6 from zope.interface import implements
7 from twisted.internet import reactor
8 from twisted.application import service
9 from twisted.python import log
11 from pycryptopp.publickey import rsa
12 from allmydata.interfaces import RIKeyGenerator
14 class KeyGenerator(service.MultiService, foolscap.Referenceable):
15 implements(RIKeyGenerator)
17 DEFAULT_KEY_SIZE = 2048
18 pool_size = 16 # no. keys to keep on hand in the pool
19 pool_refresh_delay = 6 # no. sec to wait after a fetch before generating new keys
23 service.MultiService.__init__(self)
27 def startService(self):
28 self.timer = reactor.callLater(0, self.maybe_refill_pool)
29 return service.MultiService.startService(self)
31 def stopService(self):
32 if self.timer.active():
34 return service.MultiService.stopService(self)
37 return '<KeyGenerator[%s]>' % (len(self.keypool),)
43 def reset_timer(self):
44 self.last_fetch = time.time()
45 if self.timer.active():
46 self.timer.reset(self.pool_refresh_delay)
48 self.timer = reactor.callLater(self.pool_refresh_delay, self.maybe_refill_pool)
50 def maybe_refill_pool(self):
52 if self.last_fetch + self.pool_refresh_delay < now:
53 self.vlog('%s refilling pool' % (self,))
54 while len(self.keypool) < self.pool_size:
55 self.keypool.append(self.gen_key(self.DEFAULT_KEY_SIZE))
57 self.vlog('%s not refilling pool' % (self,))
59 def gen_key(self, key_size):
60 self.vlog('%s generating key size %s' % (self, key_size, ))
61 signer = rsa.generate(key_size)
62 verifier = signer.get_verifying_key()
63 return verifier.serialize(), signer.serialize()
65 def remote_get_rsa_key_pair(self, key_size):
66 self.vlog('%s remote_get_key' % (self,))
67 if key_size != self.DEFAULT_KEY_SIZE or not self.keypool:
69 return self.gen_key(key_size)
72 return self.keypool.pop()
74 class KeyGeneratorService(service.MultiService):
75 furl_file = 'key_generator.furl'
77 def __init__(self, basedir='.', display_furl=True):
78 service.MultiService.__init__(self)
79 self.basedir = basedir
80 self.tub = foolscap.Tub(certFile=os.path.join(self.basedir, 'key_generator.pem'))
81 self.tub.setServiceParent(self)
82 self.key_generator = KeyGenerator()
83 self.key_generator.setServiceParent(self)
85 portnum = self.get_portnum()
86 self.listener = self.tub.listenOn(portnum or 'tcp:0')
87 d = self.tub.setLocationAutomatically()
89 d.addCallback(self.save_portnum)
90 d.addCallback(self.tub_ready, display_furl)
93 def get_portnum(self):
94 portnumfile = os.path.join(self.basedir, 'portnum')
95 if os.path.exists(portnumfile):
96 return file(portnumfile, 'rb').read().strip()
98 def save_portnum(self, junk):
99 portnum = self.listener.getPortnum()
100 portnumfile = os.path.join(self.basedir, 'portnum')
101 file(portnumfile, 'wb').write('%d\n' % (portnum,))
103 def tub_ready(self, junk, display_furl):
104 kgf = os.path.join(self.basedir, self.furl_file)
105 self.keygen_furl = self.tub.registerReference(self.key_generator, furlFile=kgf)
107 print 'key generator at:', self.keygen_furl