildAdd(ca, add_child_request))).await {
ApiResponse::ParentCaContact(info) => info,
ApiResponse::Rfc8183ParentResponse(response) => ParentCaContact::for_rfc8183_parent_response(response).unwrap(),
_ => panic!("Expected ParentCaInfo response"),
}
}
+6 -5
View File
@@ -1,11 +1,12 @@
#![type_length_limit = "5000000"]
use rpki::ca::idexchange;
extern crate krill;
#[tokio::test]
async fn add_and_remove_certificate_authority() {
use std::fs;
use std::matches;
use std::str::FromStr;
use rpki::{
@@ -63,7 +64,7 @@ async fn add_and_remove_certificate_authority() {
// <child_request/> --> testbed
// <parent_response/> <-- testbed
let child_id_cert = rfc8183_child_request.validate().unwrap();
let add_child_response: ParentCaContact = post_json_with_response(
let parent_response: idexchange::ParentResponse = post_json_with_response(
&format!("{}testbed/children", KRILL_SERVER_URI),
&AddChildRequest::new(
dummy_ca_handle.convert(),
@@ -75,7 +76,7 @@ async fn add_and_remove_certificate_authority() {
.await
.unwrap();
assert!(matches!(add_child_response, ParentCaContact::Rfc6492(_)));
let parent_contact_for_child = ParentCaContact::for_rfc8183_parent_response(parent_response).unwrap();
// verify that the testbed shows that it now has the expected child CA
let testbed_ca = ca_details(&testbed_ca_handle).await;
@@ -102,13 +103,13 @@ async fn add_and_remove_certificate_authority() {
assert!(xml::reader::EventReader::from_str(&parent_response_xml).next().is_ok());
// complete the RFC 8183 child registration process on the "client" side
let parent_ca_req = ParentCaReq::new(testbed_ca_handle.convert(), add_child_response.clone());
let parent_ca_req = ParentCaReq::new(testbed_ca_handle.convert(), parent_contact_for_child.clone());
add_parent_to_ca(&dummy_ca_handle, parent_ca_req).await;
// verify that the child CA now has the correct parent
let dummy_ca = ca_details(&dummy_ca_handle).await;
let dummy_ca_parents = dummy_ca.parents();
let expected_parent_info = ParentInfo::new(testbed_ca_handle.convert(), add_child_response);
let expected_parent_info = ParentInfo::new(testbed_ca_handle.convert(), parent_contact_for_child);
let actual_parent_info = &dummy_ca_parents[0];
assert_eq!(1, dummy_ca_parents.len());
assert_eq!(&expected_parent_info, actual_parent_info);