| Commit message (Collapse) | Author | Age | Files | Lines | ||
|---|---|---|---|---|---|---|
| ... | ||||||
| | * | | | tor-keymgr: Make SshKeyData accessors more idiomatic. | Gabriela Moldovan | 2023-09-26 | 2 | -9/+11 | |
| | | | | | ||||||
| | * | | | tor-keymgr: Fix broken doc link. | Gabriela Moldovan | 2023-09-26 | 1 | -1/+1 | |
| | | | | | ||||||
| | * | | | tor-keymgr: Make SshKeyData non-exhaustive. | Gabriela Moldovan | 2023-09-26 | 1 | -1/+1 | |
| | | | | | | | | | | | | | | | | | | | | | We will need to add another variant to this when we add support for certificates. | |||||
| | * | | | tor-keymgr: Derive Clone, Debug for SshKeyData. | Gabriela Moldovan | 2023-09-26 | 1 | -1/+1 | |
| | |/ / | ||||||
| | * | | tor-keymgr: Rename as_ssh_keypair_data to as_ssh_key_data. | Gabriela Moldovan | 2023-09-26 | 3 | -8/+8 | |
| | | | | | | | | | | | | | | | | This function no longer returns `KeypairData` (it now returns `SshKeyData`). | |||||
| | * | | tor-keymgr: Add tests for OpenSSH public key parsing. | Gabriela Moldovan | 2023-09-26 | 5 | -0/+30 | |
| | | | | ||||||
| | * | | tor-keymgr: Use a macro to make the tests less repetitive. | Gabriela Moldovan | 2023-09-26 | 1 | -33/+45 | |
| | | | | ||||||
| | * | | tor-keymgr: Add TODO about rethinking KeyType. | Gabriela Moldovan | 2023-09-26 | 1 | -0/+8 | |
| | | | | ||||||
| | * | | tor-keymgr: Make parse_ssh_format_erased handle public keys too (fmt). | Gabriela Moldovan | 2023-09-26 | 1 | -8/+15 | |
| | | | | ||||||
| | * | | tor-keymgr: Make parse_ssh_format_erased handle public keys too. | Gabriela Moldovan | 2023-09-26 | 1 | -57/+5 | |
| | | | | | | | | | | | | | | | | This rewrites `KeyType::parse_ssh_format_erased` to use the new `parse_openssh!` macro. | |||||
| | * | | tor-keymgr: Add helpers for parsing OpenSSH public and private keys. | Gabriela Moldovan | 2023-09-26 | 1 | -0/+103 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | `KeyType::parse_ssh_format_erased` currently only handles private keys. The code for parsing public keys is very similar, so we introduce a macro to avoid code duplication. Note: the macro is currently unused (it will be used in a future commit). | |||||
| | * | | tor-keymgr: Implement ToEncodableKey for HsIdKey. | Gabriela Moldovan | 2023-09-25 | 1 | -3/+3 | |
| | | | | ||||||
| | * | | tor-keymgr: Implement EncodableKey for ed25519 public keys. | Gabriela Moldovan | 2023-09-25 | 1 | -3/+5 | |
| | | | | ||||||
| | * | | tor-keymgr: Implement EncodableKey for x25519 public keys. | Gabriela Moldovan | 2023-09-25 | 1 | -0/+26 | |
| | | | | ||||||
| | * | | tor-keymgr: Add KeyType variants for public keys. | Gabriela Moldovan | 2023-09-25 | 2 | -4/+15 | |
| | | | | ||||||
| | * | | tor-keymgr: Make EncodableKey support public keys too. | Gabriela Moldovan | 2023-09-25 | 4 | -22/+61 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, `EncodableKey::to_keypair_data` could only be used for encoding private keys (its return type was `KeypairData`). Now `EncodableKey::to_keypair_data` can return public key data (`KeyData`) too. Note: `to_keypair_data()` will be renamed in a future commit. | |||||
| | * | | tor-keymgr: Represent unparsed ssh key as strings. | Gabriela Moldovan | 2023-09-25 | 2 | -10/+10 | |
| |/ / | | | | | | | | | | | | | | | The underlying representation of an `UnparsedOpenSshKey` is now a `String`. This will make it easier to support storing public keys in the keystores: in the future, we will use `PublicKey::from_openssh` to parse public keys, and `PublicKey::from_openssh` expects a string slice (unlike `PrivateKey::from_openssh`, which takes a `&[u8]`). | |||||
| * | | Merge branch 'keymgr-curve25519-keypair' into 'main' | gabi-250 | 2023-09-25 | 17 | -56/+112 | |
| |\ \ | | | | | | | | | | | | | tor-hsclient, arti-client, tor-keymgr, tor-netdoc: Use a keypair instead of StaticSecret. See merge request tpo/core/arti!1617 | |||||
| | * | | tor-hsclient: Update HsClientSecretKeys docs. | Gabriela Moldovan | 2023-09-25 | 1 | -1/+1 | |
| | | | | ||||||
| | * | | tor-keymgr: Add (experimental) notices to semver.md | Gabriela Moldovan | 2023-09-25 | 1 | -6/+6 | |
| | | | | ||||||
| | * | | tor-llcrypto: Implement Clone and Debug for StaticKeypair. | Gabriela Moldovan | 2023-09-25 | 1 | -0/+11 | |
| | | | | ||||||
| | * | | tor-netdoc: Remove outdated note. | Gabriela Moldovan | 2023-09-25 | 1 | -4/+0 | |
| | | | | ||||||
| | * | | tor-hsclient, arti-client, tor-keymgr, tor-netdoc: Use a keypair instead of ↵ | Gabriela Moldovan | 2023-09-25 | 7 | -17/+17 | |
| | | | | | | | | | | | | | StaticSecret (fmt). | |||||
| | * | | tor-hsclient, arti-client, tor-keymgr, tor-netdoc: Use a keypair instead of ↵ | Gabriela Moldovan | 2023-09-25 | 13 | -45/+62 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | StaticSecret. Previously, when retrieving `KS_hsc_desc_enc` keys (or any other x25519 keys) from the keystore, the keymgr would discard the public part of the key (SSH private keys contain the public part of the key too). Instead of discarding the public key and returning just the `StaticSecret`, the keymgr now returns a `StaticKeypair`. This makes the x25519 `EncodableKey`/`ToEncodableKey` implementation consistent with the ed25519 one (which retrieves key pairs rather than "unescorted" secrets). | |||||
| | * | | tor-hsservice: Add HsClientDescEncKeypair. | Gabriela Moldovan | 2023-09-25 | 3 | -0/+22 | |
| | | | | ||||||
| | * | | tor-llcrypto: Add a type for x25519 StaticSecret/PublicKey keypairs. | Gabriela Moldovan | 2023-09-25 | 2 | -0/+10 | |
| |/ / | ||||||
| * | | Merge branch 'pad_intro2' into 'main' | Nick Mathewson | 2023-09-25 | 2 | -10/+45 | |
| |\ \ | |/ |/| | | | | | | | | | Accept and transmit padding in introduce2 plaintexts Closes #1031 See merge request tpo/core/arti!1602 | |||||
| | * | Generate padding in Introduce1 messages. | Nick Mathewson | 2023-09-18 | 1 | -7/+41 | |
| | | | | | | | | | | | | | Closes #1031. This padding ensures that the introduction point doesn't learn the length of the plaintext being sent to the onion service. | |||||
| | * | HSS: accept padding at the end of an introduce2 encrypted payload | Nick Mathewson | 2023-09-18 | 1 | -3/+4 | |
| | | | | | | | | | | | According to rend-spec, we intentionally accept and discard extra bytes here. | |||||
| * | | Merge branch 'publisher-keymgr' into 'main' | gabi-250 | 2023-09-22 | 10 | -78/+270 | |
| |\ \ | | | | | | | | | | | | | | | | | | | tor-hsservice: Make the descriptor publisher load keys from KeyMgr Closes #1042 See merge request tpo/core/arti!1615 | |||||
| | * | | tor-hsservice: Add TODO about MissingKeys errors. | Gabriela Moldovan | 2023-09-22 | 2 | -0/+31 | |
| | | | | ||||||
| | * | | tor-hsservice: Add semver.md file. | Gabriela Moldovan | 2023-09-22 | 1 | -0/+1 | |
| | | | | ||||||
| | * | | tor-hsservice: Make keys.rs a top-level module. | Gabriela Moldovan | 2023-09-22 | 5 | -5/+4 | |
| | | | | ||||||
| | * | | tor-hsservice: Make the caller of build_sign calculate `now()`. | Gabriela Moldovan | 2023-09-22 | 2 | -6/+7 | |
| | | | | ||||||
| | * | | tor-hsservice: Add TODO regarding the KeySpecifier::ctor_path()s of service ↵ | Gabriela Moldovan | 2023-09-22 | 1 | -0/+5 | |
| | | | | | | | | | | | | | keys. | |||||
| | * | | tor-hsservice: Use "hs" instead of "service" the ArtiPaths of services. | Gabriela Moldovan | 2023-09-22 | 1 | -1/+1 | |
| | | | | ||||||
| | * | | tor-hsservice: Add some derives for HsSvcKeySpecifier. | Gabriela Moldovan | 2023-09-22 | 1 | -0/+1 | |
| | | | | ||||||
| | * | | tor-hsservice: Remove unnecessary placeholder struct. | Gabriela Moldovan | 2023-09-22 | 1 | -15/+0 | |
| | | | | | | | | | | | | | | | | | | | This cert should've an Ed25519Cert anyway (but the descriptor publisher doesn't need to worry about the `intro_{auth, enc}_key_cert` certs because they will be generated internally by `HsDescBuilder`. | |||||
| | * | | tor-hsservice: Specify the expiry time for the intro_{auth, enc}_key_cert. | Gabriela Moldovan | 2023-09-22 | 2 | -5/+21 | |
| | | | | | | | | | | | | | | | | The certs are generated internally by `HsDescBuilder`. The publisher just needs to set their expiry. | |||||
| | * | | tor-hsservice: Remove unused keys module. | Gabriela Moldovan | 2023-09-22 | 2 | -35/+0 | |
| | | | | ||||||
| | * | | tor-hsservice: Make the publisher load keys from the keystore. | Gabriela Moldovan | 2023-09-22 | 2 | -15/+25 | |
| | | | | ||||||
| | * | | tor-hsservice: Add a helper for reading service keys from the keystore. | Gabriela Moldovan | 2023-09-22 | 2 | -2/+20 | |
| | | | | ||||||
| | * | | tor-hsservice: Support storing desc signing keys in the keystore. | Gabriela Moldovan | 2023-09-22 | 2 | -1/+22 | |
| | | | | ||||||
| | * | | tor-hsservice: Support storing HsIdKeys in the keystore. | Gabriela Moldovan | 2023-09-22 | 2 | -4/+41 | |
| | | | | ||||||
| | * | | tor-hscrypto: Reinstate HsDescSigningKey/HsDescSigningKeypair. | Gabriela Moldovan | 2023-09-22 | 1 | -2/+0 | |
| | | | | | | | | | | | | | We need it to sign descriptors. | |||||
| | * | | tor-hsservice: Add an error variant for key-not-found errors. | Gabriela Moldovan | 2023-09-22 | 1 | -0/+5 | |
| | | | | ||||||
| | * | | tor-hsservice: Add key specifier for blinded_id keypairs. | Gabriela Moldovan | 2023-09-22 | 4 | -1/+71 | |
| | | | | ||||||
| | * | | tor-hsservice: Return a ReactorError from build_sign. | Gabriela Moldovan | 2023-09-22 | 1 | -2/+2 | |
| | | | | | | | | | | | | | | | | | | | `build_sign` will soon be using the `KeyMgr` to look up keys, so we need to be able to propagate `KeystoreError`s (via the `ReactorError::KeyStore` variant). | |||||
| | * | | tor-hsservice: Add an error variant for keystore errors. | Gabriela Moldovan | 2023-09-22 | 1 | -1/+5 | |
| | | | | ||||||
| | * | | tor-hsservice: Give the publisher a reference to the key manager. | Gabriela Moldovan | 2023-09-22 | 3 | -8/+33 | |
| |/ / | ||||||
