ff21675c5b
* Initial work on signing key update EDUs * Fix build * Produce/consume EDUs * Producer logging * Only produce key change notifications for local users * Better naming * Try to notify sync * Enable feature * Use key change topic * Don't bother verifying signatures, validate key lengths if we can, notifier fixes * Copyright notices * Remove tests from whitelist until matrix-org/sytest#1117 * Some review comment fixes * Update to matrix-org/gomatrixserverlib@f9416ac * Remove unneeded parameter |
||
---|---|---|
.. | ||
api | ||
consumers | ||
internal | ||
inthttp | ||
producers | ||
storage | ||
types | ||
keyserver.go | ||
README.md |
Key Server
This is an internal component which manages E2E keys from clients. It handles all the Key Management APIs with the exception of /keys/changes
which is handled by Sync API. This component is designed to shard by user ID.
Keys are uploaded and stored in this component, and key changes are emitted to a Kafka topic for downstream components such as Sync API.
Internal APIs
PerformUploadKeys
stores identity keys and one-time public keys for given user(s).PerformClaimKeys
acquires one-time public keys for given user(s). This may involve outbound federation calls.QueryKeys
returns identity keys for given user(s). This may involve outbound federation calls. This component may then cache federated identity keys to avoid repeatedly hitting remote servers.- A topic which emits identity keys every time there is a change (addition or deletion).
### Endpoint mappings
- Client API maps
/keys/upload
toPerformUploadKeys
. - Client API maps
/keys/query
toQueryKeys
. - Client API maps
/keys/claim
toPerformClaimKeys
. - Federation API maps
/user/keys/query
toQueryKeys
. - Federation API maps
/user/keys/claim
toPerformClaimKeys
. - Sync API maps
/keys/changes
to consuming from the Kafka topic.