blob: 5baccc3e32b1772f631b5cde3ebfe0d805a9da69 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
|
package dns
import (
"context"
"fmt"
"net"
"git.sigsum.org/sigsum-go/pkg/hex"
"git.sigsum.org/sigsum-go/pkg/types"
)
// Verifier can verify that a domain name is aware of a public key
type Verifier interface {
Verify(ctx context.Context, name string, key *types.PublicKey) error
}
// DefaultResolver implements the Verifier interface with Go's default resolver
type DefaultResolver struct {
resolver net.Resolver
}
func NewDefaultResolver() Verifier {
return &DefaultResolver{}
}
func (dr *DefaultResolver) Verify(ctx context.Context, name string, key *types.PublicKey) error {
rsp, err := dr.resolver.LookupTXT(ctx, name)
if err != nil {
return fmt.Errorf("domain name look-up failed: %v", err)
}
want := hex.Serialize(types.HashFn(key[:])[:])
for _, got := range rsp {
if got == want {
return nil
}
}
return fmt.Errorf("%q is not aware of key hash %q", name, want)
}
|