Commit Graph
208 Commits
Author SHA1 Message Date
Martin HoffmannandGitHub fc104247ae Restructure authentication policies. (#1232)
This PR restructures how authentication policies are used in Krill. It
removes the use of Oso and its policy definition language and instead
switches to simple, straightforward mappings between permissions, roles,
and users.

The existing concept of roles is augmented to serve as the central
configuration option for limiting a user’s access to certain action and
resources. Roles are now user configurable via the new auth_roles
configuration directive. For each role, a set of permissions has to be
provided. Optionally, a list of resource handles (vulgo: CAs) can be given
in which case access is limited to these resources.

The authentication providers now assign one of these roles to each logged
in user.

The OpenID Connect provider now only determines claims for “id,” i.e., the
user name, and the “role.” Since we replaced the previous use of JMES
paths with custom functions with a more stringent model of matching and
substitution, the configuration had to change in a non-compatible way,
anyway, so we cleaned it up a bit and switched from a map to an array for
the claims.

For the config file provider, this was already possible by adding a “role”
attribute. This has now been changed into a “role” field of the user
details. In order to make upgrading seamless, the “role” attribute is
still accepted but a deprecation warning is logged. Since the auth_users
configuration is not used for the OpenID Connect provider any more, the
password_hash and salt fields of the user details are now mandatory.

Custom policies have been removed.

This is a breaking change.
2025-02-05 11:45:49 +01:00
Martin HoffmannandGitHub b4a750831e Update dependencies and resulting fix uuid-related errors. (#1248)
This PR update dependencies and fixes compile errors resulting from changes in the uuid crate.
2025-01-23 16:25:52 +01:00
Martin HoffmannandGitHub 9ef5e22134 Replace once_cell::OnceCell with std::sync::OnceLock. (#1246)
This PR removes the dependency on once_cell since all the relevant functionality is now in std.
2025-01-10 12:17:24 +01:00
Koen van HoveandGitHub c13d44fb8a Remove fslock and libflate dependencies. (#1245) 2025-01-08 13:04:19 +01:00
Koen van HoveandGitHub 7d989c16ed Bump dependencies (#1244) 2025-01-06 14:50:14 +01:00
Koen van HoveandGitHub 6da2c80d68 Integrate roto-api in Krill replacing RISwhois (#1233)
This PR replaces the downloading and parsing of RISwhois files in Krill
with the roto-api.
2024-12-20 14:28:00 +01:00
Martin Hoffmann d34df0c881 Switch back to rpki-rs main branch. 2024-08-20 15:57:53 +02:00
Martin Hoffmann 4b00231104 Experimentally update rpki-rs for backslashes in handles. 2024-08-20 14:44:15 +02:00
Martin Hoffmann bb2eef96ae Update dependencies. 2024-08-20 14:12:32 +02:00
Martin HoffmannandGitHub 6d253c22da Refactor cli to use clap’s derive. (#1228)
This PR changes how the clients -- krillc, krillta, as well as the
integration tests -- work to better fit the derive model provided by clap.
This results in basically everything in the cli module and all the
integration tests being different now.

The PR slightly changes the options for both krillc and krillta. For krillc,
the --server, --token, --format, and --api options are now before the first
subcommand (since they affect all commands). For krillta, those options are
now after krillta proxy but before the next subcommand, while --format is
now after krillta signer.

This PR also removes client support and integration tests for RTA.

This is a breaking change.
2024-08-20 14:05:06 +02:00
Martin Hoffmann 5fb6835b3e Switch to released rpki-rs. 2024-06-25 10:27:52 +02:00
Martin HoffmannandGitHub 5a86110a92 Upgrade cryptoki to 0.7. (#1212)
This PR upgrades cryptoki to 0.7. It doesn’t take advantage of the changes
yet. This will happen in follow-up PRs.
2024-06-24 17:53:19 +02:00
Martin HoffmannandGitHub fff64ce16f Update hyper to 1.3.1 and reqwest to 0.12.5. (#1211)
This PR updates hyper, reqwest, and the rustls stack to their current versions.
2024-06-24 17:32:43 +02:00
Martin HoffmannandGitHub 3837a4d4a1 Upgrade most dependencies. (#1202)
This PR updates the dependencies that don’t require complex changes.
2024-06-24 17:04:34 +02:00
Martin HoffmannandGitHub 99c6dd2079 Reorder Cargo.toml (and do a soft upgrade). (#1210)
This PR reorders the dependency list in Cargo.toml alphabetically. It also
does a soft cargo update.
2024-06-18 10:06:24 +02:00
Martin HoffmannandGitHub 2c8cd95ee5 Switch to rpki-rs git main to pull in fix for empty CRLs. (#1200)
This is just a reminder to require the latest release of rpki-rs when we release Krill.
2024-06-12 13:05:26 +02:00
Martin Hoffmann 141d8b79b4 Soft update of dependencies. 2024-06-11 12:58:58 +02:00
Ximon Eighteen 33e072ef44 Bump version for development, to work around Ploutos packaging failure due to upgrade to same version as last published. 2024-04-08 22:40:05 +02:00
Ximon Eighteen 46feb1e64a Don't use dependency versions that cause warnings.
* Upgrade yanked dependency deunicode.
* Upgrade yanked dependency hermit-abi.
* Update the changelog.
2023-12-13 22:52:21 +01:00
Ximon Eighteen 5a8986b1b9 Upgrade KVX dependency to fix #1171. (#1172) 2023-12-13 22:52:21 +01:00
ximon18 3dd7f5ab19 Version bump in preparation for release. 2023-12-13 22:52:21 +01:00
Tim Bruijnzeels 1e5348c796 Update version and readme for release 0.14.3 2023-12-06 09:55:57 +01:00
Tim Bruijnzeels ae90c4f88c Update dependencies and code to allow using rpki-rs 0.18.0 (#1166)
* Update rpki-rs, backoff, tokio_rustls, and include rustls_pemfile
* Clean up extern crate statements
2023-12-06 09:55:57 +01:00
Tim Bruijnzeels 5b7e353e96 Depend on kvx 0.9.2 to ensure tempfiles are used properly. #1160 2023-12-06 09:55:57 +01:00
Tim Bruijnzeels 6240544a90 Update version and readme for development. 2023-11-15 20:31:47 +01:00
Tim Bruijnzeels eafb258720 Update readme and version for release 0.14.2 2023-11-06 13:17:14 +01:00
Tim Bruijnzeels c7b44e59a1 Update version and readme for release 0.14.1 2023-11-03 11:57:31 +01:00
Tim Bruijnzeels 4cdf31285b Update version and readme for release 0.14.0 2023-10-31 11:53:21 +01:00
Tim Bruijnzeels 28b56d5805 Update version and readme for release 0.14.0-rc3 2023-10-23 12:00:46 +02:00
Tim Bruijnzeels 04cbfdadea Depend on latest rpki-rs with ASPA v1. 2023-10-23 12:00:46 +02:00
Tim Bruijnzeels f29d490652 Update to expected version for release. 2023-10-23 12:00:46 +02:00
Tim Bruijnzeels 8dcec56557 Update version and readme for release 0.14.0-rc2 2023-10-18 09:33:04 +02:00
Tim Bruijnzeels 38ee1e8686 Upgrade to kvx that uses locks outside of scope dir. (#1134) 2023-10-17 15:31:11 +02:00
Tim Bruijnzeels 4f4eafdfd3 Crash Krill if a fatal error is encountered by the task scheduler. (#1132)
* Crash Krill if a fatal error is encountered by the task scheduler.
* Do not finish running task when just adding a new task.
2023-10-17 15:31:11 +02:00
Tim Bruijnzeels 1d7c424f74 Remove library that is no longer used. 2023-10-17 15:31:11 +02:00
Tim Bruijnzeels d03022f495 Use kvx based transactional task queue #1090 2023-10-17 15:31:11 +02:00
Tim Bruijnzeels a5249fd185 Use transactions/locks (kvx::execute) for AggregateStore. (#1104) 2023-10-17 15:31:11 +02:00
dependabot[bot]andTim Bruijnzeels e6a6563ec6 Bump bcder from 0.7.1 to 0.7.3
Bumps [bcder](https://github.com/nlnetlabs/bcder) from 0.7.1 to 0.7.3.
- [Release notes](https://github.com/nlnetlabs/bcder/releases)
- [Changelog](https://github.com/NLnetLabs/bcder/blob/main/Changelog.md)
- [Commits](https://github.com/nlnetlabs/bcder/compare/v0.7.1...v0.7.3)

---
updated-dependencies:
- dependency-name: bcder
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-10-17 15:31:11 +02:00
dependabot[bot]andTim Bruijnzeels 3663cef411 Bump openssl from 0.10.51 to 0.10.55
Bumps [openssl](https://github.com/sfackler/rust-openssl) from 0.10.51 to 0.10.55.
- [Release notes](https://github.com/sfackler/rust-openssl/releases)
- [Commits](https://github.com/sfackler/rust-openssl/compare/openssl-v0.10.51...openssl-v0.10.55)

---
updated-dependencies:
- dependency-name: openssl
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2023-10-17 15:31:11 +02:00
Tim Bruijnzeels b9e66dcbec Migrate data store (#1100)
* Use kvx with explicit namespace type.
* Do not depend on a data dir for storage.
* Add support for data migration.
* Add command line option to migrate data to krillup.
2023-10-17 15:31:11 +02:00
Tim Bruijnzeels 263d870ca8 Support migrations using non-disk storage #1094
* Use kvx with explicit namespace type.
* Do not depend on a data dir for storage.
* Fix upgrade code.
2023-10-17 15:31:11 +02:00
Tim BruijnzeelsandArjen dd037c7e70 Kvx storage 1067 (#1069)
* Depend on kvx 0.6.0
* Update minimum rust version to 1.65 (required by kvx)
---------

Co-authored-by: Arjen <4867268+arjentz@users.noreply.github.com>
2023-10-17 15:31:11 +02:00
Tim Bruijnzeels c16a1f7e5b Update version to release candidate 0.14.0-rc1 2023-10-17 15:31:11 +02:00
Tim Bruijnzeels 2037d8e4fd Update version and readme for release 0.13.1 2023-06-01 16:27:08 +02:00
Tim Bruijnzeels a03cedc777 Update version for release 0.13.0 2023-05-22 15:59:13 +02:00
Tim Bruijnzeels fcd6071da2 Update version for release candidate 0.13.0-rc7 2023-05-18 12:59:55 +02:00
Tim Bruijnzeels b74389e576 Update version for 0.13.0-rc6 release 2023-05-12 13:28:59 +02:00
Tim Bruijnzeels fae1586080 Update version for release candidate 0.13.0-rc5 2023-05-11 15:31:59 +02:00
Tim Bruijnzeels 69a25a6140 Update version for release 0.13.0-rc4 2023-05-05 16:42:06 +02:00
Tim Bruijnzeels 8d2c6c2068 Update version for release 0.13.0-rc3 2023-05-03 11:22:51 +02:00