| Commit message (Collapse) | Author | Age | Files | Lines | ||
|---|---|---|---|---|---|---|
| ... | ||||||
| * | | tor-hsclient, arti-client, tor-keymgr, tor-netdoc: Use a keypair instead of ↵ | Gabriela Moldovan | 2023-09-25 | 13 | -45/+62 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | StaticSecret. Previously, when retrieving `KS_hsc_desc_enc` keys (or any other x25519 keys) from the keystore, the keymgr would discard the public part of the key (SSH private keys contain the public part of the key too). Instead of discarding the public key and returning just the `StaticSecret`, the keymgr now returns a `StaticKeypair`. This makes the x25519 `EncodableKey`/`ToEncodableKey` implementation consistent with the ed25519 one (which retrieves key pairs rather than "unescorted" secrets). | |||||
| * | | tor-hsservice: Add HsClientDescEncKeypair. | Gabriela Moldovan | 2023-09-25 | 3 | -0/+22 | |
| | | | ||||||
| * | | tor-llcrypto: Add a type for x25519 StaticSecret/PublicKey keypairs. | Gabriela Moldovan | 2023-09-25 | 2 | -0/+10 | |
| | | | ||||||
| * | | Merge branch 'pad_intro2' into 'main' | Nick Mathewson | 2023-09-25 | 2 | -10/+45 | |
| |\ \ | |/ |/| | | | | | | | | | Accept and transmit padding in introduce2 plaintexts Closes #1031 See merge request tpo/core/arti!1602 | |||||
| | * | Generate padding in Introduce1 messages. | Nick Mathewson | 2023-09-18 | 1 | -7/+41 | |
| | | | | | | | | | | | | | Closes #1031. This padding ensures that the introduction point doesn't learn the length of the plaintext being sent to the onion service. | |||||
| | * | HSS: accept padding at the end of an introduce2 encrypted payload | Nick Mathewson | 2023-09-18 | 1 | -3/+4 | |
| | | | | | | | | | | | According to rend-spec, we intentionally accept and discard extra bytes here. | |||||
| * | | tor-hsservice: Add TODO about MissingKeys errors. | Gabriela Moldovan | 2023-09-22 | 2 | -0/+31 | |
| | | | ||||||
| * | | tor-hsservice: Add semver.md file. | Gabriela Moldovan | 2023-09-22 | 1 | -0/+1 | |
| | | | ||||||
| * | | tor-hsservice: Make keys.rs a top-level module. | Gabriela Moldovan | 2023-09-22 | 5 | -5/+4 | |
| | | | ||||||
| * | | tor-hsservice: Make the caller of build_sign calculate `now()`. | Gabriela Moldovan | 2023-09-22 | 2 | -6/+7 | |
| | | | ||||||
| * | | tor-hsservice: Add TODO regarding the KeySpecifier::ctor_path()s of service ↵ | Gabriela Moldovan | 2023-09-22 | 1 | -0/+5 | |
| | | | | | | | | | keys. | |||||
| * | | tor-hsservice: Use "hs" instead of "service" the ArtiPaths of services. | Gabriela Moldovan | 2023-09-22 | 1 | -1/+1 | |
| | | | ||||||
| * | | tor-hsservice: Add some derives for HsSvcKeySpecifier. | Gabriela Moldovan | 2023-09-22 | 1 | -0/+1 | |
| | | | ||||||
| * | | tor-hsservice: Remove unnecessary placeholder struct. | Gabriela Moldovan | 2023-09-22 | 1 | -15/+0 | |
| | | | | | | | | | | | | | This cert should've an Ed25519Cert anyway (but the descriptor publisher doesn't need to worry about the `intro_{auth, enc}_key_cert` certs because they will be generated internally by `HsDescBuilder`. | |||||
| * | | tor-hsservice: Specify the expiry time for the intro_{auth, enc}_key_cert. | Gabriela Moldovan | 2023-09-22 | 2 | -5/+21 | |
| | | | | | | | | | | | The certs are generated internally by `HsDescBuilder`. The publisher just needs to set their expiry. | |||||
| * | | tor-hsservice: Remove unused keys module. | Gabriela Moldovan | 2023-09-22 | 2 | -35/+0 | |
| | | | ||||||
| * | | tor-hsservice: Make the publisher load keys from the keystore. | Gabriela Moldovan | 2023-09-22 | 2 | -15/+25 | |
| | | | ||||||
| * | | tor-hsservice: Add a helper for reading service keys from the keystore. | Gabriela Moldovan | 2023-09-22 | 2 | -2/+20 | |
| | | | ||||||
| * | | tor-hsservice: Support storing desc signing keys in the keystore. | Gabriela Moldovan | 2023-09-22 | 2 | -1/+22 | |
| | | | ||||||
| * | | tor-hsservice: Support storing HsIdKeys in the keystore. | Gabriela Moldovan | 2023-09-22 | 2 | -4/+41 | |
| | | | ||||||
| * | | tor-hscrypto: Reinstate HsDescSigningKey/HsDescSigningKeypair. | Gabriela Moldovan | 2023-09-22 | 1 | -2/+0 | |
| | | | | | | | | | We need it to sign descriptors. | |||||
| * | | tor-hsservice: Add an error variant for key-not-found errors. | Gabriela Moldovan | 2023-09-22 | 1 | -0/+5 | |
| | | | ||||||
| * | | tor-hsservice: Add key specifier for blinded_id keypairs. | Gabriela Moldovan | 2023-09-22 | 4 | -1/+71 | |
| | | | ||||||
| * | | tor-hsservice: Return a ReactorError from build_sign. | Gabriela Moldovan | 2023-09-22 | 1 | -2/+2 | |
| | | | | | | | | | | | | | `build_sign` will soon be using the `KeyMgr` to look up keys, so we need to be able to propagate `KeystoreError`s (via the `ReactorError::KeyStore` variant). | |||||
| * | | tor-hsservice: Add an error variant for keystore errors. | Gabriela Moldovan | 2023-09-22 | 1 | -1/+5 | |
| | | | ||||||
| * | | tor-hsservice: Give the publisher a reference to the key manager. | Gabriela Moldovan | 2023-09-22 | 3 | -8/+33 | |
| | | | ||||||
| * | | hss: Un-parameterize OnionService. | Nick Mathewson | 2023-09-21 | 1 | -20/+31 | |
| | | | ||||||
| * | | publish: note a possible behavior change on launch(). | Nick Mathewson | 2023-09-21 | 1 | -0/+4 | |
| | | | ||||||
| * | | hss: remove an "#[allow(...)]". | Nick Mathewson | 2023-09-21 | 1 | -2/+0 | |
| | | | ||||||
| * | | hss: adjust members of OnionService type. | Nick Mathewson | 2023-09-21 | 2 | -23/+13 | |
| | | | ||||||
| * | | hss: fix error return from OnionService::launch() | Nick Mathewson | 2023-09-21 | 2 | -1/+13 | |
| | | | ||||||
| * | | hss: start filling in a "launch" function for OnionService. | Nick Mathewson | 2023-09-21 | 2 | -39/+57 | |
| | | | ||||||
| * | | tor-hsservice: Update Publisher::new docs. | Gabriela Moldovan | 2023-09-21 | 1 | -1/+3 | |
| | | | ||||||
| * | | tor-hsservice: Add must_use for Publisher::launch. | Gabriela Moldovan | 2023-09-21 | 1 | -0/+1 | |
| | | | ||||||
| * | | tor-hsservice: Remove outdated TODO. | Gabriela Moldovan | 2023-09-21 | 1 | -1/+0 | |
| | | | ||||||
| * | | tor-hsservice: Give the descriptor publisher a separate launch function. | Gabriela Moldovan | 2023-09-21 | 3 | -28/+54 | |
| | | | | | | | | | | | | | | | | | | | | | | | This also makes `Publisher::new` synchronous. If `Reactor::new` fails, `Publisher::launch` propagates the error to its caller (to achieve this, I had to give `PublisherError` a new `ReactorLaunch` variant and make `ReactorError` and `UploadError` crate-public). Closes #1042 | |||||
| * | | Merge branch 'intro_rend' into 'main' | Nick Mathewson | 2023-09-21 | 8 | -91/+255 | |
| |\ \ | | | | | | | | | | | | | HSS: Route necessary material into RendRequest See merge request tpo/core/arti!1610 | |||||
| | * | | hs_ntor: replace "32" with a const. | Nick Mathewson | 2023-09-21 | 1 | -1/+1 | |
| | | | | ||||||
| | * | | hs_ntor: rename get_{introduce,rendezvous}1_key_material. | Nick Mathewson | 2023-09-21 | 1 | -6/+6 | |
| | | | | ||||||
| | * | | hs_ntor: improve several comments. | Nick Mathewson | 2023-09-21 | 1 | -3/+10 | |
| | | | | ||||||
| | * | | hs_ntor: rename enc_key to dec_key in service code. | Nick Mathewson | 2023-09-21 | 1 | -5/+5 | |
| | | | | ||||||
| | * | | hs_ntor: allow attempting handshake with a set of subcredentials. | Nick Mathewson | 2023-09-20 | 3 | -43/+53 | |
| | | | | | | | | | | | | | | | | | | | | | | Since we are using the same introduction point circuits for multiple time periods, we need the ability to provide a set of subcredentials and see which of them acually works. Fortunately, we "only" have to do digest operations here, which are much faster than public key. | |||||
| | * | | hs_ntor: Take our k_hss_ntor keypair explicitly. | Nick Mathewson | 2023-09-20 | 3 | -20/+24 | |
| | | | | ||||||
| | * | | HSS: Enable RendRequests to be answered. | Nick Mathewson | 2023-09-20 | 5 | -25/+79 | |
| | | | | | | | | | | | | | | | | This requires yet more plumbing—this time, of HsCircPool and NetDirProvider. | |||||
| | * | | hss: Minor hack to avoid parameterizing RendRequestContext on Runtime | Nick Mathewson | 2023-09-20 | 1 | -2/+29 | |
| | | | | | | | | | | | | | | | | We need to pass around an Arc<HsCircPool<R>>, but doing so directly would force us to make RendRequestContext parameterized on R. | |||||
| | * | | HSS: route most necessary key material to RendRequest | Nick Mathewson | 2023-09-20 | 3 | -15/+77 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | When we go to answer a RendRequest, we need to have a few objects present. This commit makes sure that they're available at the right places. We also note a significant problem with the need for a Subcredential here. | |||||
| * | | | Merge branch 'slow-test' into 'main' | Nick Mathewson | 2023-09-20 | 1 | -1/+2 | |
| |\ \ \ | | | | | | | | | | | | | | | | | tor-hsclient: state expiry test: Use MockSleepProvider advance See merge request tpo/core/arti!1609 | |||||
| | * | | | tor-hsclient: state expiry test: Use MockSleepProvider advance | Ian Jackson | 2023-09-20 | 1 | -1/+2 | |
| | | | | | | | | | | | | | | | | | | | | | See https://gitlab.torproject.org/tpo/core/arti/-/issues/1040 | |||||
| * | | | | tor-hsservice: Fix compile error, make Publisher use Arc<OnionServiceConfig>. | Gabriela Moldovan | 2023-09-20 | 4 | -11/+12 | |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This fixes a compile error introduced as a result of merging a couple of conflicting MRs (!1611 and !1604). This also makes the channel the publisher uses for watching for config changes receive `Arc<OnionServiceConfig>` (rather than `OnionServiceConfig`). | |||||
| * | | | | Merge branch 'mgr-watch' into 'main' | gabi-250 | 2023-09-20 | 1 | -6/+25 | |
| |\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | tor-hsservice: Make config a watch receiver Closes #1041 See merge request tpo/core/arti!1611 | |||||
