Tim Bruijnzeels
b3a4e7b208
Remove 'KeyRef', this is all covered by 'rpki::crypto::KeyIdentifier' now.
2019-08-28 16:34:15 +02:00
Tim Bruijnzeels
ef858be696
Re-publish ROAs during key rolls. ( #30 )
2019-08-28 14:51:44 +02:00
Tim Bruijnzeels
69e4fda17c
Update ROAs when resource entitlements change. ( #30 )
2019-08-28 13:44:51 +02:00
Tim Bruijnzeels
21f4119e16
Refuse authorization for prefix not held by CA. ( #30 )
2019-08-27 15:29:59 +02:00
Tim Bruijnzeels
a8b17ec93d
Improve testing: check that expected files are published.
2019-08-26 13:58:20 +02:00
Tim Bruijnzeels
9398c45ee4
Remove a ROA ( #30 ).
2019-08-26 10:54:39 +02:00
Tim Bruijnzeels
6233616adf
Create new ROAs ( #30 ).
2019-08-23 12:02:46 +02:00
Tim Bruijnzeels
86ea370e8f
Support (great-) grandchildren under multiple lineages. Closes : #25
2019-08-20 14:01:48 +02:00
Tim Bruijnzeels
60a60fd5d2
Change the notion of being a TA to having a special parent proxy, thus making TAs and normal CAs more alike.
2019-08-16 11:40:27 +02:00
Tim Bruijnzeels
f421502253
Automatically shrink certificates after the grace period expires. ( Closes #55 )
2019-08-15 11:47:31 +02:00
Tim Bruijnzeels
84bdd0c4fa
Force update resources for child CA.
2019-08-14 16:15:09 +02:00
Tim Bruijnzeels
f4f2d726b8
Let child CA remove resource class, and request key revocations, when it looses an entitlement. ( #56 )
2019-08-13 15:38:37 +02:00
Tim Bruijnzeels
3af6d08943
Simplify embedded parent/child CAs. No use for tokens here, and child cannot override parent handle.
2019-08-12 16:54:28 +02:00
Tim Bruijnzeels
c1875b9de8
Manually finish key-roll by activating the new key. Tested with apnic. Fixes #23
2019-08-12 15:25:58 +02:00
Tim Bruijnzeels
47e0240734
Manually initialise a key roll for a CA. ( #23 )
2019-08-07 16:15:07 +02:00
Tim Bruijnzeels
d6ac0db936
Guard key status life cycle in an enum (state machine). ( #23 )
2019-08-07 10:27:56 +02:00
Tim Bruijnzeels
c37c257821
Some cleanup
2019-08-06 10:47:11 +02:00
Tim Bruijnzeels
0c39530f22
Refreshing CA certificates in the background - not yet handling losing resources. ( #50 )
2019-08-05 17:23:46 +02:00
Tim Bruijnzeels
24b038d7ff
Update child token, id_cert and/or resources. Closes #51 .
2019-08-02 20:42:04 +02:00
Tim Bruijnzeels
cd2e7133e9
Rustfmt
2019-07-30 13:58:48 +02:00
Tim Bruijnzeels
1ea10bb0cd
Be more lenient in accepting RFC8181/6492 CMS structures and Id Certs - because they are poorly defined. ( #13 )
2019-07-24 16:26:30 -04:00
Tim Bruijnzeels
b1bdd08071
Should fix the RFC6492 CMS signatures. ( #13 )
2019-07-24 09:47:38 -04:00
Tim Bruijnzeels
69b0172070
Fix build.
2019-07-23 10:21:49 -04:00
Tim Bruijnzeels
29ce65ab46
Improve test for running an rfc6492 child under the embedded ta.
2019-07-22 18:47:05 -04:00
Tim Bruijnzeels
831cfed299
Renamed and organised CA code. ( #13 )
2019-07-22 14:02:52 -04:00
Tim Bruijnzeels
2e7b6258fe
Get certificate from RFC6492 parent / issue to child. ( #13 )
2019-07-21 15:53:37 -04:00
Tim Bruijnzeels
2737a829da
Support publishing to embedded pub server through scheduler. ( #13 )
2019-07-19 22:57:35 +02:00
Tim Bruijnzeels
38464aa2cf
Introducing message queue for asynchronous triggered processes: request certs, publish. (work in progress for #13 )
2019-07-19 21:20:18 +02:00
Tim Bruijnzeels
446a1c339b
Add rfc6492 parent to child CA ( #13 ).
2019-07-19 09:16:22 +02:00
Tim Bruijnzeels
901e2dfae7
Accept invalid certs when connecting to localhost or 127.0.0.1 - useful when testing.
2019-07-18 12:05:22 +02:00
Tim Bruijnzeels
a6cbddbdf5
Generate the RFC8183 ID when a CA is initialised. Return RFC 8183 Child Request for CAs.
2019-07-18 11:55:20 +02:00
Tim Bruijnzeels
b30c3a02b7
Merging cms_proxy module back into commons, so that we can define RFC8183 parents more easily. ( #13 )
2019-07-17 13:09:07 +02:00
Tim Bruijnzeels
8f64fdf38b
Rephrase 'decode' as 'validate' because we are really validating RFC8183 XML. ( #13 )
2019-07-17 11:30:40 +02:00
Tim Bruijnzeels
4cb43debb8
Fixes support for RFC8181 clients again.
2019-07-11 14:31:48 +02:00
Tim Bruijnzeels
57b3096418
Manage embedded delegated CA through CLI.
2019-07-10 15:06:28 +02:00
Tim Bruijnzeels
0280e6eaec
Simplify: let TA and CA use same codebase 'CertAuth'
2019-07-09 12:17:40 +02:00
Tim Bruijnzeels
e0d7596de4
Support child CA under embedded TA. Work in progress. Issue #14
2019-07-05 12:13:39 +02:00
Tim Bruijnzeels
38f7c15eca
Fix clippy warnings in tests
2019-06-11 17:07:28 +02:00
Tim Bruijnzeels
40b154c577
Upgrade to actix-web 1.0
2019-06-11 12:49:50 +02:00
Tim Bruijnzeels
16ce1db2ec
Automate (re)-publication. Closes #33 .
2019-06-05 17:15:27 +02:00
Tim Bruijnzeels
2d122d6664
Reduce complexity in eventsourcing. Closes #41
2019-06-04 17:13:44 +02:00
Tim Bruijnzeels
a6d9aade03
Manual publication of TA MFT and CRL. Closes #12 .
2019-06-04 08:46:58 +02:00
Tim Bruijnzeels
488a53fe88
Use healthcheck to wait for server to come up when testing with running krill server.
2019-05-09 14:32:38 +02:00
Tim Bruijnzeels
d58e386acf
Show / init embedded TA from CLI.
2019-05-08 17:19:30 +02:00
Tim Bruijnzeels
b92e035314
Use closure for testing with running krill server.
2019-05-08 16:14:24 +02:00
Tim Bruijnzeels
3e3759f789
Start test server using https for integration testing - accept self signed certs in these tests.
2019-05-07 14:41:02 +02:00
Tim Bruijnzeels
f3d7c4f47e
Replacing 127.0.0.1 with localhost to help testing using https (seems there are exceptions when localhost is used)
2019-05-03 16:58:29 +02:00
Tim Bruijnzeels
710323db01
Initialising TA from UI. Not displaying properly yet. (See #12 )
...
Also note: had to change http -> https all over the place, and this currently breaks the client connections for the CLI and integration tests. Will fix this soon!
2019-05-03 16:14:02 +02:00
Tim Bruijnzeels
8a66853ff9
IGNORING integration tests for now -> MUST fix connecting to self-signed HTTPS server.
2019-05-03 16:08:29 +02:00
Tim Bruijnzeels
0bbfebfbb6
Use workspaces in project.
2019-04-11 16:36:33 +02:00