Conversation
- Extend the Cascade CLI `kmip add` subcommand to take an optional SNI `--server-name` argument. - Extend the Cascade CLI `kmip show` subcommand to report the SNI server name value that is configured. - Extend the Cascade API HsmAddError type to also report missing client certificate or key, or I/O errors (if the server is unable to write the given certificate and key files to its filesystem). - Improve the user experience of adding a KMIP HSM via the CLI with additional feedback about what is happening. - Factor out Json type wrapping in the API kmip_server_add() function to a wrapper fn to improve readability. - Extend the API kmip_server_add() function to write given certificate and key files to the server filesystem on connection success. - Extend KMIP state file handling code to read and write mTLS related details. - Extend the key manager unit to read mTLS related details from the KMIP state file and to pass mTLS related KMIP command line arguments to the `dnst keyset kmip add-server` subcommand. - Factor KMIP credential file access out of the key manager unit to src/common/kmip_creds.rs. - Rename `KmpClientCredentialsFile` to `KmipCredentialsManager` and add fn `save_mtls_data()` to save mTLS certificate files to disk. - Factor KMIP mTLS certificate and key loading out of the zone signer unit into `KmipCredentialsManager`. - Update signer key loading to use KmipCredentialsManager::load_mtls_data(). - Follow changed location in domain_kmip of export SyncConnPool type.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
kmip addsubcommand to take an optional SNI--server-nameargument.kmip showsubcommand to report the SNI server name value that is configured.HsmAddErrortype to also report missing client certificate or key, or I/O errors (if the server is unable to write the given certificate and key files to its filesystem).Jsontype wrapping in the APIkmip_server_add()function to a wrapper fn to improve readability.kmip_server_add()function to write given certificate and key files to the server filesystem on connection success.dnst keyset kmip add-serversubcommand.src/common/kmip_creds.rs.KmpClientCredentialsFiletoKmipCredentialsManagerand add fnsave_mtls_data()to save mTLS certificate files to disk.KmipCredentialsManager.KmipCredentialsManager::load_mtls_data().SyncConnPooltype.Note: Draft because it requires updated
dnst,domain-kmipandkmip-protocolcrates that haven't been released yet, and probably still needs more polishing and the new SNI server name command line argument still needs documenting.If you are changing Rust code or integration tests (
Cargo.*,crates/,etc/,integration-tests/,src/):actthrough theact-wrapper(as described inTESTING.md)?If you are adding/deleting man pages:
man_pagesconfig indoc/manual/source/conf.py?Cargo.toml?