pki

package
v6.2.12 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 21, 2026 License: GPL-3.0 Imports: 24 Imported by: 0

Documentation

Overview

Package pki is a generated GoMock package.

Index

Constants

This section is empty.

Variables

View Source
var (
	ErrCRLMissing    = errors.New("crl is missing")
	ErrCRLExpired    = errors.New("crl has expired")
	ErrCertRevoked   = errors.New("certificate is revoked")
	ErrUnknownIssuer = errors.New("unknown certificate issuer")
	// ErrDenylistMissing occurs when the denylist cannot be downloaded
	ErrDenylistMissing = errors.New("denylist cannot be retrieved")

	// ErrCertBanned means the certificate was banned by a denylist rather than revoked by a CRL
	ErrCertBanned = errors.New("certificate is banned")
)

errors

Functions

func FlagSet

func FlagSet() *pflag.FlagSet

FlagSet contains flags relevant for JSON-LD

func SetNewDenylistWithCert

func SetNewDenylistWithCert(t *testing.T, val Validator, cert *x509.Certificate)

SetNewDenylistWithCert sets a new Denylist on the Validator and adds the certificate. This is useful in integrations tests etc.

Types

type Config

type Config struct {
	// Denylist specifies config options for the PKI denylist, which acts as a global CRL
	Denylist DenylistConfig `koanf:"denylist"`

	// MaxUpdateFailHours specifies the maximum number of hours that a denylist update can fail
	MaxUpdateFailHours int `koanf:"maxupdatefailhours"`

	// Softfail still accepts connections if the revocation status of a certificate cannot be reliably established if set to true
	Softfail bool `koanf:"softfail"`
}

Config specifies configuration parameters for PKI functionality

func DefaultConfig

func DefaultConfig() Config

func TestConfig

func TestConfig(t *testing.T) Config

TestConfig is the same as DefaultConfig without a denylist URL set.

type Denylist

type Denylist interface {
	// LastUpdated provides the time at which the denylist was last retrieved
	LastUpdated() time.Time

	// Update fetches a new copy of the denylist
	Update() error

	// URL returns the URL of the denylist
	URL() string

	// ValidateCert returns an error if a certificate should not be used
	ValidateCert(cert *x509.Certificate) error

	// Subscribe registers a callback that is triggered everytime the denylist is updated
	Subscribe(f func())
}

Denylist implements a global certificate rejection

func NewDenylist

func NewDenylist(config DenylistConfig) (Denylist, error)

NewDenylist creates a denylist with the specified configuration

type DenylistConfig

type DenylistConfig struct {
	// URL specifies the URL where the certificate blacklist is downloaded
	URL string `koanf:"url"`

	// TrustedSigner specifies the PEM Ed25519 public key which must sign the blacklist
	TrustedSigner string `koanf:"trustedsigner"`
}

DenylistConfig specifies the config structure for the crl/certificate blacklist module

type MockDenylist

type MockDenylist struct {
	// contains filtered or unexported fields
}

MockDenylist is a mock of Denylist interface.

func NewMockDenylist

func NewMockDenylist(ctrl *gomock.Controller) *MockDenylist

NewMockDenylist creates a new mock instance.

func (*MockDenylist) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockDenylist) LastUpdated

func (m *MockDenylist) LastUpdated() time.Time

LastUpdated mocks base method.

func (*MockDenylist) Subscribe

func (m *MockDenylist) Subscribe(f func())

Subscribe mocks base method.

func (*MockDenylist) URL

func (m *MockDenylist) URL() string

URL mocks base method.

func (*MockDenylist) Update

func (m *MockDenylist) Update() error

Update mocks base method.

func (*MockDenylist) ValidateCert

func (m *MockDenylist) ValidateCert(cert *x509.Certificate) error

ValidateCert mocks base method.

type MockDenylistMockRecorder

type MockDenylistMockRecorder struct {
	// contains filtered or unexported fields
}

MockDenylistMockRecorder is the mock recorder for MockDenylist.

func (*MockDenylistMockRecorder) LastUpdated

func (mr *MockDenylistMockRecorder) LastUpdated() *gomock.Call

LastUpdated indicates an expected call of LastUpdated.

func (*MockDenylistMockRecorder) Subscribe

func (mr *MockDenylistMockRecorder) Subscribe(f any) *gomock.Call

Subscribe indicates an expected call of Subscribe.

func (*MockDenylistMockRecorder) URL

URL indicates an expected call of URL.

func (*MockDenylistMockRecorder) Update

func (mr *MockDenylistMockRecorder) Update() *gomock.Call

Update indicates an expected call of Update.

func (*MockDenylistMockRecorder) ValidateCert

func (mr *MockDenylistMockRecorder) ValidateCert(cert any) *gomock.Call

ValidateCert indicates an expected call of ValidateCert.

type MockProvider

type MockProvider struct {
	// contains filtered or unexported fields
}

MockProvider is a mock of Provider interface.

func NewMockProvider

func NewMockProvider(ctrl *gomock.Controller) *MockProvider

NewMockProvider creates a new mock instance.

func (*MockProvider) CheckCRL

func (m *MockProvider) CheckCRL(chain []*x509.Certificate) error

CheckCRL mocks base method.

func (*MockProvider) CheckCRLStrict

func (m *MockProvider) CheckCRLStrict(chain []*x509.Certificate) error

CheckCRLStrict mocks base method.

func (*MockProvider) CreateTLSConfig

func (m *MockProvider) CreateTLSConfig(cfg core.TLSConfig) (*tls.Config, error)

CreateTLSConfig mocks base method.

func (*MockProvider) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockProvider) SetVerifyPeerCertificateFunc

func (m *MockProvider) SetVerifyPeerCertificateFunc(config *tls.Config) error

SetVerifyPeerCertificateFunc mocks base method.

func (*MockProvider) SubscribeDenied

func (m *MockProvider) SubscribeDenied(f func())

SubscribeDenied mocks base method.

type MockProviderMockRecorder

type MockProviderMockRecorder struct {
	// contains filtered or unexported fields
}

MockProviderMockRecorder is the mock recorder for MockProvider.

func (*MockProviderMockRecorder) CheckCRL

func (mr *MockProviderMockRecorder) CheckCRL(chain any) *gomock.Call

CheckCRL indicates an expected call of CheckCRL.

func (*MockProviderMockRecorder) CheckCRLStrict

func (mr *MockProviderMockRecorder) CheckCRLStrict(chain any) *gomock.Call

CheckCRLStrict indicates an expected call of CheckCRLStrict.

func (*MockProviderMockRecorder) CreateTLSConfig

func (mr *MockProviderMockRecorder) CreateTLSConfig(cfg any) *gomock.Call

CreateTLSConfig indicates an expected call of CreateTLSConfig.

func (*MockProviderMockRecorder) SetVerifyPeerCertificateFunc

func (mr *MockProviderMockRecorder) SetVerifyPeerCertificateFunc(config any) *gomock.Call

SetVerifyPeerCertificateFunc indicates an expected call of SetVerifyPeerCertificateFunc.

func (*MockProviderMockRecorder) SubscribeDenied

func (mr *MockProviderMockRecorder) SubscribeDenied(f any) *gomock.Call

SubscribeDenied indicates an expected call of SubscribeDenied.

type MockValidator

type MockValidator struct {
	// contains filtered or unexported fields
}

MockValidator is a mock of Validator interface.

func NewMockValidator

func NewMockValidator(ctrl *gomock.Controller) *MockValidator

NewMockValidator creates a new mock instance.

func (*MockValidator) CheckCRL

func (m *MockValidator) CheckCRL(chain []*x509.Certificate) error

CheckCRL mocks base method.

func (*MockValidator) CheckCRLStrict

func (m *MockValidator) CheckCRLStrict(chain []*x509.Certificate) error

CheckCRLStrict mocks base method.

func (*MockValidator) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockValidator) SetVerifyPeerCertificateFunc

func (m *MockValidator) SetVerifyPeerCertificateFunc(config *tls.Config) error

SetVerifyPeerCertificateFunc mocks base method.

func (*MockValidator) SubscribeDenied

func (m *MockValidator) SubscribeDenied(f func())

SubscribeDenied mocks base method.

type MockValidatorMockRecorder

type MockValidatorMockRecorder struct {
	// contains filtered or unexported fields
}

MockValidatorMockRecorder is the mock recorder for MockValidator.

func (*MockValidatorMockRecorder) CheckCRL

func (mr *MockValidatorMockRecorder) CheckCRL(chain any) *gomock.Call

CheckCRL indicates an expected call of CheckCRL.

func (*MockValidatorMockRecorder) CheckCRLStrict

func (mr *MockValidatorMockRecorder) CheckCRLStrict(chain any) *gomock.Call

CheckCRLStrict indicates an expected call of CheckCRLStrict.

func (*MockValidatorMockRecorder) SetVerifyPeerCertificateFunc

func (mr *MockValidatorMockRecorder) SetVerifyPeerCertificateFunc(config any) *gomock.Call

SetVerifyPeerCertificateFunc indicates an expected call of SetVerifyPeerCertificateFunc.

func (*MockValidatorMockRecorder) SubscribeDenied

func (mr *MockValidatorMockRecorder) SubscribeDenied(f any) *gomock.Call

SubscribeDenied indicates an expected call of SubscribeDenied.

type PKI

type PKI struct {
	// contains filtered or unexported fields
}

func New

func New() *PKI

func (PKI) CheckCRL

func (v PKI) CheckCRL(chain []*x509.Certificate) error

func (PKI) CheckCRLStrict

func (v PKI) CheckCRLStrict(chain []*x509.Certificate) error

func (*PKI) CheckHealth

func (p *PKI) CheckHealth() map[string]core.Health

func (*PKI) Config

func (p *PKI) Config() any

func (*PKI) Configure

func (p *PKI) Configure(config core.ServerConfig) error

func (*PKI) CreateTLSConfig

func (p *PKI) CreateTLSConfig(cfg core.TLSConfig) (*tls.Config, error)

CreateTLSConfig creates a tls.Config based on the given core.TLSConfig for outbound connections to other Nuts nodes. It registers a VerifyPeerCertificateFunc in the tls.Config which will validate the peer certificate against the CRLs. If TLS is not enabled, it returns nil (and no error).

func (*PKI) Name

func (p *PKI) Name() string

func (PKI) SetVerifyPeerCertificateFunc

func (v PKI) SetVerifyPeerCertificateFunc(config *tls.Config) error

func (*PKI) Shutdown

func (p *PKI) Shutdown() error

func (*PKI) Start

func (p *PKI) Start() error

func (PKI) SubscribeDenied

func (v PKI) SubscribeDenied(f func())

type Provider

type Provider interface {
	Validator
	// CreateTLSConfig creates a tls.Config from the core.TLSConfig for outbound connections.
	// It returns (nil, nil)  if core.TLSConfig.Enabled() == false.
	CreateTLSConfig(cfg core.TLSConfig) (*tls.Config, error)
}

Provider is an interface for providing PKI services (e.g. TLS configuration, certificate validation).

type Validator

type Validator interface {
	// CheckCRL returns an error if any of the certificates in the chain has been revoked, or if the request cannot be processed.
	// All certificates in the chain are considered trusted, which means that the caller has verified the integrity of the chain and appropriateness for the use-case.
	// Any new CA / CRL in the chain will be added to the internal watchlist and updated periodically, so it MUST NOT be called on untrusted/invalid chains.
	// The certificate chain MUST be sorted leaf to root.
	//
	// ErrCertRevoked and ErrUnknownIssuer indicate that at least one of the certificates is revoked, or signed by an unknown CA (so we have no key to verify the CRL).
	// ErrCRLMissing and ErrCRLExpired signal that at least one of the certificates cannot be validated reliably.
	// If the certificate was revoked on an expired CRL, it wil return ErrCertRevoked.
	//
	// CheckCRL uses the configured soft-/hard-fail strategy
	// If set to soft-fail it ignores ErrCRLMissing and ErrCRLExpired errors.
	CheckCRL(chain []*x509.Certificate) error

	// CheckCRLStrict does the same as CheckCRL, except it always uses the hard-fail strategy.
	CheckCRLStrict(chain []*x509.Certificate) error

	// SetVerifyPeerCertificateFunc sets config.ValidatePeerCertificate to use CheckCRL.
	SetVerifyPeerCertificateFunc(config *tls.Config) error

	// SubscribeDenied registers a callback that is triggered everytime the denylist is updated.
	// This can be used to revalidate all certificates on long-lasting connections by calling CheckCRL on them again.
	SubscribeDenied(f func())
}

Validator is used to check the revocation status of certificates on the issuer controlled CRL and the user controlled Denylist. It does NOT manage trust and assumes all presented certificates belong to a trusted certificate tree.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL