docs: add comprehensive project wiki for v1.0
CI / cargo fmt (push) Has been cancelled
CI / cargo clippy (macos-latest) (push) Has been cancelled
CI / cargo clippy (ubuntu-latest) (push) Has been cancelled
CI / cargo clippy (windows-latest) (push) Has been cancelled
CI / cargo test (macos-latest) (push) Has been cancelled
CI / cargo test (ubuntu-latest) (push) Has been cancelled
CI / cargo test (windows-latest) (push) Has been cancelled
CI / cargo build (macos-latest) (push) Has been cancelled
CI / cargo build (ubuntu-latest) (push) Has been cancelled
CI / cargo build (windows-latest) (push) Has been cancelled
CI / cargo build --release (macos-latest) (push) Has been cancelled
CI / cargo build --release (ubuntu-latest) (push) Has been cancelled
CI / cargo build --release (windows-latest) (push) Has been cancelled
CI / CLI smoke (macos-latest) (push) Has been cancelled
CI / CLI smoke (ubuntu-latest) (push) Has been cancelled
CI / CLI smoke (windows-latest) (push) Has been cancelled
CI / Minimal E2E (macos-latest) (push) Has been cancelled
CI / Minimal E2E (ubuntu-latest) (push) Has been cancelled
CI / Minimal E2E (windows-latest) (push) Has been cancelled
CI / cargo fmt (push) Has been cancelled
CI / cargo clippy (macos-latest) (push) Has been cancelled
CI / cargo clippy (ubuntu-latest) (push) Has been cancelled
CI / cargo clippy (windows-latest) (push) Has been cancelled
CI / cargo test (macos-latest) (push) Has been cancelled
CI / cargo test (ubuntu-latest) (push) Has been cancelled
CI / cargo test (windows-latest) (push) Has been cancelled
CI / cargo build (macos-latest) (push) Has been cancelled
CI / cargo build (ubuntu-latest) (push) Has been cancelled
CI / cargo build (windows-latest) (push) Has been cancelled
CI / cargo build --release (macos-latest) (push) Has been cancelled
CI / cargo build --release (ubuntu-latest) (push) Has been cancelled
CI / cargo build --release (windows-latest) (push) Has been cancelled
CI / CLI smoke (macos-latest) (push) Has been cancelled
CI / CLI smoke (ubuntu-latest) (push) Has been cancelled
CI / CLI smoke (windows-latest) (push) Has been cancelled
CI / Minimal E2E (macos-latest) (push) Has been cancelled
CI / Minimal E2E (ubuntu-latest) (push) Has been cancelled
CI / Minimal E2E (windows-latest) (push) Has been cancelled
Co-authored-by: factory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com>
This commit is contained in:
co-authored by
factory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com>
parent
a758e8e0bc
commit
0166fb6511
@@ -0,0 +1,45 @@
|
||||
# TLS stack
|
||||
|
||||
The TLS stack in `src/tls.rs` configures rustls for both server (listener) and client (connector) roles with mutual TLS.
|
||||
|
||||
## Purpose
|
||||
|
||||
Provide safe, fail-closed TLS configuration builders that load certificates and keys, validate certificate identities, and support both secure and insecure (lab-only) modes.
|
||||
|
||||
## Key abstractions
|
||||
|
||||
| Type/Function | File | Description |
|
||||
| ------------- | ---- | ----------- |
|
||||
| `build_server_config` | `src/tls.rs` | Build a rustls `ServerConfig` with client certificate verification |
|
||||
| `build_client_config` | `src/tls.rs` | Build a rustls `ClientConfig` with server certificate verification |
|
||||
| `build_server_config_insecure` | `src/tls.rs` | Build a server config that skips client cert verification |
|
||||
| `build_client_config_insecure` | `src/tls.rs` | Build a client config that skips server cert verification |
|
||||
| `load_certs` | `src/tls.rs` | Load PEM-encoded certificates from a file |
|
||||
| `load_key` | `src/tls.rs` | Load a PEM-encoded private key from a file |
|
||||
| `validate_cert_identity` | `src/tls.rs` | Check SANs and CN against an expected hostname |
|
||||
| `check_cert_not_expired` | `src/tls.rs` | Verify certificate validity period |
|
||||
| `cert_fingerprint_sha256` | `src/tls.rs` | Compute SHA-256 fingerprint of a certificate |
|
||||
| `InsecureServerCertVerifier` | `src/tls.rs` | Dangerous verifier that accepts any certificate |
|
||||
|
||||
## How it works
|
||||
|
||||
Server config building:
|
||||
|
||||
1. Load the server certificate chain and private key.
|
||||
2. Load the CA certificate into a `RootCertStore`.
|
||||
3. Build a `WebPkiClientVerifier` from the root store.
|
||||
4. Use `ServerConfig::builder().with_client_cert_verifier(...).with_single_cert(...)`.
|
||||
|
||||
Client config building:
|
||||
|
||||
1. Load the client certificate chain and private key.
|
||||
2. Load the CA certificate into a `RootCertStore`.
|
||||
3. Use `ClientConfig::builder().with_root_certificates(...).with_client_auth_cert(...)`.
|
||||
|
||||
Identity validation uses `x509-parser` to extract Subject Alternative Names and the subject CN, matching against the expected hostname or IP address.
|
||||
|
||||
## Key source files
|
||||
|
||||
| File | Purpose |
|
||||
| ---- | ------- |
|
||||
| `src/tls.rs` | TLS configuration, certificate loading, identity validation |
|
||||
Reference in New Issue
Block a user