Commit Graph
50 Commits
Author SHA1 Message Date
Tim Bruijnzeels b3a4e7b208 Remove 'KeyRef', this is all covered by 'rpki::crypto::KeyIdentifier' now. 2019-08-28 16:34:15 +02:00
Tim Bruijnzeels ef858be696 Re-publish ROAs during key rolls. (#30) 2019-08-28 14:51:44 +02:00
Tim Bruijnzeels 69e4fda17c Update ROAs when resource entitlements change. (#30) 2019-08-28 13:44:51 +02:00
Tim Bruijnzeels 21f4119e16 Refuse authorization for prefix not held by CA. (#30) 2019-08-27 15:29:59 +02:00
Tim Bruijnzeels a8b17ec93d Improve testing: check that expected files are published. 2019-08-26 13:58:20 +02:00
Tim Bruijnzeels 9398c45ee4 Remove a ROA (#30). 2019-08-26 10:54:39 +02:00
Tim Bruijnzeels 6233616adf Create new ROAs (#30). 2019-08-23 12:02:46 +02:00
Tim Bruijnzeels 86ea370e8f Support (great-) grandchildren under multiple lineages. Closes: #25 2019-08-20 14:01:48 +02:00
Tim Bruijnzeels 60a60fd5d2 Change the notion of being a TA to having a special parent proxy, thus making TAs and normal CAs more alike. 2019-08-16 11:40:27 +02:00
Tim Bruijnzeels f421502253 Automatically shrink certificates after the grace period expires. (Closes #55) 2019-08-15 11:47:31 +02:00
Tim Bruijnzeels 84bdd0c4fa Force update resources for child CA. 2019-08-14 16:15:09 +02:00
Tim Bruijnzeels f4f2d726b8 Let child CA remove resource class, and request key revocations, when it looses an entitlement. (#56) 2019-08-13 15:38:37 +02:00
Tim Bruijnzeels 3af6d08943 Simplify embedded parent/child CAs. No use for tokens here, and child cannot override parent handle. 2019-08-12 16:54:28 +02:00
Tim Bruijnzeels c1875b9de8 Manually finish key-roll by activating the new key. Tested with apnic. Fixes #23 2019-08-12 15:25:58 +02:00
Tim Bruijnzeels 47e0240734 Manually initialise a key roll for a CA. (#23) 2019-08-07 16:15:07 +02:00
Tim Bruijnzeels d6ac0db936 Guard key status life cycle in an enum (state machine). (#23) 2019-08-07 10:27:56 +02:00
Tim Bruijnzeels c37c257821 Some cleanup 2019-08-06 10:47:11 +02:00
Tim Bruijnzeels 0c39530f22 Refreshing CA certificates in the background - not yet handling losing resources. (#50) 2019-08-05 17:23:46 +02:00
Tim Bruijnzeels 24b038d7ff Update child token, id_cert and/or resources. Closes #51. 2019-08-02 20:42:04 +02:00
Tim Bruijnzeels cd2e7133e9 Rustfmt 2019-07-30 13:58:48 +02:00
Tim Bruijnzeels 1ea10bb0cd Be more lenient in accepting RFC8181/6492 CMS structures and Id Certs - because they are poorly defined. (#13) 2019-07-24 16:26:30 -04:00
Tim Bruijnzeels b1bdd08071 Should fix the RFC6492 CMS signatures. (#13) 2019-07-24 09:47:38 -04:00
Tim Bruijnzeels 69b0172070 Fix build. 2019-07-23 10:21:49 -04:00
Tim Bruijnzeels 29ce65ab46 Improve test for running an rfc6492 child under the embedded ta. 2019-07-22 18:47:05 -04:00
Tim Bruijnzeels 831cfed299 Renamed and organised CA code. (#13) 2019-07-22 14:02:52 -04:00
Tim Bruijnzeels 2e7b6258fe Get certificate from RFC6492 parent / issue to child. (#13) 2019-07-21 15:53:37 -04:00
Tim Bruijnzeels 2737a829da Support publishing to embedded pub server through scheduler. (#13) 2019-07-19 22:57:35 +02:00
Tim Bruijnzeels 38464aa2cf Introducing message queue for asynchronous triggered processes: request certs, publish. (work in progress for #13) 2019-07-19 21:20:18 +02:00
Tim Bruijnzeels 446a1c339b Add rfc6492 parent to child CA (#13). 2019-07-19 09:16:22 +02:00
Tim Bruijnzeels 901e2dfae7 Accept invalid certs when connecting to localhost or 127.0.0.1 - useful when testing. 2019-07-18 12:05:22 +02:00
Tim Bruijnzeels a6cbddbdf5 Generate the RFC8183 ID when a CA is initialised. Return RFC 8183 Child Request for CAs. 2019-07-18 11:55:20 +02:00
Tim Bruijnzeels b30c3a02b7 Merging cms_proxy module back into commons, so that we can define RFC8183 parents more easily. (#13) 2019-07-17 13:09:07 +02:00
Tim Bruijnzeels 8f64fdf38b Rephrase 'decode' as 'validate' because we are really validating RFC8183 XML. (#13) 2019-07-17 11:30:40 +02:00
Tim Bruijnzeels 4cb43debb8 Fixes support for RFC8181 clients again. 2019-07-11 14:31:48 +02:00
Tim Bruijnzeels 57b3096418 Manage embedded delegated CA through CLI. 2019-07-10 15:06:28 +02:00
Tim Bruijnzeels 0280e6eaec Simplify: let TA and CA use same codebase 'CertAuth' 2019-07-09 12:17:40 +02:00
Tim Bruijnzeels e0d7596de4 Support child CA under embedded TA. Work in progress. Issue #14 2019-07-05 12:13:39 +02:00
Tim Bruijnzeels 38f7c15eca Fix clippy warnings in tests 2019-06-11 17:07:28 +02:00
Tim Bruijnzeels 40b154c577 Upgrade to actix-web 1.0 2019-06-11 12:49:50 +02:00
Tim Bruijnzeels 16ce1db2ec Automate (re)-publication. Closes #33. 2019-06-05 17:15:27 +02:00
Tim Bruijnzeels 2d122d6664 Reduce complexity in eventsourcing. Closes #41 2019-06-04 17:13:44 +02:00
Tim Bruijnzeels a6d9aade03 Manual publication of TA MFT and CRL. Closes #12. 2019-06-04 08:46:58 +02:00
Tim Bruijnzeels 488a53fe88 Use healthcheck to wait for server to come up when testing with running krill server. 2019-05-09 14:32:38 +02:00
Tim Bruijnzeels d58e386acf Show / init embedded TA from CLI. 2019-05-08 17:19:30 +02:00
Tim Bruijnzeels b92e035314 Use closure for testing with running krill server. 2019-05-08 16:14:24 +02:00
Tim Bruijnzeels 3e3759f789 Start test server using https for integration testing - accept self signed certs in these tests. 2019-05-07 14:41:02 +02:00
Tim Bruijnzeels f3d7c4f47e Replacing 127.0.0.1 with localhost to help testing using https (seems there are exceptions when localhost is used) 2019-05-03 16:58:29 +02:00
Tim Bruijnzeels 710323db01 Initialising TA from UI. Not displaying properly yet. (See #12)
Also note: had to change http -> https all over the place, and this currently breaks the client connections for the CLI and integration tests. Will fix this soon!
2019-05-03 16:14:02 +02:00
Tim Bruijnzeels 8a66853ff9 IGNORING integration tests for now -> MUST fix connecting to self-signed HTTPS server. 2019-05-03 16:08:29 +02:00
Tim Bruijnzeels 0bbfebfbb6 Use workspaces in project. 2019-04-11 16:36:33 +02:00