mirror of
https://github.com/NLnetLabs/krill.git
synced 2026-09-28 20:34:54 +02:00
- Formalize support for different logout strategies and add the fallback strategy. - Generate the logout URL at logout time in preparation for supporting dynamic logout requests (as needed by token revocation). - Secure the connection to the mock OpenID Connect provider with a self-signed TLS certificate. - Allow self-signed certificates for HTTPS connections to localhost (same policy as elsewhere in Krill). - Upgrade openidconnect-rs to latest v2.0.0 alpha to gain contributed support for OAuth 2.0 Token Revocation. (#385 and #397) - Use reqwest 0.9.x directly instead of via the openidconnect-rs crate (we cannot use the v0.11.x reqwest that comes with the crate as (a) it doesn't permit self-signed certificates, (b) the blocking implementation was changed to be async which causes problems when inside an existing async runtime, and (c) switching the OpenID Connect client code over to be async is non-trivial - see #428). - Pass the ID token as `id_token_hint` to the OpenID Connect RP-Initiated Logout 1.0 endpoint. (#408) - Refined logic for the various logout mechanism permutations. (#425). - Require OpenID Connection RP-Initiated Logout 1.0 and OAuth 2.0 Token Revocation endpoints to be HTTPS per the specs. - Passes manual testing with Microsoft Azure Active Directory RP-Initiated Logout support and Google Compute Cloud OAuth 2.0 Token Revocation support. - Added a Google Cloud Platform example to the comments in the default config file. - Updated and added tests. - Fixed logout and token revocation in the mock OpenID Connect provider to actually terminate login sessions. - Handle a race condition in Lagosta where null user data was accessed that was just deleted due to logout. - Handle errors from the Krill logout endpoint in Lagosta.
146 lines
5.4 KiB
TOML
146 lines
5.4 KiB
TOML
[package]
|
|
# Note: some of these values are also used when building Debian packages below.
|
|
name = "krill"
|
|
version = "0.8.2-bis"
|
|
edition = "2018"
|
|
authors = [ "The NLnet Labs RPKI team <rpki-team@nlnetlabs.nl>" ]
|
|
description = "Resource Public Key Infrastructure (RPKI) daemon"
|
|
homepage = "https://www.nlnetlabs.nl/projects/rpki/krill/"
|
|
repository = "https://github.com/NLnetLabs/krill"
|
|
keywords = ["rpki", "routing-security", "bgp"]
|
|
readme = "README.md"
|
|
license = "MPL-2.0"
|
|
exclude = [
|
|
"test-resources/*",
|
|
"tests/*",
|
|
]
|
|
build = "build.rs"
|
|
|
|
[dependencies]
|
|
base64 = "^0.13"
|
|
basic-cookies = { version = "^0.1", optional = true }
|
|
bcder = "0.5.0"
|
|
bytes = "^0.5"
|
|
chrono = { version = "^0.4", features = ["serde"] }
|
|
clap = "^2.33"
|
|
clokwerk = "^0.3"
|
|
fern = { version = "^0.5", features = ["syslog-4"] }
|
|
futures = "^0.3"
|
|
futures-util = "^0.3"
|
|
hex = "^0.4"
|
|
hyper = "^0.13"
|
|
intervaltree = "0.2.6"
|
|
jmespatch = { version = "^0.3", features = ["sync"], optional = true }
|
|
libflate = "^1.0"
|
|
log = "^0.4"
|
|
openidconnect = { version = "^2.0.0-alpha", optional = true, default_features = false }
|
|
openssl = { version = "^0.10", features = ["v110"] }
|
|
oso = { version = "^0.8", optional = true }
|
|
regex = { version = "^1.4", optional = true }
|
|
reqwest = { version = "0.10.8", features = ["json"] }
|
|
reqwestblocking = { version = "0.9.24", optional = true, package = "reqwest" }
|
|
rpki = "^0.10.0"
|
|
serde = { version = "^1.0", features = ["derive"] }
|
|
serde_json = "^1.0"
|
|
tokio = { version = "^0.2", features = ["rt-core", "macros", "time"] }
|
|
tokio-rustls = "^0.14"
|
|
toml = "^0.5"
|
|
urlparse = { version = "^0.7", optional = true }
|
|
uuid = { version = "^0.8", features = [ "v4"] }
|
|
xml-rs = "^0.8"
|
|
|
|
[target.'cfg(unix)'.dependencies]
|
|
libc = "^0.2"
|
|
syslog = "^4.0"
|
|
|
|
[build-dependencies]
|
|
rustc_version = "0.2.3"
|
|
|
|
[features]
|
|
default = []
|
|
rta = []
|
|
multi-user = [ "basic-cookies", "jmespatch/sync", "regex", "oso", "openidconnect", "reqwestblocking", "urlparse" ]
|
|
functional-tests = []
|
|
ui-tests = []
|
|
extra-debug = [ "rpki/extra-debug" ]
|
|
static-openssl = [ "openssl/vendored" ]
|
|
|
|
# Make sure that Krill crashes on panics, rather than losing threads and
|
|
# limping on in a bad state.
|
|
[profile.release]
|
|
panic = "abort"
|
|
|
|
[dev-dependencies]
|
|
# for user management
|
|
tiny_http = { version = "^0.8", features = ["ssl"] }
|
|
ctrlc = "^3.1"
|
|
|
|
# ------------------------------------------------------------------------------
|
|
# START DEBIAN PACKAGING
|
|
#
|
|
# Configurations for the cargo-deb cargo plugin which builds Debian packages in
|
|
# target/debian/ when invoked with: cargo deb. Tested with cargo-deb v1.23.1.
|
|
# Use `--variant` to select which section below to use. Variant sections inherit
|
|
# and override the settings in the base [package.metadata.deb] section. The
|
|
# configs vary because of differing degrees of OpenSSL and systemd support
|
|
# across operating systems.
|
|
#
|
|
# Note that as the postinst script uses the adduser command we declare a
|
|
# dependency on the adduser package to keep the lintian tool happy.
|
|
# Note: krill.conf is deliberately NOT specified as a "conf-file" because it is
|
|
# generated.
|
|
#
|
|
# The GitHub Actions pkg.yml workflow definition file uses these configurations
|
|
# to build and test Ubuntu/Debian packages for Krill.
|
|
#
|
|
# See:
|
|
# - https://github.com/mmstick/cargo-deb
|
|
# - https://lintian.debian.org/tags/systemd-service-file-outside-lib.html
|
|
# - https://www.debian.org/doc/debian-policy/ch-files.html#behavior
|
|
# - .github/workflows/pkg.yml
|
|
[package.metadata.deb]
|
|
name = "krill"
|
|
priority = "optional"
|
|
section = "net"
|
|
extended-description-file = "debian/description.txt"
|
|
license-file = ["LICENSE", "0"]
|
|
depends = "$auto, adduser, libssl1.1"
|
|
maintainer-scripts = "debian/"
|
|
changelog = "debian/changelog" # this will be generated by the pkg workflow
|
|
copyright = "Copyright (c) 2019, NLnet Labs. All rights reserved."
|
|
assets = [
|
|
["target/release/krill", "/usr/bin/krill", "755"],
|
|
["target/release/krillc", "/usr/bin/krillc", "755"],
|
|
["defaults/krill.conf", "/usr/share/doc/krill/krill.conf", "644"],
|
|
["doc/krill.1", "/usr/share/man/man1/krill.1", "644"],
|
|
["doc/krillc.1", "/usr/share/man/man1/krillc.1", "644"],
|
|
["debian/krill.service.preset", "/lib/systemd/system-preset/50-krill.preset", "644"],
|
|
]
|
|
systemd-units = { unit-name = "krill", enable = false }
|
|
|
|
# Variant of the Debian packaging configuration that:
|
|
# a) statically links with OpenSSL when building a Debian package because the
|
|
# newest OpenSSL available on Ubuntu 16.04 at the time of writing is 1.0.2g
|
|
# (see: https://packages.ubuntu.com/xenial/openssl) while Krill requires
|
|
# OpenSSL >= 1.1.0.
|
|
# b) uses a simpler systemd service unit file because Ubuntu 16.04 doesn't
|
|
# support newer features supported by Ubuntu 18.04 and 20.04.
|
|
[package.metadata.deb.variants.ubuntu-xenial]
|
|
features = [ "static-openssl" ]
|
|
depends = "$auto, adduser"
|
|
|
|
[package.metadata.deb.variants.ubuntu-bionic]
|
|
|
|
[package.metadata.deb.variants.ubuntu-focal]
|
|
|
|
[package.metadata.deb.variants.debian-stretch]
|
|
features = [ "static-openssl" ]
|
|
depends = "$auto, adduser"
|
|
|
|
[package.metadata.deb.variants.debian-buster]
|
|
|
|
[package.metadata.deb.variants.debian-bullseye]
|
|
|
|
# END DEBIAN PACKAGING
|
|
# ------------------------------------------------------------------------------
|