mirror of
https://github.com/qdrant/qdrant.git
synced 2026-10-03 19:37:41 -05:00
Migrate from OpenSSL to Rustls (#1865)
* Migrate from OpenSSL to Rustls * Add TTL based certificate rotation for Rustls in actix See: <https://github.com/qdrant/qdrant/pull/1865#issuecomment-1539752859> * Update last update time when certificate is replaced * Update error message * Add option to disable certificate TTL, add TTL validation * Cleanup * Update comment for service.enable_tls, also enables TLS for gRPC * Apply suggestions from code review Co-authored-by: Roman Titov <ffuugoo@users.noreply.github.com> * Move with_buf_read into certificate_helpers, it is used there Co-authored-by: Roman Titov <ffuugoo@users.noreply.github.com> * Remove level of scoping * Add TLS enabled/disabled log messages --------- Co-authored-by: timvisee <tim@visee.me> Co-authored-by: Tim Visée <tim+github@visee.me> Co-authored-by: Roman Titov <ffuugoo@users.noreply.github.com>
This commit is contained in:
committed by
Andrey Vasnetsov
co-authored by
Roman Titov
timvisee
Tim Visée
parent
99c3592f9b
commit
403162125a
Generated
+7
-218
@@ -209,10 +209,10 @@ dependencies = [
|
||||
"actix-utils",
|
||||
"futures-core",
|
||||
"log",
|
||||
"openssl",
|
||||
"pin-project-lite",
|
||||
"tokio-openssl",
|
||||
"tokio-rustls 0.23.4",
|
||||
"tokio-util",
|
||||
"webpki-roots",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
@@ -1111,16 +1111,6 @@ dependencies = [
|
||||
"version_check",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "core-foundation"
|
||||
version = "0.9.3"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "194a7a9e6de53fa55116934067c844d9d749312f75c6f6d0980e8c252f8c2146"
|
||||
dependencies = [
|
||||
"core-foundation-sys",
|
||||
"libc",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "core-foundation-sys"
|
||||
version = "0.8.3"
|
||||
@@ -1536,21 +1526,6 @@ version = "1.0.7"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "3f9eec918d3f24069decb9af1554cad7c880e2da24a9afd88aca000531ab82c1"
|
||||
|
||||
[[package]]
|
||||
name = "foreign-types"
|
||||
version = "0.3.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "f6f339eb8adc052cd2ca78910fda869aefa38d22d5cb648e6485e4d3fc06f3b1"
|
||||
dependencies = [
|
||||
"foreign-types-shared",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "foreign-types-shared"
|
||||
version = "0.1.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "00b0228411908ca8685dba7fc2cdd70ec9990a6e753e89b6ac91a84c40fbaf4b"
|
||||
|
||||
[[package]]
|
||||
name = "form_urlencoded"
|
||||
version = "1.1.0"
|
||||
@@ -2020,19 +1995,6 @@ dependencies = [
|
||||
"tokio-io-timeout",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "hyper-tls"
|
||||
version = "0.5.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "d6183ddfa99b85da61a140bea0efc93fdf56ceaa041b37d553518030827f9905"
|
||||
dependencies = [
|
||||
"bytes",
|
||||
"hyper",
|
||||
"native-tls",
|
||||
"tokio",
|
||||
"tokio-native-tls",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "iana-time-zone"
|
||||
version = "0.1.53"
|
||||
@@ -2490,24 +2452,6 @@ version = "0.8.3"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "e5ce46fe64a9d73be07dcbe690a38ce1b293be448fd8ce1e6c1b8062c9f72c6a"
|
||||
|
||||
[[package]]
|
||||
name = "native-tls"
|
||||
version = "0.2.11"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "07226173c32f2926027b63cce4bcd8076c3552846cbe7925f3aaffeac0a3b92e"
|
||||
dependencies = [
|
||||
"lazy_static",
|
||||
"libc",
|
||||
"log",
|
||||
"openssl",
|
||||
"openssl-probe",
|
||||
"openssl-sys",
|
||||
"schannel",
|
||||
"security-framework",
|
||||
"security-framework-sys",
|
||||
"tempfile",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "nias"
|
||||
version = "0.5.0"
|
||||
@@ -2641,60 +2585,6 @@ version = "11.1.3"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "0ab1bc2a289d34bd04a330323ac98a1b4bc82c9d9fcb1e66b63caa84da26b575"
|
||||
|
||||
[[package]]
|
||||
name = "openssl"
|
||||
version = "0.10.52"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "01b8574602df80f7b85fdfc5392fa884a4e3b3f4f35402c070ab34c3d3f78d56"
|
||||
dependencies = [
|
||||
"bitflags",
|
||||
"cfg-if",
|
||||
"foreign-types",
|
||||
"libc",
|
||||
"once_cell",
|
||||
"openssl-macros",
|
||||
"openssl-sys",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openssl-macros"
|
||||
version = "0.1.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "b501e44f11665960c7e7fcf062c7d96a14ade4aa98116c004b2e37b5be7d736c"
|
||||
dependencies = [
|
||||
"proc-macro2",
|
||||
"quote",
|
||||
"syn 1.0.107",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openssl-probe"
|
||||
version = "0.1.5"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "ff011a302c396a5197692431fc1948019154afc178baf7d8e37367442a4601cf"
|
||||
|
||||
[[package]]
|
||||
name = "openssl-src"
|
||||
version = "111.25.0+1.1.1t"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "3173cd3626c43e3854b1b727422a276e568d9ec5fe8cec197822cf52cfb743d6"
|
||||
dependencies = [
|
||||
"cc",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "openssl-sys"
|
||||
version = "0.9.87"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "8e17f59264b2809d77ae94f0e1ebabc434773f370d6ca667bd223ea10e06cc7e"
|
||||
dependencies = [
|
||||
"cc",
|
||||
"libc",
|
||||
"openssl-src",
|
||||
"pkg-config",
|
||||
"vcpkg",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "ordered-float"
|
||||
version = "2.10.0"
|
||||
@@ -3151,13 +3041,14 @@ dependencies = [
|
||||
"log",
|
||||
"num-traits",
|
||||
"num_cpus",
|
||||
"openssl",
|
||||
"parking_lot",
|
||||
"prometheus",
|
||||
"prost",
|
||||
"raft",
|
||||
"raft-proto",
|
||||
"reqwest",
|
||||
"rustls 0.20.7",
|
||||
"rustls-pemfile",
|
||||
"rusty-hook",
|
||||
"schemars",
|
||||
"sealed_test",
|
||||
@@ -3428,12 +3319,10 @@ dependencies = [
|
||||
"http-body",
|
||||
"hyper",
|
||||
"hyper-rustls",
|
||||
"hyper-tls",
|
||||
"ipnet",
|
||||
"js-sys",
|
||||
"log",
|
||||
"mime",
|
||||
"native-tls",
|
||||
"once_cell",
|
||||
"percent-encoding",
|
||||
"pin-project-lite",
|
||||
@@ -3443,7 +3332,6 @@ dependencies = [
|
||||
"serde_json",
|
||||
"serde_urlencoded",
|
||||
"tokio",
|
||||
"tokio-native-tls",
|
||||
"tokio-rustls 0.23.4",
|
||||
"tokio-util",
|
||||
"tower-service",
|
||||
@@ -3639,11 +3527,11 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "rustls-pemfile"
|
||||
version = "1.0.1"
|
||||
version = "1.0.2"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "0864aeff53f8c05aa08d86e5ef839d3dfcf07aeba2db32f12db0ef716e87bd55"
|
||||
checksum = "d194b56d58803a43635bdc398cd17e383d6f71f9182b9a192c127ca42494a59b"
|
||||
dependencies = [
|
||||
"base64 0.13.1",
|
||||
"base64 0.21.0",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
@@ -3713,16 +3601,6 @@ dependencies = [
|
||||
"winapi-util",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "schannel"
|
||||
version = "0.1.20"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "88d6731146462ea25d9244b2ed5fd1d716d25c52e4d54aa4fb0f3c4e9854dbe2"
|
||||
dependencies = [
|
||||
"lazy_static",
|
||||
"windows-sys 0.36.1",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "schemars"
|
||||
version = "0.8.12"
|
||||
@@ -3807,29 +3685,6 @@ dependencies = [
|
||||
"syn 1.0.107",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "security-framework"
|
||||
version = "2.7.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "2bc1bb97804af6631813c55739f771071e0f2ed33ee20b68c86ec505d906356c"
|
||||
dependencies = [
|
||||
"bitflags",
|
||||
"core-foundation",
|
||||
"core-foundation-sys",
|
||||
"libc",
|
||||
"security-framework-sys",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "security-framework-sys"
|
||||
version = "2.6.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "0160a13a177a45bfb43ce71c01580998474f556ad854dcbca936dd2841a5c556"
|
||||
dependencies = [
|
||||
"core-foundation-sys",
|
||||
"libc",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "segment"
|
||||
version = "0.6.0"
|
||||
@@ -4127,7 +3982,6 @@ dependencies = [
|
||||
"itertools",
|
||||
"log",
|
||||
"num_cpus",
|
||||
"openssl",
|
||||
"parking_lot",
|
||||
"proptest",
|
||||
"prost",
|
||||
@@ -4453,28 +4307,6 @@ dependencies = [
|
||||
"syn 2.0.11",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tokio-native-tls"
|
||||
version = "0.3.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "f7d995660bd2b7f8c1568414c1126076c13fbb725c40112dc0120b78eb9b717b"
|
||||
dependencies = [
|
||||
"native-tls",
|
||||
"tokio",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tokio-openssl"
|
||||
version = "0.6.3"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "c08f9ffb7809f1b20c1b398d92acf4cc719874b3b2b2d9ea2f09b4a80350878a"
|
||||
dependencies = [
|
||||
"futures-util",
|
||||
"openssl",
|
||||
"openssl-sys",
|
||||
"tokio",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "tokio-rustls"
|
||||
version = "0.23.4"
|
||||
@@ -5081,19 +4913,6 @@ dependencies = [
|
||||
"windows-targets 0.48.0",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "windows-sys"
|
||||
version = "0.36.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "ea04155a16a59f9eab786fe12a4a450e75cdb175f9e0d80da1e17db09f55b8d2"
|
||||
dependencies = [
|
||||
"windows_aarch64_msvc 0.36.1",
|
||||
"windows_i686_gnu 0.36.1",
|
||||
"windows_i686_msvc 0.36.1",
|
||||
"windows_x86_64_gnu 0.36.1",
|
||||
"windows_x86_64_msvc 0.36.1",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "windows-sys"
|
||||
version = "0.42.0"
|
||||
@@ -5169,12 +4988,6 @@ version = "0.48.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "91ae572e1b79dba883e0d315474df7305d12f569b400fcf90581b06062f7e1bc"
|
||||
|
||||
[[package]]
|
||||
name = "windows_aarch64_msvc"
|
||||
version = "0.36.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "9bb8c3fd39ade2d67e9874ac4f3db21f0d710bee00fe7cab16949ec184eeaa47"
|
||||
|
||||
[[package]]
|
||||
name = "windows_aarch64_msvc"
|
||||
version = "0.42.2"
|
||||
@@ -5187,12 +5000,6 @@ version = "0.48.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "b2ef27e0d7bdfcfc7b868b317c1d32c641a6fe4629c171b8928c7b08d98d7cf3"
|
||||
|
||||
[[package]]
|
||||
name = "windows_i686_gnu"
|
||||
version = "0.36.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "180e6ccf01daf4c426b846dfc66db1fc518f074baa793aa7d9b9aaeffad6a3b6"
|
||||
|
||||
[[package]]
|
||||
name = "windows_i686_gnu"
|
||||
version = "0.42.2"
|
||||
@@ -5205,12 +5012,6 @@ version = "0.48.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "622a1962a7db830d6fd0a69683c80a18fda201879f0f447f065a3b7467daa241"
|
||||
|
||||
[[package]]
|
||||
name = "windows_i686_msvc"
|
||||
version = "0.36.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "e2e7917148b2812d1eeafaeb22a97e4813dfa60a3f8f78ebe204bcc88f12f024"
|
||||
|
||||
[[package]]
|
||||
name = "windows_i686_msvc"
|
||||
version = "0.42.2"
|
||||
@@ -5223,12 +5024,6 @@ version = "0.48.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "4542c6e364ce21bf45d69fdd2a8e455fa38d316158cfd43b3ac1c5b1b19f8e00"
|
||||
|
||||
[[package]]
|
||||
name = "windows_x86_64_gnu"
|
||||
version = "0.36.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "4dcd171b8776c41b97521e5da127a2d86ad280114807d0b2ab1e462bc764d9e1"
|
||||
|
||||
[[package]]
|
||||
name = "windows_x86_64_gnu"
|
||||
version = "0.42.2"
|
||||
@@ -5253,12 +5048,6 @@ version = "0.48.0"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "7896dbc1f41e08872e9d5e8f8baa8fdd2677f29468c4e156210174edc7f7b953"
|
||||
|
||||
[[package]]
|
||||
name = "windows_x86_64_msvc"
|
||||
version = "0.36.1"
|
||||
source = "registry+https://github.com/rust-lang/crates.io-index"
|
||||
checksum = "c811ca4a8c853ef420abd8592ba53ddbbac90410fab6903b3e79972a631f7680"
|
||||
|
||||
[[package]]
|
||||
name = "windows_x86_64_msvc"
|
||||
version = "0.42.2"
|
||||
|
||||
+4
-3
@@ -54,7 +54,7 @@ config = "~0.13.3"
|
||||
|
||||
tokio = { version = "~1.28", features = ["full"] }
|
||||
|
||||
actix-web = { version = "4.3.1", optional = true, features = ["openssl"] }
|
||||
actix-web = { version = "4.3.1", optional = true, features = ["rustls", "actix-tls"] }
|
||||
actix-cors = "0.6.4"
|
||||
actix-files = "0.6.2"
|
||||
tonic = { version = "0.9.2", features = ["gzip", "tls"] }
|
||||
@@ -62,8 +62,9 @@ tower = "0.4.13"
|
||||
tower-layer = "0.3.2"
|
||||
num-traits = "0.2.15"
|
||||
tar = "0.4.38"
|
||||
reqwest = { version = "0.11", features = ["stream", "rustls-tls", "blocking"] }
|
||||
openssl = { version = "0.10", features = ["vendored"] }
|
||||
reqwest = { version = "0.11", default-features = false, features = ["stream", "rustls-tls", "blocking"] }
|
||||
rustls = "0.20.7"
|
||||
rustls-pemfile = "1.0.2"
|
||||
prometheus = { version = "0.13.3", default-features = false }
|
||||
validator = { version = "0.16", features = ["derive"] }
|
||||
actix-web-validator = "5.0.1"
|
||||
|
||||
+4
-4
@@ -133,7 +133,7 @@ service:
|
||||
# Default: true
|
||||
enable_cors: true
|
||||
|
||||
# Use HTTPS for the REST API
|
||||
# Enable HTTPS for the REST and gRPC API
|
||||
enable_tls: false
|
||||
|
||||
# Check user HTTPS client certificate against CA file specified in tls config
|
||||
@@ -196,8 +196,8 @@ tls:
|
||||
# Required if cluster.p2p.enable_tls is true.
|
||||
ca_cert: ./tls/cacert.pem
|
||||
|
||||
# TTL, in seconds, to re-load certificate from disk. Useful for certificate rotations,
|
||||
# Only works for HTTPS endpoints, gRPC endpoints (including intra-cluster communication)
|
||||
# doesn't support certificate re-load
|
||||
# TTL in seconds to reload certificate from disk, useful for certificate rotations.
|
||||
# Only works for HTTPS endpoints. Does not support gRPC (and intra-cluster communication).
|
||||
# If `null` - TTL is disabled.
|
||||
cert_ttl: 3600
|
||||
|
||||
|
||||
@@ -42,6 +42,5 @@ futures = "0.3.28"
|
||||
anyhow = "1.0.71"
|
||||
uuid = "1.3.3"
|
||||
url = "2.3.1"
|
||||
reqwest = { version = "0.11", features = ["stream", "rustls-tls"] }
|
||||
openssl = { version = "0.10", features = ["vendored"] }
|
||||
reqwest = { version = "0.11", default-features = false, features = ["stream", "rustls-tls"] }
|
||||
tempfile = "3.5.0"
|
||||
|
||||
@@ -1,126 +1,172 @@
|
||||
use std::fs;
|
||||
use std::fs::File;
|
||||
use std::io::{self, BufRead, BufReader};
|
||||
use std::sync::Arc;
|
||||
use std::time::{Duration, Instant};
|
||||
|
||||
use openssl::error::ErrorStack;
|
||||
use openssl::ssl::{
|
||||
SniError, SslAcceptor, SslAcceptorBuilder, SslContext, SslContextBuilder, SslFiletype,
|
||||
SslMethod, SslVerifyMode,
|
||||
};
|
||||
use openssl::x509::store::X509StoreBuilder;
|
||||
use openssl::x509::X509;
|
||||
use parking_lot::RwLock;
|
||||
use rustls::server::{AllowAnyAuthenticatedClient, ClientHello, ResolvesServerCert};
|
||||
use rustls::sign::CertifiedKey;
|
||||
use rustls::{Certificate, RootCertStore, ServerConfig};
|
||||
use rustls_pemfile::Item;
|
||||
|
||||
use crate::settings::{Settings, TlsConfig};
|
||||
|
||||
struct SslContextHolder {
|
||||
ssl_context: SslContext,
|
||||
/// A TTL based rotating server certificate resolver
|
||||
struct RotatingCertificateResolver {
|
||||
/// TLS configuration used for loading/refreshing certified key
|
||||
tls_config: TlsConfig,
|
||||
verify_client_cert: bool,
|
||||
refresh_interval: Duration,
|
||||
last_updated: Instant,
|
||||
|
||||
/// TTL for each rotation
|
||||
ttl: Option<Duration>,
|
||||
|
||||
/// Current certified key
|
||||
key: RwLock<CertifiedKeyWithAge>,
|
||||
}
|
||||
|
||||
impl SslContextHolder {
|
||||
fn new(
|
||||
tls_config: &TlsConfig,
|
||||
verify_client_cert: bool,
|
||||
refresh_interval: Duration,
|
||||
) -> Result<SslContextHolder, ErrorStack> {
|
||||
let ssl_context = build_ssl_context(tls_config, verify_client_cert)?;
|
||||
Ok(SslContextHolder {
|
||||
ssl_context,
|
||||
tls_config: tls_config.clone(),
|
||||
verify_client_cert,
|
||||
refresh_interval,
|
||||
last_updated: Instant::now(),
|
||||
impl RotatingCertificateResolver {
|
||||
pub fn new(tls_config: TlsConfig, ttl: Option<Duration>) -> io::Result<Self> {
|
||||
let certified_key = load_certified_key(&tls_config)?;
|
||||
|
||||
Ok(Self {
|
||||
tls_config,
|
||||
ttl,
|
||||
key: RwLock::new(CertifiedKeyWithAge::from(certified_key)),
|
||||
})
|
||||
}
|
||||
|
||||
fn try_get_ssl_context(&self) -> Option<&SslContext> {
|
||||
(self.last_updated.elapsed() < self.refresh_interval).then_some(&self.ssl_context)
|
||||
}
|
||||
/// Get certificate key or refresh
|
||||
///
|
||||
/// The key is automatically refreshed when the TTL is reached.
|
||||
/// If refreshing fails, an error is logged and the old key is persisted.
|
||||
fn get_key_or_refresh(&self) -> Arc<CertifiedKey> {
|
||||
// Get read-only lock to the key. If TTL is not configured or is not expired, return key.
|
||||
let key = self.key.read();
|
||||
let ttl = match self.ttl {
|
||||
Some(ttl) if key.is_expired(ttl) => ttl,
|
||||
_ => return key.key.clone(),
|
||||
};
|
||||
drop(key);
|
||||
|
||||
fn get_ssl_context_or_refresh(&mut self) -> Result<&SslContext, ()> {
|
||||
if self.last_updated.elapsed() >= self.refresh_interval {
|
||||
self.refresh()?;
|
||||
// If TTL is expired:
|
||||
// - get read-write lock to the key
|
||||
// - *re-check that TTL is expired* (to avoid refreshing the key multiple times from concurrent threads)
|
||||
// - refresh and return the key
|
||||
let mut key = self.key.write();
|
||||
if key.is_expired(ttl) {
|
||||
if let Err(err) = key.refresh(&self.tls_config) {
|
||||
log::error!("Failed to refresh TLS certificate, keeping current: {err}");
|
||||
}
|
||||
}
|
||||
Ok(&self.ssl_context)
|
||||
}
|
||||
|
||||
fn refresh(&mut self) -> Result<(), ()> {
|
||||
log::info!("Refreshing TLS certificates for actix!");
|
||||
self.ssl_context =
|
||||
build_ssl_context(&self.tls_config, self.verify_client_cert).map_err(|_| ())?;
|
||||
Ok(())
|
||||
key.key.clone()
|
||||
}
|
||||
}
|
||||
|
||||
pub fn build_ssl_acceptor(settings: &Settings) -> std::io::Result<SslAcceptorBuilder> {
|
||||
let mut acceptor = SslAcceptor::mozilla_modern_v5(SslMethod::tls())?;
|
||||
impl ResolvesServerCert for RotatingCertificateResolver {
|
||||
fn resolve(&self, _client_hello: ClientHello<'_>) -> Option<Arc<CertifiedKey>> {
|
||||
Some(self.get_key_or_refresh())
|
||||
}
|
||||
}
|
||||
|
||||
struct CertifiedKeyWithAge {
|
||||
/// Last time the certificate was updated/replaced
|
||||
last_update: Instant,
|
||||
|
||||
/// Current certified key
|
||||
key: Arc<CertifiedKey>,
|
||||
}
|
||||
|
||||
impl CertifiedKeyWithAge {
|
||||
pub fn from(key: Arc<CertifiedKey>) -> Self {
|
||||
Self {
|
||||
last_update: Instant::now(),
|
||||
key,
|
||||
}
|
||||
}
|
||||
|
||||
pub fn refresh(&mut self, tls_config: &TlsConfig) -> io::Result<()> {
|
||||
*self = Self::from(load_certified_key(tls_config)?);
|
||||
Ok(())
|
||||
}
|
||||
|
||||
pub fn age(&self) -> Duration {
|
||||
self.last_update.elapsed()
|
||||
}
|
||||
|
||||
pub fn is_expired(&self, ttl: Duration) -> bool {
|
||||
self.age() >= ttl
|
||||
}
|
||||
}
|
||||
|
||||
/// Load TLS configuration and construct certified key.
|
||||
fn load_certified_key(tls_config: &TlsConfig) -> io::Result<Arc<CertifiedKey>> {
|
||||
// Load certificates
|
||||
let certs: Vec<Certificate> = with_buf_read(&tls_config.cert, rustls_pemfile::read_all)?
|
||||
.into_iter()
|
||||
.filter_map(|item| match item {
|
||||
Item::X509Certificate(data) => Some(Certificate(data)),
|
||||
_ => None,
|
||||
})
|
||||
.collect();
|
||||
if certs.is_empty() {
|
||||
return Err(io::Error::new(
|
||||
io::ErrorKind::Other,
|
||||
"No server certificate found",
|
||||
));
|
||||
}
|
||||
|
||||
// Load private key
|
||||
let private_key_item = with_buf_read(&tls_config.key, rustls_pemfile::read_one)?
|
||||
.ok_or_else(|| io::Error::new(io::ErrorKind::Other, "No private key found"))?;
|
||||
let (Item::RSAKey(pkey) | Item::PKCS8Key(pkey) | Item::ECKey(pkey)) = private_key_item else {
|
||||
return Err(io::Error::new(io::ErrorKind::Other, "No private key found"))
|
||||
};
|
||||
let private_key = rustls::PrivateKey(pkey);
|
||||
let signing_key = rustls::sign::any_supported_type(&private_key)
|
||||
.map_err(|err| io::Error::new(io::ErrorKind::Other, err))?;
|
||||
|
||||
// Construct certified key
|
||||
let certified_key = CertifiedKey::new(certs, signing_key);
|
||||
Ok(Arc::new(certified_key))
|
||||
}
|
||||
|
||||
/// Generate an actix server configuration with TLS
|
||||
///
|
||||
/// Uses TLS settings as configured in configuration by user.
|
||||
pub fn actix_tls_server_config(settings: &Settings) -> io::Result<ServerConfig> {
|
||||
let config = ServerConfig::builder().with_safe_defaults();
|
||||
let tls_config = settings
|
||||
.tls
|
||||
.clone()
|
||||
.ok_or_else(Settings::tls_config_is_undefined_error)?;
|
||||
|
||||
let verify_client_cert = settings.service.verify_https_client_certificate;
|
||||
let ssl_context_holder = RwLock::new(SslContextHolder::new(
|
||||
&tls_config,
|
||||
verify_client_cert,
|
||||
Duration::from_secs(tls_config.cert_ttl),
|
||||
)?);
|
||||
// Verify client CA or not
|
||||
let config = if settings.service.verify_https_client_certificate {
|
||||
let mut root_cert_store = RootCertStore::empty();
|
||||
let ca_certs: Vec<Vec<u8>> = with_buf_read(&tls_config.ca_cert, rustls_pemfile::certs)?;
|
||||
root_cert_store.add_parsable_certificates(&ca_certs[..]);
|
||||
config.with_client_cert_verifier(AllowAnyAuthenticatedClient::new(root_cert_store))
|
||||
} else {
|
||||
config.with_no_client_auth()
|
||||
};
|
||||
|
||||
// Use set_servername_callback to implement dynamic certificate loading and refresh
|
||||
acceptor.set_servername_callback(move |ssl, _alert| -> Result<(), SniError> {
|
||||
{
|
||||
let reader = ssl_context_holder.read();
|
||||
if let Some(ssl_context) = reader.try_get_ssl_context() {
|
||||
ssl.set_ssl_context(ssl_context).map_err(|error_stack| {
|
||||
log::error!("Failed to set SSL context: {}", error_stack);
|
||||
SniError::ALERT_FATAL
|
||||
})?;
|
||||
return Ok(());
|
||||
}
|
||||
}
|
||||
// Configure rotating certificate resolver
|
||||
let ttl = match tls_config.cert_ttl {
|
||||
None | Some(0) => None,
|
||||
Some(seconds) => Some(Duration::from_secs(seconds)),
|
||||
};
|
||||
let cert_resolver = RotatingCertificateResolver::new(tls_config, ttl)?;
|
||||
let config = config.with_cert_resolver(Arc::new(cert_resolver));
|
||||
|
||||
// If getting the SSL context failed, try to get it again with refreshing
|
||||
let mut writer = ssl_context_holder.write();
|
||||
let ssl_context = writer
|
||||
.get_ssl_context_or_refresh()
|
||||
.map_err(|_refresh_error| {
|
||||
log::error!("Failed to refresh certificates!");
|
||||
SniError::ALERT_FATAL
|
||||
})?;
|
||||
ssl.set_ssl_context(ssl_context).map_err(|error_stack| {
|
||||
log::error!("Failed to set SSL context: {}", error_stack);
|
||||
SniError::ALERT_FATAL
|
||||
})?;
|
||||
Ok(())
|
||||
});
|
||||
Ok(acceptor)
|
||||
Ok(config)
|
||||
}
|
||||
|
||||
fn build_ssl_context(
|
||||
tls_config: &TlsConfig,
|
||||
verify_client_cert: bool,
|
||||
) -> Result<SslContext, ErrorStack> {
|
||||
let mut ssl_context_builder = SslContextBuilder::new(SslMethod::tls_server())?;
|
||||
// Server TLS config
|
||||
ssl_context_builder.set_private_key_file(&tls_config.key, SslFiletype::PEM)?;
|
||||
ssl_context_builder.set_certificate_chain_file(&tls_config.cert)?;
|
||||
ssl_context_builder.check_private_key()?;
|
||||
|
||||
// Verify client TLS certification
|
||||
if verify_client_cert {
|
||||
let client_ca =
|
||||
fs::read_to_string(&tls_config.ca_cert).expect("Failed to load CA certificate");
|
||||
let client_ca = X509::from_pem(client_ca.as_bytes())?;
|
||||
|
||||
let mut x509_client_store_builder = X509StoreBuilder::new()?;
|
||||
x509_client_store_builder.add_cert(client_ca)?;
|
||||
let client_cert_store = x509_client_store_builder.build();
|
||||
ssl_context_builder.set_verify_cert_store(client_cert_store)?;
|
||||
ssl_context_builder.set_verify(SslVerifyMode::PEER | SslVerifyMode::FAIL_IF_NO_PEER_CERT);
|
||||
}
|
||||
Ok(ssl_context_builder.build())
|
||||
fn with_buf_read<T>(
|
||||
path: &str,
|
||||
f: impl FnOnce(&mut dyn BufRead) -> io::Result<T>,
|
||||
) -> io::Result<T> {
|
||||
let file = File::open(path)?;
|
||||
let mut reader = BufReader::new(file);
|
||||
let dyn_reader: &mut dyn BufRead = &mut reader;
|
||||
f(dyn_reader)
|
||||
}
|
||||
|
||||
+17
-3
@@ -6,6 +6,7 @@ mod certificate_helpers;
|
||||
#[allow(dead_code)] // May contain functions used in different binaries. Not actually dead
|
||||
pub mod helpers;
|
||||
|
||||
use std::io;
|
||||
use std::sync::Arc;
|
||||
|
||||
use ::api::grpc::models::{ApiResponse, ApiStatus, VersionInfo};
|
||||
@@ -17,7 +18,6 @@ use actix_web::{error, get, web, App, HttpRequest, HttpResponse, HttpServer, Res
|
||||
use collection::operations::validation;
|
||||
use storage::dispatcher::Dispatcher;
|
||||
|
||||
use self::certificate_helpers::build_ssl_acceptor;
|
||||
use crate::actix::api::cluster_api::config_cluster_api;
|
||||
use crate::actix::api::collections_api::config_collections_api;
|
||||
use crate::actix::api::count_api::count_points;
|
||||
@@ -41,7 +41,7 @@ pub fn init(
|
||||
dispatcher: Arc<Dispatcher>,
|
||||
telemetry_collector: Arc<tokio::sync::Mutex<TelemetryCollector>>,
|
||||
settings: Settings,
|
||||
) -> std::io::Result<()> {
|
||||
) -> io::Result<()> {
|
||||
actix_web::rt::System::new().block_on(async {
|
||||
let toc_data = web::Data::from(dispatcher.toc().clone());
|
||||
let dispatcher_data = web::Data::from(dispatcher);
|
||||
@@ -103,9 +103,23 @@ pub fn init(
|
||||
|
||||
let bind_addr = format!("{}:{}", settings.service.host, settings.service.http_port);
|
||||
|
||||
// With TLS enabled, bind with certificate helper and Rustls, or bind regularly
|
||||
server = if settings.service.enable_tls {
|
||||
server.bind_openssl(bind_addr, build_ssl_acceptor(&settings)?)?
|
||||
log::info!(
|
||||
"TLS enabled for REST API (TTL: {})",
|
||||
settings
|
||||
.tls
|
||||
.as_ref()
|
||||
.and_then(|tls| tls.cert_ttl)
|
||||
.map(|ttl| ttl.to_string())
|
||||
.unwrap_or_else(|| "none".into()),
|
||||
);
|
||||
|
||||
let config = certificate_helpers::actix_tls_server_config(&settings)?;
|
||||
server.bind_rustls(bind_addr, config)?
|
||||
} else {
|
||||
log::info!("TLS disabled for REST API");
|
||||
|
||||
server.bind(bind_addr)?
|
||||
};
|
||||
|
||||
|
||||
+6
-4
@@ -93,13 +93,14 @@ impl Default for ConsensusConfig {
|
||||
}
|
||||
}
|
||||
|
||||
#[derive(Debug, Deserialize, Clone)]
|
||||
#[derive(Debug, Deserialize, Clone, Validate)]
|
||||
pub struct TlsConfig {
|
||||
pub cert: String,
|
||||
pub key: String,
|
||||
pub ca_cert: String,
|
||||
#[serde(default = "default_tls_cert_ttl")]
|
||||
pub cert_ttl: u64,
|
||||
#[validate(range(min = 1))]
|
||||
pub cert_ttl: Option<u64>,
|
||||
}
|
||||
|
||||
#[derive(Debug, Deserialize, Clone, Validate)]
|
||||
@@ -117,6 +118,7 @@ pub struct Settings {
|
||||
pub cluster: ClusterConfig,
|
||||
#[serde(default = "default_telemetry_disabled")]
|
||||
pub telemetry_disabled: bool,
|
||||
#[validate]
|
||||
pub tls: Option<TlsConfig>,
|
||||
/// A list of messages for errors that happened during loading the configuration. We collect
|
||||
/// them and store them here while loading because then our logger is not configured yet.
|
||||
@@ -210,9 +212,9 @@ const fn default_message_timeout_tics() -> u64 {
|
||||
10
|
||||
}
|
||||
|
||||
const fn default_tls_cert_ttl() -> u64 {
|
||||
const fn default_tls_cert_ttl() -> Option<u64> {
|
||||
// Default one hour
|
||||
3600
|
||||
Some(3600)
|
||||
}
|
||||
|
||||
impl Settings {
|
||||
|
||||
+9
-1
@@ -67,12 +67,16 @@ pub fn init(
|
||||
let mut server = Server::builder();
|
||||
|
||||
if settings.service.enable_tls {
|
||||
log::info!("TLS enabled for gRPC API (TTL not supported)");
|
||||
|
||||
let tls_server_config = helpers::load_tls_external_server_config(settings.tls()?)?;
|
||||
|
||||
server = server
|
||||
.tls_config(tls_server_config)
|
||||
.map_err(helpers::tonic_error_to_io_error)?;
|
||||
};
|
||||
} else {
|
||||
log::info!("TLS disabled for gRPC API");
|
||||
}
|
||||
|
||||
// The stack of middleware that our service will be wrapped in
|
||||
let middleware_layer = tower::ServiceBuilder::new()
|
||||
@@ -154,7 +158,11 @@ pub fn init_internal(
|
||||
let mut server = Server::builder();
|
||||
|
||||
if let Some(config) = tls_config {
|
||||
log::info!("TLS enabled for internal gRPC API (TTL not supported)");
|
||||
|
||||
server = server.tls_config(config)?;
|
||||
} else {
|
||||
log::info!("TLS disabled for internal gRPC API");
|
||||
};
|
||||
|
||||
// The stack of middleware that our service will be wrapped in
|
||||
|
||||
Reference in New Issue
Block a user