1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
//! **The two acts over a trust root that already exists** (REMOTE §8, §8.2;
//! bl-64a7, bl-52f4): one extra client leaf under a stated common name, and
//! this box's own server leaf re-issued over more hosts.
//!
//! Split from [`provision`](super) at the seam the module's own vocabulary
//! already draws: **what a box lacks** is a question the mint answers, once,
//! and it may found a CA to answer it; **one more leaf, now** is a question
//! only a box that already holds the CA key can be asked, and answering it
//! founds nothing, writes no address and touches no other leaf. The rotation
//! guard standing in front of a mint would be exactly backwards in front of
//! either of these — both are performed *because* the directory already holds
//! material.
use openssl;
use ;
use ;
/// Issue **one extra client leaf** under a stated common name — the host half
/// of provisioning an entry (REMOTE §8.2, bl-64a7). The operator mints a leaf
/// for a visiting box; the anchors, that leaf and its key are then carried to
/// it by hand, which is §1.4 verbatim and forever. Nothing here is reachable
/// from the channel, and nothing here founds a trust root: this is one more
/// artifact the one recipe can be asked for, over a CA that already exists.
///
/// It refuses three ways, each naming its remedy:
///
/// - **An identity the registry would refuse.** The same rule, spent once
/// ([`Client::parse`](crate::registry::Client::parse)): a common name is one
/// path component and `local` is reserved for the certificate-less in-world
/// callers (§4.1). A name that could carry a separator is a name that could
/// address the filesystem — here, and again on the box that files the pair.
/// - **No CA key.** A box holding an operator's `ca.pem` with no key beside it
/// is a *client* machine, and the mint never replaces an operator's trust
/// root (§8). `ca.key`'s presence is exactly the question "can this box
/// mint?", so it is exactly the question asked here.
/// - **A pair already under that name.** Re-issuing distrusts nothing — the
/// certificate already carried away stays valid until the CA behind it is
/// rotated — so it would put two live certificates under one identity for no
/// gain. A fresh common name is the remedy; rotating the trust root stays the
/// verb's `FORCE` over the whole directory.
///
/// **`grade` is minted into the subject** (REMOTE §4.2, bl-7ff3). Making a foot
/// is minting a certificate for it, out of channel, on the operator's own CA —
/// which is exactly the friction the out-of-channel ruling wants, and the
/// reason the grade is not a registration field a gesture over the wire could
/// widen, nor a config file on the box being trusted.
pub
/// **Every file a client leaf's bundle is, and the name each lands under**
/// (REMOTE §8.2, §13.2; bl-9043): the pair [`issue`] wrote — renamed to the
/// client end's own names, since the common name inside is the identity — the
/// anchors, and on a box holding rendezvous material `rendezvous.pub` and
/// `pairing.salt`, under the names a seat reads them by. One out-of-channel
/// hand-off then carries everything a seat or a foot needs; a loopback box
/// minted no rendezvous material and hands off none.
pub
/// Re-issue **this box's own server leaf** over the CA already here (REMOTE §8,
/// bl-52f4), covering every host stated. It is the same kind of act as
/// [`issue`] and carries the same guard: a trust root that already exists, no
/// CA founded, no address written, no other leaf touched.
///
/// **It is not a rotation, and that is the whole point.** A client verifies the
/// CA, so the one artifact whose replacement strands nobody is the server's own
/// leaf — while `FORCE=1` re-founds the CA and distrusts every leaf already
/// carried to another box. Widening what a certificate covers used to cost that
/// fleet; here it costs one signature.
///
/// The pair is removed before it is re-minted so a failure leaves NO leaf
/// rather than a new key beside an old certificate: absence is a state
/// [`ensure`](super::ensure) heals on the next boot, and a mismatched pair is a handshake that
/// fails for a reason nothing can read.
pub
/// The one guard in front of every act over a trust root that already exists
/// ([`issue`], [`reissue`]). A box holding an operator's `ca.pem` with no key
/// beside it is a *client* machine, and the mint never replaces an operator's
/// trust root (§8) — so `ca.key`'s presence is exactly the question "can this
/// box issue?", asked once for both acts.
/// **State the address this engine binds** (REMOTE §8 as amended, bl-98ef) —
/// the third act over a trust root that already exists, and the smallest: one
/// line of text, no signature, nothing distrusted.
///
/// It exists because the fact had no non-destructive spelling. `address` is
/// written once, by whichever mint founded the directory, and a boot that
/// provisioned its own box wrote `127.0.0.1:0` — a request only the listener
/// ever learns the answer to, which no seat can dial and no enrollment can put
/// in a QR. The only act that could replace it was `FORCE=1`, which re-founds
/// the CA and distrusts every leaf already carried to every other box. Saying
/// where a server listens is not a rotation, so this is not one.
///
/// It writes rather than adds, unlike everything else here: the endpoint is the
/// one fact this file is the home of, and stating it is the whole act.
pub