aboutsummaryrefslogtreecommitdiff
path: root/crates/tor-netdoc/src/doc/authcert.rs
Commit message (Collapse)AuthorAgeFilesLines
...
* tor-netdoc: authcert: Provide encoding and signing methodIan Jackson2026-04-011-1/+26
|
* tor-netdoc: Provide `new` methods for CrossCert and AuthCertIan Jackson2026-04-011-0/+60
|
* tor-netdoc: Turn AuthCertSignature into RsaSignatureIan Jackson2026-04-011-24/+7
| | | | | | | | These are in fact just a completely normal RSA signature like in the spec! Move the type to the types module, and rename it. Leave a compatibility alias.
* tor-netdoc: derive enncoding for AuthCert, AuthCertSignature[s]Ian Jackson2026-04-011-2/+5
|
* tor-netdoc: Move raw_data_object to new container moduleIan Jackson2026-04-011-1/+1
| | | | This will allow us to use it for encoding as well as parsing.
* tor-netdoc: impl encoding traits for authcert cross-cert typesIan Jackson2026-04-011-1/+19
|
* tor-netdoc: authcert: Debug CrossCertObject in hexIan Jackson2026-04-011-1/+3
|
* tor-netdoc: Constructor: Fix it so it actually worksIan Jackson2026-04-011-2/+2
| | | | | | The hidden __non_exhaustive field has to be pub. And, fix the use site, currently AuthCert.
* tor-netdoc: Rename `AuthCertUnverified::verify_self_signed`Ian Jackson2026-03-311-15/+15
| | | | | | | | | | | This method verifies all the signatures, and checks that the signing authority is in the provided list. Anyway, authcerts aren't really self-signed: they're a signature by KS_auth_id_rsa on KP_auth_sign_rsa. Note that there is also a `verify_selfcert` method which does only some of the checks, and has some code duplication. That will be cleaned up later.
* tor-netdoc: Apply deferred rustfmt churn to importsIan Jackson2026-03-191-1/+3
|
* tor-netdoc: authcert test: Avoid using NetdocParseable for AuthCertIan Jackson2026-03-191-3/+4
| | | | | | | | | We want to stop deriving NetdocParseable directly for body structs. This test case does in fact parse a signed authcert and extract just the body without verifying the signatures. That's fine in a test, but we're going to make it involve some hoop-jumping. So, jump those hoops.
* tor-netdoc: parse2: Unify top-level derive as NetdocUParseablenverifiedIan Jackson2026-03-191-1/+1
| | | | | | | | | | | | | | | | Replace the two separate NetdocParseable and NetdocUnverified derives, for toplevel signed documents, with a single derive. This makes the derive API simpler. It will also make it reasonably possible to avoid deriving NetdocParseable directly for body structs. Such impls are a security hazard! In detail: * Rename NetdocUnverified to NetdocParseableUnverified * Have it use $IMPL_NETDOC_PARSEABLE from the NetdocParseable deftly module so that it derives NetdocParseable for the body. (We'll change this later in the series.) * Adjust the docs and all call sites.
* tor-netdoc: parse2: Move hash out of signature itemsIan Jackson2026-03-191-7/+4
| | | | | | | | | | During encoding, including these hashes in the signature items makes no sense. The hashes are an *input* to the signature items, but not part of them. Move the hashes out of the items. Instead, provide each signatures section type with a hash accumulator type, in which the hash(es) are stored.
* tor-netdoc: parse2: Introduce SignatureData structIan Jackson2026-03-191-3/+3
| | | | This is going to contain body information, and the hashes, too.
* tor-netdoc: NetdocParseableSignatures: Make into its own macroIan Jackson2026-03-191-2/+1
| | | | | | This is going to be its own trait and it is usually best if macros are named after traits, rather than having the macro derive a different trait depending on meta attributes.
* tor-netdoc: Apply rustfmt churnIan Jackson2026-03-031-7/+2
|
* tor-netdoc: Rename *Signed to *UnverifiedIan Jackson2026-03-031-8/+8
| | | | | | | | | | This was a weird name, and while working in this area it all seemed to make the docs strange. Rename it. This is quite invasive! In theory we could have the macros generate compatibility aliases, but that seems quite complex.
* tor-netdoc: Drop dir_auth_key_cert_signatures test caseIan Jackson2026-03-031-56/+1
| | | | | | | | | | | | | | This test case constructs a "netdoc" which consists of one dir-key-certification item, and parses it using `AuthCertSignatures as NetdocParseable`. But we're going to split out the parsing trait for signatures sections, so that's not going to work any more. This test tests only corner cases of the derived SignatureItemParseable implementation; but that's unit tested in the parse2 tests. (Once upon a time there was perhaps manual parsing code which needed a specific test.) Remove it.
* tor-netdoc: EncodedAuthCert: bodge the features for nowIan Jackson2026-01-151-2/+3
| | | | | The feature arrangements in tor-netdoc are getting to be in need of a serious overhaul.
* tor-netdoc: EncodedAuthCert: implementIan Jackson2026-01-151-0/+5
| | | | As per doc/dev/notes/authcert-in-consensus.md.
* tor-netdoc: constructors: Use manual non exhaustiveIan Jackson2026-01-141-2/+8
| | | | With `#[non_exhaustive]`, you're not allowed to write even `Thing { ..base }`.
* tor-netdoc: Remove TODO re AuthCert constructionIan Jackson2026-01-131-2/+0
|
* tor-netdoc: Deprecate AuthCertBuilderIan Jackson2026-01-131-0/+3
|
* tor-netdoc: Provide AuthCertConstructorIan Jackson2026-01-131-0/+10
|
* tor-netdoc: Fix an attribute position in AuthCertIan Jackson2026-01-131-1/+1
| | | | The compiler doesn't notice this, but it's odd.
* tor-netdoc: authcert: Fix wrong linkIan Jackson2026-01-061-1/+1
|
* tor-netdoc: authcert: Add TODO about constructorsIan Jackson2026-01-061-0/+2
|
* tor-netdoc: authcert: rustfmtIan Jackson2026-01-061-5/+5
|
* tor-netdoc: authcert: Delete syntax info from rustdocsIan Jackson2026-01-061-37/+2
| | | | | This is in the spec. I don't think it is a great idea to duplicate it here.
* tor-netdoc: authcert: Fix remaining old names/paths in docsIan Jackson2026-01-061-8/+8
| | | | | These names came from tmp, and we renamed things as we went, but didn't change the docs everywhere.
* tor-netdoc: authcert: Improve docs for CrossCertIan Jackson2026-01-061-13/+12
| | | | Fix the type names while we're here.
* tor-netdoc: authcert: rename tmp test moduleIan Jackson2026-01-061-1/+1
| | | | This module is now the "proper" tests for the parse2 impl on AuthCert.
* tor-netdoc: authcert: abolish tmp module (reindent)Ian Jackson2026-01-061-50/+50
|
* tor-netdoc: authcert: abolish tmp moduleIan Jackson2026-01-061-140/+14
| | | | | | | | | | | tmp's version of AuthCert is gone. Each of its fields is already in AuthCert, including the docs links. I've decided not to transfer the syntax snippets. The remaining function in that module is now an inherent method on AuthCert, not on tmp's version. This needs reformatting since verify_self_signed is now at the wrong level!
* tor-netdoc: authcert: derive PartialEq and Eq in testsIan Jackson2026-01-061-0/+1
| | | | | It's not clear that we want to expose these impls, but our existing tests (in test::tmp) want them.
* tor-netdoc: authcert: Transfer spec links into AuthCert from tmpIan Jackson2026-01-061-28/+14
|
* tor-netdoc: authcert: derive parse2Ian Jackson2026-01-061-1/+12
|
* tor-netdoc: authcert: Add CrossCert to AuthCertIan Jackson2026-01-061-1/+12
| | | | This will enable parse2 to process it.
* tor-netdoc: authcert: Move signatures out of tmp (fmt)Ian Jackson2026-01-061-2/+2
|
* tor-netdoc: authcert: Move signatures out of tmpIan Jackson2026-01-061-68/+79
|
* tor-netdoc: authcert: Move CrossCert out of tmpIan Jackson2026-01-061-86/+97
| | | | | | | | We can call this type authcert::CrossCert. The names in the docs are getting rather wrong, and right now the docs build produces warnings. We'll tidy all that at the end after we're done moving and renaming.
* tor-netdoc: authcert: Rename verify_selfcert to verify_self_signedIan Jackson2026-01-061-14/+14
| | | | | | The distinction is: `verify_selfcert` sounds like it only verifies the self certificate. `veriify_self_signed` completely verifies a document, albeit one that is expected to be self-signed.
* tor-netdoc: authcert: Move AuthCertVersion out of tmpIan Jackson2026-01-061-19/+29
| | | | | Let's keep the existing name `AuthCert` in authcert.rs, so we want to rename this from DirKeyCertificateVersion, while we move it.
* tor-netdoc: authcert: Make all fields pubIan Jackson2026-01-061-7/+7
| | | | This is our new style. Now there's no known-dead code.
* tor-netdoc: authcert: Use Iso8601TimeSp for time fieldsIan Jackson2026-01-061-9/+7
| | | | This will let the parse2 derive work properly.
* tor-netdoc: authcert: Shuffle fingerprint values aboutIan Jackson2026-01-061-11/+9
| | | | | | | | | Make AuthCert look like the network document. This means removing its stored copy of H(KP_auth_sign_rsa), which it previously had via the embedded AuthCertKeyIds. We reculculate it as needed in AuthCert::key_ids().
* tor-netdoc: authcert: Abolish AuthCert::sk_fingerprintIan Jackson2026-01-061-6/+1
| | | | There are no in-tree callers.
* tor-netdoc: authcert: Make key_ids return owned AuthCertKeyIdsIan Jackson2026-01-061-2/+2
| | | | | AuthCert is about to lose its copy of H(KP_auth_sign_rsa) so it needs to return an owned value.
* tor-netdoc: RSA: rename helper type to RsaPublicParse1HelperIan Jackson2026-01-061-3/+3
| | | | | | This is used by the old parsing code, apparently as a thing to hang the checking methods off. It is confusing to have so many different RSA types! Let's at least rename this one.
* tor-netdoc: authcert: Improve docs a bitIan Jackson2026-01-061-5/+12
| | | | Spec links from the tmp module will be added later.