pub enum NetHsmUserMapping {
Admin(UserId),
Backup {
backend_user: SystemWideUserId,
ssh_authorized_key: AuthorizedKeyEntry,
system_user: SystemUserId,
},
HermeticMetrics {
backend_users: NetHsmMetricsUsers,
system_user: SystemUserId,
},
Metrics {
backend_users: NetHsmMetricsUsers,
ssh_authorized_key: AuthorizedKeyEntry,
system_user: SystemUserId,
},
Signing {
backend_user: UserId,
signing_key_id: KeyId,
key_setup: SigningKeySetup,
ssh_authorized_key: AuthorizedKeyEntry,
system_user: SystemUserId,
tag: String,
},
}Expand description
User and data mapping between system users and NetHSM users.
Variants§
Admin(UserId)
A NetHsm user in the Administrator role, without a system user mapped to it.
Backup
A system user, with SSH access, mapped to a system-wide NetHSM user in the Backup role.
Fields
backend_user: SystemWideUserIdThe name of the NetHSM user.
The SSH public key used for connecting to the system_user.
system_user: SystemUserIdThe name of the system user.
HermeticMetrics
A system user, without SSH access, mapped to a system-wide NetHSM user in the Metrics role and one or more NetHsm users in the Operator role with read-only access to zero or more keys.
Fields
backend_users: NetHsmMetricsUsersThe NetHSM users in the [Metrics][UserRole::Metrics] and
[operator][UserRole::Operator] role.
system_user: SystemUserIdThe name of the system user.
Metrics
A system user, with SSH access, mapped to a system-wide NetHSM user
in the Metrics role and n users in the Operator role with read-only access to zero or
more keys.
Fields
backend_users: NetHsmMetricsUsersThe NetHSM users in the [Metrics][UserRole::Metrics] and
[operator][UserRole::Operator] role.
The SSH public key used for connecting to the system_user.
system_user: SystemUserIdThe name of the system user.
Signing
A system user, with SSH access, mapped to a NetHSM user in the Operator role with access to a single signing key.
Signing key and NetHSM user are mapped using a tag.
Fields
backend_user: UserIdThe name of the NetHSM user.
signing_key_id: KeyIdThe ID of the NetHSM key.
key_setup: SigningKeySetupThe setup of a NetHSM key.
The SSH public key used for connecting to the system_user.
system_user: SystemUserIdThe name of the system user.
Implementations§
Source§impl NetHsmUserMapping
impl NetHsmUserMapping
Sourcepub fn namespaces(&self) -> Vec<&NamespaceId>
pub fn namespaces(&self) -> Vec<&NamespaceId>
Returns the list of [NamespaceId]s associated with this NetHsmUserMapping.
Sourcepub fn tag(&self, namespace: Option<&NamespaceId>) -> Option<&str>
pub fn tag(&self, namespace: Option<&NamespaceId>) -> Option<&str>
Returns the optional tag used in the NetHsmUserMapping.
§Note
Only NetHsmUserMapping::Signing can have a tag.
Sourcepub fn nethsm_user_ids(&self) -> Vec<UserId>
pub fn nethsm_user_ids(&self) -> Vec<UserId>
Returns the list of [UserId] objects associated with this NetHsmUserMapping.
Sourcepub fn nethsm_user_data<'a>(&'a self) -> HashSet<NetHsmUserData<'a>>
pub fn nethsm_user_data<'a>(&'a self) -> HashSet<NetHsmUserData<'a>>
Returns the list of NetHsmUserData objects associated with this NetHsmUserMapping.
Sourcepub fn nethsm_user_key_data<'a>(
&'a self,
filter: NetHsmUserKeysFilter,
) -> Option<NetHsmUserKeyData<'a>>
pub fn nethsm_user_key_data<'a>( &'a self, filter: NetHsmUserKeysFilter, ) -> Option<NetHsmUserKeyData<'a>>
Returns a filtered list of NetHsmUserKeyData objects from this NetHsmUserMapping.
Based on a NetHsmUserKeysFilter it is possible to target only namespaced or system-wide,
or all user mappings that have associated key configs.
Trait Implementations§
Source§impl Clone for NetHsmUserMapping
impl Clone for NetHsmUserMapping
Source§fn clone(&self) -> NetHsmUserMapping
fn clone(&self) -> NetHsmUserMapping
1.0.0 · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for NetHsmUserMapping
impl Debug for NetHsmUserMapping
Source§impl<'de> Deserialize<'de> for NetHsmUserMapping
impl<'de> Deserialize<'de> for NetHsmUserMapping
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Source§impl Hash for NetHsmUserMapping
impl Hash for NetHsmUserMapping
Source§impl MappingAuthorizedKeyEntry for NetHsmUserMapping
impl MappingAuthorizedKeyEntry for NetHsmUserMapping
authorized_keys entry. Read moreSource§impl<'a> MappingBackendDomain<NetHsmConfigDomainFilter<'a>> for NetHsmUserMapping
impl<'a> MappingBackendDomain<NetHsmConfigDomainFilter<'a>> for NetHsmUserMapping
Source§fn backend_domain(
&self,
filter: Option<&NetHsmConfigDomainFilter<'_>>,
) -> Option<String>
fn backend_domain( &self, filter: Option<&NetHsmConfigDomainFilter<'_>>, ) -> Option<String>
Source§impl<'a> MappingBackendKeyId<NetHsmBackendKeyIdFilter<'a>> for NetHsmUserMapping
impl<'a> MappingBackendKeyId<NetHsmBackendKeyIdFilter<'a>> for NetHsmUserMapping
Source§fn backend_key_id(
&self,
filter: &NetHsmBackendKeyIdFilter<'a>,
) -> Option<String>
fn backend_key_id( &self, filter: &NetHsmBackendKeyIdFilter<'a>, ) -> Option<String>
String representing a backend key ID according to a filter.Source§impl MappingBackendUserIds for NetHsmUserMapping
impl MappingBackendUserIds for NetHsmUserMapping
Source§fn backend_user_ids(&self, filter: BackendUserIdFilter) -> Vec<String>
fn backend_user_ids(&self, filter: BackendUserIdFilter) -> Vec<String>
Strings representing backend User IDs according to a filter.Source§fn backend_user_with_passphrase(
&self,
name: &str,
passphrase: Passphrase,
) -> Result<Box<dyn UserWithPassphrase>, Error>
fn backend_user_with_passphrase( &self, name: &str, passphrase: Passphrase, ) -> Result<Box<dyn UserWithPassphrase>, Error>
UserWithPassphrase implementation for a backend user. Read moreSource§fn backend_users_with_new_passphrase(
&self,
filter: BackendUserIdFilter,
) -> Vec<Box<dyn UserWithPassphrase>>
fn backend_users_with_new_passphrase( &self, filter: BackendUserIdFilter, ) -> Vec<Box<dyn UserWithPassphrase>>
Source§impl MappingBackendUserSecrets for NetHsmUserMapping
impl MappingBackendUserSecrets for NetHsmUserMapping
Source§fn create_non_admin_backend_user_secrets(
&self,
secret_handling: NonAdministrativeSecretHandling,
) -> Result<Option<Vec<Box<dyn UserWithPassphrase>>>, Error>
fn create_non_admin_backend_user_secrets( &self, secret_handling: NonAdministrativeSecretHandling, ) -> Result<Option<Vec<Box<dyn UserWithPassphrase>>>, Error>
Source§fn load_non_admin_backend_user_secrets(
&self,
secret_handling: NonAdministrativeSecretHandling,
filter: NonAdminBackendUserIdFilter,
) -> Result<Option<Vec<Box<dyn UserWithPassphrase>>>, Error>
fn load_non_admin_backend_user_secrets( &self, secret_handling: NonAdministrativeSecretHandling, filter: NonAdminBackendUserIdFilter, ) -> Result<Option<Vec<Box<dyn UserWithPassphrase>>>, Error>
filter. Read moreSource§impl MappingSystemUserId for NetHsmUserMapping
impl MappingSystemUserId for NetHsmUserMapping
Source§fn system_user_id(&self) -> Option<&SystemUserId>
fn system_user_id(&self) -> Option<&SystemUserId>
SystemUserId. Read moreSource§impl Ord for NetHsmUserMapping
impl Ord for NetHsmUserMapping
Source§fn cmp(&self, other: &NetHsmUserMapping) -> Ordering
fn cmp(&self, other: &NetHsmUserMapping) -> Ordering
1.21.0 · Source§fn max(self, other: Self) -> Selfwhere
Self: Sized,
fn max(self, other: Self) -> Selfwhere
Self: Sized,
Source§impl PartialEq for NetHsmUserMapping
impl PartialEq for NetHsmUserMapping
Source§impl PartialOrd for NetHsmUserMapping
impl PartialOrd for NetHsmUserMapping
Source§impl Serialize for NetHsmUserMapping
impl Serialize for NetHsmUserMapping
impl Eq for NetHsmUserMapping
impl StructuralPartialEq for NetHsmUserMapping
Auto Trait Implementations§
impl Freeze for NetHsmUserMapping
impl RefUnwindSafe for NetHsmUserMapping
impl Send for NetHsmUserMapping
impl Sync for NetHsmUserMapping
impl Unpin for NetHsmUserMapping
impl UnwindSafe for NetHsmUserMapping
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<T> Conv for T
impl<T> Conv for T
§impl<T> FmtForward for T
impl<T> FmtForward for T
§fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
self to use its Binary implementation when Debug-formatted.§fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
self to use its Display implementation when
Debug-formatted.§fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
self to use its LowerExp implementation when
Debug-formatted.§fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
self to use its LowerHex implementation when
Debug-formatted.§fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
self to use its Octal implementation when Debug-formatted.§fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
self to use its Pointer implementation when
Debug-formatted.§fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
self to use its UpperExp implementation when
Debug-formatted.§fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
self to use its UpperHex implementation when
Debug-formatted.§fn fmt_list(self) -> FmtList<Self>where
&'a Self: for<'a> IntoIterator,
fn fmt_list(self) -> FmtList<Self>where
&'a Self: for<'a> IntoIterator,
§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read more§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read more§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
self, then passes self.as_ref() into the pipe function.§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
self, then passes self.as_mut() into the pipe
function.§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
self, then passes self.deref() into the pipe function.§impl<T> Tap for T
impl<T> Tap for T
§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Borrow<B> of a value. Read more§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
BorrowMut<B> of a value. Read more§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
AsRef<R> view of a value. Read more§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
AsMut<R> view of a value. Read more§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Deref::Target of a value. Read more§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Deref::Target of a value. Read more§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
.tap() only in debug builds, and is erased in release builds.§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
.tap_mut() only in debug builds, and is erased in release
builds.§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
.tap_borrow() only in debug builds, and is erased in release
builds.§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
.tap_borrow_mut() only in debug builds, and is erased in release
builds.§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
.tap_ref() only in debug builds, and is erased in release
builds.§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
.tap_ref_mut() only in debug builds, and is erased in release
builds.§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
.tap_deref() only in debug builds, and is erased in release
builds.