feat: scope server pins by port, default port inherits (agreed with bunshin)
This commit is contained in:
parent
96a558da16
commit
13c624f2b0
7 changed files with 149 additions and 48 deletions
|
|
@ -26,12 +26,14 @@ pub enum Error {
|
|||
UnknownStatus(u8, String),
|
||||
/// The host has no pinned server key, so the session cannot be
|
||||
/// authenticated (sec 4). A GUI routes this to pinning; an auth failure
|
||||
/// is terminal.
|
||||
NotPinned { host: String },
|
||||
/// is terminal. The port scopes the pin (address::trust_label).
|
||||
NotPinned { host: String, port: u16 },
|
||||
/// A pinned server presented a different key (sec 4): a hard abort, the
|
||||
/// pin is the entire trust model.
|
||||
/// pin is the entire trust model. The port scopes the pin
|
||||
/// (address::trust_label).
|
||||
PinMismatch {
|
||||
host: String,
|
||||
port: u16,
|
||||
pinned: [u8; KEY_LEN],
|
||||
presented: [u8; KEY_LEN],
|
||||
},
|
||||
|
|
@ -89,14 +91,20 @@ impl fmt::Display for Error {
|
|||
Self::UnknownStatus(status, what) => {
|
||||
write!(f, "{what} failed: unknown status {status}")
|
||||
}
|
||||
Self::NotPinned { host } => write!(f, "no pinned key for {host}"),
|
||||
Self::NotPinned { host, port } => write!(
|
||||
f,
|
||||
"no pinned key for {}",
|
||||
crate::address::trust_label(host, *port)
|
||||
),
|
||||
Self::PinMismatch {
|
||||
host,
|
||||
port,
|
||||
pinned,
|
||||
presented,
|
||||
} => write!(
|
||||
f,
|
||||
"{host} presented a different key than the one pinned\n pinned: {}\n presented: {}",
|
||||
"{} presented a different key than the one pinned\n pinned: {}\n presented: {}",
|
||||
crate::address::trust_label(host, *port),
|
||||
b32(pinned),
|
||||
b32(presented)
|
||||
),
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue