2 # Registry is a SfaServer that implements the Registry interface
13 from sfa.util.server import SfaServer
14 from sfa.util.faults import *
15 from sfa.util.storage import *
16 from sfa.trust.gid import GID
17 from sfa.util.table import SfaTable
18 import sfa.util.xmlrpcprotocol as xmlrpcprotocol
19 import sfa.util.soapprotocol as soapprotocol
21 # GeniLight client support is optional
23 from egeni.geniLight_client import *
25 GeniClientLight = None
28 # Registry is a SfaServer that serves registry and slice operations at PLC.
29 class Registry(SfaServer):
31 # Create a new registry object.
33 # @param ip the ip address to listen on
34 # @param port the port to listen on
35 # @param key_file private key filename of registry
36 # @param cert_file certificate filename containing public key (could be a GID file)
38 def __init__(self, ip, port, key_file, cert_file):
39 SfaServer.__init__(self, ip, port, key_file, cert_file)
40 self.server.interface = 'registry'
44 # Registries is a dictionary of registry connections keyed on the registry
47 class Registries(dict):
55 def __init__(self, api, file = "/etc/sfa/registries.xml"):
56 dict.__init__(self, {})
59 # create default connection dict
60 registries_dict = {'registries': {'registry': [default_fields]}}
63 self.registry_info = XmlStorage(file, registries_dict)
64 self.registry_info.load()
65 self.interfaces = self.registry_info['registries']['registry']
66 if not isinstance(self.interfaces, list):
67 self.interfaces = [self.interfaces]
69 # Attempt to get any missing peer gids
70 # There should be a gid file in /etc/sfa/trusted_roots for every
71 # peer registry found in in the registries.xml config file. If there
72 # are any missing gids, request a new one from the peer registry.
73 gids_current = self.api.auth.trusted_cert_list.get_list()
74 hrns_current = [gid.get_hrn() for gid in gids_found]
75 hrns_expected = self.interfaces.keys()
76 new_hrns = set(hrns_current).difference(hrns_expected)
78 self.get_peer_gids(new_hrns)
80 # update the local db records for these registries
81 self.update_db_records()
83 # create connections to the registries
84 self.update(self.get_connections(interfaces))
86 def get_peer_gids(self, new_hrns):
88 Install trusted gids from the specified interfaces.
93 trusted_certs_dir = self.api.config.get_trustedroots_dir()
94 for new_hrn in new_hrns:
96 # get gid from the registry
97 registry = self.get_connections(self.interfaces[new_hrn])[new_hrn]
98 trusted_gids = registry.get_trusted_certs()
100 message = "interface: registry\tunable to retrieve and install trusted gid for %s" % new_hrn
102 # the gid we want shoudl be the first one in the list, but lets
104 for trusted_gid in trusted_gids:
105 gid = GID(string=trusted_gids[0])
106 if gid.get_hrn() == new_hrn:
107 gid_filename = os.path.join(trusted_certs_dir, '%s.gid' % new_hrn)
108 gid.save_to_file(gid_filename, save_parents=True)
109 message = "interface: registry\tinstalled trusted gid for %s" % \
112 self.api.logger.info(message)
114 message = "interface: registry\tunable to retrieve and install trusted gid for %s" % new_hrn
115 self.api.logger.info(message)
117 # reload the trusted certs list
118 self.api.auth.load_trusted_certs()
120 def update_db_records(self):
122 Make sure there is a record in the local db for allowed registries
123 defined in the config file (registries.xml). Removes old records from
126 # get hrns we expect to find
127 hrns_expected = self.interfaces.keys()
129 # get hrns that actually exist in the db
131 records = table.find({'type': 'sa'})
132 hrns_found = [record['hrn'] for record in records]
135 for record in records:
136 if record['hrn'] not in hrns_expected:
140 for hrn in hrns_expected:
141 if hrn not in hrns_found:
149 def get_connections(self, registries):
151 read connection details for the trusted peer registries from file return
152 a dictionary of connections keyed on interface hrn.
155 required_fields = self.default_fields.keys()
156 if not isinstance(registries, []):
157 registries = [registries]
158 for registry in registries:
159 # make sure the required fields are present and not null
160 for key in required_fields
161 if not registry.get(key):
163 hrn, address, port = registry['hrn'], registry['addr'], registry['port']
164 url = 'http://%(address)s:%(port)s' % locals()
165 # check which client we should use
166 # sfa.util.xmlrpcprotocol is default
167 client_type = 'xmlrpcprotocol'
168 if registry.has_key('client') and \
169 registry['client'] in ['geniclientlight'] and \
171 client_type = 'geniclientlight'
172 connections[hrn] = GeniClientLight(url, self.api.key_file, self.api.cert_file)
174 connections[hrn] = xmlrpcprotocol.get_server(url, self.api.key_file, self.api.cert_file)
176 # set up a connection to the local registry
177 address = self.api.config.SFA_REGISTRY_HOST
178 port = self.api.config.SFA_REGISTRY_PORT
179 url = 'http://%(address)s:%(port)s' % locals()
180 local_registry = {'hrn': self.api.hrn, 'addr': address, 'port': port}
181 connections[self.api.hrn] = xmlrpcprotocol.get_server(url, self.api.key_file, self.api.cert_file)