Repository navigation
feat(tsa): switch the time-stamp authority on from machine config - #354
Merged
Merged
Conversation
Map pki.tsa into the config with the protocol block rules: an absent block keeps the stored one, enabled=false keeps the settings off, a Root refuses enabled=true, and an enabled block needs a valid policy OID (there is no default), an accuracy of at most 60 s, a certificate validity of at most 365 days with a shorter overlap, and parseable allowed networks. Every change is reboot-required. At boot an Intermediate or Issuing node with the block on issues its TSA certificate with a key from the CA key backend, starts the listener (port 318 by default), and re-checks the certificate hourly. Status reports the TSA's configured and running state and a pending reboot. ListTsaCertificates is served from the store whether or not the TSA runs, and cryptosctl tsa certificates lists them. Closes #287 Signed-off-by: Bugs5382 <12115015+Bugs5382@users.noreply.github.com>
Contributor
Author
|
Closing summary: maps pki.tsa into the config under the protocol block rules (policy OID required, Root refuses enabled, reboot-required), starts the TSA at boot on Intermediate/Issuing nodes with a CA-backend (TPM where present) key and an hourly certificate check, reports SERVICE_PROTOCOL_TSA in status, serves ListTsaCertificates, and adds cryptosctl tsa certificates plus docs/tsa.md. Companion docs CryptOS-PKI/website#97 merged. CI green. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
Last of the RFC 3161 time-stamp authority PRs (task 5 of the issue): the
pki.tsaconfig mapping, theboot-time start, status, the
ListTsaCertificatesRPC andcryptosctl tsa certificates. With this theTSA can be switched on from machine config.
Config (
internal/config/tsa.go):pki.tsafollows the protocol block rules ACME and EST use. A block withoutenabled(YAML) or withenabled=true(proto) is on.enabled=falsekeeps the settings in an off block that is never servedand never checked for completeness. An apply that leaves the block out keeps the stored one.
enabled=trueand accepts an off block.policy_oid. There is no default, as the contract says. It is atleast two decimal arcs without leading zeros, a first arc of 0 to 2, and a second arc below 40 under
0 or 1.
accuracy_msof at most 60000, a port in range, parseableallowed_networks(CIDR prefixes or bare addresses), andcertificate.validity_daysof at most 365with a shorter overlap.
NeedsReboot), and changing only an off block stays live.30 days.
Boot (
internal/init/tsa.go,run.go12f):before the listener starts. The key is created through the CA key backend (TPM-held on a TPM node)
with the CA key's configured algorithm.
the profile
tsa. It carries CDP and AIA pointers whenrevocation_base_urlis set.re-checked every hour.
failing the boot.
Status and RPC:
NodeStatus.protocolsreportsSERVICE_PROTOCOL_TSA: configured from the stored config, runningfrom this boot, and a pending reboot when they differ.
ListTsaCertificatesis served on the local and mTLS servers, authorized likeListIssued. It readsthe store whether or not the TSA runs this boot, newest first. Only the certificate in use while the
TSA runs is
current, and every past certificate stays listed.FailedPrecondition.cryptosctl tsa certificatesprints the list, and--pemprints the certificates.Removed, because the RPC is now served:
internal/grpc/unserved.go(the Unimplemented stub) andinternal/grpc/unserved_test.go(
TestUnservedRPCs_ReturnUnimplemented, which pinned the stub's answer).ListTsaCertificatesentry inunservedByDesignininternal/apiconformance/roundtrip_test.go.Docs:
docs/tsa.md(new) and the README. The companion site PR is CryptOS-PKI/website#97 (the TSAhow-to, the policy OID walkthrough, the
pki.tsareference and the cryptosctl reference).Closes #287
Merge order: after #351, #352 and #353 (merged). Merge CryptOS-PKI/website#97
first, then this one.
Verification
How this was verified
task ciandtask licensepass locally. New tests:internal/config: every validation rule, including the OID grammar and a Root with an on or offblock; defaults; proto and YAML round trips of on and off blocks; the block rules (absent keeps, off
keeps settings, an off block is not checked, on without a policy is refused); reboot classification.
internal/node: status reports the TSA configured, running and pending across aconfig applythatswitches it off, and that apply needs a reboot.
internal/init: with the real software key backend and an embedded etcd, the built TSA answers aquery over its handler. The token's signer chains to the CA and is not the CA certificate, and the CA
key is released. The TSA certificate is in the issued set under
tsa, a client outsideallowed_networksgets 403, and an unsynced clock givestimeNotAvailable. The catalog marks thecurrent certificate only while running and still lists it when not.
internal/grpc: maintenanceFailedPrecondition, non-adminPermissionDenied, the list over mTLSand the local socket, and a read failure as
Internal.cmd/cryptosctl: the table (newest first, current marked),--pem, and the empty case.No QEMU or lab run here. The image suite on this PR and the integration lane cover the boot path.