2022-04-24 07:25:04 +00:00
|
|
|
/*
|
|
|
|
Copyright 2022 CAcert Inc.
|
|
|
|
SPDX-License-Identifier: Apache-2.0
|
|
|
|
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
you may not use this file except in compliance with the License.
|
|
|
|
You may obtain a copy of the License at
|
|
|
|
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
See the License for the specific language governing permissions and
|
|
|
|
limitations under the License.
|
|
|
|
*/
|
|
|
|
|
2022-04-19 14:48:32 +00:00
|
|
|
package hsm
|
|
|
|
|
|
|
|
import (
|
2022-05-01 10:36:17 +00:00
|
|
|
"fmt"
|
2022-04-19 14:48:32 +00:00
|
|
|
|
|
|
|
"github.com/ThalesIgnite/crypto11"
|
|
|
|
|
|
|
|
"git.cacert.org/cacert-gosigner/pkg/config"
|
|
|
|
)
|
|
|
|
|
2022-08-03 07:59:26 +00:00
|
|
|
type ConfigOption func(a *Access)
|
2022-04-19 14:48:32 +00:00
|
|
|
|
2022-08-03 07:59:26 +00:00
|
|
|
func CADirectoryOption(path string) func(a *Access) {
|
|
|
|
return func(a *Access) {
|
|
|
|
a.caDirectory = path
|
2022-05-01 10:36:17 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-08-03 07:59:26 +00:00
|
|
|
func CaConfigOption(signerConfig *config.SignerConfig) func(a *Access) {
|
|
|
|
return func(a *Access) {
|
|
|
|
a.signerConfig = signerConfig
|
2022-04-20 07:03:26 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-08-03 07:59:26 +00:00
|
|
|
func SetupModeOption() func(a *Access) {
|
|
|
|
return func(a *Access) {
|
|
|
|
a.setupMode = true
|
2022-04-20 07:03:26 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-08-03 07:59:26 +00:00
|
|
|
func VerboseLoggingOption() func(a *Access) {
|
|
|
|
return func(a *Access) {
|
|
|
|
a.verbose = true
|
2022-04-20 07:03:26 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-08-03 07:59:26 +00:00
|
|
|
// setupContext sets global context for HSM operations.
|
|
|
|
func (a *Access) setupContext(options ...ConfigOption) {
|
|
|
|
a.p11Contexts = make(map[string]*crypto11.Context)
|
2022-04-20 07:03:26 +00:00
|
|
|
|
|
|
|
for _, opt := range options {
|
2022-08-03 07:59:26 +00:00
|
|
|
opt(a)
|
2022-04-20 07:03:26 +00:00
|
|
|
}
|
2022-04-19 14:48:32 +00:00
|
|
|
}
|
|
|
|
|
2022-08-03 07:59:26 +00:00
|
|
|
func (a *Access) GetSignerConfig() *config.SignerConfig {
|
|
|
|
return a.signerConfig
|
2022-04-19 14:48:32 +00:00
|
|
|
}
|
|
|
|
|
2022-08-03 07:59:26 +00:00
|
|
|
func (a *Access) IsSetupMode() bool {
|
|
|
|
return a.setupMode
|
2022-04-20 07:03:26 +00:00
|
|
|
}
|
|
|
|
|
2022-08-03 07:59:26 +00:00
|
|
|
func (a *Access) IsVerbose() bool {
|
|
|
|
return a.verbose
|
2022-04-19 14:48:32 +00:00
|
|
|
}
|
|
|
|
|
2022-08-03 07:59:26 +00:00
|
|
|
func (a *Access) GetP11Context(entry *config.CaCertificateEntry) (*crypto11.Context, error) {
|
|
|
|
if p11Context, ok := a.p11Contexts[entry.Storage]; ok {
|
2022-04-19 14:48:32 +00:00
|
|
|
return p11Context, nil
|
|
|
|
}
|
|
|
|
|
2022-08-03 07:59:26 +00:00
|
|
|
p11Context, err := a.prepareCrypto11Context(entry.Storage)
|
2022-04-19 14:48:32 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2022-08-03 07:59:26 +00:00
|
|
|
a.p11Contexts[entry.Storage] = p11Context
|
2022-04-19 14:48:32 +00:00
|
|
|
|
|
|
|
return p11Context, nil
|
|
|
|
}
|
2022-05-01 10:36:17 +00:00
|
|
|
|
2022-08-03 07:59:26 +00:00
|
|
|
func (a *Access) CloseP11Contexts() error {
|
2022-05-01 10:36:17 +00:00
|
|
|
seen := make(map[*crypto11.Context]struct{}, 0)
|
|
|
|
|
2022-08-03 07:59:26 +00:00
|
|
|
for _, p11Context := range a.p11Contexts {
|
2022-05-01 10:36:17 +00:00
|
|
|
if _, ok := seen[p11Context]; ok {
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
|
|
|
|
seen[p11Context] = struct{}{}
|
|
|
|
|
|
|
|
err := p11Context.Close()
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("could not close context: %w", err)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|