mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
rust: Refactoring and reduce API surface
Prepare pv & pv_core crates to be released on crates.io: * Remove any unused API to stay flexible * Remove utils dependency * Move cli, tmpfile and version utilities to local utils crate * Use the new utilities in the pv tools * Rename Secret into Confidential to avoid confusion of Secret (now Confidential) and AddSecret requests. * Move the uvsecret module out of the request module and change the name to secret. * Cleanup dependencies * Precise and correct minimal dependency versions * Inline `Aes256Key::from_digest` The cleanup ensures that the code also compiles with the dependencies resolved to their minimal versions using: $ cargo +nightly -Z minimal-versions update $ cargo build For more information refer to this blog post: https://users.rust-lang.org/t/psa-please-specify-precise-dependency-versions-in-cargo-toml/71277/8 Signed-off-by: Marc Hartmayer <mhartmay@de.ibm.com> Signed-off-by: Steffen Eiden <seiden@linux.ibm.com>
This commit is contained in:
+3
-31
@@ -3,7 +3,7 @@
|
||||
// Copyright IBM Corp. 2023
|
||||
use crate::{Error, Result};
|
||||
use openssl::{
|
||||
pkey::{PKey, Private},
|
||||
error::ErrorStack,
|
||||
x509::{X509Crl, X509},
|
||||
};
|
||||
|
||||
@@ -26,29 +26,15 @@ pub fn read_crls(buf: &[u8]) -> Result<Vec<X509Crl>> {
|
||||
/// # Errors
|
||||
///
|
||||
/// This function will return an error if the underlying OpenSSL implementation cannot parse `buf`
|
||||
|
||||
pub fn read_certs(buf: &[u8]) -> Result<Vec<X509>> {
|
||||
pub fn read_certs(buf: &[u8]) -> Result<Vec<X509>, ErrorStack> {
|
||||
X509::from_der(buf)
|
||||
.map(|crt| vec![crt])
|
||||
.or_else(|_| X509::stack_from_pem(buf))
|
||||
.map_err(Error::Crypto)
|
||||
}
|
||||
|
||||
/// Read+parse the first key from the buffer.
|
||||
///
|
||||
/// # Errors
|
||||
///
|
||||
/// This function will return an error if the underlying OpenSSL implementation cannot parse `buf`
|
||||
/// as `DER` or `PEM`.
|
||||
pub fn read_private_key(buf: &[u8]) -> Result<PKey<Private>> {
|
||||
PKey::private_key_from_der(buf)
|
||||
.or_else(|_| PKey::private_key_from_pem(buf))
|
||||
.map_err(Error::Crypto)
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use crate::{get_test_asset, test_utils::*};
|
||||
use crate::test_utils::*;
|
||||
|
||||
#[test]
|
||||
fn read_crls() {
|
||||
@@ -69,18 +55,4 @@ mod tests {
|
||||
assert_eq!(super::read_certs(&crt_der).unwrap().len(), 1);
|
||||
assert_eq!(super::read_certs(&fail).unwrap().len(), 0);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn read_private_key() {
|
||||
let key = get_test_asset!("keys/rsa3072key.pem");
|
||||
let key = super::read_private_key(key).unwrap();
|
||||
assert_eq!(key.rsa().unwrap().size(), 384);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn read_private_key_fail() {
|
||||
let key = get_test_asset!("exp/secure_guest.hdr");
|
||||
let key = super::read_private_key(key);
|
||||
assert!(key.is_err());
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user