Commit Graph
84 Commits
Author SHA1 Message Date
Tim Bruijnzeels b3a4e7b208 Remove 'KeyRef', this is all covered by 'rpki::crypto::KeyIdentifier' now. 2019-08-28 16:34:15 +02:00
Tim Bruijnzeels ef858be696 Re-publish ROAs during key rolls. (#30) 2019-08-28 14:51:44 +02:00
Tim Bruijnzeels 69e4fda17c Update ROAs when resource entitlements change. (#30) 2019-08-28 13:44:51 +02:00
Tim Bruijnzeels 73473443b4 Add listing/updating ROAs to the CLI (#30). 2019-08-26 17:05:31 +02:00
Tim Bruijnzeels a8b17ec93d Improve testing: check that expected files are published. 2019-08-26 13:58:20 +02:00
Tim Bruijnzeels 9398c45ee4 Remove a ROA (#30). 2019-08-26 10:54:39 +02:00
Tim Bruijnzeels 6233616adf Create new ROAs (#30). 2019-08-23 12:02:46 +02:00
Tim Bruijnzeels 86ea370e8f Support (great-) grandchildren under multiple lineages. Closes: #25 2019-08-20 14:01:48 +02:00
Tim Bruijnzeels fc98944d66 Split parent and resource class maps.
This is a little more hassle when talking to a parent, however this is easier
when talking to children. Also there is now an explicit split in the names used
by the parent, and local simple (numbered) names for resources and their name-
spaces when it comes to publishing.
2019-08-19 15:13:08 +02:00
Tim Bruijnzeels 7925e72e88 Create real type for ResourceClassName. 2019-08-19 11:18:00 +02:00
Tim Bruijnzeels 60a60fd5d2 Change the notion of being a TA to having a special parent proxy, thus making TAs and normal CAs more alike. 2019-08-16 11:40:27 +02:00
Tim Bruijnzeels 84bdd0c4fa Force update resources for child CA. 2019-08-14 16:15:09 +02:00
Tim Bruijnzeels f4f2d726b8 Let child CA remove resource class, and request key revocations, when it looses an entitlement. (#56) 2019-08-13 15:38:37 +02:00
Tim Bruijnzeels 816c0a7be9 Avoid race condition. Only notify listeners of events after everything has been saved. 2019-08-13 11:37:30 +02:00
Tim Bruijnzeels 3af6d08943 Simplify embedded parent/child CAs. No use for tokens here, and child cannot override parent handle. 2019-08-12 16:54:28 +02:00
Tim Bruijnzeels 00e9165388 Remove the 'remote krill parent ca option' 2019-08-12 16:18:11 +02:00
Tim Bruijnzeels c1875b9de8 Manually finish key-roll by activating the new key. Tested with apnic. Fixes #23 2019-08-12 15:25:58 +02:00
Tim Bruijnzeels 47e0240734 Manually initialise a key roll for a CA. (#23) 2019-08-07 16:15:07 +02:00
Tim Bruijnzeels d6ac0db936 Guard key status life cycle in an enum (state machine). (#23) 2019-08-07 10:27:56 +02:00
Tim Bruijnzeels fe614d927f Clean up removed resource class and withdraw contents. Closes #50. 2019-08-06 12:47:08 +02:00
Tim Bruijnzeels c37c257821 Some cleanup 2019-08-06 10:47:11 +02:00
Tim Bruijnzeels 0c39530f22 Refreshing CA certificates in the background - not yet handling losing resources. (#50) 2019-08-05 17:23:46 +02:00
Tim Bruijnzeels 98ee1202c6 Cleanup: use rpki::x509::Time everywhere. 2019-08-05 12:54:13 +02:00
Tim Bruijnzeels 21baec11ea Do not use AKI extension in RFC6492/8181 CMS embedded CRL. 2019-08-05 12:33:50 +02:00
Tim Bruijnzeels 24b038d7ff Update child token, id_cert and/or resources. Closes #51. 2019-08-02 20:42:04 +02:00
Tim Bruijnzeels 5d2593857e Refactor events - use parent/child handle consistently for clarity. 2019-07-30 15:06:57 +02:00
Tim Bruijnzeels cd2e7133e9 Rustfmt 2019-07-30 13:58:48 +02:00
Tim Bruijnzeels 73a525c9b1 Fix interop with apnic RFC6492 (better check for CA bit) - (#13) 2019-07-26 11:30:29 -04:00
Tim Bruijnzeels 1ea10bb0cd Be more lenient in accepting RFC8181/6492 CMS structures and Id Certs - because they are poorly defined. (#13) 2019-07-24 16:26:30 -04:00
Tim Bruijnzeels b1bdd08071 Should fix the RFC6492 CMS signatures. (#13) 2019-07-24 09:47:38 -04:00
Tim Bruijnzeels 9b790757f4 Ignore critical extensions on IdCert (for interop testing). 2019-07-23 11:41:52 -04:00
Tim Bruijnzeels 3c8e9a470c Fix racecondition (save the updated aggregate!), and deadlock (use outer_lock on pub functions). 2019-07-21 15:54:59 -04:00
Tim Bruijnzeels 2e7b6258fe Get certificate from RFC6492 parent / issue to child. (#13) 2019-07-21 15:53:37 -04:00
Tim Bruijnzeels 2737a829da Support publishing to embedded pub server through scheduler. (#13) 2019-07-19 22:57:35 +02:00
Tim Bruijnzeels 38464aa2cf Introducing message queue for asynchronous triggered processes: request certs, publish. (work in progress for #13) 2019-07-19 21:20:18 +02:00
Tim Bruijnzeels 446a1c339b Add rfc6492 parent to child CA (#13). 2019-07-19 09:16:22 +02:00
Tim Bruijnzeels 901e2dfae7 Accept invalid certs when connecting to localhost or 127.0.0.1 - useful when testing. 2019-07-18 12:05:22 +02:00
Tim Bruijnzeels a6cbddbdf5 Generate the RFC8183 ID when a CA is initialised. Return RFC 8183 Child Request for CAs. 2019-07-18 11:55:20 +02:00
Tim Bruijnzeels b30c3a02b7 Merging cms_proxy module back into commons, so that we can define RFC8183 parents more easily. (#13) 2019-07-17 13:09:07 +02:00
Tim Bruijnzeels 3b7dd8fe20 Clippy knows best. 2019-07-17 11:32:26 +02:00
Tim Bruijnzeels 46f2d189e4 Support RFC8183 Parent Response. See issue #13. 2019-07-17 11:02:12 +02:00
Tim Bruijnzeels 5a79d0c18f Support RFC8183 Child Request. See issue #13. 2019-07-16 16:05:48 +02:00
Tim Bruijnzeels f8c83950a4 Support RFC6492 Revocation Request XML. 2019-07-16 12:21:43 +02:00
Tim Bruijnzeels 6b2d64e4f8 Support RFC6492 Issuance Report XML, and use it internally as well. (Issue #13) 2019-07-16 12:16:24 +02:00
Tim Bruijnzeels f622c14588 Support RFC6492 Issuance Report XML, and use it internally as well. (Issue #13) 2019-07-15 17:10:00 +02:00
Tim Bruijnzeels 63ddaec0b0 Support RFC6492 Certificate Issuance Request XML. (Issue #13) 2019-07-15 14:13:19 +02:00
Tim Bruijnzeels e859146bad Support RFC6492 List Response XML (for issue: #13) 2019-07-15 13:42:05 +02:00
Tim Bruijnzeels 57b3096418 Manage embedded delegated CA through CLI. 2019-07-10 15:06:28 +02:00
Tim Bruijnzeels 0280e6eaec Simplify: let TA and CA use same codebase 'CertAuth' 2019-07-09 12:17:40 +02:00
Tim Bruijnzeels fd1df3bb82 Merge branch 'master' into child-ca 2019-07-05 15:51:55 +02:00