summaryrefslogtreecommitdiff
path: root/crates
Commit message (Collapse)AuthorAgeFilesLines
...
* | | | | | arti: Reinstate the keystore.enabled option.Gabriela Moldovan2024-09-232-54/+27
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is a follow-up from !2394 I want to keep the `keystore.enabled` option, because I'm planning on extending `ArtiKeystoreConfig` to support configuring secondary keystores too (currently, the only supported setting is `keystore.kind`, which configures the primary keystore). `keystore.enabled` will disable keystore use altogether (i.e. both primary and secondary). Currently, we only support configuring the "primary" (previously known as "default") keystore, which can be either "native" (the on-disk Arti keystore), or "ephemeral" (an in-memory keystore). To implement #858, we will need to support configuring additional keystores too, so we will need to move to a config of the form ```toml [storage.keystore] # Whether the keystore is enabled. #enabled = "auto" # Configure the primary keystore. [storage.keystore.primary] # The type of primary keystore to use kind = "auto" | "native" | "ephemeral" # Optionally configure C Tor keystores for arti to use. # # Note: The keystores listed here are read-only (keys are only # ever written to the primary keystore, configured in # `storage.keystore.primary`). [[storage.keystore.ctor]] # If the `kind` is `service`, this should be set to the `HiddenServiceDirectory` # of your hidden service. Arti will read `HiddenServiceDirectory/hostname` # and `HiddenServiceDirectory/private_key`. (Note: if your service is running # in restricted discovery mode, you must set the # `[[onion_services."<the nickname of your svc>".restricted_discovery.key_dirs]]` # to `HiddenServiceDirectory/client_keys` # # If the `kind` is `client`, this should be set to `ClientOnionAuthDir` of # your client. If Arti is configured to run as a client (i.e. if it runs in SOCKS # proxy mode), it will read the client restricted discovery keys from this path. path = "/foo/bar" # The type of keystore `path` should be interpreted as kind = "client" | "service" ``` This moves the current keystore settings to `storage.keystore.primary` in preparation for that change.
* | | | | | tor-keymgr: Add back ArtiKeystoreConfig::is_enabled().Gabriela Moldovan2024-09-232-1/+7
|/ / / / / | | | | | | | | | | | | | | | | | | | | I am adding `is_enabled()` back because I plan to un-deprecate the `enabled` setting.
* | | | | tor-hsservice: Update docs to reflect KeystoreSelector renaming.Gabriela Moldovan2024-09-231-1/+1
| | | | |
* | | | | arti-client: Update docs to reflect KeystoreSelector renaming.Gabriela Moldovan2024-09-231-3/+3
| | | | |
* | | | | tor-keymgr: Rename the primary keystore for clarity.Gabriela Moldovan2024-09-2310-44/+46
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously, arti's primary keystore was referred to as its "default" keystore. However, "default" is inaccurate here: there is no way to meaningfully override this "default" (the "default" store acts as the main keystore). Throughout the codebase, we query all keystores for keys (including the secondary ones), but only ever write to the default/primary keystore. This is OK for now, because it enables us to have one mutable keystore, and multiple secondary, read-only stores.
* | | | | arti-client: added support for constructing ArtiEphemeralKeystore to ↵Morgan2024-09-201-22/+37
| | | | | | | | | | | | | | | | | | | | InertTorClient::create_keymgr()
* | | | | tor-keymgr: added dummy implementation of ArtiEphemeralKeyStoreMorgan2024-09-201-0/+14
| | | | |
* | | | | tor-keymgr: added support for specifying keystore kind to ArtiKeystoreConfigMorgan2024-09-204-18/+102
| | | | |
* | | | | tor-keymgr: renamed ArtiNativeKeystoreConfig to ArtiKeystoreConfigMorgan2024-09-206-11/+14
| | | | |
* | | | | arti-client: expose key-mgr/ephemeral-keystore feature in arti-clientMorgan2024-09-201-0/+3
|/ / / /
* | | | Merge branch 'rotate-keys' into 'main'gabi-2502024-09-2010-20/+225
|\ \ \ \ | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | arti: Add hsc subcommands for key rotation and deletion Closes #1475 See merge request tpo/core/arti!2435
| * | | | arti: Tolerate lowercase "no" in confirmation prompt.Gabriela Moldovan2024-09-191-3/+7
| | | | | | | | | | | | | | | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2435#note_3080452
| * | | | arti: Fix typo in display_service_discovery_key function name.Gabriela Moldovan2024-09-191-3/+3
| | | | |
| * | | | arti: Gate the arti hsc subcommand behind a new "hsc" feature (fmt).Gabriela Moldovan2024-09-191-4/+1
| | | | |
| * | | | arti: Gate the arti hsc subcommand behind a new "hsc" feature.Gabriela Moldovan2024-09-195-17/+9
| | | | | | | | | | | | | | | | | | | | This new feature is experimental.
| * | | | arti: Add a test for the "hsc key" subcommand help output.Gabriela Moldovan2024-09-193-0/+19
| | | | |
| * | | | arti: Add a subcommand for removing a client discovery key.Gabriela Moldovan2024-09-191-0/+35
| | | | | | | | | | | | | | | | | | | | Closes #1475
| * | | | arti: Add an hsc subcommand for rotating client keys.Gabriela Moldovan2024-09-192-0/+69
| | | | | | | | | | | | | | | | | | | | Part of #1475
| * | | | arti: Move public key output logic to a separate function.Gabriela Moldovan2024-09-191-4/+13
| | | | | | | | | | | | | | | | | | | | | | | | | This will be reused for `arti hsc key rotate`, which also outputs the public key.
| * | | | arti-client: Add APIs for rotating service discovery keys.Gabriela Moldovan2024-09-191-0/+80
| | | | |
* | | | | key-forge: Add curve25519 key wrapper macroDavid Goulet2024-09-191-8/+161
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Closes #1619 Signed-off-by: David Goulet <[email protected]>
* | | | | Merge branch 'forge-macros' into 'main'David Goulet2024-09-194-45/+44
|\ \ \ \ \ | |/ / / / |/| | | | | | | | | | | | | | tor-key-forge: encapsulate `define_ed25519_keypair` macro dependencies See merge request tpo/core/arti!2433
| * | | | tor-key-forge: encapsulate `define_ed25519_keypair` macro depsSteven Engler2024-09-184-45/+44
| |/ / / | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This re-exports the types/traits needed by the `define_ed25519_keypair` macro so that the macro caller doesn't need to import a bunch of extra packages in its Cargo.toml that it doesn't use, and so that the caller doesn't need a `use prelude::*` before invoking the macro. This makes the macro nicer to use for the caller, and should prevent the macro from causing "cannot find ... in this scope" errors.
* | | | arti: Satisfy clippy.Gabriela Moldovan2024-09-181-4/+4
| | | |
* | | | arti: Add hsc key subcommand, deprecate hsc get-key.Gabriela Moldovan2024-09-183-5/+34
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | I am deprecating the old `hsc get-key` subcommand in favor of the new `hsc key get` subcommand. This is because I plan to implement the rest of the key management functionality (key deletion, rotation, etc.) as subcommands of the `hsc key` command. The alternative would be to add a new distinct top-level `hsc rotate-key`, `hsc remove-key`, etc. subcommand alongside the existing `hsc get-key` command (which IMO is less nice than the alternative I'm proposing).
* | | | arti: Move the keygen-related args to a separate struct.Gabriela Moldovan2024-09-181-9/+17
| | | | | | | | | | | | | | | | These will be reused by a future `key rotate` subcommand.
* | | | arti: Make sure we check the KeyType before running the command.Gabriela Moldovan2024-09-181-1/+5
| | | | | | | | | | | | | | | | | | | | Otherwise, if/when we add support for other `KeyType`s we risk forgetting to update the rest of the implementation.
* | | | arti: Move the shared arti hsc args to CommonArgs (fmt).Gabriela Moldovan2024-09-181-2/+4
| | | |
* | | | arti: Move the shared arti hsc args to CommonArgs.Gabriela Moldovan2024-09-181-16/+22
| | | |
* | | | arti: Move TorClient creation to the top-level (fmt).Gabriela Moldovan2024-09-181-4/+1
| | | |
* | | | arti: Move TorClient creation to the top-level.Gabriela Moldovan2024-09-181-8/+7
|/ / / | | | | | | | | | | | | The client will be used by future subcommands too, not just `prepare_service_discovery_key`.
* | | Merge branch 'ticket1604_01' into 'main'David Goulet2024-09-1813-22/+334
|\ \ \ | |_|/ |/| | | | | | | | | | | | | | relay: Declare keys and add a KeyMgr to TorRelay Closes #1604 See merge request tpo/core/arti!2411
| * | relay: Require keymgr feature from tor-keymgrDavid Goulet2024-09-181-1/+1
| | | | | | | | | | | | | | | | | | | | | A relay can't operate without a KeyMgr so enable it by default from the tor-keymgr crate. Signed-off-by: David Goulet <[email protected]>
| * | key-forge: Fix a comment with the wrong nameDavid Goulet2024-09-181-2/+2
| | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * | key-forge: Support extra docs and attributes to ed25519 keypairDavid Goulet2024-09-182-9/+19
| | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * | tor-keymgr: Set KeySpecifier deftly exported struct non_exhaustiveDavid Goulet2024-09-181-0/+1
| | | | | | | | | | | | Signed-off-by: David Goulet <[email protected]>
| * | relay: Try to generate long-term identity keyDavid Goulet2024-09-182-5/+31
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | When creating the KeyMgr, attempt to create the long-term identity key if none are found in the KeyMgr. Until the KeyMgr has certificate support, we can't create the certificate. Add a TODO comment item about future work needed there. Related to #1604 Signed-off-by: David Goulet <[email protected]>
| * | relay: Add KeyMgr to TorRelayDavid Goulet2024-09-184-2/+66
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This is the first step before creating relay key definition and storing them into a keystore. The KeyMgr should be passed on the ChanMgr in later commit so the ChanMgr can use it for the authenticated channel handshake. Part of #1604 Signed-off-by: David Goulet <[email protected]>
| * | relay-crypto: Initial import of new tor-relay-crypto crateDavid Goulet2024-09-185-0/+175
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This adds a new crate called tor-relay-crypto which is responsible for declaring the relay keys and certificate that will be used by a relay and stored in a KeyMgr. This is in its own crate and considered pretty low level so other crates can use it to access the relay keys, like tor-proto, for cryptographic actions like channel authentication or descriptor signing. The lower level cryptographic keys are wrapped in a higher level object in this crate, using tor-key-forge crate, so we can have proper semantic and strong type check on those keys so they are not misused or confused with other keys. At this point, the key declaration might change once the KeyMgr supports attaching a certificate to a key. We are likely going to see more code related to certificate creation in this crate in the future. Part of #1604 Signed-off-by: David Goulet <[email protected]>
| * | key-forge: Add helper function and implement traitsDavid Goulet2024-09-183-12/+48
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Implement the signature::Signer and Ed25519PublicKey trait so the ed25519 keypair wrapper can be easily used for certificate creation. This also adds a to_ed25519_id() so we can get a Ed25519Identity which is an object used around. Finally, add a prelude module as the list of imports started to grow a bit out of control. Part of #1604 Signed-off-by: David Goulet <[email protected]>
* | | tor-keymgr: Enable the keymgr feature by default.Gabriela Moldovan2024-09-181-1/+1
|/ / | | | | | | `tor-keymgr` users now get the real keymgr implementation by default.
* | tor-keymgr: put ephemeral keystore behind experimental featureSteven Engler2024-09-173-2/+11
| | | | | | | | Feature is named "ephemeral-keystore".
* | Merge branch 'svc-no-proxy-port' into 'main'David Goulet2024-09-172-14/+36
|\ \ | | | | | | | | | | | | | | | | | | arti: Allow running hidden services with SOCKS/DNS proxying disabled. Closes #1569 See merge request tpo/core/arti!2423
| * | arti: Don't log that we are in SOCKS mode unless socks_listen is set.Gabriela Moldovan2024-09-171-6/+13
| | | | | | | | | | | | If `socks_listen` is disabled, we're not actually running in SOCKS mode.
| * | arti: Allow running hidden services with SOCKS/DNS ports disabled.Gabriela Moldovan2024-09-172-8/+23
| | | | | | | | | | | | Closes #1569
* | | Merge branch 'mq-tidy' into 'main'David Goulet2024-09-177-5/+80
|\ \ \ | | | | | | | | | | | | | | | | memquota: be more firm about avoiding panics, and tidy up docs See merge request tpo/core/arti!2404
| * | | tor-memquota: queue plan: Add a cross-referenceIan Jackson2024-09-101-0/+3
| | | |
| * | | tor-memquota: queue plan: Clean up intent and make into a doc commentIan Jackson2024-09-101-32/+24
| | | | | | | | | | | | | | | | Remove extraneous text, wrap it, and change to a more declarative style.
| * | | tor-memquota: queue plan: Copy from !1997 discussionIan Jackson2024-09-101-0/+32
| | | |
| * | | tor-memquota: Worsify formatting to stop rustfmt making it even worseIan Jackson2024-09-101-1/+3
| | | |