summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
* | | tor-keymgr: Represent unparsed ssh key as strings.Gabriela Moldovan2023-09-252-10/+10
|/ / | | | | | | | | | | | | | | The underlying representation of an `UnparsedOpenSshKey` is now a `String`. This will make it easier to support storing public keys in the keystores: in the future, we will use `PublicKey::from_openssh` to parse public keys, and `PublicKey::from_openssh` expects a string slice (unlike `PrivateKey::from_openssh`, which takes a `&[u8]`).
* | tor-hsclient: Update HsClientSecretKeys docs.Gabriela Moldovan2023-09-251-1/+1
| |
* | tor-keymgr: Add (experimental) notices to semver.mdGabriela Moldovan2023-09-251-6/+6
| |
* | tor-llcrypto: Implement Clone and Debug for StaticKeypair.Gabriela Moldovan2023-09-251-0/+11
| |
* | tor-netdoc: Remove outdated note.Gabriela Moldovan2023-09-251-4/+0
| |
* | tor-hsclient, arti-client, tor-keymgr, tor-netdoc: Use a keypair instead of ↵Gabriela Moldovan2023-09-257-17/+17
| | | | | | | | StaticSecret (fmt).
* | tor-hsclient, arti-client, tor-keymgr, tor-netdoc: Use a keypair instead of ↵Gabriela Moldovan2023-09-2513-45/+62
| | | | | | | | | | | | | | | | | | | | | | | | | | StaticSecret. Previously, when retrieving `KS_hsc_desc_enc` keys (or any other x25519 keys) from the keystore, the keymgr would discard the public part of the key (SSH private keys contain the public part of the key too). Instead of discarding the public key and returning just the `StaticSecret`, the keymgr now returns a `StaticKeypair`. This makes the x25519 `EncodableKey`/`ToEncodableKey` implementation consistent with the ed25519 one (which retrieves key pairs rather than "unescorted" secrets).
* | tor-hsservice: Add HsClientDescEncKeypair.Gabriela Moldovan2023-09-253-0/+22
| |
* | tor-llcrypto: Add a type for x25519 StaticSecret/PublicKey keypairs.Gabriela Moldovan2023-09-252-0/+10
| |
* | Merge branch 'pad_intro2' into 'main'Nick Mathewson2023-09-252-10/+45
|\ \ | |/ |/| | | | | | | | | Accept and transmit padding in introduce2 plaintexts Closes #1031 See merge request tpo/core/arti!1602
| * Generate padding in Introduce1 messages.Nick Mathewson2023-09-181-7/+41
| | | | | | | | | | | | Closes #1031. This padding ensures that the introduction point doesn't learn the length of the plaintext being sent to the onion service.
| * HSS: accept padding at the end of an introduce2 encrypted payloadNick Mathewson2023-09-181-3/+4
| | | | | | | | | | According to rend-spec, we intentionally accept and discard extra bytes here.
* | tor-hsservice: Add TODO about MissingKeys errors.Gabriela Moldovan2023-09-222-0/+31
| |
* | tor-hsservice: Add semver.md file.Gabriela Moldovan2023-09-221-0/+1
| |
* | tor-hsservice: Make keys.rs a top-level module.Gabriela Moldovan2023-09-225-5/+4
| |
* | tor-hsservice: Make the caller of build_sign calculate `now()`.Gabriela Moldovan2023-09-222-6/+7
| |
* | tor-hsservice: Add TODO regarding the KeySpecifier::ctor_path()s of service ↵Gabriela Moldovan2023-09-221-0/+5
| | | | | | | | keys.
* | tor-hsservice: Use "hs" instead of "service" the ArtiPaths of services.Gabriela Moldovan2023-09-221-1/+1
| |
* | tor-hsservice: Add some derives for HsSvcKeySpecifier.Gabriela Moldovan2023-09-221-0/+1
| |
* | tor-hsservice: Remove unnecessary placeholder struct.Gabriela Moldovan2023-09-221-15/+0
| | | | | | | | | | | | This cert should've an Ed25519Cert anyway (but the descriptor publisher doesn't need to worry about the `intro_{auth, enc}_key_cert` certs because they will be generated internally by `HsDescBuilder`.
* | tor-hsservice: Specify the expiry time for the intro_{auth, enc}_key_cert.Gabriela Moldovan2023-09-222-5/+21
| | | | | | | | | | The certs are generated internally by `HsDescBuilder`. The publisher just needs to set their expiry.
* | tor-hsservice: Remove unused keys module.Gabriela Moldovan2023-09-222-35/+0
| |
* | tor-hsservice: Make the publisher load keys from the keystore.Gabriela Moldovan2023-09-222-15/+25
| |
* | tor-hsservice: Add a helper for reading service keys from the keystore.Gabriela Moldovan2023-09-222-2/+20
| |
* | tor-hsservice: Support storing desc signing keys in the keystore.Gabriela Moldovan2023-09-222-1/+22
| |
* | tor-hsservice: Support storing HsIdKeys in the keystore.Gabriela Moldovan2023-09-222-4/+41
| |
* | tor-hscrypto: Reinstate HsDescSigningKey/HsDescSigningKeypair.Gabriela Moldovan2023-09-221-2/+0
| | | | | | | | We need it to sign descriptors.
* | tor-hsservice: Add an error variant for key-not-found errors.Gabriela Moldovan2023-09-221-0/+5
| |
* | tor-hsservice: Add key specifier for blinded_id keypairs.Gabriela Moldovan2023-09-224-1/+71
| |
* | tor-hsservice: Return a ReactorError from build_sign.Gabriela Moldovan2023-09-221-2/+2
| | | | | | | | | | | | `build_sign` will soon be using the `KeyMgr` to look up keys, so we need to be able to propagate `KeystoreError`s (via the `ReactorError::KeyStore` variant).
* | tor-hsservice: Add an error variant for keystore errors.Gabriela Moldovan2023-09-221-1/+5
| |
* | tor-hsservice: Give the publisher a reference to the key manager.Gabriela Moldovan2023-09-223-8/+33
| |
* | hss: Un-parameterize OnionService.Nick Mathewson2023-09-211-20/+31
| |
* | publish: note a possible behavior change on launch().Nick Mathewson2023-09-211-0/+4
| |
* | hss: remove an "#[allow(...)]".Nick Mathewson2023-09-211-2/+0
| |
* | hss: adjust members of OnionService type.Nick Mathewson2023-09-212-23/+13
| |
* | hss: fix error return from OnionService::launch()Nick Mathewson2023-09-212-1/+13
| |
* | hss: start filling in a "launch" function for OnionService.Nick Mathewson2023-09-212-39/+57
| |
* | tor-hsservice: Update Publisher::new docs.Gabriela Moldovan2023-09-211-1/+3
| |
* | tor-hsservice: Add must_use for Publisher::launch.Gabriela Moldovan2023-09-211-0/+1
| |
* | tor-hsservice: Remove outdated TODO.Gabriela Moldovan2023-09-211-1/+0
| |
* | tor-hsservice: Give the descriptor publisher a separate launch function.Gabriela Moldovan2023-09-213-28/+54
| | | | | | | | | | | | | | | | | | | | | | This also makes `Publisher::new` synchronous. If `Reactor::new` fails, `Publisher::launch` propagates the error to its caller (to achieve this, I had to give `PublisherError` a new `ReactorLaunch` variant and make `ReactorError` and `UploadError` crate-public). Closes #1042
* | Merge branch 'intro_rend' into 'main'Nick Mathewson2023-09-218-91/+255
|\ \ | | | | | | | | | | | | HSS: Route necessary material into RendRequest See merge request tpo/core/arti!1610
| * | hs_ntor: replace "32" with a const.Nick Mathewson2023-09-211-1/+1
| | |
| * | hs_ntor: rename get_{introduce,rendezvous}1_key_material.Nick Mathewson2023-09-211-6/+6
| | |
| * | hs_ntor: improve several comments.Nick Mathewson2023-09-211-3/+10
| | |
| * | hs_ntor: rename enc_key to dec_key in service code.Nick Mathewson2023-09-211-5/+5
| | |
| * | hs_ntor: allow attempting handshake with a set of subcredentials.Nick Mathewson2023-09-203-43/+53
| | | | | | | | | | | | | | | | | | | | | Since we are using the same introduction point circuits for multiple time periods, we need the ability to provide a set of subcredentials and see which of them acually works. Fortunately, we "only" have to do digest operations here, which are much faster than public key.
| * | hs_ntor: Take our k_hss_ntor keypair explicitly.Nick Mathewson2023-09-203-20/+24
| | |
| * | HSS: Enable RendRequests to be answered.Nick Mathewson2023-09-205-25/+79
| | | | | | | | | | | | | | | This requires yet more plumbing—this time, of HsCircPool and NetDirProvider.