| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| | | | | | |
|
| |/ / / /
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Previously, arti's primary keystore was referred to as its "default"
keystore. However, "default" is inaccurate here: there is no way to
meaningfully override this "default" (the "default" store acts as the
main keystore). Throughout the codebase, we query all keystores for keys
(including the secondary ones), but only ever write to the
default/primary keystore. This is OK for now, because it enables us to
have one mutable keystore, and multiple secondary, read-only stores.
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Bug 1610: Add support for constructing ArtiEphemeralKeystore to InertTorClient::create_keymgr()
Closes #1610
See merge request tpo/core/arti!2394
|
| | | | | |
| | | | |
| | | | |
| | | | | |
InertTorClient::create_keymgr()
|
| | | | | | |
|
| | | | | | |
|
| | | | | | |
|
| | |/ / / |
|
| |\ \ \ \
| |/ / /
|/| | |
| | | |
| | | | |
Add CI job integration-chutney-shadow
See merge request tpo/core/arti!2427
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
We'll want this in the shadow-chutney test too.
No harm in just doing it for all jobs.
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
This is a wrapper script for running `tests/chutney/integration-e2e`
under shadow.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
Previously `tests/chutney/setup` would locate *or install* chutney and
set `CHUTNEY_PATH` for itself. However that `CHUTNEY_PATH` wasn't
propagated to other steps or "up" to the new `integration-e2e` wrapper
script.
Tracking it in the arti.run along with other dynamic info lets us ensure
we consistently use the same chutney across steps, and in the higher
level `integration-e2e` script.
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
It looks like it changed at some point. Rather than hard-coding,
just do the lookup locally and compare the tor-lookup result against
that.
|
| | |/ /
| | |
| | |
| | |
| | |
| | |
| | | |
Having this in a script is a step towards being able to run exactly the
same test under shadow without duplicating this high-level logic.
It's also convenient for running the ci test locally.
|
| |\ \ \
| | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
arti: Add hsc subcommands for key rotation and deletion
Closes #1475
See merge request tpo/core/arti!2435
|
| | | | |
| | | |
| | | |
| | | | |
Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2435#note_3080452
|
| | | | | |
|
| | | | | |
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | | |
This new feature is experimental.
|
| | | | |
| | | |
| | | |
| | | |
| | | |
| | | | |
By default `--key-type` is set to `restricted-discovery` so it can
omitted from these examples (omitting it makes the usage a bit clearer
IMO).
|
| | | | | |
|
| | | | | |
|
| | | | |
| | | |
| | | |
| | | | |
Closes #1475
|
| | | | |
| | | |
| | | |
| | | | |
Part of #1475
|
| | | | |
| | | |
| | | |
| | | |
| | | | |
This will be reused for `arti hsc key rotate`, which also outputs
the public key.
|
| | | | | |
|
| |\ \ \ \
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
key-forge: Add curve25519 key wrapper macro
Closes #1619
See merge request tpo/core/arti!2430
|
| |/ / / /
| | | |
| | | |
| | | |
| | | |
| | | | |
Closes #1619
Signed-off-by: David Goulet <[email protected]>
|
| |\ \ \ \
| |/ / /
|/| | |
| | | |
| | | | |
tor-key-forge: encapsulate `define_ed25519_keypair` macro dependencies
See merge request tpo/core/arti!2433
|
| | |/ /
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
This re-exports the types/traits needed by the `define_ed25519_keypair`
macro so that the macro caller doesn't need to import a bunch of extra
packages in its Cargo.toml that it doesn't use, and so that the caller
doesn't need a `use prelude::*` before invoking the macro. This makes
the macro nicer to use for the caller, and should prevent the macro from
causing "cannot find ... in this scope" errors.
|
| |\ \ \
| |/ /
|/| |
| | |
| | | |
arti: Add hsc key subcommand, deprecate hsc get-key.
See merge request tpo/core/arti!2432
|
| | | | |
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
I am deprecating the old `hsc get-key` subcommand in favor of the new
`hsc key get` subcommand. This is because I plan to implement the rest
of the key management functionality (key deletion, rotation, etc.) as
subcommands of the `hsc key` command. The alternative would be to add a
new distinct top-level `hsc rotate-key`, `hsc remove-key`, etc.
subcommand alongside the existing `hsc get-key` command (which IMO is
less nice than the alternative I'm proposing).
|
| | | |
| | |
| | |
| | | |
These will be reused by a future `key rotate` subcommand.
|
| | | |
| | |
| | |
| | |
| | | |
Otherwise, if/when we add support for other `KeyType`s we risk
forgetting to update the rest of the implementation.
|
| | | | |
|
| | | | |
|
| | | | |
|
| |/ /
| |
| |
| |
| | |
The client will be used by future subcommands too, not just
`prepare_service_discovery_key`.
|
| |\ \
| | |
| | |
| | |
| | |
| | |
| | | |
relay: Declare keys and add a KeyMgr to TorRelay
Closes #1604
See merge request tpo/core/arti!2411
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | | |
A relay can't operate without a KeyMgr so enable it by default from the
tor-keymgr crate.
Signed-off-by: David Goulet <[email protected]>
|
| | | |
| | |
| | |
| | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | |
| | |
| | |
| | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | |
| | |
| | |
| | | |
Signed-off-by: David Goulet <[email protected]>
|
| | | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | |
| | | |
When creating the KeyMgr, attempt to create the long-term identity key
if none are found in the KeyMgr.
Until the KeyMgr has certificate support, we can't create the
certificate. Add a TODO comment item about future work needed there.
Related to #1604
Signed-off-by: David Goulet <[email protected]>
|