pki

package
v5.4.39 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 21, 2026 License: GPL-3.0 Imports: 21 Imported by: 0

Documentation

Overview

Package pki is a generated GoMock package.

Index

Constants

This section is empty.

Variables

View Source
var (
	ErrCRLMissing    = errors.New("crl is missing")
	ErrCRLExpired    = errors.New("crl has expired")
	ErrCertRevoked   = errors.New("certificate is revoked")
	ErrCertUntrusted = errors.New("certificate's issuer is not trusted")
	// ErrDenylistMissing occurs when the denylist cannot be downloaded
	ErrDenylistMissing = errors.New("denylist cannot be retrieved")

	// ErrCertBanned means the certificate was banned by a denylist rather than revoked by a CRL
	ErrCertBanned = errors.New("certificate is banned")
)

errors

Functions

func FlagSet

func FlagSet() *pflag.FlagSet

FlagSet contains flags relevant for JSON-LD

func SetNewDenylistWithCert

func SetNewDenylistWithCert(t *testing.T, val Validator, cert *x509.Certificate)

SetNewDenylistWithCert sets a new Denylist on the Validator and adds the certificate. This is useful in integrations tests etc.

Types

type Config

type Config struct {
	// Denylist specifies config options for the PKI denylist, which acts as a global CRL
	Denylist DenylistConfig `koanf:"denylist"`

	// MaxUpdateFailHours specifies the maximum number of hours that a denylist update can fail
	MaxUpdateFailHours int `koanf:"maxupdatefailhours"`

	// Softfail still accepts connections if the revocation status of a certificate cannot be reliably established if set to true
	Softfail bool `koanf:"softfail"`
}

Config specifies configuration parameters for PKI functionality

func DefaultConfig

func DefaultConfig() Config

func TestConfig

func TestConfig(t *testing.T) Config

TestConfig is the same as DefaultConfig without a denylist URL set.

type Denylist

type Denylist interface {
	// LastUpdated provides the time at which the denylist was last retrieved
	LastUpdated() time.Time

	// Update fetches a new copy of the denylist
	Update() error

	// URL returns the URL of the denylist
	URL() string

	// ValidateCert returns an error if a certificate should not be used
	ValidateCert(cert *x509.Certificate) error

	// Subscribe registers a callback that is triggered everytime the denylist is updated
	Subscribe(f func())
}

Denylist implements a global certificate rejection

func NewDenylist

func NewDenylist(config DenylistConfig) (Denylist, error)

NewDenylist creates a denylist with the specified configuration

type DenylistConfig

type DenylistConfig struct {
	// URL specifies the URL where the certificate blacklist is downloaded
	URL string `koanf:"url"`

	// TrustedSigner specifies the PEM Ed25519 public key which must sign the blacklist
	TrustedSigner string `koanf:"trustedsigner"`
}

DenylistConfig specifies the config structure for the crl/certificate blacklist module

type MockDenylist

type MockDenylist struct {
	// contains filtered or unexported fields
}

MockDenylist is a mock of Denylist interface.

func NewMockDenylist

func NewMockDenylist(ctrl *gomock.Controller) *MockDenylist

NewMockDenylist creates a new mock instance.

func (*MockDenylist) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockDenylist) LastUpdated

func (m *MockDenylist) LastUpdated() time.Time

LastUpdated mocks base method.

func (*MockDenylist) Subscribe

func (m *MockDenylist) Subscribe(f func())

Subscribe mocks base method.

func (*MockDenylist) URL

func (m *MockDenylist) URL() string

URL mocks base method.

func (*MockDenylist) Update

func (m *MockDenylist) Update() error

Update mocks base method.

func (*MockDenylist) ValidateCert

func (m *MockDenylist) ValidateCert(cert *x509.Certificate) error

ValidateCert mocks base method.

type MockDenylistMockRecorder

type MockDenylistMockRecorder struct {
	// contains filtered or unexported fields
}

MockDenylistMockRecorder is the mock recorder for MockDenylist.

func (*MockDenylistMockRecorder) LastUpdated

func (mr *MockDenylistMockRecorder) LastUpdated() *gomock.Call

LastUpdated indicates an expected call of LastUpdated.

func (*MockDenylistMockRecorder) Subscribe

func (mr *MockDenylistMockRecorder) Subscribe(f interface{}) *gomock.Call

Subscribe indicates an expected call of Subscribe.

func (*MockDenylistMockRecorder) URL

URL indicates an expected call of URL.

func (*MockDenylistMockRecorder) Update

func (mr *MockDenylistMockRecorder) Update() *gomock.Call

Update indicates an expected call of Update.

func (*MockDenylistMockRecorder) ValidateCert

func (mr *MockDenylistMockRecorder) ValidateCert(cert interface{}) *gomock.Call

ValidateCert indicates an expected call of ValidateCert.

type MockProvider

type MockProvider struct {
	// contains filtered or unexported fields
}

MockProvider is a mock of Provider interface.

func NewMockProvider

func NewMockProvider(ctrl *gomock.Controller) *MockProvider

NewMockProvider creates a new mock instance.

func (*MockProvider) AddTruststore

func (m *MockProvider) AddTruststore(chain []*x509.Certificate) error

AddTruststore mocks base method.

func (*MockProvider) CreateTLSConfig

func (m *MockProvider) CreateTLSConfig(cfg core.TLSConfig) (*tls.Config, error)

CreateTLSConfig mocks base method.

func (*MockProvider) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockProvider) SetVerifyPeerCertificateFunc

func (m *MockProvider) SetVerifyPeerCertificateFunc(config *tls.Config) error

SetVerifyPeerCertificateFunc mocks base method.

func (*MockProvider) SubscribeDenied

func (m *MockProvider) SubscribeDenied(f func())

SubscribeDenied mocks base method.

func (*MockProvider) Validate

func (m *MockProvider) Validate(chain []*x509.Certificate) error

Validate mocks base method.

type MockProviderMockRecorder

type MockProviderMockRecorder struct {
	// contains filtered or unexported fields
}

MockProviderMockRecorder is the mock recorder for MockProvider.

func (*MockProviderMockRecorder) AddTruststore

func (mr *MockProviderMockRecorder) AddTruststore(chain interface{}) *gomock.Call

AddTruststore indicates an expected call of AddTruststore.

func (*MockProviderMockRecorder) CreateTLSConfig

func (mr *MockProviderMockRecorder) CreateTLSConfig(cfg interface{}) *gomock.Call

CreateTLSConfig indicates an expected call of CreateTLSConfig.

func (*MockProviderMockRecorder) SetVerifyPeerCertificateFunc

func (mr *MockProviderMockRecorder) SetVerifyPeerCertificateFunc(config interface{}) *gomock.Call

SetVerifyPeerCertificateFunc indicates an expected call of SetVerifyPeerCertificateFunc.

func (*MockProviderMockRecorder) SubscribeDenied

func (mr *MockProviderMockRecorder) SubscribeDenied(f interface{}) *gomock.Call

SubscribeDenied indicates an expected call of SubscribeDenied.

func (*MockProviderMockRecorder) Validate

func (mr *MockProviderMockRecorder) Validate(chain interface{}) *gomock.Call

Validate indicates an expected call of Validate.

type MockValidator

type MockValidator struct {
	// contains filtered or unexported fields
}

MockValidator is a mock of Validator interface.

func NewMockValidator

func NewMockValidator(ctrl *gomock.Controller) *MockValidator

NewMockValidator creates a new mock instance.

func (*MockValidator) AddTruststore

func (m *MockValidator) AddTruststore(chain []*x509.Certificate) error

AddTruststore mocks base method.

func (*MockValidator) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockValidator) SetVerifyPeerCertificateFunc

func (m *MockValidator) SetVerifyPeerCertificateFunc(config *tls.Config) error

SetVerifyPeerCertificateFunc mocks base method.

func (*MockValidator) SubscribeDenied

func (m *MockValidator) SubscribeDenied(f func())

SubscribeDenied mocks base method.

func (*MockValidator) Validate

func (m *MockValidator) Validate(chain []*x509.Certificate) error

Validate mocks base method.

type MockValidatorMockRecorder

type MockValidatorMockRecorder struct {
	// contains filtered or unexported fields
}

MockValidatorMockRecorder is the mock recorder for MockValidator.

func (*MockValidatorMockRecorder) AddTruststore

func (mr *MockValidatorMockRecorder) AddTruststore(chain interface{}) *gomock.Call

AddTruststore indicates an expected call of AddTruststore.

func (*MockValidatorMockRecorder) SetVerifyPeerCertificateFunc

func (mr *MockValidatorMockRecorder) SetVerifyPeerCertificateFunc(config interface{}) *gomock.Call

SetVerifyPeerCertificateFunc indicates an expected call of SetVerifyPeerCertificateFunc.

func (*MockValidatorMockRecorder) SubscribeDenied

func (mr *MockValidatorMockRecorder) SubscribeDenied(f interface{}) *gomock.Call

SubscribeDenied indicates an expected call of SubscribeDenied.

func (*MockValidatorMockRecorder) Validate

func (mr *MockValidatorMockRecorder) Validate(chain interface{}) *gomock.Call

Validate indicates an expected call of Validate.

type PKI

type PKI struct {
	// contains filtered or unexported fields
}

func New

func New() *PKI

func (PKI) AddTruststore

func (v PKI) AddTruststore(chain []*x509.Certificate) error

func (*PKI) CheckHealth

func (p *PKI) CheckHealth() map[string]core.Health

func (*PKI) Config

func (p *PKI) Config() any

func (*PKI) Configure

func (p *PKI) Configure(_ core.ServerConfig) error

func (*PKI) CreateTLSConfig

func (p *PKI) CreateTLSConfig(cfg core.TLSConfig) (*tls.Config, error)

CreateTLSConfig creates a tls.Config based on the given core.TLSConfig for outbound connections to other Nuts nodes. It registers the CA certificates in the trust store in the validator which will start fetching their CRLs. It finally registers a VerifyPeerCertificateFunc in the tls.Config which will validate the peer certificate against the validator. If TLS is not enabled, it returns nil (and no error).

func (*PKI) Name

func (p *PKI) Name() string

func (PKI) SetVerifyPeerCertificateFunc

func (v PKI) SetVerifyPeerCertificateFunc(config *tls.Config) error

func (*PKI) Shutdown

func (p *PKI) Shutdown() error

func (*PKI) Start

func (p *PKI) Start() error

func (PKI) SubscribeDenied

func (v PKI) SubscribeDenied(f func())

func (PKI) Validate

func (v PKI) Validate(chain []*x509.Certificate) error

type Provider

type Provider interface {
	Validator
	// CreateTLSConfig creates a tls.Config for outbound connections. It returns nil (and no error) if TLS is disabled.
	CreateTLSConfig(cfg core.TLSConfig) (*tls.Config, error)
}

Provider is an interface for providing PKI services (e.g. TLS configuration, certificate validation).

type Validator

type Validator interface {
	// Validate returns an error if any of the certificates in the chain has been revoked, or if the request cannot be processed.
	// ErrCertRevoked and ErrCertUntrusted indicate that at least one of the certificates is revoked, or signed by a CA that is not in the truststore.
	// ErrCRLMissing and ErrCRLExpired signal that at least one of the certificates cannot be validated reliably.
	// If the certificate was revoked on an expired CRL, it wil return ErrCertRevoked.
	// Ignoring all errors except ErrCertRevoked changes the behavior from hard-fail to soft-fail. Without a truststore, the Validator is a noop if set to soft-fail
	// The certificate chain is expected to be sorted leaf to root.
	Validate(chain []*x509.Certificate) error

	// SetVerifyPeerCertificateFunc sets config.ValidatePeerCertificate to use Validate.
	SetVerifyPeerCertificateFunc(config *tls.Config) error

	// AddTruststore adds all CAs to the truststore for validation of CRL signatures. It also adds all CRL Distribution Endpoints found in the chain.
	// CRL Distribution Points encountered during operation, such as on end user certificates, are only added to the monitored CRLs if their issuer is in the truststore.
	AddTruststore(chain []*x509.Certificate) error

	// SubscribeDenied registers a callback that is triggered everytime the denylist is updated.
	// This can be used to revalidate all certificates on long-lasting connections by calling Validate on them again.
	SubscribeDenied(f func())
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL