| Commit message (Collapse) | Author | Age | Files | Lines |
| ... | |
| |/ / / / /
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | |
| | | | | |
Upstream `ssh-key` is missing some important features we need for
arti-relay:
* a bug fix without which we can't convert deserialized RSA keys to
their rsa counterparts: https://github.com/RustCrypto/SSH/pull/318
* @wesleyac 's patch https://github.com/RustCrypto/SSH/pull/412 for
allowing insecure (1024 bits long) RSA keys (needed because the
relay KS_relayid_rsa identity keys are 1024 bits long)
We plan to switch back to mainline `ssh-key` when `ssh-key 0.7.0` comes
out.
See the discussion in #2398 for more details.
|
| |\ \ \ \ \
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
proto: Add more logging to the new circuit reactors
See merge request tpo/core/arti!3776
|
| | | | | | | |
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
Fix various typos
See merge request tpo/core/arti!3781
|
| | | | | | | | |
|
| | | | | | | | |
|
| |\ \ \ \ \ \ \
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
RPC: Provide superuser mode
Closes #2285
See merge request tpo/core/arti!3743
|
| | | | | | | | | |
|
| | | | | | | | | |
|
| | | | | | | | | |
|
| | | | | | | | | |
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This is not exactly the most _urgent_ superuser functionality,
but it is probably the easiest to implement.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
When connection point provides superuser support, provide a
(currently inert) RpcSuperuser object to the RPC session.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
Currently does nothing.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
This makes it a little easier to drop unwanted capabilities.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
The Connection will know the options that the listener was created
with, as opposed to RpcMgr, which is the same for every listener.
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
(For now, the su capability doesn't actually do anything,
and there is no ability to actually have a session start with one.)
|
| |\ \ \ \ \ \ \ \
| |_|/ / / / / /
|/| | | | | | |
| | | | | | | |
| | | | | | | | |
arti-rpc-client-core: Fix windows build
See merge request tpo/core/arti!3780
|
| | | | | | | | |
| | | | | | | |
| | | | | | | |
| | | | | | | | |
Disable use-statements which are only needed for unix.
|
| |/ / / / / / /
| | | | | | |
| | | | | | |
| | | | | | | |
Fix a typo in use-statement for windows.
|
| |\ \ \ \ \ \ \
| |/ / / / / /
|/| | | | | |
| | | | | | |
| | | | | | | |
proto: Move criterion-cycles-per-byte to dev-dependencies
See merge request tpo/core/arti!3778
|
| |/ / / / / /
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
This may help fix our CI cross compilation tests on platforms
without a C compiler install. In any case, it may speed up non-test
builds by a tiny bit.
Possible solution for #2366.
|
| |\ \ \ \ \ \
| |/ / / / /
|/| | | | |
| | | | | |
| | | | | | |
shadow ci: keep going after first failure
See merge request tpo/core/arti!3766
|
| | | | | | |
| | | | | |
| | | | | |
| | | | | | |
It can be useful to see the outcome of the other tests/analysis.
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
arti-relay: Log relay identities
See merge request tpo/core/arti!3773
|
| | | | | | | | |
|
| |\ \ \ \ \ \ \
| |/ / / / / /
|/| | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
keymgr: New `CertSpecifier` macro and cert APIs
Closes #2376
See merge request tpo/core/arti!3770
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This tests that the `KeyMgr` returns an error if you try to retrieve an
invalid cert.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This is a bit of a hack, but we need it to make the tests pass.
The issue is that our test keystore stores `TestItem`s, and all our
other test used `TestItem` as their key types. Now that we have certs,
we have this concept of a `ToEncodableCert::ParsedCert`, which is what
the keymgr downcasts the retrieved certs to before validating them and
returning the final cert result (which is usually going to be of a
different type than `ParsedCert`).
This wrapper ensures that the keystore returns the expected `ParsedCert`
type, so that validation doesn't fail.
Before this change, we were hackily returning `TestItem` in the tests,
even for certificates, but that doesn't work anymore, because the
`ItemType` impl of `TestItem` returns `KeyType::Ed25519Keypair`, which
is obviously not a `CertType`. Using it resulted in an error because
there is a mismatch between the cert `ItemType` (`Ed25519Keypair`) and
the `ItemType` of the `KeystoreItem::Cert` entry (`Ed25519TorCert`).
Normally this wouldn't happen, but the whole test keystore
implementation is funky and inconsistent.
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This will enable us to test against other keymgr APIs (e.g.
`list_matching()`), which require some extra trait impls that get
generated for free by our new `CertSpecifier` macro.
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This will soon be used by other tests too.
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
For relays these are pretty basic (they have no globbing components),
because relay certs don't have specifiers (their `ArtiPath`s are
identical to the `ArtiPath` of the subject key).
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This will enable us to retrieve a cert given its `KeystoreEntry`. This
is useful for retrieving certificates listed with
`KeyMgr::list_matching()`.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This was replaced by the new `CertSpecifier` d-d macro.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This enables the `experimental-api` feature in `tor-keymgr` because
`CertSpecifier` is experimental.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This will replace the `has_certificate()` attr from the
`KeySpecifier` d-d macro.
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
This will soon be used for parsing the denotators of cert paths too.
|
| | | | | | | | |
|
| | | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
We need to be able to parse KeyPaths into KeyCertificateSpecifier,
and we can't do that if the signing key is part of the cert specifier
(because the signing key doesn't get encoded in the key path, unlike the
subject key, which does)
|
| |/ / / / / /
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
These are significantly different from `KeySpecifierPattern`s, so it's
best to have a separate trait.
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
tor-netdir: Add spec link to flag descriptions
See merge request tpo/core/arti!3768
|
| | | |/ / / /
| |/| | | | |
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
cert-x509: Generate TLS certs with RSA2048 subject keys
Closes #2403
See merge request tpo/core/arti!3769
|
| |/ / / / / /
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | |
| | | | | | |
We'd rather use p256, but unfortunately C tor has a bug when TLS
cert subject keys are not RSA: see tor#41226.
Closes #2403.
|
| |\ \ \ \ \ \
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | | |
tor-dirclient: Attempt to explain AnonymizedRequest
See merge request tpo/core/arti!3767
|
| | | | | | | | |
|
| | |/ / / / / |
|