Skip to main content

wire_e2e_identity/pki_env/
crl.rs

1use std::collections::HashMap;
2
3use core_crypto_keystore::{Transaction, entities::X509Crl, traits::EntityDatabaseMutation as _};
4
5use super::{Error, Result};
6use crate::pki_env::{PkiEnvironment, hooks::HttpMethod};
7
8impl PkiEnvironment {
9    /// Fetch certificate revocation lists from the given URIs, return a map from the URLs to a DER-encoded certificate
10    /// list.
11    pub async fn fetch_crls(&self, uris: impl Iterator<Item = &str>) -> Result<HashMap<String, Vec<u8>>> {
12        let mut crls = HashMap::with_capacity(uris.size_hint().0);
13
14        for uri in uris {
15            let uri = uri.to_owned();
16            let response = self
17                .hooks
18                .http_request(HttpMethod::Get, uri.clone(), vec![], vec![])
19                .await?;
20            if !(200..300).contains(&response.status) {
21                return Err(Error::CrlFetchUnsuccessful {
22                    uri,
23                    status: response.status,
24                });
25            }
26
27            crls.insert(uri, response.body);
28        }
29
30        Ok(crls)
31    }
32
33    /// Validate the CRL (trust anchors must be configured prior to this) and
34    /// save it to the database.
35    pub async fn save_crl(&self, tx: &Transaction, crl_dp: &str, crl_der: &[u8]) -> Result<()> {
36        let guard = self.env.lock().await;
37
38        let crl = crate::validation::validate_crl(&guard, crl_der)?;
39        guard.add_crl(crl_der, &crl, crl_dp).map_err(Error::Certval)?;
40
41        let crl_data = X509Crl {
42            content: crl_der.to_owned(),
43            distribution_point: crl_dp.to_owned(),
44        };
45
46        crl_data.save(tx).map_err(Into::into)
47    }
48}