Commit Graph
56 Commits
Author SHA1 Message Date
Tim Bruijnzeels c1875b9de8 Manually finish key-roll by activating the new key. Tested with apnic. Fixes #23 2019-08-12 15:25:58 +02:00
Tim Bruijnzeels 47e0240734 Manually initialise a key roll for a CA. (#23) 2019-08-07 16:15:07 +02:00
Tim Bruijnzeels d6ac0db936 Guard key status life cycle in an enum (state machine). (#23) 2019-08-07 10:27:56 +02:00
Tim Bruijnzeels 6f61084457 Separating out ResourceClass. 2019-08-06 14:38:56 +02:00
Tim Bruijnzeels fe614d927f Clean up removed resource class and withdraw contents. Closes #50. 2019-08-06 12:47:08 +02:00
Tim Bruijnzeels baacf0e8f1 Change default to logging to file. 2019-08-06 10:54:23 +02:00
Tim Bruijnzeels c37c257821 Some cleanup 2019-08-06 10:47:11 +02:00
Tim Bruijnzeels 0c39530f22 Refreshing CA certificates in the background - not yet handling losing resources. (#50) 2019-08-05 17:23:46 +02:00
Tim Bruijnzeels 24b038d7ff Update child token, id_cert and/or resources. Closes #51. 2019-08-02 20:42:04 +02:00
Tim Bruijnzeels 5d2593857e Refactor events - use parent/child handle consistently for clarity. 2019-07-30 15:06:57 +02:00
Tim Bruijnzeels cd2e7133e9 Rustfmt 2019-07-30 13:58:48 +02:00
Tim Bruijnzeels 73a525c9b1 Fix interop with apnic RFC6492 (better check for CA bit) - (#13) 2019-07-26 11:30:29 -04:00
Tim Bruijnzeels b1bdd08071 Should fix the RFC6492 CMS signatures. (#13) 2019-07-24 09:47:38 -04:00
Tim Bruijnzeels d6ecccb224 Log error with base64 of RFC6492 response CMS in case response cannot be decoded. 2019-07-23 12:34:46 -04:00
Tim Bruijnzeels 69b0172070 Fix build. 2019-07-23 10:21:49 -04:00
Tim Bruijnzeels 5ec918b26b Add type alias for ChildHandle -> Handle 2019-07-22 19:36:58 -04:00
Tim Bruijnzeels 831cfed299 Renamed and organised CA code. (#13) 2019-07-22 14:02:52 -04:00
Tim Bruijnzeels 2e7b6258fe Get certificate from RFC6492 parent / issue to child. (#13) 2019-07-21 15:53:37 -04:00
Tim Bruijnzeels 329c35eba2 Moving republish (all) to Scheduler. (#13) 2019-07-21 15:51:01 -04:00
Tim Bruijnzeels 2737a829da Support publishing to embedded pub server through scheduler. (#13) 2019-07-19 22:57:35 +02:00
Tim Bruijnzeels 38464aa2cf Introducing message queue for asynchronous triggered processes: request certs, publish. (work in progress for #13) 2019-07-19 21:20:18 +02:00
Tim Bruijnzeels 446a1c339b Add rfc6492 parent to child CA (#13). 2019-07-19 09:16:22 +02:00
Tim Bruijnzeels 901e2dfae7 Accept invalid certs when connecting to localhost or 127.0.0.1 - useful when testing. 2019-07-18 12:05:22 +02:00
Tim Bruijnzeels a6cbddbdf5 Generate the RFC8183 ID when a CA is initialised. Return RFC 8183 Child Request for CAs. 2019-07-18 11:55:20 +02:00
Tim Bruijnzeels b30c3a02b7 Merging cms_proxy module back into commons, so that we can define RFC8183 parents more easily. (#13) 2019-07-17 13:09:07 +02:00
Tim Bruijnzeels 6b2d64e4f8 Support RFC6492 Issuance Report XML, and use it internally as well. (Issue #13) 2019-07-16 12:16:24 +02:00
Tim Bruijnzeels 4cb43debb8 Fixes support for RFC8181 clients again. 2019-07-11 14:31:48 +02:00
Tim Bruijnzeels 57b3096418 Manage embedded delegated CA through CLI. 2019-07-10 15:06:28 +02:00
Tim Bruijnzeels 0280e6eaec Simplify: let TA and CA use same codebase 'CertAuth' 2019-07-09 12:17:40 +02:00
Tim Bruijnzeels e0d7596de4 Support child CA under embedded TA. Work in progress. Issue #14 2019-07-05 12:13:39 +02:00
Tim Bruijnzeels 821274a8d0 Fix authorisation checks. 2019-06-11 17:06:42 +02:00
Tim Bruijnzeels 40b154c577 Upgrade to actix-web 1.0 2019-06-11 12:49:50 +02:00
Tim Bruijnzeels 26411075c7 Clean up dependencies on actix (not needed at all) and actix-web. 2019-06-06 13:26:43 +02:00
Tim Bruijnzeels f93cbebbff Clarify full-sync scenario, and use more descriptive error identifiers in code. 2019-06-06 11:14:24 +02:00
Tim Bruijnzeels 16ce1db2ec Automate (re)-publication. Closes #33. 2019-06-05 17:15:27 +02:00
Tim Bruijnzeels 2d122d6664 Reduce complexity in eventsourcing. Closes #41 2019-06-04 17:13:44 +02:00
Tim Bruijnzeels a6d9aade03 Manual publication of TA MFT and CRL. Closes #12. 2019-06-04 08:46:58 +02:00
Tim Bruijnzeels 733f76f53b Refactoring the TrustAnchor in preparation of publication. 2019-05-23 11:34:21 +02:00
Tim Bruijnzeels 2705418eab Create Manifest and CRL for TA (initially). 2019-05-14 12:31:17 +02:00
Tim Bruijnzeels 488a53fe88 Use healthcheck to wait for server to come up when testing with running krill server. 2019-05-09 14:32:38 +02:00
Tim Bruijnzeels d58e386acf Show / init embedded TA from CLI. 2019-05-08 17:19:30 +02:00
Tim Bruijnzeels b92e035314 Use closure for testing with running krill server. 2019-05-08 16:14:24 +02:00
Tim Bruijnzeels cd7dcfa437 Download ta.cer. 2019-05-08 15:18:18 +02:00
Tim Bruijnzeels fb46d2c04a Download TAL for embedded TA. 2019-05-08 14:55:17 +02:00
Tim Bruijnzeels 619fef9f35 Fix clippy. 2019-05-07 16:44:44 +02:00
Tim Bruijnzeels 3e3759f789 Start test server using https for integration testing - accept self signed certs in these tests. 2019-05-07 14:41:02 +02:00
Tim Bruijnzeels f3d7c4f47e Replacing 127.0.0.1 with localhost to help testing using https (seems there are exceptions when localhost is used) 2019-05-03 16:58:29 +02:00
Tim Bruijnzeels 710323db01 Initialising TA from UI. Not displaying properly yet. (See #12)
Also note: had to change http -> https all over the place, and this currently breaks the client connections for the CLI and integration tests. Will fix this soon!
2019-05-03 16:14:02 +02:00
Tim Bruijnzeels 4616d1d018 Update use statements for latest rpki-rs 2019-05-02 14:18:33 +02:00
Tim Bruijnzeels f7ec726852 Update to rpki-rs with revised-cert-handling. 2019-05-01 09:28:58 +02:00