Documentation
¶
Overview ¶
Package pki is a generated GoMock package.
Index ¶
- Variables
- func FlagSet() *pflag.FlagSet
- func SetNewDenylistWithCert(t *testing.T, val Validator, cert *x509.Certificate)
- type Config
- type Denylist
- type DenylistConfig
- type MockDenylist
- type MockDenylistMockRecorder
- func (mr *MockDenylistMockRecorder) LastUpdated() *gomock.Call
- func (mr *MockDenylistMockRecorder) Subscribe(f interface{}) *gomock.Call
- func (mr *MockDenylistMockRecorder) URL() *gomock.Call
- func (mr *MockDenylistMockRecorder) Update() *gomock.Call
- func (mr *MockDenylistMockRecorder) ValidateCert(cert interface{}) *gomock.Call
- type MockProvider
- func (m *MockProvider) AddTruststore(chain []*x509.Certificate) error
- func (m *MockProvider) CreateTLSConfig(cfg core.TLSConfig) (*tls.Config, error)
- func (m *MockProvider) EXPECT() *MockProviderMockRecorder
- func (m *MockProvider) SetVerifyPeerCertificateFunc(config *tls.Config) error
- func (m *MockProvider) SubscribeDenied(f func())
- func (m *MockProvider) Validate(chain []*x509.Certificate) error
- type MockProviderMockRecorder
- func (mr *MockProviderMockRecorder) AddTruststore(chain interface{}) *gomock.Call
- func (mr *MockProviderMockRecorder) CreateTLSConfig(cfg interface{}) *gomock.Call
- func (mr *MockProviderMockRecorder) SetVerifyPeerCertificateFunc(config interface{}) *gomock.Call
- func (mr *MockProviderMockRecorder) SubscribeDenied(f interface{}) *gomock.Call
- func (mr *MockProviderMockRecorder) Validate(chain interface{}) *gomock.Call
- type MockValidator
- func (m *MockValidator) AddTruststore(chain []*x509.Certificate) error
- func (m *MockValidator) EXPECT() *MockValidatorMockRecorder
- func (m *MockValidator) SetVerifyPeerCertificateFunc(config *tls.Config) error
- func (m *MockValidator) SubscribeDenied(f func())
- func (m *MockValidator) Validate(chain []*x509.Certificate) error
- type MockValidatorMockRecorder
- func (mr *MockValidatorMockRecorder) AddTruststore(chain interface{}) *gomock.Call
- func (mr *MockValidatorMockRecorder) SetVerifyPeerCertificateFunc(config interface{}) *gomock.Call
- func (mr *MockValidatorMockRecorder) SubscribeDenied(f interface{}) *gomock.Call
- func (mr *MockValidatorMockRecorder) Validate(chain interface{}) *gomock.Call
- type PKI
- func (v PKI) AddTruststore(chain []*x509.Certificate) error
- func (p *PKI) CheckHealth() map[string]core.Health
- func (p *PKI) Config() any
- func (p *PKI) Configure(_ core.ServerConfig) error
- func (p *PKI) CreateTLSConfig(cfg core.TLSConfig) (*tls.Config, error)
- func (p *PKI) Name() string
- func (v PKI) SetVerifyPeerCertificateFunc(config *tls.Config) error
- func (p *PKI) Shutdown() error
- func (p *PKI) Start() error
- func (v PKI) SubscribeDenied(f func())
- func (v PKI) Validate(chain []*x509.Certificate) error
- type Provider
- type Validator
Constants ¶
This section is empty.
Variables ¶
var ( ErrCRLMissing = errors.New("crl is missing") ErrCRLExpired = errors.New("crl has expired") ErrCertRevoked = errors.New("certificate is revoked") ErrCertUntrusted = errors.New("certificate's issuer is not trusted") // ErrDenylistMissing occurs when the denylist cannot be downloaded ErrDenylistMissing = errors.New("denylist cannot be retrieved") // ErrCertBanned means the certificate was banned by a denylist rather than revoked by a CRL ErrCertBanned = errors.New("certificate is banned") )
errors
Functions ¶
func SetNewDenylistWithCert ¶
func SetNewDenylistWithCert(t *testing.T, val Validator, cert *x509.Certificate)
SetNewDenylistWithCert sets a new Denylist on the Validator and adds the certificate. This is useful in integrations tests etc.
Types ¶
type Config ¶
type Config struct {
// Denylist specifies config options for the PKI denylist, which acts as a global CRL
Denylist DenylistConfig `koanf:"denylist"`
// MaxUpdateFailHours specifies the maximum number of hours that a denylist update can fail
MaxUpdateFailHours int `koanf:"maxupdatefailhours"`
// Softfail still accepts connections if the revocation status of a certificate cannot be reliably established if set to true
Softfail bool `koanf:"softfail"`
}
Config specifies configuration parameters for PKI functionality
func DefaultConfig ¶
func DefaultConfig() Config
func TestConfig ¶
TestConfig is the same as DefaultConfig without a denylist URL set.
type Denylist ¶
type Denylist interface {
// LastUpdated provides the time at which the denylist was last retrieved
LastUpdated() time.Time
// Update fetches a new copy of the denylist
Update() error
// URL returns the URL of the denylist
URL() string
// ValidateCert returns an error if a certificate should not be used
ValidateCert(cert *x509.Certificate) error
// Subscribe registers a callback that is triggered everytime the denylist is updated
Subscribe(f func())
}
Denylist implements a global certificate rejection
func NewDenylist ¶
func NewDenylist(config DenylistConfig) (Denylist, error)
NewDenylist creates a denylist with the specified configuration
type DenylistConfig ¶
type DenylistConfig struct {
// URL specifies the URL where the certificate blacklist is downloaded
URL string `koanf:"url"`
// TrustedSigner specifies the PEM Ed25519 public key which must sign the blacklist
TrustedSigner string `koanf:"trustedsigner"`
}
DenylistConfig specifies the config structure for the crl/certificate blacklist module
type MockDenylist ¶
type MockDenylist struct {
// contains filtered or unexported fields
}
MockDenylist is a mock of Denylist interface.
func NewMockDenylist ¶
func NewMockDenylist(ctrl *gomock.Controller) *MockDenylist
NewMockDenylist creates a new mock instance.
func (*MockDenylist) EXPECT ¶
func (m *MockDenylist) EXPECT() *MockDenylistMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
func (*MockDenylist) LastUpdated ¶
func (m *MockDenylist) LastUpdated() time.Time
LastUpdated mocks base method.
func (*MockDenylist) Subscribe ¶
func (m *MockDenylist) Subscribe(f func())
Subscribe mocks base method.
func (*MockDenylist) ValidateCert ¶
func (m *MockDenylist) ValidateCert(cert *x509.Certificate) error
ValidateCert mocks base method.
type MockDenylistMockRecorder ¶
type MockDenylistMockRecorder struct {
// contains filtered or unexported fields
}
MockDenylistMockRecorder is the mock recorder for MockDenylist.
func (*MockDenylistMockRecorder) LastUpdated ¶
func (mr *MockDenylistMockRecorder) LastUpdated() *gomock.Call
LastUpdated indicates an expected call of LastUpdated.
func (*MockDenylistMockRecorder) Subscribe ¶
func (mr *MockDenylistMockRecorder) Subscribe(f interface{}) *gomock.Call
Subscribe indicates an expected call of Subscribe.
func (*MockDenylistMockRecorder) URL ¶
func (mr *MockDenylistMockRecorder) URL() *gomock.Call
URL indicates an expected call of URL.
func (*MockDenylistMockRecorder) Update ¶
func (mr *MockDenylistMockRecorder) Update() *gomock.Call
Update indicates an expected call of Update.
func (*MockDenylistMockRecorder) ValidateCert ¶
func (mr *MockDenylistMockRecorder) ValidateCert(cert interface{}) *gomock.Call
ValidateCert indicates an expected call of ValidateCert.
type MockProvider ¶
type MockProvider struct {
// contains filtered or unexported fields
}
MockProvider is a mock of Provider interface.
func NewMockProvider ¶
func NewMockProvider(ctrl *gomock.Controller) *MockProvider
NewMockProvider creates a new mock instance.
func (*MockProvider) AddTruststore ¶
func (m *MockProvider) AddTruststore(chain []*x509.Certificate) error
AddTruststore mocks base method.
func (*MockProvider) CreateTLSConfig ¶
CreateTLSConfig mocks base method.
func (*MockProvider) EXPECT ¶
func (m *MockProvider) EXPECT() *MockProviderMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
func (*MockProvider) SetVerifyPeerCertificateFunc ¶
func (m *MockProvider) SetVerifyPeerCertificateFunc(config *tls.Config) error
SetVerifyPeerCertificateFunc mocks base method.
func (*MockProvider) SubscribeDenied ¶
func (m *MockProvider) SubscribeDenied(f func())
SubscribeDenied mocks base method.
func (*MockProvider) Validate ¶
func (m *MockProvider) Validate(chain []*x509.Certificate) error
Validate mocks base method.
type MockProviderMockRecorder ¶
type MockProviderMockRecorder struct {
// contains filtered or unexported fields
}
MockProviderMockRecorder is the mock recorder for MockProvider.
func (*MockProviderMockRecorder) AddTruststore ¶
func (mr *MockProviderMockRecorder) AddTruststore(chain interface{}) *gomock.Call
AddTruststore indicates an expected call of AddTruststore.
func (*MockProviderMockRecorder) CreateTLSConfig ¶
func (mr *MockProviderMockRecorder) CreateTLSConfig(cfg interface{}) *gomock.Call
CreateTLSConfig indicates an expected call of CreateTLSConfig.
func (*MockProviderMockRecorder) SetVerifyPeerCertificateFunc ¶
func (mr *MockProviderMockRecorder) SetVerifyPeerCertificateFunc(config interface{}) *gomock.Call
SetVerifyPeerCertificateFunc indicates an expected call of SetVerifyPeerCertificateFunc.
func (*MockProviderMockRecorder) SubscribeDenied ¶
func (mr *MockProviderMockRecorder) SubscribeDenied(f interface{}) *gomock.Call
SubscribeDenied indicates an expected call of SubscribeDenied.
func (*MockProviderMockRecorder) Validate ¶
func (mr *MockProviderMockRecorder) Validate(chain interface{}) *gomock.Call
Validate indicates an expected call of Validate.
type MockValidator ¶
type MockValidator struct {
// contains filtered or unexported fields
}
MockValidator is a mock of Validator interface.
func NewMockValidator ¶
func NewMockValidator(ctrl *gomock.Controller) *MockValidator
NewMockValidator creates a new mock instance.
func (*MockValidator) AddTruststore ¶
func (m *MockValidator) AddTruststore(chain []*x509.Certificate) error
AddTruststore mocks base method.
func (*MockValidator) EXPECT ¶
func (m *MockValidator) EXPECT() *MockValidatorMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
func (*MockValidator) SetVerifyPeerCertificateFunc ¶
func (m *MockValidator) SetVerifyPeerCertificateFunc(config *tls.Config) error
SetVerifyPeerCertificateFunc mocks base method.
func (*MockValidator) SubscribeDenied ¶
func (m *MockValidator) SubscribeDenied(f func())
SubscribeDenied mocks base method.
func (*MockValidator) Validate ¶
func (m *MockValidator) Validate(chain []*x509.Certificate) error
Validate mocks base method.
type MockValidatorMockRecorder ¶
type MockValidatorMockRecorder struct {
// contains filtered or unexported fields
}
MockValidatorMockRecorder is the mock recorder for MockValidator.
func (*MockValidatorMockRecorder) AddTruststore ¶
func (mr *MockValidatorMockRecorder) AddTruststore(chain interface{}) *gomock.Call
AddTruststore indicates an expected call of AddTruststore.
func (*MockValidatorMockRecorder) SetVerifyPeerCertificateFunc ¶
func (mr *MockValidatorMockRecorder) SetVerifyPeerCertificateFunc(config interface{}) *gomock.Call
SetVerifyPeerCertificateFunc indicates an expected call of SetVerifyPeerCertificateFunc.
func (*MockValidatorMockRecorder) SubscribeDenied ¶
func (mr *MockValidatorMockRecorder) SubscribeDenied(f interface{}) *gomock.Call
SubscribeDenied indicates an expected call of SubscribeDenied.
func (*MockValidatorMockRecorder) Validate ¶
func (mr *MockValidatorMockRecorder) Validate(chain interface{}) *gomock.Call
Validate indicates an expected call of Validate.
type PKI ¶
type PKI struct {
// contains filtered or unexported fields
}
func (PKI) AddTruststore ¶
func (v PKI) AddTruststore(chain []*x509.Certificate) error
func (*PKI) CreateTLSConfig ¶
CreateTLSConfig creates a tls.Config based on the given core.TLSConfig for outbound connections to other Nuts nodes. It registers the CA certificates in the trust store in the validator which will start fetching their CRLs. It finally registers a VerifyPeerCertificateFunc in the tls.Config which will validate the peer certificate against the validator. If TLS is not enabled, it returns nil (and no error).
func (PKI) SetVerifyPeerCertificateFunc ¶
func (PKI) SubscribeDenied ¶
func (v PKI) SubscribeDenied(f func())
func (PKI) Validate ¶
func (v PKI) Validate(chain []*x509.Certificate) error
type Provider ¶
type Provider interface {
Validator
// CreateTLSConfig creates a tls.Config for outbound connections. It returns nil (and no error) if TLS is disabled.
CreateTLSConfig(cfg core.TLSConfig) (*tls.Config, error)
}
Provider is an interface for providing PKI services (e.g. TLS configuration, certificate validation).
type Validator ¶
type Validator interface {
// Validate returns an error if any of the certificates in the chain has been revoked, or if the request cannot be processed.
// ErrCertRevoked and ErrCertUntrusted indicate that at least one of the certificates is revoked, or signed by a CA that is not in the truststore.
// ErrCRLMissing and ErrCRLExpired signal that at least one of the certificates cannot be validated reliably.
// If the certificate was revoked on an expired CRL, it wil return ErrCertRevoked.
// Ignoring all errors except ErrCertRevoked changes the behavior from hard-fail to soft-fail. Without a truststore, the Validator is a noop if set to soft-fail
// The certificate chain is expected to be sorted leaf to root.
Validate(chain []*x509.Certificate) error
// SetVerifyPeerCertificateFunc sets config.ValidatePeerCertificate to use Validate.
SetVerifyPeerCertificateFunc(config *tls.Config) error
// AddTruststore adds all CAs to the truststore for validation of CRL signatures. It also adds all CRL Distribution Endpoints found in the chain.
// CRL Distribution Points encountered during operation, such as on end user certificates, are only added to the monitored CRLs if their issuer is in the truststore.
AddTruststore(chain []*x509.Certificate) error
// SubscribeDenied registers a callback that is triggered everytime the denylist is updated.
// This can be used to revalidate all certificates on long-lasting connections by calling Validate on them again.
SubscribeDenied(f func())
}