Skip to main content

rusthound_ce/modules/adcs/
mod.rs

1//! ADCS active modules, ESC8 web enrollment probe.
2//!
3//! Exposes `probe_enterpriseca_esc8`, called from `run_modules` after LDAP
4//! collection, once per EnterpriseCA, on Tokio's blocking thread pool.
5
6pub mod esc8;
7
8use crate::modules::adcs::esc8::{check_esc8, Esc8Result};
9use crate::objects::enterpriseca::WebEnrollmentEndpoint;
10
11// Public result type
12
13/// ESC8 probe data ready to inject into EnterpriseCA.
14pub struct Esc8Data {
15    pub http_enrollment_endpoints: Vec<WebEnrollmentEndpoint>,
16}
17
18impl Default for Esc8Data {
19    fn default() -> Self {
20        Self { http_enrollment_endpoints: vec![] }
21    }
22}
23
24impl From<Esc8Result> for Esc8Data {
25    fn from(r: Esc8Result) -> Self {
26        Self { http_enrollment_endpoints: r.endpoints }
27    }
28}
29
30// Public API
31
32/// Probe web enrollment endpoints for a single Enterprise CA.
33///
34/// Always returns the two certsrv endpoints, including when the host is
35/// unreachable: a negative probe is reported, not dropped. CES endpoints are
36/// added when `ca_name` is non-empty. Returns the empty default only when
37/// `dns_host` is empty, since there is no URL to build in that case.
38/// DCOnly guard is handled by the caller (`run_modules`).
39pub fn probe_enterpriseca_esc8(dns_host: &str, ca_name: &str) -> Esc8Data {
40    if dns_host.is_empty() {
41        log::debug!("[adcs] ESC8 probe skipped: CA has no dnshostname");
42        return Esc8Data::default();
43    }
44    Esc8Data::from(check_esc8(dns_host, ca_name))
45}