mirror of
https://github.com/NLnetLabs/krill.git
synced 2026-09-28 12:24:52 +02:00
Show RFC8183 XML in CLI (#868)
This commit is contained in:
@@ -37,6 +37,7 @@ in RC1 and RC2:
|
||||
- Manifest of 0.10.0-rc1 includes CRL, but nothing else #853
|
||||
- Security fixes in KMIP dependencies (HSM support).
|
||||
- Handle more PKCS#11 transient failure scenarios (HSM support).
|
||||
- Show RFC8183 XML in the CLI output #868
|
||||
|
||||
In this release we introduce the following major features:
|
||||
- BGPSec Router Certificate Signing
|
||||
|
||||
+4
-4
@@ -191,8 +191,8 @@ impl KrillClient {
|
||||
|
||||
CaCommand::ParentResponse(handle, child) => {
|
||||
let uri = format!("api/v1/cas/{}/children/{}/contact", handle, child);
|
||||
let info: ParentCaContact = get_json(&self.server, &self.token, &uri).await?;
|
||||
Ok(ApiResponse::ParentCaContact(info))
|
||||
let response: idexchange::ParentResponse = get_json(&self.server, &self.token, &uri).await?;
|
||||
Ok(ApiResponse::Rfc8183ParentResponse(response))
|
||||
}
|
||||
|
||||
CaCommand::ChildRequest(handle) => {
|
||||
@@ -263,8 +263,8 @@ impl KrillClient {
|
||||
|
||||
CaCommand::ChildAdd(handle, req) => {
|
||||
let uri = format!("api/v1/cas/{}/children", handle);
|
||||
let info: ParentCaContact = post_json_with_response(&self.server, &self.token, &uri, req).await?;
|
||||
Ok(ApiResponse::ParentCaContact(info))
|
||||
let response = post_json_with_response(&self.server, &self.token, &uri, req).await?;
|
||||
Ok(ApiResponse::Rfc8183ParentResponse(response))
|
||||
}
|
||||
CaCommand::ChildUpdate(handle, child, req) => {
|
||||
let uri = format!("api/v1/cas/{}/children/{}", handle, child);
|
||||
|
||||
+25
-3
@@ -55,6 +55,7 @@ pub enum ApiResponse {
|
||||
PublisherList(PublisherList),
|
||||
RepoStats(RepoStats),
|
||||
|
||||
Rfc8183ParentResponse(idexchange::ParentResponse),
|
||||
Rfc8183RepositoryResponse(idexchange::RepositoryResponse),
|
||||
Rfc8183ChildRequest(idexchange::ChildRequest),
|
||||
Rfc8183PublisherRequest(idexchange::PublisherRequest),
|
||||
@@ -100,6 +101,7 @@ impl ApiResponse {
|
||||
ApiResponse::PublisherList(list) => Ok(Some(list.report(fmt)?)),
|
||||
ApiResponse::PublisherDetails(details) => Ok(Some(details.report(fmt)?)),
|
||||
ApiResponse::RepoStats(stats) => Ok(Some(stats.report(fmt)?)),
|
||||
ApiResponse::Rfc8183ParentResponse(res) => Ok(Some(res.report(fmt)?)),
|
||||
ApiResponse::Rfc8183ChildRequest(req) => Ok(Some(req.report(fmt)?)),
|
||||
ApiResponse::Rfc8183PublisherRequest(req) => Ok(Some(req.report(fmt)?)),
|
||||
ApiResponse::Rfc8183RepositoryResponse(res) => Ok(Some(res.report(fmt)?)),
|
||||
@@ -196,9 +198,29 @@ impl Report for ChildrenConnectionStats {}
|
||||
|
||||
impl Report for PublisherDetails {}
|
||||
|
||||
impl Report for idexchange::RepositoryResponse {}
|
||||
impl Report for idexchange::ChildRequest {}
|
||||
impl Report for idexchange::PublisherRequest {}
|
||||
impl Report for idexchange::RepositoryResponse {
|
||||
fn text(&self) -> Result<String, ReportError> {
|
||||
Ok(self.to_xml_string())
|
||||
}
|
||||
}
|
||||
|
||||
impl Report for idexchange::ParentResponse {
|
||||
fn text(&self) -> Result<String, ReportError> {
|
||||
Ok(self.to_xml_string())
|
||||
}
|
||||
}
|
||||
|
||||
impl Report for idexchange::ChildRequest {
|
||||
fn text(&self) -> Result<String, ReportError> {
|
||||
Ok(self.to_xml_string())
|
||||
}
|
||||
}
|
||||
|
||||
impl Report for idexchange::PublisherRequest {
|
||||
fn text(&self) -> Result<String, ReportError> {
|
||||
Ok(self.to_xml_string())
|
||||
}
|
||||
}
|
||||
|
||||
impl Report for RoaDefinitions {}
|
||||
|
||||
|
||||
@@ -450,24 +450,22 @@ impl CaManager {
|
||||
/// # CAs as parents
|
||||
///
|
||||
impl CaManager {
|
||||
/// Adds a child under a CA. The 'service_uri' is used here so that
|
||||
/// the appropriate `ParentCaContact` can be returned. If the `AddChildRequest`
|
||||
/// contains resources not held by this CA, then an `Error::CaChildExtraResources`
|
||||
/// is returned.
|
||||
/// Adds a child under a CA. If the `AddChildRequest` contains resources not held
|
||||
/// by this CA, then an `Error::CaChildExtraResources` is returned.
|
||||
pub async fn ca_add_child(
|
||||
&self,
|
||||
ca: &CaHandle,
|
||||
req: AddChildRequest,
|
||||
service_uri: &uri::Https,
|
||||
actor: &Actor,
|
||||
) -> KrillResult<ParentCaContact> {
|
||||
) -> KrillResult<idexchange::ParentResponse> {
|
||||
info!("CA '{}' process add child request: {}", &ca, &req);
|
||||
let (child_handle, child_res, id_cert) = req.unpack();
|
||||
|
||||
let add_child = CmdDet::child_add(ca, child_handle.clone(), id_cert.into(), child_res, actor);
|
||||
self.send_command(add_child).await?;
|
||||
|
||||
self.ca_parent_contact(ca, child_handle, service_uri).await
|
||||
self.ca_parent_response(ca, child_handle, service_uri).await
|
||||
}
|
||||
|
||||
/// Show details for a child under the CA.
|
||||
|
||||
@@ -1404,15 +1404,6 @@ async fn api_ca_stats_child_connections(req: Request, ca: CaHandle) -> RoutingRe
|
||||
)
|
||||
}
|
||||
|
||||
async fn api_ca_parent_contact(req: Request, ca: CaHandle, child: ChildHandle) -> RoutingResult {
|
||||
aa!(
|
||||
req,
|
||||
Permission::CA_READ,
|
||||
Handle::from(&ca),
|
||||
render_json_res(req.state().ca_parent_contact(&ca, child.clone()).await)
|
||||
)
|
||||
}
|
||||
|
||||
async fn api_ca_parent_res_json(req: Request, ca: CaHandle, child: ChildHandle) -> RoutingResult {
|
||||
aa!(
|
||||
req,
|
||||
@@ -1597,8 +1588,7 @@ async fn api_ca_children(req: Request, path: &mut RequestPath, ca: CaHandle) ->
|
||||
Method::DELETE => api_ca_child_remove(req, ca, child).await,
|
||||
_ => render_unknown_method(),
|
||||
},
|
||||
Some("contact") => api_ca_parent_contact(req, ca, child).await,
|
||||
Some("parent_response.json") => api_ca_parent_res_json(req, ca, child).await,
|
||||
Some("contact") | Some("parent_response.json") => api_ca_parent_res_json(req, ca, child).await,
|
||||
Some("parent_response.xml") => api_ca_parent_res_xml(req, ca, child).await,
|
||||
_ => render_unknown_method(),
|
||||
},
|
||||
|
||||
+15
-11
@@ -216,10 +216,14 @@ impl KrillServer {
|
||||
let child_req =
|
||||
AddChildRequest::new(testbed_ca_handle.convert(), testbed_ca_resources, child_id_cert);
|
||||
|
||||
let parent_ca_contact = ca_manager
|
||||
let parent_response = ca_manager
|
||||
.ca_add_child(&ta_handle, child_req, &service_uri, &system_actor)
|
||||
.await?;
|
||||
let parent_ca_contact =
|
||||
ParentCaContact::for_rfc8183_parent_response(parent_response).map_err(Error::rfc8183)?;
|
||||
|
||||
let parent_req = ParentCaReq::new(ta_handle.convert(), parent_ca_contact);
|
||||
|
||||
ca_manager
|
||||
.ca_parent_add_or_update(testbed_ca_handle.clone(), parent_req, &system_actor)
|
||||
.await?;
|
||||
@@ -408,9 +412,13 @@ impl KrillServer {
|
||||
let child_id_cert = ca.child_request().validate().map_err(Error::rfc8183)?;
|
||||
let child_req = AddChildRequest::new(ca_handle.convert(), resources, child_id_cert);
|
||||
|
||||
let parent_ca_contact = ca_manager
|
||||
let parent_response = ca_manager
|
||||
.ca_add_child(&parent_handle.convert(), child_req, &service_uri, &system_actor)
|
||||
.await?;
|
||||
|
||||
let parent_ca_contact =
|
||||
ParentCaContact::for_rfc8183_parent_response(parent_response).map_err(Error::rfc8183)?;
|
||||
|
||||
let parent_req = ParentCaReq::new(parent_handle.clone(), parent_ca_contact);
|
||||
ca_manager
|
||||
.ca_parent_add_or_update(ca_handle.clone(), parent_req, &system_actor)
|
||||
@@ -549,15 +557,13 @@ impl KrillServer {
|
||||
ca: &CaHandle,
|
||||
req: AddChildRequest,
|
||||
actor: &Actor,
|
||||
) -> KrillResult<ParentCaContact> {
|
||||
let contact = self.ca_manager.ca_add_child(ca, req, &self.service_uri, actor).await?;
|
||||
Ok(contact)
|
||||
) -> KrillResult<idexchange::ParentResponse> {
|
||||
self.ca_manager.ca_add_child(ca, req, &self.service_uri, actor).await
|
||||
}
|
||||
|
||||
/// Shows the parent contact for a child.
|
||||
pub async fn ca_parent_contact(&self, ca: &CaHandle, child: ChildHandle) -> KrillResult<ParentCaContact> {
|
||||
let contact = self.ca_manager.ca_parent_contact(ca, child, &self.service_uri).await?;
|
||||
Ok(contact)
|
||||
self.ca_manager.ca_parent_contact(ca, child, &self.service_uri).await
|
||||
}
|
||||
|
||||
/// Shows the parent contact for a child.
|
||||
@@ -566,8 +572,7 @@ impl KrillServer {
|
||||
ca: &CaHandle,
|
||||
child: ChildHandle,
|
||||
) -> KrillResult<idexchange::ParentResponse> {
|
||||
let contact = self.ca_manager.ca_parent_response(ca, child, &self.service_uri).await?;
|
||||
Ok(contact)
|
||||
self.ca_manager.ca_parent_response(ca, child, &self.service_uri).await
|
||||
}
|
||||
|
||||
/// Update IdCert or resources of a child.
|
||||
@@ -578,8 +583,7 @@ impl KrillServer {
|
||||
req: UpdateChildRequest,
|
||||
actor: &Actor,
|
||||
) -> KrillEmptyResult {
|
||||
self.ca_manager.ca_child_update(ca, child, req, actor).await?;
|
||||
Ok(())
|
||||
self.ca_manager.ca_child_update(ca, child, req, actor).await
|
||||
}
|
||||
|
||||
/// Update IdCert or resources of a child.
|
||||
|
||||
+1
-16
@@ -289,21 +289,6 @@ pub async fn request(ca: &CaHandle) -> idexchange::ChildRequest {
|
||||
}
|
||||
}
|
||||
|
||||
pub async fn add_child_to_ta_rfc6492(
|
||||
child: &ChildHandle,
|
||||
child_request: idexchange::ChildRequest,
|
||||
resources: ResourceSet,
|
||||
) -> ParentCaContact {
|
||||
let id_cert = child_request.validate().unwrap();
|
||||
let req = AddChildRequest::new(child.clone(), resources, id_cert);
|
||||
let res = krill_admin(Command::CertAuth(CaCommand::ChildAdd(ta_handle(), req))).await;
|
||||
|
||||
match res {
|
||||
ApiResponse::ParentCaContact(info) => info,
|
||||
_ => panic!("Expected ParentCaInfo response"),
|
||||
}
|
||||
}
|
||||
|
||||
pub async fn add_child_rfc6492(
|
||||
ca: CaHandle,
|
||||
child: ChildHandle,
|
||||
@@ -315,7 +300,7 @@ pub async fn add_child_rfc6492(
|
||||
let add_child_request = AddChildRequest::new(child, resources, id_cert);
|
||||
|
||||
match krill_admin(Command::CertAuth(CaCommand::ChildAdd(ca, add_child_request))).await {
|
||||
ApiResponse::ParentCaContact(info) => info,
|
||||
ApiResponse::Rfc8183ParentResponse(response) => ParentCaContact::for_rfc8183_parent_response(response).unwrap(),
|
||||
_ => panic!("Expected ParentCaInfo response"),
|
||||
}
|
||||
}
|
||||
|
||||
+6
-5
@@ -1,11 +1,12 @@
|
||||
#![type_length_limit = "5000000"]
|
||||
|
||||
use rpki::ca::idexchange;
|
||||
|
||||
extern crate krill;
|
||||
|
||||
#[tokio::test]
|
||||
async fn add_and_remove_certificate_authority() {
|
||||
use std::fs;
|
||||
use std::matches;
|
||||
use std::str::FromStr;
|
||||
|
||||
use rpki::{
|
||||
@@ -63,7 +64,7 @@ async fn add_and_remove_certificate_authority() {
|
||||
// <child_request/> --> testbed
|
||||
// <parent_response/> <-- testbed
|
||||
let child_id_cert = rfc8183_child_request.validate().unwrap();
|
||||
let add_child_response: ParentCaContact = post_json_with_response(
|
||||
let parent_response: idexchange::ParentResponse = post_json_with_response(
|
||||
&format!("{}testbed/children", KRILL_SERVER_URI),
|
||||
&AddChildRequest::new(
|
||||
dummy_ca_handle.convert(),
|
||||
@@ -75,7 +76,7 @@ async fn add_and_remove_certificate_authority() {
|
||||
.await
|
||||
.unwrap();
|
||||
|
||||
assert!(matches!(add_child_response, ParentCaContact::Rfc6492(_)));
|
||||
let parent_contact_for_child = ParentCaContact::for_rfc8183_parent_response(parent_response).unwrap();
|
||||
|
||||
// verify that the testbed shows that it now has the expected child CA
|
||||
let testbed_ca = ca_details(&testbed_ca_handle).await;
|
||||
@@ -102,13 +103,13 @@ async fn add_and_remove_certificate_authority() {
|
||||
assert!(xml::reader::EventReader::from_str(&parent_response_xml).next().is_ok());
|
||||
|
||||
// complete the RFC 8183 child registration process on the "client" side
|
||||
let parent_ca_req = ParentCaReq::new(testbed_ca_handle.convert(), add_child_response.clone());
|
||||
let parent_ca_req = ParentCaReq::new(testbed_ca_handle.convert(), parent_contact_for_child.clone());
|
||||
add_parent_to_ca(&dummy_ca_handle, parent_ca_req).await;
|
||||
|
||||
// verify that the child CA now has the correct parent
|
||||
let dummy_ca = ca_details(&dummy_ca_handle).await;
|
||||
let dummy_ca_parents = dummy_ca.parents();
|
||||
let expected_parent_info = ParentInfo::new(testbed_ca_handle.convert(), add_child_response);
|
||||
let expected_parent_info = ParentInfo::new(testbed_ca_handle.convert(), parent_contact_for_child);
|
||||
let actual_parent_info = &dummy_ca_parents[0];
|
||||
assert_eq!(1, dummy_ca_parents.len());
|
||||
assert_eq!(&expected_parent_info, actual_parent_info);
|
||||
|
||||
Reference in New Issue
Block a user