| Commit message (Collapse) | Author | Age | Files | Lines | ||
|---|---|---|---|---|---|---|
| ... | ||||||
| | * | Add an exception for RUSTSEC-2024-0421 to fix CI. | Nick Mathewson | 2024-12-09 | 1 | -0/+9 | |
| |/ | ||||||
| * | Merge branch 'use-tpo-images' into 'main' | David Goulet | 2024-12-09 | 1 | -2/+4 | |
| |\ | | | | | | | | | Use TPA-maintained debian image See merge request tpo/core/arti!2656 | |||||
| | * | Use TPA-maintained debian image | Jim Newsome | 2024-12-04 | 1 | -2/+4 | |
| | | | | | | | | | | | | | This is primarily to reduce usage of our dockerhub pull quota. See https://gitlab.torproject.org/tpo/tpa/team/-/wikis/service/ci#tpa-maintained-images | |||||
| * | | Merge branch 'dev/cve/mit' into 'main' | Ian Jackson | 2024-12-05 | 1 | -1/+1 | |
| |\ \ | |/ |/| | | | | | meta: Update license year range to 2024 See merge request tpo/core/arti!2658 | |||||
| | * | meta: Update license year range to 2024 | Clara Engler | 2024-12-05 | 1 | -1/+1 | |
| |/ | ||||||
| * | Merge branch 'release_clarify_pages' into 'main' | Nick Mathewson | 2024-12-04 | 1 | -4/+27 | |
| |\ | | | | | | | | | Release.md: clarify some post-release steps See merge request tpo/core/arti!2614 | |||||
| | * | release: Clarify how to alert network-team and when. | Nick Mathewson | 2024-11-12 | 1 | -1/+10 | |
| | | | ||||||
| | * | Release.md: Add an "unfreeze the tree" step | Nick Mathewson | 2024-11-05 | 1 | -1/+4 | |
| | | | ||||||
| | * | Release.md: Add "email bekeela" step, with explanation. | Nick Mathewson | 2024-11-05 | 1 | -1/+7 | |
| | | | ||||||
| | * | Clarify "update pages branch" in the Release.md instructions. | Nick Mathewson | 2024-11-05 | 1 | -2/+7 | |
| | | | ||||||
| * | | Merge branch 'keymgr-certmgr' into 'main' | David Goulet | 2024-12-04 | 27 | -391/+1438 | |
| |\ \ | | | | | | | | | | | | | | | | | | | tor-keymgr: Add support for storing certificates Closes #1617 See merge request tpo/core/arti!2644 | |||||
| | * | | tor-keymgr: Replace internal error with keystore corruption error. | Gabriela Moldovan | 2024-12-04 | 2 | -1/+5 | |
| | | | | | | | | | | | | | | | | This replaces a placeholder error with a concrete `KeystoreCorruptionError` variant. | |||||
| | * | | tor-keymgr: Add tests for ArtiNativeKeystore's handling of certs. | Gabriela Moldovan | 2024-12-04 | 1 | -1/+29 | |
| | | | | ||||||
| | * | | tor-keymgr: Add support for certs in ArtiNativeKeystore::insert(). | Gabriela Moldovan | 2024-12-04 | 1 | -5/+8 | |
| | | | | ||||||
| | * | | tor-keymgr: Add support for certs in ArtiNativeKeystore::get(). | Gabriela Moldovan | 2024-12-04 | 1 | -8/+36 | |
| | | | | | | | | | | | | | | | | This makes `ArtiNativeKeystore::get` deserialize the keystore item as a cert, if its `KeystoreItemType` is `Cert`. | |||||
| | * | | tor-keymgr: Add arti native keystore helper for parsing tor certs. | Gabriela Moldovan | 2024-12-04 | 2 | -0/+42 | |
| | | | | | | | | | | | | | | | | We'll soon use this in `ArtiNativeKeystore`'s `Keystore` implementation for parsing certs read from disk. | |||||
| | * | | tor-keymgr: Add tests for the new cert mgmt functions. | Gabriela Moldovan | 2024-12-04 | 1 | -1/+172 | |
| | | | | ||||||
| | * | | tor-keymgr: s/TestKey/TestItem in tests. | Gabriela Moldovan | 2024-12-04 | 1 | -55/+55 | |
| | | | | | | | | | | | | | | | | We're about to reuse TestKey as our test key "certificate", so let's preemptively rename it to something more fitting. | |||||
| | * | | tor-keymgr: Add a test certificate specifier to test_utils. | Gabriela Moldovan | 2024-12-04 | 1 | -1/+34 | |
| | | | | | | | | | | | | | This is about to be used in a couple of places. | |||||
| | * | | tor-key-forge: Enable use of tor-cert experimental APIs. | Gabriela Moldovan | 2024-12-04 | 1 | -1/+1 | |
| | | | | ||||||
| | * | | tor-cert: Add constructor for creating an encoded cert from a byte slice. | Gabriela Moldovan | 2024-12-04 | 2 | -0/+18 | |
| | | | | | | | | | | | | | | | | | | | This adds an experimental API for creating an `EncodedEd25519Cert` from a byte slice. We will need this in `ArtiNativeKeystore` for deserializing the on-disk certs to `KeystoreItem`s. | |||||
| | * | | tor-key-forge: Export certificate-related types. | Gabriela Moldovan | 2024-12-04 | 1 | -0/+5 | |
| | | | | ||||||
| | * | | tor-keymgr: Note some breaking changes in semver.md. | Gabriela Moldovan | 2024-12-04 | 1 | -0/+3 | |
| | | | | ||||||
| | * | | tor-key-forge: Implement KeystoreItem::item_type. | Gabriela Moldovan | 2024-12-04 | 2 | -2/+9 | |
| | | | | ||||||
| | * | | tor-keymgr: s/key/item in error message test. | Gabriela Moldovan | 2024-12-04 | 2 | -2/+2 | |
| | | | | ||||||
| | * | | tor-key-forge: s/EncodableKey/EncodableItem in documentation. | Gabriela Moldovan | 2024-12-04 | 1 | -11/+11 | |
| | | | | ||||||
| | * | | tor-keymgr: Rename error variant. | Gabriela Moldovan | 2024-12-04 | 3 | -14/+13 | |
| | | | | ||||||
| | * | | tor-keymgr: Remove unused KeyType import. | Gabriela Moldovan | 2024-12-04 | 1 | -1/+1 | |
| | | | | ||||||
| | * | | tor-keymgr: Add KeyMgr::get_or_generate_key_and_cert. | Gabriela Moldovan | 2024-12-04 | 1 | -0/+119 | |
| | | | | ||||||
| | * | | tor-keymgr: Add KeyMgr::get_key_and_cert() (fmt). | Gabriela Moldovan | 2024-12-04 | 2 | -6/+11 | |
| | | | | ||||||
| | * | | tor-keymgr: Add KeyMgr::get_key_and_cert(). | Gabriela Moldovan | 2024-12-04 | 4 | -3/+98 | |
| | | | | ||||||
| | * | | tor-keymgr: Remove no-longer-needed explicit link targets. | Gabriela Moldovan | 2024-12-04 | 1 | -2/+2 | |
| | | | | | | | | | | | | | | | | These aren't needed anymore now that `KeySpecifierComponent` is in scope. | |||||
| | * | | tor-keymgr: Add helper for building certificate ArtiPaths. | Gabriela Moldovan | 2024-12-04 | 3 | -2/+130 | |
| | | | | | | | | | | | | | This will be used for looking up certificates in the keystore. | |||||
| | * | | tor-keymgr: Split some logic out of KeyMgr::get_from_store(). | Gabriela Moldovan | 2024-12-04 | 1 | -6/+24 | |
| | | | | | | | | | | | | | | | | We're soon going to need the "raw" version of the function (the one that returns the key as `K::Key`). | |||||
| | * | | tor-keymgr: Add variants for missing cert/signing key errors. | Gabriela Moldovan | 2024-12-04 | 1 | -0/+8 | |
| | | | | | | | | | | | | | | | | These will be soon be returned by `KeyMgr::{get_key_and_cert,get_or_generate_key_and_cert}`. | |||||
| | * | | tor-key-forge: Implement EncodableItem for Tor ed25519 certs. | Gabriela Moldovan | 2024-12-04 | 3 | -5/+20 | |
| | | | | | | | | | | | | | | | | This will enable us to store `tor_cert::EncodedEd25519Cert`s in the keystore. | |||||
| | * | | tor-keymgr: Replace as_ssh_key_data with as_keystore_item (fmt). | Gabriela Moldovan | 2024-12-04 | 4 | -4/+5 | |
| | | | | ||||||
| | * | | tor-keymgr: Replace as_ssh_key_data with as_keystore_item. | Gabriela Moldovan | 2024-12-04 | 6 | -39/+42 | |
| | | | | ||||||
| | * | | tor-key-forge: Add into_erased impl for KeystoreItem. | Gabriela Moldovan | 2024-12-04 | 1 | -1/+12 | |
| | | | | | | | | | | | | | This will be used by the `Keystore` implementations. | |||||
| | * | | tor-key-forge: Replace EncodableItem::key_type() with item_type() (fmt). | Gabriela Moldovan | 2024-12-04 | 1 | -2/+1 | |
| | | | | ||||||
| | * | | tor-key-forge: Replace EncodableItem::key_type() with item_type(). | Gabriela Moldovan | 2024-12-04 | 5 | -38/+34 | |
| | | | | | | | | | | | | | | | | This function now returns a `KeystoreItemType`, enabling us to represent certs as `EncodableItem`s. | |||||
| | * | | tor-keymgr: Update docs post-renaming. | Gabriela Moldovan | 2024-12-04 | 1 | -9/+9 | |
| | | | | ||||||
| | * | | tor-key-forge: Let declare_item_type macro generate the tests. | Gabriela Moldovan | 2024-12-04 | 1 | -32/+52 | |
| | | | | | | | | | | | | | | | | This enables us to auto-generate tests for all the supported key/cert file extensions. | |||||
| | * | | tor-keymgr: Replace KeyType with KeystoreItemType (fmt). | Gabriela Moldovan | 2024-12-04 | 7 | -21/+70 | |
| | | | | ||||||
| | * | | tor-keymgr: Remove now-unused import. | Gabriela Moldovan | 2024-12-04 | 1 | -1/+1 | |
| | | | | ||||||
| | * | | tor-key-forge: Remove no longer needed KeyType::Unknown variant. | Gabriela Moldovan | 2024-12-04 | 2 | -42/+3 | |
| | | | | | | | | | | | | | | | | Items that have an unrecognized file extension now get mapped to `KeystoreItemType::Unknown`. | |||||
| | * | | tor-keymgr: Replace KeyType with KeystoreItemType. | Gabriela Moldovan | 2024-12-04 | 9 | -148/+172 | |
| | | | | | | | | | | | | | | | | This is part of the work needed to support storing certificates in the keystore (they won't have a `KeyType`, but rather `CertType`). | |||||
| | * | | tor-key-forge: Export KeystoreItem. | Gabriela Moldovan | 2024-12-04 | 1 | -1/+1 | |
| | | | | ||||||
| | * | | tor-key-forge: Rename EncodableKey to EncodableItem. | Gabriela Moldovan | 2024-12-04 | 11 | -46/+46 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | This is the first step in replacing `EncodableKey` with the new `EncodableItem` trait (see doc/dev/keymgr-certificates.md). (this refactoring is split over multiple commits to make reviewing easier) | |||||
| | * | | tor-key-forge: Add a KeystoreItem type to replace SshKeyData. | Gabriela Moldovan | 2024-12-04 | 1 | -1/+22 | |
| | | | | | | | | | | | | | | | | | | | | | | The `EncodableKey` trait will soon be extended to support encoding certificates too (in addition to keys), so we need a type to represent an object that is either a key or a certificate (in other words, an encodable *item*). | |||||
