2015-05-28 21:28:50 +00:00
|
|
|
package http
|
|
|
|
|
|
|
|
import (
|
2018-01-19 06:44:44 +00:00
|
|
|
"context"
|
2016-08-15 20:01:15 +00:00
|
|
|
"encoding/base64"
|
2015-05-28 21:28:50 +00:00
|
|
|
"encoding/hex"
|
|
|
|
"errors"
|
|
|
|
"fmt"
|
|
|
|
"net/http"
|
|
|
|
|
2017-02-16 20:15:02 +00:00
|
|
|
"github.com/hashicorp/vault/helper/consts"
|
2015-12-16 21:56:15 +00:00
|
|
|
"github.com/hashicorp/vault/helper/pgpkeys"
|
2015-05-28 21:28:50 +00:00
|
|
|
"github.com/hashicorp/vault/vault"
|
|
|
|
)
|
|
|
|
|
2016-04-04 14:44:22 +00:00
|
|
|
func handleSysRekeyInit(core *vault.Core, recovery bool) http.Handler {
|
2015-05-28 21:28:50 +00:00
|
|
|
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
2016-09-13 15:59:12 +00:00
|
|
|
standby, _ := core.Standby()
|
|
|
|
if standby {
|
|
|
|
respondStandby(core, w, r.URL)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2017-02-16 20:15:02 +00:00
|
|
|
repState := core.ReplicationState()
|
2017-09-04 23:38:37 +00:00
|
|
|
if repState.HasState(consts.ReplicationPerformanceSecondary) {
|
2017-02-16 20:15:02 +00:00
|
|
|
respondError(w, http.StatusBadRequest,
|
|
|
|
fmt.Errorf("rekeying can only be performed on the primary cluster when replication is activated"))
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2018-01-19 06:44:44 +00:00
|
|
|
ctx, cancel := core.GetContext()
|
|
|
|
defer cancel()
|
|
|
|
|
2016-04-04 14:44:22 +00:00
|
|
|
switch {
|
2018-01-19 08:44:06 +00:00
|
|
|
case recovery && !core.SealAccess().RecoveryKeySupported():
|
2016-04-04 14:44:22 +00:00
|
|
|
respondError(w, http.StatusBadRequest, fmt.Errorf("recovery rekeying not supported"))
|
|
|
|
case r.Method == "GET":
|
2018-01-19 06:44:44 +00:00
|
|
|
handleSysRekeyInitGet(ctx, core, recovery, w, r)
|
2016-04-04 14:44:22 +00:00
|
|
|
case r.Method == "POST" || r.Method == "PUT":
|
2018-01-19 06:44:44 +00:00
|
|
|
handleSysRekeyInitPut(ctx, core, recovery, w, r)
|
2016-04-04 14:44:22 +00:00
|
|
|
case r.Method == "DELETE":
|
|
|
|
handleSysRekeyInitDelete(core, recovery, w, r)
|
2015-05-28 21:28:50 +00:00
|
|
|
default:
|
|
|
|
respondError(w, http.StatusMethodNotAllowed, nil)
|
|
|
|
}
|
|
|
|
})
|
|
|
|
}
|
|
|
|
|
2018-01-19 06:44:44 +00:00
|
|
|
func handleSysRekeyInitGet(ctx context.Context, core *vault.Core, recovery bool, w http.ResponseWriter, r *http.Request) {
|
|
|
|
barrierConfig, err := core.SealAccess().BarrierConfig(ctx)
|
2015-05-28 21:28:50 +00:00
|
|
|
if err != nil {
|
|
|
|
respondError(w, http.StatusInternalServerError, err)
|
|
|
|
return
|
|
|
|
}
|
2016-04-04 14:44:22 +00:00
|
|
|
if barrierConfig == nil {
|
2015-05-28 21:28:50 +00:00
|
|
|
respondError(w, http.StatusBadRequest, fmt.Errorf(
|
|
|
|
"server is not yet initialized"))
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
// Get the rekey configuration
|
2016-04-04 14:44:22 +00:00
|
|
|
rekeyConf, err := core.RekeyConfig(recovery)
|
2015-05-28 21:28:50 +00:00
|
|
|
if err != nil {
|
|
|
|
respondError(w, http.StatusInternalServerError, err)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
// Get the progress
|
2016-04-04 14:44:22 +00:00
|
|
|
progress, err := core.RekeyProgress(recovery)
|
2015-05-28 21:28:50 +00:00
|
|
|
if err != nil {
|
|
|
|
respondError(w, http.StatusInternalServerError, err)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2018-01-19 06:44:44 +00:00
|
|
|
sealThreshold, err := core.RekeyThreshold(ctx, recovery)
|
2016-04-04 14:44:22 +00:00
|
|
|
if err != nil {
|
|
|
|
respondError(w, http.StatusInternalServerError, err)
|
2016-04-25 19:39:04 +00:00
|
|
|
return
|
2016-04-04 14:44:22 +00:00
|
|
|
}
|
|
|
|
|
2015-05-28 21:28:50 +00:00
|
|
|
// Format the status
|
|
|
|
status := &RekeyStatusResponse{
|
|
|
|
Started: false,
|
|
|
|
T: 0,
|
|
|
|
N: 0,
|
|
|
|
Progress: progress,
|
2016-04-04 14:44:22 +00:00
|
|
|
Required: sealThreshold,
|
2015-05-28 21:28:50 +00:00
|
|
|
}
|
|
|
|
if rekeyConf != nil {
|
2015-12-16 21:56:15 +00:00
|
|
|
status.Nonce = rekeyConf.Nonce
|
2015-05-28 21:28:50 +00:00
|
|
|
status.Started = true
|
|
|
|
status.T = rekeyConf.SecretThreshold
|
|
|
|
status.N = rekeyConf.SecretShares
|
2015-12-16 21:56:15 +00:00
|
|
|
if rekeyConf.PGPKeys != nil && len(rekeyConf.PGPKeys) != 0 {
|
|
|
|
pgpFingerprints, err := pgpkeys.GetFingerprints(rekeyConf.PGPKeys, nil)
|
|
|
|
if err != nil {
|
|
|
|
respondError(w, http.StatusInternalServerError, err)
|
2016-04-25 19:39:04 +00:00
|
|
|
return
|
2015-12-16 21:56:15 +00:00
|
|
|
}
|
|
|
|
status.PGPFingerprints = pgpFingerprints
|
|
|
|
status.Backup = rekeyConf.Backup
|
|
|
|
}
|
2015-05-28 21:28:50 +00:00
|
|
|
}
|
|
|
|
respondOk(w, status)
|
|
|
|
}
|
|
|
|
|
2018-01-19 06:44:44 +00:00
|
|
|
func handleSysRekeyInitPut(ctx context.Context, core *vault.Core, recovery bool, w http.ResponseWriter, r *http.Request) {
|
2015-05-28 21:28:50 +00:00
|
|
|
// Parse the request
|
|
|
|
var req RekeyRequest
|
2016-12-01 18:59:00 +00:00
|
|
|
if err := parseRequest(r, w, &req); err != nil {
|
2015-05-28 21:28:50 +00:00
|
|
|
respondError(w, http.StatusBadRequest, err)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2015-12-16 21:56:15 +00:00
|
|
|
if req.Backup && len(req.PGPKeys) == 0 {
|
|
|
|
respondError(w, http.StatusBadRequest, fmt.Errorf("cannot request a backup of the new keys without providing PGP keys for encryption"))
|
2016-04-25 19:39:04 +00:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2017-10-23 21:39:21 +00:00
|
|
|
// If the seal supports recovery keys and stored keys, then we allow rekeying the barrier key
|
|
|
|
// iff the secret shares, secret threshold, and stored shares are set to 1.
|
2018-01-19 08:44:06 +00:00
|
|
|
if !recovery && core.SealAccess().RecoveryKeySupported() && core.SealAccess().StoredKeysSupported() {
|
2017-10-23 21:39:21 +00:00
|
|
|
if req.SecretShares != 1 || req.SecretThreshold != 1 || req.StoredShares != 1 {
|
|
|
|
respondError(w, http.StatusBadRequest, fmt.Errorf("secret shares, secret threshold, and stored shares must be set to 1"))
|
|
|
|
return
|
|
|
|
}
|
2015-12-16 21:56:15 +00:00
|
|
|
}
|
|
|
|
|
2017-01-12 05:05:41 +00:00
|
|
|
if len(req.PGPKeys) > 0 && len(req.PGPKeys) != req.SecretShares-req.StoredShares {
|
|
|
|
respondError(w, http.StatusBadRequest, fmt.Errorf("incorrect number of PGP keys for rekey"))
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2015-05-28 21:28:50 +00:00
|
|
|
// Initialize the rekey
|
2018-01-19 08:44:06 +00:00
|
|
|
err := core.RekeyInit(&vault.SealConfig{
|
2015-05-28 21:28:50 +00:00
|
|
|
SecretShares: req.SecretShares,
|
|
|
|
SecretThreshold: req.SecretThreshold,
|
2016-04-04 14:44:22 +00:00
|
|
|
StoredShares: req.StoredShares,
|
2015-08-25 22:33:58 +00:00
|
|
|
PGPKeys: req.PGPKeys,
|
2015-12-16 21:56:15 +00:00
|
|
|
Backup: req.Backup,
|
2016-04-04 14:44:22 +00:00
|
|
|
}, recovery)
|
2015-05-28 21:28:50 +00:00
|
|
|
if err != nil {
|
|
|
|
respondError(w, http.StatusBadRequest, err)
|
|
|
|
return
|
|
|
|
}
|
2016-02-12 19:24:36 +00:00
|
|
|
|
2018-01-19 06:44:44 +00:00
|
|
|
handleSysRekeyInitGet(ctx, core, recovery, w, r)
|
2015-05-28 21:28:50 +00:00
|
|
|
}
|
|
|
|
|
2016-04-04 14:44:22 +00:00
|
|
|
func handleSysRekeyInitDelete(core *vault.Core, recovery bool, w http.ResponseWriter, r *http.Request) {
|
|
|
|
err := core.RekeyCancel(recovery)
|
2015-05-28 21:28:50 +00:00
|
|
|
if err != nil {
|
|
|
|
respondError(w, http.StatusInternalServerError, err)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
respondOk(w, nil)
|
|
|
|
}
|
|
|
|
|
2016-04-04 14:44:22 +00:00
|
|
|
func handleSysRekeyUpdate(core *vault.Core, recovery bool) http.Handler {
|
2015-05-28 21:28:50 +00:00
|
|
|
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
2016-09-13 15:59:12 +00:00
|
|
|
standby, _ := core.Standby()
|
|
|
|
if standby {
|
|
|
|
respondStandby(core, w, r.URL)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2015-05-28 21:28:50 +00:00
|
|
|
// Parse the request
|
|
|
|
var req RekeyUpdateRequest
|
2016-12-01 18:59:00 +00:00
|
|
|
if err := parseRequest(r, w, &req); err != nil {
|
2015-05-28 21:28:50 +00:00
|
|
|
respondError(w, http.StatusBadRequest, err)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
if req.Key == "" {
|
|
|
|
respondError(
|
|
|
|
w, http.StatusBadRequest,
|
2017-03-14 21:10:43 +00:00
|
|
|
errors.New("'key' must be specified in request body as JSON"))
|
2015-05-28 21:28:50 +00:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2016-08-15 20:01:15 +00:00
|
|
|
// Decode the key, which is base64 or hex encoded
|
|
|
|
min, max := core.BarrierKeyLength()
|
2015-05-28 21:28:50 +00:00
|
|
|
key, err := hex.DecodeString(req.Key)
|
2016-08-15 20:01:15 +00:00
|
|
|
// We check min and max here to ensure that a string that is base64
|
|
|
|
// encoded but also valid hex will not be valid and we instead base64
|
|
|
|
// decode it
|
|
|
|
if err != nil || len(key) < min || len(key) > max {
|
|
|
|
key, err = base64.StdEncoding.DecodeString(req.Key)
|
|
|
|
if err != nil {
|
|
|
|
respondError(
|
|
|
|
w, http.StatusBadRequest,
|
|
|
|
errors.New("'key' must be a valid hex or base64 string"))
|
|
|
|
return
|
|
|
|
}
|
2015-05-28 21:28:50 +00:00
|
|
|
}
|
|
|
|
|
2018-01-19 06:44:44 +00:00
|
|
|
ctx, cancel := core.GetContext()
|
|
|
|
defer cancel()
|
|
|
|
|
2015-05-28 21:28:50 +00:00
|
|
|
// Use the key to make progress on rekey
|
2018-01-19 06:44:44 +00:00
|
|
|
result, err := core.RekeyUpdate(ctx, key, req.Nonce, recovery)
|
2015-05-28 21:28:50 +00:00
|
|
|
if err != nil {
|
|
|
|
respondError(w, http.StatusBadRequest, err)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
// Format the response
|
|
|
|
resp := &RekeyUpdateResponse{}
|
|
|
|
if result != nil {
|
|
|
|
resp.Complete = true
|
2015-12-16 21:56:15 +00:00
|
|
|
resp.Nonce = req.Nonce
|
2016-08-15 20:01:15 +00:00
|
|
|
resp.Backup = result.Backup
|
|
|
|
resp.PGPFingerprints = result.PGPFingerprints
|
2015-05-28 21:28:50 +00:00
|
|
|
|
|
|
|
// Encode the keys
|
|
|
|
keys := make([]string, 0, len(result.SecretShares))
|
2016-08-15 20:01:15 +00:00
|
|
|
keysB64 := make([]string, 0, len(result.SecretShares))
|
2015-05-28 21:28:50 +00:00
|
|
|
for _, k := range result.SecretShares {
|
|
|
|
keys = append(keys, hex.EncodeToString(k))
|
2016-08-15 20:01:15 +00:00
|
|
|
keysB64 = append(keysB64, base64.StdEncoding.EncodeToString(k))
|
2015-05-28 21:28:50 +00:00
|
|
|
}
|
|
|
|
resp.Keys = keys
|
2016-08-15 20:01:15 +00:00
|
|
|
resp.KeysB64 = keysB64
|
2017-01-17 20:43:10 +00:00
|
|
|
respondOk(w, resp)
|
|
|
|
} else {
|
2018-01-19 06:44:44 +00:00
|
|
|
handleSysRekeyInitGet(ctx, core, recovery, w, r)
|
2015-05-28 21:28:50 +00:00
|
|
|
}
|
|
|
|
})
|
|
|
|
}
|
|
|
|
|
|
|
|
type RekeyRequest struct {
|
2015-08-25 21:24:19 +00:00
|
|
|
SecretShares int `json:"secret_shares"`
|
|
|
|
SecretThreshold int `json:"secret_threshold"`
|
2016-04-04 14:44:22 +00:00
|
|
|
StoredShares int `json:"stored_shares"`
|
2015-08-25 22:33:58 +00:00
|
|
|
PGPKeys []string `json:"pgp_keys"`
|
2015-12-16 21:56:15 +00:00
|
|
|
Backup bool `json:"backup"`
|
2015-05-28 21:28:50 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
type RekeyStatusResponse struct {
|
2015-12-16 21:56:15 +00:00
|
|
|
Nonce string `json:"nonce"`
|
|
|
|
Started bool `json:"started"`
|
|
|
|
T int `json:"t"`
|
|
|
|
N int `json:"n"`
|
|
|
|
Progress int `json:"progress"`
|
|
|
|
Required int `json:"required"`
|
|
|
|
PGPFingerprints []string `json:"pgp_fingerprints"`
|
|
|
|
Backup bool `json:"backup"`
|
2015-05-28 21:28:50 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
type RekeyUpdateRequest struct {
|
2015-12-16 21:56:15 +00:00
|
|
|
Nonce string
|
|
|
|
Key string
|
2015-05-28 21:28:50 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
type RekeyUpdateResponse struct {
|
2015-12-16 21:56:15 +00:00
|
|
|
Nonce string `json:"nonce"`
|
|
|
|
Complete bool `json:"complete"`
|
|
|
|
Keys []string `json:"keys"`
|
2016-08-15 20:01:15 +00:00
|
|
|
KeysB64 []string `json:"keys_base64"`
|
2015-12-16 21:56:15 +00:00
|
|
|
PGPFingerprints []string `json:"pgp_fingerprints"`
|
|
|
|
Backup bool `json:"backup"`
|
2015-05-28 21:28:50 +00:00
|
|
|
}
|