Skip to main content

YubiHsm2Backend

Struct YubiHsm2Backend 

Source
pub struct YubiHsm2Backend<'admin_creds, 'config> {
    connector: Connector,
    runner: ScenarioRunner,
    admin_credentials: &'admin_creds YubiHsm2AdminCredentials,
    yubihsm2_config: &'config YubiHsm2Config,
    admin_user_mappings_and_creds: UserMappingsAndCredentials<'config, 'admin_creds>,
    default_credentials: RefCell<bool>,
}
Expand description

A YubiHSM2 backend that provides control over a YubiHSM2 and its data.

Using a specific Connector, it is possible to synchronize a YubiHSM2 with the data provided by a YubiHsm2AdminCredentials and a YubiHsm2Config.

Fields§

§connector: Connector§runner: ScenarioRunner§admin_credentials: &'admin_creds YubiHsm2AdminCredentials§yubihsm2_config: &'config YubiHsm2Config§admin_user_mappings_and_creds: UserMappingsAndCredentials<'config, 'admin_creds>§default_credentials: RefCell<bool>

Indication whether the default credentials are in use currently.

Implementations§

Source§

impl<'admin_creds, 'config> YubiHsm2Backend<'admin_creds, 'config>

Source

pub fn new( connector: Connector, admin_credentials: &'admin_creds YubiHsm2AdminCredentials, signstar_config: &'config Config, ) -> Result<Option<Self>, Error>

Creates a new YubiHsm2Backend.

Returns Ok(None) if signstar_config contains no YubiHsm2Config.

§Errors

Returns an error if

  • the iteration of the admin_credentials does not match that of the signstar_config
  • a set of administrative user mappings and corresponding credentials cannot be created from the admin_credentials and signstar_config
Source

pub fn yubihsm2_config(&self) -> &YubiHsm2Config

Returns a reference to the YubiHsm2Config used for the backend.

Source

pub fn default_credentials_in_use(&self) -> bool

Returns whether the default administrative credentials are in use.

§Note

The default administrative credentials are considered no longer in use, if logging in with them failed once.

Source

fn check_set_default_credentials(&self) -> bool

Checks whether the default credentials are in use and sets up YubiHsm2Backend accordingly.

Returns true, if YubiHsm2AdminCredentials::default_credentials can be used to connect to the YubiHSM2 and the authentication key object contains the required capabilities and domains. Returns false in all other cases.

Source

pub fn sync(&self, user_credentials: &[Credentials]) -> Result<(), Error>

Syncs the state of a Signstar configuration with the backend using credentials for users in non-administrative roles.

Source

fn add_openpgp_certificates( &self, non_admin_user_mappings_and_creds: &UserMappingsAndCredentials<'_, '_>, ) -> Result<(), Error>

Adds the OpenPGP certificates for keys that use them.

§Note

Does not overwrite existing data!

§Errors

Returns an error, if

  • a usable administrative authentication key cannot be found
  • retrieving of opaque data info fails
  • creating an OpenPGP certificate for a signgin key fails
  • the scenario of adding OpenPGP certificates as opaque data fails
  • the return values of the scenario do not match the requested actions
Source

fn add_signing_keys(&self) -> Result<(), Error>

Adds the asymmetric signing keys.

§Note

Does not overwrite existing signing keys!

§Errors

Returns an error, if

  • a usable administrative authentication key cannot be found
  • retrieving of signing key info fails
  • the scenario of generating asymmetric signging keys fails
  • the return values of the scenario do not match the requested actions
Source

fn add_non_admin_users( &self, non_admin_user_mappings_and_creds: &UserMappingsAndCredentials<'_, '_>, ) -> Result<(), Error>

Adds non-administrative users.

§Note

Existing authentication keys are replaced!

§Errors

Returns an error, if

  • a usable administrative authentication key cannot be found
  • the list of authentication key objects cannot be retrieved from the backend
  • a new authentication key cannot be created
  • the scenario cannot be run successfully
  • one or more return values of the scenario do not match the requested actions
Source

fn add_wrap_key(&self) -> Result<(), Error>

Adds a wrap key based on the backup passphrase.

§Note

Existing wrap keys are replaced!

§Errors

Returns an error, if

  • usable administrative credentials cannot be found
  • infos about wrap keys cannot be retrieved from the backend
  • a wrap key cannot be created from the backup passphrase
  • running the scenario against the backend fails
  • the scenario’s return values do not match the request
Source

fn add_admin_users(&self) -> Result<(), Error>

Sets up all admin users in the backend.

§Note

Existing authentication keys are replaced!

§Errors

Returns an error, if

  • no usable administrative credentials can be found
  • currently used authentication keys cannot be retrieved from the backend
  • the currently used credentials cannot be found in the set of available credentials
  • the scenario for removing and/or adding all relevant administrative authentication keys fails
  • the return values for the scenario do not match the requested actions
  • the default admin credentials are still usable at the end of this function
Source

fn usable_admin_creds(&self) -> Result<Credentials, Error>

Returns the currently usable credentials for an administrative user.

§Errors

Returns an error, if no usable administrative credentials are found.

Source

pub(crate) fn user_states(&self) -> Result<Vec<YubiHsm2BackendUserData>, Error>

Returns the list of available authentication key objects in the backend.

§Errors

Returns an error, if

  • no usable administrative credentials can be found
  • retrieving the information on authentication key objects fails.
Source

pub(crate) fn key_states( &self, ) -> Result<Vec<YubiHsm2BackendUserKeyData>, Error>

Returns the list of available non-authentication key objects in the backend.

§Errors

Returns an error if

  • no usable administrative credentials can be found
  • the fetching of one or more object infos fails

Trait Implementations§

Source§

impl<'admin_creds, 'config> Debug for YubiHsm2Backend<'admin_creds, 'config>

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'admin_creds, 'config> TryFrom<&YubiHsm2Backend<'admin_creds, 'config>> for YubiHsm2BackendState

Source§

fn try_from( value: &YubiHsm2Backend<'admin_creds, 'config>, ) -> Result<Self, Self::Error>

Creates a new YubiHsm2BackendState from a YubiHsm2Backend.

§Errors

Returns an error if retrieving the user or key states from the backend fails.

Source§

type Error = Error

The type returned in the event of a conversion error.

Auto Trait Implementations§

§

impl<'admin_creds, 'config> !Freeze for YubiHsm2Backend<'admin_creds, 'config>

§

impl<'admin_creds, 'config> !RefUnwindSafe for YubiHsm2Backend<'admin_creds, 'config>

§

impl<'admin_creds, 'config> !Sync for YubiHsm2Backend<'admin_creds, 'config>

§

impl<'admin_creds, 'config> !UnwindSafe for YubiHsm2Backend<'admin_creds, 'config>

§

impl<'admin_creds, 'config> Send for YubiHsm2Backend<'admin_creds, 'config>

§

impl<'admin_creds, 'config> Unpin for YubiHsm2Backend<'admin_creds, 'config>

§

impl<'admin_creds, 'config> UnsafeUnpin for YubiHsm2Backend<'admin_creds, 'config>

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
§

impl<T> Conv for T

§

fn conv<T>(self) -> T
where Self: Into<T>,

Converts self into T using Into<T>. Read more
§

impl<T> FmtForward for T

§

fn fmt_binary(self) -> FmtBinary<Self>
where Self: Binary,

Causes self to use its Binary implementation when Debug-formatted.
§

fn fmt_display(self) -> FmtDisplay<Self>
where Self: Display,

Causes self to use its Display implementation when Debug-formatted.
§

fn fmt_lower_exp(self) -> FmtLowerExp<Self>
where Self: LowerExp,

Causes self to use its LowerExp implementation when Debug-formatted.
§

fn fmt_lower_hex(self) -> FmtLowerHex<Self>
where Self: LowerHex,

Causes self to use its LowerHex implementation when Debug-formatted.
§

fn fmt_octal(self) -> FmtOctal<Self>
where Self: Octal,

Causes self to use its Octal implementation when Debug-formatted.
§

fn fmt_pointer(self) -> FmtPointer<Self>
where Self: Pointer,

Causes self to use its Pointer implementation when Debug-formatted.
§

fn fmt_upper_exp(self) -> FmtUpperExp<Self>
where Self: UpperExp,

Causes self to use its UpperExp implementation when Debug-formatted.
§

fn fmt_upper_hex(self) -> FmtUpperHex<Self>
where Self: UpperHex,

Causes self to use its UpperHex implementation when Debug-formatted.
§

fn fmt_list(self) -> FmtList<Self>
where &'a Self: for<'a> IntoIterator,

Formats each item in a sequence. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

§

impl<T> Pipe for T
where T: ?Sized,

§

fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> R
where Self: Sized,

Pipes by value. This is generally the method you want to use. Read more
§

fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> R
where R: 'a,

Borrows self and passes that borrow into the pipe function. Read more
§

fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> R
where R: 'a,

Mutably borrows self and passes that borrow into the pipe function. Read more
§

fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
where Self: Borrow<B>, B: 'a + ?Sized, R: 'a,

Borrows self, then passes self.borrow() into the pipe function. Read more
§

fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
where Self: BorrowMut<B>, B: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.borrow_mut() into the pipe function. Read more
§

fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
where Self: AsRef<U>, U: 'a + ?Sized, R: 'a,

Borrows self, then passes self.as_ref() into the pipe function.
§

fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
where Self: AsMut<U>, U: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.as_mut() into the pipe function.
§

fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
where Self: Deref<Target = T>, T: 'a + ?Sized, R: 'a,

Borrows self, then passes self.deref() into the pipe function.
§

fn pipe_deref_mut<'a, T, R>( &'a mut self, func: impl FnOnce(&'a mut T) -> R, ) -> R
where Self: DerefMut<Target = T> + Deref, T: 'a + ?Sized, R: 'a,

Mutably borrows self, then passes self.deref_mut() into the pipe function.
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
§

impl<T> Tap for T

§

fn tap(self, func: impl FnOnce(&Self)) -> Self

Immutable access to a value. Read more
§

fn tap_mut(self, func: impl FnOnce(&mut Self)) -> Self

Mutable access to a value. Read more
§

fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
where Self: Borrow<B>, B: ?Sized,

Immutable access to the Borrow<B> of a value. Read more
§

fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
where Self: BorrowMut<B>, B: ?Sized,

Mutable access to the BorrowMut<B> of a value. Read more
§

fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
where Self: AsRef<R>, R: ?Sized,

Immutable access to the AsRef<R> view of a value. Read more
§

fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
where Self: AsMut<R>, R: ?Sized,

Mutable access to the AsMut<R> view of a value. Read more
§

fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
where Self: Deref<Target = T>, T: ?Sized,

Immutable access to the Deref::Target of a value. Read more
§

fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
where Self: DerefMut<Target = T> + Deref, T: ?Sized,

Mutable access to the Deref::Target of a value. Read more
§

fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self

Calls .tap() only in debug builds, and is erased in release builds.
§

fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self

Calls .tap_mut() only in debug builds, and is erased in release builds.
§

fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
where Self: Borrow<B>, B: ?Sized,

Calls .tap_borrow() only in debug builds, and is erased in release builds.
§

fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
where Self: BorrowMut<B>, B: ?Sized,

Calls .tap_borrow_mut() only in debug builds, and is erased in release builds.
§

fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
where Self: AsRef<R>, R: ?Sized,

Calls .tap_ref() only in debug builds, and is erased in release builds.
§

fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
where Self: AsMut<R>, R: ?Sized,

Calls .tap_ref_mut() only in debug builds, and is erased in release builds.
§

fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
where Self: Deref<Target = T>, T: ?Sized,

Calls .tap_deref() only in debug builds, and is erased in release builds.
§

fn tap_deref_mut_dbg<T>(self, func: impl FnOnce(&mut T)) -> Self
where Self: DerefMut<Target = T> + Deref, T: ?Sized,

Calls .tap_deref_mut() only in debug builds, and is erased in release builds.
§

impl<T> TryConv for T

§

fn try_conv<T>(self) -> Result<T, Self::Error>
where Self: TryInto<T>,

Attempts to convert self into T using TryInto<T>. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

§

fn vzip(self) -> V