diff --git a/README.md b/README.md index 0d7892f5..56f8c1fd 100644 --- a/README.md +++ b/README.md @@ -37,6 +37,7 @@ in RC1 and RC2: - Manifest of 0.10.0-rc1 includes CRL, but nothing else #853 - Security fixes in KMIP dependencies (HSM support). - Handle more PKCS#11 transient failure scenarios (HSM support). +- Show RFC8183 XML in the CLI output #868 In this release we introduce the following major features: - BGPSec Router Certificate Signing diff --git a/src/cli/client.rs b/src/cli/client.rs index 99311037..8ed5de7c 100644 --- a/src/cli/client.rs +++ b/src/cli/client.rs @@ -191,8 +191,8 @@ impl KrillClient { CaCommand::ParentResponse(handle, child) => { let uri = format!("api/v1/cas/{}/children/{}/contact", handle, child); - let info: ParentCaContact = get_json(&self.server, &self.token, &uri).await?; - Ok(ApiResponse::ParentCaContact(info)) + let response: idexchange::ParentResponse = get_json(&self.server, &self.token, &uri).await?; + Ok(ApiResponse::Rfc8183ParentResponse(response)) } CaCommand::ChildRequest(handle) => { @@ -263,8 +263,8 @@ impl KrillClient { CaCommand::ChildAdd(handle, req) => { let uri = format!("api/v1/cas/{}/children", handle); - let info: ParentCaContact = post_json_with_response(&self.server, &self.token, &uri, req).await?; - Ok(ApiResponse::ParentCaContact(info)) + let response = post_json_with_response(&self.server, &self.token, &uri, req).await?; + Ok(ApiResponse::Rfc8183ParentResponse(response)) } CaCommand::ChildUpdate(handle, child, req) => { let uri = format!("api/v1/cas/{}/children/{}", handle, child); diff --git a/src/cli/report.rs b/src/cli/report.rs index 2e9f7356..737f678d 100644 --- a/src/cli/report.rs +++ b/src/cli/report.rs @@ -55,6 +55,7 @@ pub enum ApiResponse { PublisherList(PublisherList), RepoStats(RepoStats), + Rfc8183ParentResponse(idexchange::ParentResponse), Rfc8183RepositoryResponse(idexchange::RepositoryResponse), Rfc8183ChildRequest(idexchange::ChildRequest), Rfc8183PublisherRequest(idexchange::PublisherRequest), @@ -100,6 +101,7 @@ impl ApiResponse { ApiResponse::PublisherList(list) => Ok(Some(list.report(fmt)?)), ApiResponse::PublisherDetails(details) => Ok(Some(details.report(fmt)?)), ApiResponse::RepoStats(stats) => Ok(Some(stats.report(fmt)?)), + ApiResponse::Rfc8183ParentResponse(res) => Ok(Some(res.report(fmt)?)), ApiResponse::Rfc8183ChildRequest(req) => Ok(Some(req.report(fmt)?)), ApiResponse::Rfc8183PublisherRequest(req) => Ok(Some(req.report(fmt)?)), ApiResponse::Rfc8183RepositoryResponse(res) => Ok(Some(res.report(fmt)?)), @@ -196,9 +198,29 @@ impl Report for ChildrenConnectionStats {} impl Report for PublisherDetails {} -impl Report for idexchange::RepositoryResponse {} -impl Report for idexchange::ChildRequest {} -impl Report for idexchange::PublisherRequest {} +impl Report for idexchange::RepositoryResponse { + fn text(&self) -> Result { + Ok(self.to_xml_string()) + } +} + +impl Report for idexchange::ParentResponse { + fn text(&self) -> Result { + Ok(self.to_xml_string()) + } +} + +impl Report for idexchange::ChildRequest { + fn text(&self) -> Result { + Ok(self.to_xml_string()) + } +} + +impl Report for idexchange::PublisherRequest { + fn text(&self) -> Result { + Ok(self.to_xml_string()) + } +} impl Report for RoaDefinitions {} diff --git a/src/daemon/ca/manager.rs b/src/daemon/ca/manager.rs index 0ffc750f..ee09bc27 100644 --- a/src/daemon/ca/manager.rs +++ b/src/daemon/ca/manager.rs @@ -450,24 +450,22 @@ impl CaManager { /// # CAs as parents /// impl CaManager { - /// Adds a child under a CA. The 'service_uri' is used here so that - /// the appropriate `ParentCaContact` can be returned. If the `AddChildRequest` - /// contains resources not held by this CA, then an `Error::CaChildExtraResources` - /// is returned. + /// Adds a child under a CA. If the `AddChildRequest` contains resources not held + /// by this CA, then an `Error::CaChildExtraResources` is returned. pub async fn ca_add_child( &self, ca: &CaHandle, req: AddChildRequest, service_uri: &uri::Https, actor: &Actor, - ) -> KrillResult { + ) -> KrillResult { info!("CA '{}' process add child request: {}", &ca, &req); let (child_handle, child_res, id_cert) = req.unpack(); let add_child = CmdDet::child_add(ca, child_handle.clone(), id_cert.into(), child_res, actor); self.send_command(add_child).await?; - self.ca_parent_contact(ca, child_handle, service_uri).await + self.ca_parent_response(ca, child_handle, service_uri).await } /// Show details for a child under the CA. diff --git a/src/daemon/http/server.rs b/src/daemon/http/server.rs index 52cc4da4..1914d159 100644 --- a/src/daemon/http/server.rs +++ b/src/daemon/http/server.rs @@ -1404,15 +1404,6 @@ async fn api_ca_stats_child_connections(req: Request, ca: CaHandle) -> RoutingRe ) } -async fn api_ca_parent_contact(req: Request, ca: CaHandle, child: ChildHandle) -> RoutingResult { - aa!( - req, - Permission::CA_READ, - Handle::from(&ca), - render_json_res(req.state().ca_parent_contact(&ca, child.clone()).await) - ) -} - async fn api_ca_parent_res_json(req: Request, ca: CaHandle, child: ChildHandle) -> RoutingResult { aa!( req, @@ -1597,8 +1588,7 @@ async fn api_ca_children(req: Request, path: &mut RequestPath, ca: CaHandle) -> Method::DELETE => api_ca_child_remove(req, ca, child).await, _ => render_unknown_method(), }, - Some("contact") => api_ca_parent_contact(req, ca, child).await, - Some("parent_response.json") => api_ca_parent_res_json(req, ca, child).await, + Some("contact") | Some("parent_response.json") => api_ca_parent_res_json(req, ca, child).await, Some("parent_response.xml") => api_ca_parent_res_xml(req, ca, child).await, _ => render_unknown_method(), }, diff --git a/src/daemon/krillserver.rs b/src/daemon/krillserver.rs index 24fce29a..267baa94 100644 --- a/src/daemon/krillserver.rs +++ b/src/daemon/krillserver.rs @@ -216,10 +216,14 @@ impl KrillServer { let child_req = AddChildRequest::new(testbed_ca_handle.convert(), testbed_ca_resources, child_id_cert); - let parent_ca_contact = ca_manager + let parent_response = ca_manager .ca_add_child(&ta_handle, child_req, &service_uri, &system_actor) .await?; + let parent_ca_contact = + ParentCaContact::for_rfc8183_parent_response(parent_response).map_err(Error::rfc8183)?; + let parent_req = ParentCaReq::new(ta_handle.convert(), parent_ca_contact); + ca_manager .ca_parent_add_or_update(testbed_ca_handle.clone(), parent_req, &system_actor) .await?; @@ -408,9 +412,13 @@ impl KrillServer { let child_id_cert = ca.child_request().validate().map_err(Error::rfc8183)?; let child_req = AddChildRequest::new(ca_handle.convert(), resources, child_id_cert); - let parent_ca_contact = ca_manager + let parent_response = ca_manager .ca_add_child(&parent_handle.convert(), child_req, &service_uri, &system_actor) .await?; + + let parent_ca_contact = + ParentCaContact::for_rfc8183_parent_response(parent_response).map_err(Error::rfc8183)?; + let parent_req = ParentCaReq::new(parent_handle.clone(), parent_ca_contact); ca_manager .ca_parent_add_or_update(ca_handle.clone(), parent_req, &system_actor) @@ -549,15 +557,13 @@ impl KrillServer { ca: &CaHandle, req: AddChildRequest, actor: &Actor, - ) -> KrillResult { - let contact = self.ca_manager.ca_add_child(ca, req, &self.service_uri, actor).await?; - Ok(contact) + ) -> KrillResult { + self.ca_manager.ca_add_child(ca, req, &self.service_uri, actor).await } /// Shows the parent contact for a child. pub async fn ca_parent_contact(&self, ca: &CaHandle, child: ChildHandle) -> KrillResult { - let contact = self.ca_manager.ca_parent_contact(ca, child, &self.service_uri).await?; - Ok(contact) + self.ca_manager.ca_parent_contact(ca, child, &self.service_uri).await } /// Shows the parent contact for a child. @@ -566,8 +572,7 @@ impl KrillServer { ca: &CaHandle, child: ChildHandle, ) -> KrillResult { - let contact = self.ca_manager.ca_parent_response(ca, child, &self.service_uri).await?; - Ok(contact) + self.ca_manager.ca_parent_response(ca, child, &self.service_uri).await } /// Update IdCert or resources of a child. @@ -578,8 +583,7 @@ impl KrillServer { req: UpdateChildRequest, actor: &Actor, ) -> KrillEmptyResult { - self.ca_manager.ca_child_update(ca, child, req, actor).await?; - Ok(()) + self.ca_manager.ca_child_update(ca, child, req, actor).await } /// Update IdCert or resources of a child. diff --git a/src/test.rs b/src/test.rs index 795c061f..cc9097f4 100644 --- a/src/test.rs +++ b/src/test.rs @@ -289,21 +289,6 @@ pub async fn request(ca: &CaHandle) -> idexchange::ChildRequest { } } -pub async fn add_child_to_ta_rfc6492( - child: &ChildHandle, - child_request: idexchange::ChildRequest, - resources: ResourceSet, -) -> ParentCaContact { - let id_cert = child_request.validate().unwrap(); - let req = AddChildRequest::new(child.clone(), resources, id_cert); - let res = krill_admin(Command::CertAuth(CaCommand::ChildAdd(ta_handle(), req))).await; - - match res { - ApiResponse::ParentCaContact(info) => info, - _ => panic!("Expected ParentCaInfo response"), - } -} - pub async fn add_child_rfc6492( ca: CaHandle, child: ChildHandle, @@ -315,7 +300,7 @@ pub async fn add_child_rfc6492( let add_child_request = AddChildRequest::new(child, resources, id_cert); match krill_admin(Command::CertAuth(CaCommand::ChildAdd(ca, add_child_request))).await { - ApiResponse::ParentCaContact(info) => info, + ApiResponse::Rfc8183ParentResponse(response) => ParentCaContact::for_rfc8183_parent_response(response).unwrap(), _ => panic!("Expected ParentCaInfo response"), } } diff --git a/tests/testbed.rs b/tests/testbed.rs index 2ff9bc96..8aa91786 100644 --- a/tests/testbed.rs +++ b/tests/testbed.rs @@ -1,11 +1,12 @@ #![type_length_limit = "5000000"] +use rpki::ca::idexchange; + extern crate krill; #[tokio::test] async fn add_and_remove_certificate_authority() { use std::fs; - use std::matches; use std::str::FromStr; use rpki::{ @@ -63,7 +64,7 @@ async fn add_and_remove_certificate_authority() { // --> testbed // <-- testbed let child_id_cert = rfc8183_child_request.validate().unwrap(); - let add_child_response: ParentCaContact = post_json_with_response( + let parent_response: idexchange::ParentResponse = post_json_with_response( &format!("{}testbed/children", KRILL_SERVER_URI), &AddChildRequest::new( dummy_ca_handle.convert(), @@ -75,7 +76,7 @@ async fn add_and_remove_certificate_authority() { .await .unwrap(); - assert!(matches!(add_child_response, ParentCaContact::Rfc6492(_))); + let parent_contact_for_child = ParentCaContact::for_rfc8183_parent_response(parent_response).unwrap(); // verify that the testbed shows that it now has the expected child CA let testbed_ca = ca_details(&testbed_ca_handle).await; @@ -102,13 +103,13 @@ async fn add_and_remove_certificate_authority() { assert!(xml::reader::EventReader::from_str(&parent_response_xml).next().is_ok()); // complete the RFC 8183 child registration process on the "client" side - let parent_ca_req = ParentCaReq::new(testbed_ca_handle.convert(), add_child_response.clone()); + let parent_ca_req = ParentCaReq::new(testbed_ca_handle.convert(), parent_contact_for_child.clone()); add_parent_to_ca(&dummy_ca_handle, parent_ca_req).await; // verify that the child CA now has the correct parent let dummy_ca = ca_details(&dummy_ca_handle).await; let dummy_ca_parents = dummy_ca.parents(); - let expected_parent_info = ParentInfo::new(testbed_ca_handle.convert(), add_child_response); + let expected_parent_info = ParentInfo::new(testbed_ca_handle.convert(), parent_contact_for_child); let actual_parent_info = &dummy_ca_parents[0]; assert_eq!(1, dummy_ca_parents.len()); assert_eq!(&expected_parent_info, actual_parent_info);