summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
...
| * tor-hsservice: Add HsClientDescEncKeypair.Gabriela Moldovan2023-09-253-0/+22
| |
| * tor-llcrypto: Add a type for x25519 StaticSecret/PublicKey keypairs.Gabriela Moldovan2023-09-252-0/+10
|/
* Merge branch 'pad_intro2' into 'main'Nick Mathewson2023-09-252-10/+45
|\ | | | | | | | | | | | | Accept and transmit padding in introduce2 plaintexts Closes #1031 See merge request tpo/core/arti!1602
| * Generate padding in Introduce1 messages.Nick Mathewson2023-09-181-7/+41
| | | | | | | | | | | | Closes #1031. This padding ensures that the introduction point doesn't learn the length of the plaintext being sent to the onion service.
| * HSS: accept padding at the end of an introduce2 encrypted payloadNick Mathewson2023-09-181-3/+4
| | | | | | | | | | According to rend-spec, we intentionally accept and discard extra bytes here.
* | Merge branch 'publisher-keymgr' into 'main'gabi-2502023-09-2210-78/+270
|\ \ | | | | | | | | | | | | | | | | | | tor-hsservice: Make the descriptor publisher load keys from KeyMgr Closes #1042 See merge request tpo/core/arti!1615
| * | tor-hsservice: Add TODO about MissingKeys errors.Gabriela Moldovan2023-09-222-0/+31
| | |
| * | tor-hsservice: Add semver.md file.Gabriela Moldovan2023-09-221-0/+1
| | |
| * | tor-hsservice: Make keys.rs a top-level module.Gabriela Moldovan2023-09-225-5/+4
| | |
| * | tor-hsservice: Make the caller of build_sign calculate `now()`.Gabriela Moldovan2023-09-222-6/+7
| | |
| * | tor-hsservice: Add TODO regarding the KeySpecifier::ctor_path()s of service ↵Gabriela Moldovan2023-09-221-0/+5
| | | | | | | | | | | | keys.
| * | tor-hsservice: Use "hs" instead of "service" the ArtiPaths of services.Gabriela Moldovan2023-09-221-1/+1
| | |
| * | tor-hsservice: Add some derives for HsSvcKeySpecifier.Gabriela Moldovan2023-09-221-0/+1
| | |
| * | tor-hsservice: Remove unnecessary placeholder struct.Gabriela Moldovan2023-09-221-15/+0
| | | | | | | | | | | | | | | | | | This cert should've an Ed25519Cert anyway (but the descriptor publisher doesn't need to worry about the `intro_{auth, enc}_key_cert` certs because they will be generated internally by `HsDescBuilder`.
| * | tor-hsservice: Specify the expiry time for the intro_{auth, enc}_key_cert.Gabriela Moldovan2023-09-222-5/+21
| | | | | | | | | | | | | | | The certs are generated internally by `HsDescBuilder`. The publisher just needs to set their expiry.
| * | tor-hsservice: Remove unused keys module.Gabriela Moldovan2023-09-222-35/+0
| | |
| * | tor-hsservice: Make the publisher load keys from the keystore.Gabriela Moldovan2023-09-222-15/+25
| | |
| * | tor-hsservice: Add a helper for reading service keys from the keystore.Gabriela Moldovan2023-09-222-2/+20
| | |
| * | tor-hsservice: Support storing desc signing keys in the keystore.Gabriela Moldovan2023-09-222-1/+22
| | |
| * | tor-hsservice: Support storing HsIdKeys in the keystore.Gabriela Moldovan2023-09-222-4/+41
| | |
| * | tor-hscrypto: Reinstate HsDescSigningKey/HsDescSigningKeypair.Gabriela Moldovan2023-09-221-2/+0
| | | | | | | | | | | | We need it to sign descriptors.
| * | tor-hsservice: Add an error variant for key-not-found errors.Gabriela Moldovan2023-09-221-0/+5
| | |
| * | tor-hsservice: Add key specifier for blinded_id keypairs.Gabriela Moldovan2023-09-224-1/+71
| | |
| * | tor-hsservice: Return a ReactorError from build_sign.Gabriela Moldovan2023-09-221-2/+2
| | | | | | | | | | | | | | | | | | `build_sign` will soon be using the `KeyMgr` to look up keys, so we need to be able to propagate `KeystoreError`s (via the `ReactorError::KeyStore` variant).
| * | tor-hsservice: Add an error variant for keystore errors.Gabriela Moldovan2023-09-221-1/+5
| | |
| * | tor-hsservice: Give the publisher a reference to the key manager.Gabriela Moldovan2023-09-223-8/+33
|/ /
* | Merge branch 'launch_onion_service' into 'main'Nick Mathewson2023-09-213-72/+105
|\ \ | | | | | | | | | | | | hsservice: Improve OnionService APIs See merge request tpo/core/arti!1616
| * | hss: Un-parameterize OnionService.Nick Mathewson2023-09-211-20/+31
| | |
| * | publish: note a possible behavior change on launch().Nick Mathewson2023-09-211-0/+4
| | |
| * | hss: remove an "#[allow(...)]".Nick Mathewson2023-09-211-2/+0
| | |
| * | hss: adjust members of OnionService type.Nick Mathewson2023-09-212-23/+13
| | |
| * | hss: fix error return from OnionService::launch()Nick Mathewson2023-09-212-1/+13
| | |
| * | hss: start filling in a "launch" function for OnionService.Nick Mathewson2023-09-212-39/+57
|/ /
* | Merge branch 'publisher-launch-fn' into 'main'gabi-2502023-09-213-31/+59
|\ \ | | | | | | | | | | | | | | | | | | tor-hsservice: Give the descriptor publisher a separate launch function. Closes #1042 See merge request tpo/core/arti!1608
| * | tor-hsservice: Update Publisher::new docs.Gabriela Moldovan2023-09-211-1/+3
| | |
| * | tor-hsservice: Add must_use for Publisher::launch.Gabriela Moldovan2023-09-211-0/+1
| | |
| * | tor-hsservice: Remove outdated TODO.Gabriela Moldovan2023-09-211-1/+0
| | |
| * | tor-hsservice: Give the descriptor publisher a separate launch function.Gabriela Moldovan2023-09-213-28/+54
|/ / | | | | | | | | | | | | | | | | | | | | This also makes `Publisher::new` synchronous. If `Reactor::new` fails, `Publisher::launch` propagates the error to its caller (to achieve this, I had to give `PublisherError` a new `ReactorLaunch` variant and make `ReactorError` and `UploadError` crate-public). Closes #1042
* | Merge branch 'intro_rend' into 'main'Nick Mathewson2023-09-218-91/+255
|\ \ | | | | | | | | | | | | HSS: Route necessary material into RendRequest See merge request tpo/core/arti!1610
| * | hs_ntor: replace "32" with a const.Nick Mathewson2023-09-211-1/+1
| | |
| * | hs_ntor: rename get_{introduce,rendezvous}1_key_material.Nick Mathewson2023-09-211-6/+6
| | |
| * | hs_ntor: improve several comments.Nick Mathewson2023-09-211-3/+10
| | |
| * | hs_ntor: rename enc_key to dec_key in service code.Nick Mathewson2023-09-211-5/+5
| | |
| * | hs_ntor: allow attempting handshake with a set of subcredentials.Nick Mathewson2023-09-203-43/+53
| | | | | | | | | | | | | | | | | | | | | Since we are using the same introduction point circuits for multiple time periods, we need the ability to provide a set of subcredentials and see which of them acually works. Fortunately, we "only" have to do digest operations here, which are much faster than public key.
| * | hs_ntor: Take our k_hss_ntor keypair explicitly.Nick Mathewson2023-09-203-20/+24
| | |
| * | HSS: Enable RendRequests to be answered.Nick Mathewson2023-09-205-25/+79
| | | | | | | | | | | | | | | This requires yet more plumbing—this time, of HsCircPool and NetDirProvider.
| * | hss: Minor hack to avoid parameterizing RendRequestContext on RuntimeNick Mathewson2023-09-201-2/+29
| | | | | | | | | | | | | | | We need to pass around an Arc<HsCircPool<R>>, but doing so directly would force us to make RendRequestContext parameterized on R.
| * | HSS: route most necessary key material to RendRequestNick Mathewson2023-09-203-15/+77
| | | | | | | | | | | | | | | | | | | | | | | | | | | When we go to answer a RendRequest, we need to have a few objects present. This commit makes sure that they're available at the right places. We also note a significant problem with the need for a Subcredential here.
* | | Merge branch 'slow-test' into 'main'Nick Mathewson2023-09-201-1/+2
|\ \ \ | | | | | | | | | | | | | | | | tor-hsclient: state expiry test: Use MockSleepProvider advance See merge request tpo/core/arti!1609
| * | | tor-hsclient: state expiry test: Use MockSleepProvider advanceIan Jackson2023-09-201-1/+2
| | | | | | | | | | | | | | | | | | | | See https://gitlab.torproject.org/tpo/core/arti/-/issues/1040