Tim Bruijnzeels
b3a4e7b208
Remove 'KeyRef', this is all covered by 'rpki::crypto::KeyIdentifier' now.
2019-08-28 16:34:15 +02:00
Tim Bruijnzeels
ef858be696
Re-publish ROAs during key rolls. ( #30 )
2019-08-28 14:51:44 +02:00
Tim Bruijnzeels
69e4fda17c
Update ROAs when resource entitlements change. ( #30 )
2019-08-28 13:44:51 +02:00
Tim Bruijnzeels
73473443b4
Add listing/updating ROAs to the CLI ( #30 ).
2019-08-26 17:05:31 +02:00
Tim Bruijnzeels
a8b17ec93d
Improve testing: check that expected files are published.
2019-08-26 13:58:20 +02:00
Tim Bruijnzeels
9398c45ee4
Remove a ROA ( #30 ).
2019-08-26 10:54:39 +02:00
Tim Bruijnzeels
6233616adf
Create new ROAs ( #30 ).
2019-08-23 12:02:46 +02:00
Tim Bruijnzeels
86ea370e8f
Support (great-) grandchildren under multiple lineages. Closes : #25
2019-08-20 14:01:48 +02:00
Tim Bruijnzeels
fc98944d66
Split parent and resource class maps.
...
This is a little more hassle when talking to a parent, however this is easier
when talking to children. Also there is now an explicit split in the names used
by the parent, and local simple (numbered) names for resources and their name-
spaces when it comes to publishing.
2019-08-19 15:13:08 +02:00
Tim Bruijnzeels
7925e72e88
Create real type for ResourceClassName.
2019-08-19 11:18:00 +02:00
Tim Bruijnzeels
60a60fd5d2
Change the notion of being a TA to having a special parent proxy, thus making TAs and normal CAs more alike.
2019-08-16 11:40:27 +02:00
Tim Bruijnzeels
84bdd0c4fa
Force update resources for child CA.
2019-08-14 16:15:09 +02:00
Tim Bruijnzeels
f4f2d726b8
Let child CA remove resource class, and request key revocations, when it looses an entitlement. ( #56 )
2019-08-13 15:38:37 +02:00
Tim Bruijnzeels
816c0a7be9
Avoid race condition. Only notify listeners of events after everything has been saved.
2019-08-13 11:37:30 +02:00
Tim Bruijnzeels
3af6d08943
Simplify embedded parent/child CAs. No use for tokens here, and child cannot override parent handle.
2019-08-12 16:54:28 +02:00
Tim Bruijnzeels
00e9165388
Remove the 'remote krill parent ca option'
2019-08-12 16:18:11 +02:00
Tim Bruijnzeels
c1875b9de8
Manually finish key-roll by activating the new key. Tested with apnic. Fixes #23
2019-08-12 15:25:58 +02:00
Tim Bruijnzeels
47e0240734
Manually initialise a key roll for a CA. ( #23 )
2019-08-07 16:15:07 +02:00
Tim Bruijnzeels
d6ac0db936
Guard key status life cycle in an enum (state machine). ( #23 )
2019-08-07 10:27:56 +02:00
Tim Bruijnzeels
fe614d927f
Clean up removed resource class and withdraw contents. Closes #50 .
2019-08-06 12:47:08 +02:00
Tim Bruijnzeels
c37c257821
Some cleanup
2019-08-06 10:47:11 +02:00
Tim Bruijnzeels
0c39530f22
Refreshing CA certificates in the background - not yet handling losing resources. ( #50 )
2019-08-05 17:23:46 +02:00
Tim Bruijnzeels
98ee1202c6
Cleanup: use rpki::x509::Time everywhere.
2019-08-05 12:54:13 +02:00
Tim Bruijnzeels
21baec11ea
Do not use AKI extension in RFC6492/8181 CMS embedded CRL.
2019-08-05 12:33:50 +02:00
Tim Bruijnzeels
24b038d7ff
Update child token, id_cert and/or resources. Closes #51 .
2019-08-02 20:42:04 +02:00
Tim Bruijnzeels
5d2593857e
Refactor events - use parent/child handle consistently for clarity.
2019-07-30 15:06:57 +02:00
Tim Bruijnzeels
cd2e7133e9
Rustfmt
2019-07-30 13:58:48 +02:00
Tim Bruijnzeels
73a525c9b1
Fix interop with apnic RFC6492 (better check for CA bit) - ( #13 )
2019-07-26 11:30:29 -04:00
Tim Bruijnzeels
1ea10bb0cd
Be more lenient in accepting RFC8181/6492 CMS structures and Id Certs - because they are poorly defined. ( #13 )
2019-07-24 16:26:30 -04:00
Tim Bruijnzeels
b1bdd08071
Should fix the RFC6492 CMS signatures. ( #13 )
2019-07-24 09:47:38 -04:00
Tim Bruijnzeels
9b790757f4
Ignore critical extensions on IdCert (for interop testing).
2019-07-23 11:41:52 -04:00
Tim Bruijnzeels
3c8e9a470c
Fix racecondition (save the updated aggregate!), and deadlock (use outer_lock on pub functions).
2019-07-21 15:54:59 -04:00
Tim Bruijnzeels
2e7b6258fe
Get certificate from RFC6492 parent / issue to child. ( #13 )
2019-07-21 15:53:37 -04:00
Tim Bruijnzeels
2737a829da
Support publishing to embedded pub server through scheduler. ( #13 )
2019-07-19 22:57:35 +02:00
Tim Bruijnzeels
38464aa2cf
Introducing message queue for asynchronous triggered processes: request certs, publish. (work in progress for #13 )
2019-07-19 21:20:18 +02:00
Tim Bruijnzeels
446a1c339b
Add rfc6492 parent to child CA ( #13 ).
2019-07-19 09:16:22 +02:00
Tim Bruijnzeels
901e2dfae7
Accept invalid certs when connecting to localhost or 127.0.0.1 - useful when testing.
2019-07-18 12:05:22 +02:00
Tim Bruijnzeels
a6cbddbdf5
Generate the RFC8183 ID when a CA is initialised. Return RFC 8183 Child Request for CAs.
2019-07-18 11:55:20 +02:00
Tim Bruijnzeels
b30c3a02b7
Merging cms_proxy module back into commons, so that we can define RFC8183 parents more easily. ( #13 )
2019-07-17 13:09:07 +02:00
Tim Bruijnzeels
3b7dd8fe20
Clippy knows best.
2019-07-17 11:32:26 +02:00
Tim Bruijnzeels
46f2d189e4
Support RFC8183 Parent Response. See issue #13 .
2019-07-17 11:02:12 +02:00
Tim Bruijnzeels
5a79d0c18f
Support RFC8183 Child Request. See issue #13 .
2019-07-16 16:05:48 +02:00
Tim Bruijnzeels
f8c83950a4
Support RFC6492 Revocation Request XML.
2019-07-16 12:21:43 +02:00
Tim Bruijnzeels
6b2d64e4f8
Support RFC6492 Issuance Report XML, and use it internally as well. (Issue #13 )
2019-07-16 12:16:24 +02:00
Tim Bruijnzeels
f622c14588
Support RFC6492 Issuance Report XML, and use it internally as well. (Issue #13 )
2019-07-15 17:10:00 +02:00
Tim Bruijnzeels
63ddaec0b0
Support RFC6492 Certificate Issuance Request XML. (Issue #13 )
2019-07-15 14:13:19 +02:00
Tim Bruijnzeels
e859146bad
Support RFC6492 List Response XML (for issue: #13 )
2019-07-15 13:42:05 +02:00
Tim Bruijnzeels
57b3096418
Manage embedded delegated CA through CLI.
2019-07-10 15:06:28 +02:00
Tim Bruijnzeels
0280e6eaec
Simplify: let TA and CA use same codebase 'CertAuth'
2019-07-09 12:17:40 +02:00
Tim Bruijnzeels
fd1df3bb82
Merge branch 'master' into child-ca
2019-07-05 15:51:55 +02:00