2 # Registry is a SfaServer that implements the Registry interface
13 from sfa.util.server import SfaServer
14 from sfa.util.faults import *
15 from sfa.util.storage import *
16 from sfa.trust.gid import GID
17 from sfa.util.table import SfaTable
18 import sfa.util.xmlrpcprotocol as xmlrpcprotocol
19 import sfa.util.soapprotocol as soapprotocol
21 # GeniLight client support is optional
23 from egeni.geniLight_client import *
25 GeniClientLight = None
28 # Registry is a SfaServer that serves registry and slice operations at PLC.
29 class Registry(SfaServer):
31 # Create a new registry object.
33 # @param ip the ip address to listen on
34 # @param port the port to listen on
35 # @param key_file private key filename of registry
36 # @param cert_file certificate filename containing public key (could be a GID file)
38 def __init__(self, ip, port, key_file, cert_file):
39 SfaServer.__init__(self, ip, port, key_file, cert_file)
40 self.server.interface = 'registry'
44 # Registries is a dictionary of registry connections keyed on the registry
47 class Registries(dict):
55 def __init__(self, api, file = "/etc/sfa/registries.xml"):
56 dict.__init__(self, {})
59 # create default connection dict
60 registries_dict = {'registries': {'registry': [default_fields]}}
63 self.registry_info = XmlStorage(file, registries_dict)
64 self.registry_info.load()
65 self.interfaces = self.registry_info['registries']['registry']
66 if not isinstance(self.interfaces, list):
67 self.interfaces = [self.interfaces]
69 # Attempt to get any missing peer gids
70 # There should be a gid file in /etc/sfa/trusted_roots for every
71 # peer registry found in in the registries.xml config file. If there
72 # are any missing gids, request a new one from the peer registry.
73 gids_current = self.api.auth.trusted_cert_list.get_list()
74 hrns_current = [gid.get_hrn() for gid in gids_found]
75 hrns_expected = self.interfaces.keys()
76 new_hrns = set(hrns_current).difference(hrns_expected)
78 self.get_peer_gids(new_hrns)
80 # update the local db records for these registries
81 self.update_db_records()
83 # create connections to the registries
84 self.update(self.get_connections(interfaces))
86 def get_peer_gids(self, new_hrns):
88 Install trusted gids from the specified interfaces.
92 for new_hrn in new_hrns:
93 # get path for the new gid file
94 trusted_certs_dir = self.api.config.get_trustedroots_dir()
95 gid_filename = os.path.join(trusted_certs_dir, '%s.gid' % new_hrn)
97 # get gid from the registry
98 registry = self.get_connections(self.interfaces[new_hrn])[new_hrn]
99 trusted_gids = registry.get_trusted_certs()
101 message = "interface: registry\tunable to retrieve and install trusted gid for %s" % new_hrn
102 self.api.logger.info(message)
104 gid = GID(string=trusted_gids[0])
105 gid.save_to_file(gid_filename, save_parents=True)
106 message = "interface: registry\tinstalled trusted gid for %s" % \
108 self.api.logger.info(message)
110 # reload the trusted certs list
111 self.api.auth.load_trusted_certs()
113 def update_db_records(self):
115 Make sure there is a record in the local db for allowed registries
116 defined in the config file (registries.xml). Removes old records from
119 # get hrns we expect to find
120 hrns_expected = self.interfaces.keys()
122 # get hrns that actually exist in the db
124 records = table.find({'type': 'sa'})
125 hrns_found = [record['hrn'] for record in records]
128 for record in records:
129 if record['hrn'] not in hrns_expected:
133 for hrn in hrns_expected:
134 if hrn not in hrns_found:
142 def get_connections(self, registries):
144 read connection details for the trusted peer registries from file return
145 a dictionary of connections keyed on interface hrn.
148 required_fields = self.default_fields.keys()
149 if not isinstance(registries, []):
150 registries = [registries]
151 for registry in registries:
152 # make sure the required fields are present and not null
153 for key in required_fields
154 if not registry.get(key):
156 hrn, address, port = registry['hrn'], registry['addr'], registry['port']
157 url = 'http://%(address)s:%(port)s' % locals()
158 # check which client we should use
159 # sfa.util.xmlrpcprotocol is default
160 client_type = 'xmlrpcprotocol'
161 if registry.has_key('client') and \
162 registry['client'] in ['geniclientlight'] and \
164 client_type = 'geniclientlight'
165 connections[hrn] = GeniClientLight(url, self.api.key_file, self.api.cert_file)
167 connections[hrn] = xmlrpcprotocol.get_server(url, self.api.key_file, self.api.cert_file)
169 # set up a connection to the local registry
170 address = self.api.config.SFA_REGISTRY_HOST
171 port = self.api.config.SFA_REGISTRY_PORT
172 url = 'http://%(address)s:%(port)s' % locals()
173 local_registry = {'hrn': self.api.hrn, 'addr': address, 'port': port}
174 connections[self.api.hrn] = xmlrpcprotocol.get_server(url, self.api.key_file, self.api.cert_file)