2022-11-29 15:23:16 +00:00
|
|
|
/*
|
|
|
|
Copyright 2022 CAcert Inc.
|
|
|
|
SPDX-License-Identifier: Apache-2.0
|
|
|
|
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
you may not use this file except in compliance with the License.
|
|
|
|
You may obtain a copy of the License at
|
|
|
|
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
See the License for the specific language governing permissions and
|
|
|
|
limitations under the License.
|
|
|
|
*/
|
|
|
|
|
|
|
|
package handler
|
|
|
|
|
|
|
|
import (
|
2022-12-01 20:43:07 +00:00
|
|
|
"context"
|
2022-11-29 15:23:16 +00:00
|
|
|
"fmt"
|
|
|
|
"time"
|
|
|
|
|
|
|
|
"github.com/shamaton/msgpackgen/msgpack"
|
|
|
|
"github.com/sirupsen/logrus"
|
|
|
|
|
2022-11-30 17:56:57 +00:00
|
|
|
"git.cacert.org/cacert-gosignerclient/internal/client"
|
|
|
|
|
2022-11-29 15:23:16 +00:00
|
|
|
"git.cacert.org/cacert-gosigner/pkg/messages"
|
|
|
|
|
|
|
|
"git.cacert.org/cacert-gosigner/pkg/protocol"
|
|
|
|
"git.cacert.org/cacert-gosignerclient/internal/config"
|
|
|
|
)
|
|
|
|
|
|
|
|
type SignerClientHandler struct {
|
2022-11-30 17:56:57 +00:00
|
|
|
logger *logrus.Logger
|
|
|
|
commands chan *protocol.Command
|
|
|
|
config *config.ClientConfig
|
|
|
|
clientCallback chan interface{}
|
2022-11-29 15:23:16 +00:00
|
|
|
}
|
|
|
|
|
2022-12-01 20:43:07 +00:00
|
|
|
func (s *SignerClientHandler) Send(ctx context.Context, command *protocol.Command, out chan []byte) error {
|
2022-11-29 15:23:16 +00:00
|
|
|
var (
|
|
|
|
frame []byte
|
|
|
|
err error
|
|
|
|
)
|
|
|
|
|
|
|
|
frame, err = msgpack.Marshal(command.Announce)
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("could not marshal command annoucement: %w", err)
|
|
|
|
}
|
|
|
|
|
2022-11-30 17:56:57 +00:00
|
|
|
s.logger.WithField("announcement", command.Announce).Debug("write command announcement")
|
2022-11-29 15:23:16 +00:00
|
|
|
|
|
|
|
s.logger.Trace("writing command announcement")
|
|
|
|
|
2022-12-01 20:43:07 +00:00
|
|
|
select {
|
|
|
|
case <-ctx.Done():
|
|
|
|
return nil
|
|
|
|
case out <- frame:
|
|
|
|
break
|
|
|
|
}
|
2022-11-29 15:23:16 +00:00
|
|
|
|
|
|
|
frame, err = msgpack.Marshal(command.Command)
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("could not marshal command data: %w", err)
|
|
|
|
}
|
|
|
|
|
2022-11-30 17:56:57 +00:00
|
|
|
s.logger.WithField("command", command.Command).Debug("write command data")
|
2022-11-29 15:23:16 +00:00
|
|
|
|
2022-12-01 20:43:07 +00:00
|
|
|
select {
|
|
|
|
case <-ctx.Done():
|
|
|
|
return nil
|
|
|
|
case out <- frame:
|
|
|
|
return nil
|
|
|
|
}
|
2022-11-29 15:23:16 +00:00
|
|
|
}
|
|
|
|
|
2022-12-01 20:43:07 +00:00
|
|
|
func (s *SignerClientHandler) ResponseAnnounce(ctx context.Context, in chan []byte) (*protocol.Response, error) {
|
2022-11-29 15:23:16 +00:00
|
|
|
response := &protocol.Response{}
|
|
|
|
|
|
|
|
var announce messages.ResponseAnnounce
|
|
|
|
|
|
|
|
select {
|
2022-12-01 20:43:07 +00:00
|
|
|
case <-ctx.Done():
|
|
|
|
return nil, nil
|
2022-11-29 15:23:16 +00:00
|
|
|
case frame := <-in:
|
|
|
|
if err := msgpack.Unmarshal(frame, &announce); err != nil {
|
|
|
|
return nil, fmt.Errorf("could not unmarshal response announcement: %w", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
response.Announce = &announce
|
|
|
|
|
|
|
|
s.logger.WithField("announcement", response.Announce).Debug("received response announcement")
|
|
|
|
|
|
|
|
return response, nil
|
|
|
|
case <-time.After(s.config.ResponseAnnounceTimeout):
|
|
|
|
return nil, protocol.ErrResponseAnnounceTimeoutExpired
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-12-01 20:43:07 +00:00
|
|
|
func (s *SignerClientHandler) ResponseData(ctx context.Context, in chan []byte, response *protocol.Response) error {
|
2022-11-29 15:23:16 +00:00
|
|
|
select {
|
2022-12-01 20:43:07 +00:00
|
|
|
case <-ctx.Done():
|
|
|
|
return nil
|
2022-11-29 15:23:16 +00:00
|
|
|
case frame := <-in:
|
|
|
|
switch response.Announce.Code {
|
|
|
|
case messages.RespHealth:
|
|
|
|
var resp messages.HealthResponse
|
|
|
|
if err := msgpack.Unmarshal(frame, &resp); err != nil {
|
|
|
|
return fmt.Errorf("could not unmarshal health response data: %w", err)
|
|
|
|
}
|
|
|
|
|
2022-12-03 10:52:32 +00:00
|
|
|
response.Response = &resp
|
|
|
|
case messages.RespCAInfo:
|
|
|
|
var resp messages.CAInfoResponse
|
|
|
|
if err := msgpack.Unmarshal(frame, &resp); err != nil {
|
|
|
|
return fmt.Errorf("could not unmarshal CA info response data: %w", err)
|
|
|
|
}
|
|
|
|
|
2022-11-29 15:23:16 +00:00
|
|
|
response.Response = &resp
|
|
|
|
case messages.RespFetchCRL:
|
|
|
|
var resp messages.FetchCRLResponse
|
|
|
|
if err := msgpack.Unmarshal(frame, &resp); err != nil {
|
|
|
|
return fmt.Errorf("could not unmarshal fetch CRL response data: %w", err)
|
|
|
|
}
|
|
|
|
|
2022-11-30 17:56:57 +00:00
|
|
|
response.Response = &resp
|
|
|
|
case messages.RespError:
|
|
|
|
var resp messages.ErrorResponse
|
|
|
|
if err := msgpack.Unmarshal(frame, &resp); err != nil {
|
|
|
|
return fmt.Errorf("could not unmarshal error response data: %w", err)
|
|
|
|
}
|
|
|
|
|
2022-11-29 15:23:16 +00:00
|
|
|
response.Response = &resp
|
|
|
|
default:
|
|
|
|
return fmt.Errorf("unhandled response code %s", response.Announce.Code)
|
|
|
|
}
|
|
|
|
case <-time.After(s.config.ResponseDataTimeout):
|
|
|
|
return protocol.ErrResponseDataTimeoutExpired
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2022-12-01 20:43:07 +00:00
|
|
|
func (s *SignerClientHandler) HandleResponse(ctx context.Context, response *protocol.Response) error {
|
2022-11-29 15:23:16 +00:00
|
|
|
s.logger.WithField("response", response.Announce).Info("handled response")
|
|
|
|
s.logger.WithField("response", response).Debug("full response")
|
|
|
|
|
2022-11-30 17:56:57 +00:00
|
|
|
switch r := response.Response.(type) {
|
|
|
|
case *messages.ErrorResponse:
|
|
|
|
s.logger.WithField("message", r.Message).Error("error from signer")
|
|
|
|
case *messages.HealthResponse:
|
2022-12-01 20:43:07 +00:00
|
|
|
s.handleHealthResponse(ctx, r)
|
2022-12-03 10:52:32 +00:00
|
|
|
case *messages.CAInfoResponse:
|
|
|
|
s.handleCAInfoResponse(ctx, r)
|
2022-11-30 17:56:57 +00:00
|
|
|
case *messages.FetchCRLResponse:
|
2022-12-01 20:43:07 +00:00
|
|
|
s.handleFetchCRLResponse(ctx, r)
|
2022-11-30 17:56:57 +00:00
|
|
|
default:
|
|
|
|
s.logger.WithField("response", response).Warnf("unhandled response of type %T", response.Response)
|
|
|
|
}
|
2022-11-29 15:23:16 +00:00
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2022-12-01 20:43:07 +00:00
|
|
|
func (s *SignerClientHandler) handleHealthResponse(ctx context.Context, r *messages.HealthResponse) {
|
2022-11-30 17:56:57 +00:00
|
|
|
signerInfo := client.SignerInfo{}
|
|
|
|
|
|
|
|
signerInfo.SignerHealth = r.Healthy
|
|
|
|
signerInfo.SignerVersion = r.Version
|
|
|
|
|
|
|
|
if !r.Healthy {
|
|
|
|
// it might be a good idea to notify monitoring if the signer is not OK
|
|
|
|
s.logger.Error("signer is not healthy")
|
|
|
|
}
|
|
|
|
|
|
|
|
for _, item := range r.Info {
|
|
|
|
if !item.Healthy {
|
|
|
|
s.logger.WithField("component", item.Source).Error("signer component is not healthy")
|
|
|
|
}
|
|
|
|
|
|
|
|
switch item.Source {
|
|
|
|
case "HSM":
|
2022-12-03 10:52:32 +00:00
|
|
|
signerInfo.CACertificates = make([]string, 0)
|
2022-11-30 17:56:57 +00:00
|
|
|
|
2022-12-03 10:52:32 +00:00
|
|
|
for certName, status := range item.MoreInfo {
|
|
|
|
if status == string(messages.CertStatusOk) {
|
|
|
|
signerInfo.CACertificates = append(signerInfo.CACertificates, certName)
|
2022-11-30 17:56:57 +00:00
|
|
|
|
2022-12-03 10:52:32 +00:00
|
|
|
continue
|
2022-11-30 17:56:57 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
s.logger.WithFields(map[string]interface{}{
|
|
|
|
"certificate": certName,
|
2022-12-03 10:52:32 +00:00
|
|
|
"status": status,
|
|
|
|
}).Warn("certificate has issues")
|
2022-11-30 17:56:57 +00:00
|
|
|
}
|
|
|
|
default:
|
|
|
|
s.logger.WithField("source", item.Source).Warn("unhandled health source")
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-12-01 20:43:07 +00:00
|
|
|
select {
|
|
|
|
case <-ctx.Done():
|
|
|
|
return
|
|
|
|
case s.clientCallback <- signerInfo:
|
|
|
|
break
|
|
|
|
}
|
2022-11-30 17:56:57 +00:00
|
|
|
}
|
|
|
|
|
2022-12-03 10:52:32 +00:00
|
|
|
func (s *SignerClientHandler) handleCAInfoResponse(ctx context.Context, r *messages.CAInfoResponse) {
|
|
|
|
select {
|
|
|
|
case <-ctx.Done():
|
|
|
|
return
|
|
|
|
case s.clientCallback <- r:
|
|
|
|
break
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-12-01 20:43:07 +00:00
|
|
|
func (s *SignerClientHandler) handleFetchCRLResponse(ctx context.Context, r *messages.FetchCRLResponse) {
|
|
|
|
select {
|
|
|
|
case <-ctx.Done():
|
|
|
|
return
|
|
|
|
case s.clientCallback <- r:
|
|
|
|
break
|
|
|
|
}
|
2022-11-30 17:56:57 +00:00
|
|
|
}
|
|
|
|
|
2022-11-29 15:23:16 +00:00
|
|
|
func New(
|
|
|
|
config *config.ClientConfig,
|
|
|
|
logger *logrus.Logger,
|
|
|
|
commands chan *protocol.Command,
|
2022-11-30 17:56:57 +00:00
|
|
|
clientCallback chan interface{},
|
2022-11-29 15:23:16 +00:00
|
|
|
) (protocol.ClientHandler, error) {
|
|
|
|
return &SignerClientHandler{
|
2022-11-30 17:56:57 +00:00
|
|
|
logger: logger,
|
|
|
|
config: config,
|
|
|
|
commands: commands,
|
|
|
|
clientCallback: clientCallback,
|
2022-11-29 15:23:16 +00:00
|
|
|
}, nil
|
|
|
|
}
|