Documentation
¶
Overview ¶
Package pki is a generated GoMock package.
Index ¶
- Variables
- func FlagSet() *pflag.FlagSet
- func SetNewDenylistWithCert(t *testing.T, val Validator, cert *x509.Certificate)
- type Config
- type Denylist
- type DenylistConfig
- type MockDenylist
- type MockDenylistMockRecorder
- func (mr *MockDenylistMockRecorder) LastUpdated() *gomock.Call
- func (mr *MockDenylistMockRecorder) Subscribe(f any) *gomock.Call
- func (mr *MockDenylistMockRecorder) URL() *gomock.Call
- func (mr *MockDenylistMockRecorder) Update() *gomock.Call
- func (mr *MockDenylistMockRecorder) ValidateCert(cert any) *gomock.Call
- type MockProvider
- func (m *MockProvider) CheckCRL(chain []*x509.Certificate) error
- func (m *MockProvider) CheckCRLStrict(chain []*x509.Certificate) error
- func (m *MockProvider) CreateTLSConfig(cfg core.TLSConfig) (*tls.Config, error)
- func (m *MockProvider) EXPECT() *MockProviderMockRecorder
- func (m *MockProvider) SetVerifyPeerCertificateFunc(config *tls.Config) error
- func (m *MockProvider) SubscribeDenied(f func())
- type MockProviderMockRecorder
- func (mr *MockProviderMockRecorder) CheckCRL(chain any) *gomock.Call
- func (mr *MockProviderMockRecorder) CheckCRLStrict(chain any) *gomock.Call
- func (mr *MockProviderMockRecorder) CreateTLSConfig(cfg any) *gomock.Call
- func (mr *MockProviderMockRecorder) SetVerifyPeerCertificateFunc(config any) *gomock.Call
- func (mr *MockProviderMockRecorder) SubscribeDenied(f any) *gomock.Call
- type MockValidator
- func (m *MockValidator) CheckCRL(chain []*x509.Certificate) error
- func (m *MockValidator) CheckCRLStrict(chain []*x509.Certificate) error
- func (m *MockValidator) EXPECT() *MockValidatorMockRecorder
- func (m *MockValidator) SetVerifyPeerCertificateFunc(config *tls.Config) error
- func (m *MockValidator) SubscribeDenied(f func())
- type MockValidatorMockRecorder
- func (mr *MockValidatorMockRecorder) CheckCRL(chain any) *gomock.Call
- func (mr *MockValidatorMockRecorder) CheckCRLStrict(chain any) *gomock.Call
- func (mr *MockValidatorMockRecorder) SetVerifyPeerCertificateFunc(config any) *gomock.Call
- func (mr *MockValidatorMockRecorder) SubscribeDenied(f any) *gomock.Call
- type PKI
- func (v PKI) CheckCRL(chain []*x509.Certificate) error
- func (v PKI) CheckCRLStrict(chain []*x509.Certificate) error
- func (p *PKI) CheckHealth() map[string]core.Health
- func (p *PKI) Config() any
- func (p *PKI) Configure(config core.ServerConfig) error
- func (p *PKI) CreateTLSConfig(cfg core.TLSConfig) (*tls.Config, error)
- func (p *PKI) Name() string
- func (v PKI) SetVerifyPeerCertificateFunc(config *tls.Config) error
- func (p *PKI) Shutdown() error
- func (p *PKI) Start() error
- func (v PKI) SubscribeDenied(f func())
- type Provider
- type Validator
Constants ¶
This section is empty.
Variables ¶
var ( ErrCRLMissing = errors.New("crl is missing") ErrCRLExpired = errors.New("crl has expired") ErrCertRevoked = errors.New("certificate is revoked") ErrUnknownIssuer = errors.New("unknown certificate issuer") // ErrDenylistMissing occurs when the denylist cannot be downloaded ErrDenylistMissing = errors.New("denylist cannot be retrieved") // ErrCertBanned means the certificate was banned by a denylist rather than revoked by a CRL ErrCertBanned = errors.New("certificate is banned") )
errors
Functions ¶
func SetNewDenylistWithCert ¶
func SetNewDenylistWithCert(t *testing.T, val Validator, cert *x509.Certificate)
SetNewDenylistWithCert sets a new Denylist on the Validator and adds the certificate. This is useful in integrations tests etc.
Types ¶
type Config ¶
type Config struct {
// Denylist specifies config options for the PKI denylist, which acts as a global CRL
Denylist DenylistConfig `koanf:"denylist"`
// MaxUpdateFailHours specifies the maximum number of hours that a denylist update can fail
MaxUpdateFailHours int `koanf:"maxupdatefailhours"`
// Softfail still accepts connections if the revocation status of a certificate cannot be reliably established if set to true
Softfail bool `koanf:"softfail"`
}
Config specifies configuration parameters for PKI functionality
func DefaultConfig ¶
func DefaultConfig() Config
func TestConfig ¶
TestConfig is the same as DefaultConfig without a denylist URL set.
type Denylist ¶
type Denylist interface {
// LastUpdated provides the time at which the denylist was last retrieved
LastUpdated() time.Time
// Update fetches a new copy of the denylist
Update() error
// URL returns the URL of the denylist
URL() string
// ValidateCert returns an error if a certificate should not be used
ValidateCert(cert *x509.Certificate) error
// Subscribe registers a callback that is triggered everytime the denylist is updated
Subscribe(f func())
}
Denylist implements a global certificate rejection
func NewDenylist ¶
func NewDenylist(config DenylistConfig) (Denylist, error)
NewDenylist creates a denylist with the specified configuration
type DenylistConfig ¶
type DenylistConfig struct {
// URL specifies the URL where the certificate blacklist is downloaded
URL string `koanf:"url"`
// TrustedSigner specifies the PEM Ed25519 public key which must sign the blacklist
TrustedSigner string `koanf:"trustedsigner"`
}
DenylistConfig specifies the config structure for the crl/certificate blacklist module
type MockDenylist ¶
type MockDenylist struct {
// contains filtered or unexported fields
}
MockDenylist is a mock of Denylist interface.
func NewMockDenylist ¶
func NewMockDenylist(ctrl *gomock.Controller) *MockDenylist
NewMockDenylist creates a new mock instance.
func (*MockDenylist) EXPECT ¶
func (m *MockDenylist) EXPECT() *MockDenylistMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
func (*MockDenylist) LastUpdated ¶
func (m *MockDenylist) LastUpdated() time.Time
LastUpdated mocks base method.
func (*MockDenylist) Subscribe ¶
func (m *MockDenylist) Subscribe(f func())
Subscribe mocks base method.
func (*MockDenylist) ValidateCert ¶
func (m *MockDenylist) ValidateCert(cert *x509.Certificate) error
ValidateCert mocks base method.
type MockDenylistMockRecorder ¶
type MockDenylistMockRecorder struct {
// contains filtered or unexported fields
}
MockDenylistMockRecorder is the mock recorder for MockDenylist.
func (*MockDenylistMockRecorder) LastUpdated ¶
func (mr *MockDenylistMockRecorder) LastUpdated() *gomock.Call
LastUpdated indicates an expected call of LastUpdated.
func (*MockDenylistMockRecorder) Subscribe ¶
func (mr *MockDenylistMockRecorder) Subscribe(f any) *gomock.Call
Subscribe indicates an expected call of Subscribe.
func (*MockDenylistMockRecorder) URL ¶
func (mr *MockDenylistMockRecorder) URL() *gomock.Call
URL indicates an expected call of URL.
func (*MockDenylistMockRecorder) Update ¶
func (mr *MockDenylistMockRecorder) Update() *gomock.Call
Update indicates an expected call of Update.
func (*MockDenylistMockRecorder) ValidateCert ¶
func (mr *MockDenylistMockRecorder) ValidateCert(cert any) *gomock.Call
ValidateCert indicates an expected call of ValidateCert.
type MockProvider ¶
type MockProvider struct {
// contains filtered or unexported fields
}
MockProvider is a mock of Provider interface.
func NewMockProvider ¶
func NewMockProvider(ctrl *gomock.Controller) *MockProvider
NewMockProvider creates a new mock instance.
func (*MockProvider) CheckCRL ¶
func (m *MockProvider) CheckCRL(chain []*x509.Certificate) error
CheckCRL mocks base method.
func (*MockProvider) CheckCRLStrict ¶
func (m *MockProvider) CheckCRLStrict(chain []*x509.Certificate) error
CheckCRLStrict mocks base method.
func (*MockProvider) CreateTLSConfig ¶
CreateTLSConfig mocks base method.
func (*MockProvider) EXPECT ¶
func (m *MockProvider) EXPECT() *MockProviderMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
func (*MockProvider) SetVerifyPeerCertificateFunc ¶
func (m *MockProvider) SetVerifyPeerCertificateFunc(config *tls.Config) error
SetVerifyPeerCertificateFunc mocks base method.
func (*MockProvider) SubscribeDenied ¶
func (m *MockProvider) SubscribeDenied(f func())
SubscribeDenied mocks base method.
type MockProviderMockRecorder ¶
type MockProviderMockRecorder struct {
// contains filtered or unexported fields
}
MockProviderMockRecorder is the mock recorder for MockProvider.
func (*MockProviderMockRecorder) CheckCRL ¶
func (mr *MockProviderMockRecorder) CheckCRL(chain any) *gomock.Call
CheckCRL indicates an expected call of CheckCRL.
func (*MockProviderMockRecorder) CheckCRLStrict ¶
func (mr *MockProviderMockRecorder) CheckCRLStrict(chain any) *gomock.Call
CheckCRLStrict indicates an expected call of CheckCRLStrict.
func (*MockProviderMockRecorder) CreateTLSConfig ¶
func (mr *MockProviderMockRecorder) CreateTLSConfig(cfg any) *gomock.Call
CreateTLSConfig indicates an expected call of CreateTLSConfig.
func (*MockProviderMockRecorder) SetVerifyPeerCertificateFunc ¶
func (mr *MockProviderMockRecorder) SetVerifyPeerCertificateFunc(config any) *gomock.Call
SetVerifyPeerCertificateFunc indicates an expected call of SetVerifyPeerCertificateFunc.
func (*MockProviderMockRecorder) SubscribeDenied ¶
func (mr *MockProviderMockRecorder) SubscribeDenied(f any) *gomock.Call
SubscribeDenied indicates an expected call of SubscribeDenied.
type MockValidator ¶
type MockValidator struct {
// contains filtered or unexported fields
}
MockValidator is a mock of Validator interface.
func NewMockValidator ¶
func NewMockValidator(ctrl *gomock.Controller) *MockValidator
NewMockValidator creates a new mock instance.
func (*MockValidator) CheckCRL ¶
func (m *MockValidator) CheckCRL(chain []*x509.Certificate) error
CheckCRL mocks base method.
func (*MockValidator) CheckCRLStrict ¶
func (m *MockValidator) CheckCRLStrict(chain []*x509.Certificate) error
CheckCRLStrict mocks base method.
func (*MockValidator) EXPECT ¶
func (m *MockValidator) EXPECT() *MockValidatorMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
func (*MockValidator) SetVerifyPeerCertificateFunc ¶
func (m *MockValidator) SetVerifyPeerCertificateFunc(config *tls.Config) error
SetVerifyPeerCertificateFunc mocks base method.
func (*MockValidator) SubscribeDenied ¶
func (m *MockValidator) SubscribeDenied(f func())
SubscribeDenied mocks base method.
type MockValidatorMockRecorder ¶
type MockValidatorMockRecorder struct {
// contains filtered or unexported fields
}
MockValidatorMockRecorder is the mock recorder for MockValidator.
func (*MockValidatorMockRecorder) CheckCRL ¶
func (mr *MockValidatorMockRecorder) CheckCRL(chain any) *gomock.Call
CheckCRL indicates an expected call of CheckCRL.
func (*MockValidatorMockRecorder) CheckCRLStrict ¶
func (mr *MockValidatorMockRecorder) CheckCRLStrict(chain any) *gomock.Call
CheckCRLStrict indicates an expected call of CheckCRLStrict.
func (*MockValidatorMockRecorder) SetVerifyPeerCertificateFunc ¶
func (mr *MockValidatorMockRecorder) SetVerifyPeerCertificateFunc(config any) *gomock.Call
SetVerifyPeerCertificateFunc indicates an expected call of SetVerifyPeerCertificateFunc.
func (*MockValidatorMockRecorder) SubscribeDenied ¶
func (mr *MockValidatorMockRecorder) SubscribeDenied(f any) *gomock.Call
SubscribeDenied indicates an expected call of SubscribeDenied.
type PKI ¶
type PKI struct {
// contains filtered or unexported fields
}
func (PKI) CheckCRL ¶
func (v PKI) CheckCRL(chain []*x509.Certificate) error
func (PKI) CheckCRLStrict ¶
func (v PKI) CheckCRLStrict(chain []*x509.Certificate) error
func (*PKI) CreateTLSConfig ¶
CreateTLSConfig creates a tls.Config based on the given core.TLSConfig for outbound connections to other Nuts nodes. It registers a VerifyPeerCertificateFunc in the tls.Config which will validate the peer certificate against the CRLs. If TLS is not enabled, it returns nil (and no error).
func (PKI) SetVerifyPeerCertificateFunc ¶
func (PKI) SubscribeDenied ¶
func (v PKI) SubscribeDenied(f func())
type Provider ¶
type Provider interface {
Validator
// CreateTLSConfig creates a tls.Config from the core.TLSConfig for outbound connections.
// It returns (nil, nil) if core.TLSConfig.Enabled() == false.
CreateTLSConfig(cfg core.TLSConfig) (*tls.Config, error)
}
Provider is an interface for providing PKI services (e.g. TLS configuration, certificate validation).
type Validator ¶
type Validator interface {
// CheckCRL returns an error if any of the certificates in the chain has been revoked, or if the request cannot be processed.
// All certificates in the chain are considered trusted, which means that the caller has verified the integrity of the chain and appropriateness for the use-case.
// Any new CA / CRL in the chain will be added to the internal watchlist and updated periodically, so it MUST NOT be called on untrusted/invalid chains.
// The certificate chain MUST be sorted leaf to root.
//
// ErrCertRevoked and ErrUnknownIssuer indicate that at least one of the certificates is revoked, or signed by an unknown CA (so we have no key to verify the CRL).
// ErrCRLMissing and ErrCRLExpired signal that at least one of the certificates cannot be validated reliably.
// If the certificate was revoked on an expired CRL, it wil return ErrCertRevoked.
//
// CheckCRL uses the configured soft-/hard-fail strategy
// If set to soft-fail it ignores ErrCRLMissing and ErrCRLExpired errors.
CheckCRL(chain []*x509.Certificate) error
// CheckCRLStrict does the same as CheckCRL, except it always uses the hard-fail strategy.
CheckCRLStrict(chain []*x509.Certificate) error
// SetVerifyPeerCertificateFunc sets config.ValidatePeerCertificate to use CheckCRL.
SetVerifyPeerCertificateFunc(config *tls.Config) error
// SubscribeDenied registers a callback that is triggered everytime the denylist is updated.
// This can be used to revalidate all certificates on long-lasting connections by calling CheckCRL on them again.
SubscribeDenied(f func())
}
Validator is used to check the revocation status of certificates on the issuer controlled CRL and the user controlled Denylist. It does NOT manage trust and assumes all presented certificates belong to a trusted certificate tree.