CI / cargo fmt (push) Has been cancelled
CI / cargo clippy (macos-latest) (push) Has been cancelled
CI / cargo clippy (ubuntu-latest) (push) Has been cancelled
CI / cargo clippy (windows-latest) (push) Has been cancelled
CI / cargo test (macos-latest) (push) Has been cancelled
CI / cargo test (ubuntu-latest) (push) Has been cancelled
CI / cargo test (windows-latest) (push) Has been cancelled
CI / cargo build (macos-latest) (push) Has been cancelled
CI / cargo build (ubuntu-latest) (push) Has been cancelled
CI / cargo build (windows-latest) (push) Has been cancelled
CI / cargo build --release (macos-latest) (push) Has been cancelled
CI / cargo build --release (ubuntu-latest) (push) Has been cancelled
CI / cargo build --release (windows-latest) (push) Has been cancelled
CI / CLI smoke (macos-latest) (push) Has been cancelled
CI / CLI smoke (ubuntu-latest) (push) Has been cancelled
CI / CLI smoke (windows-latest) (push) Has been cancelled
CI / Minimal E2E (macos-latest) (push) Has been cancelled
CI / Minimal E2E (ubuntu-latest) (push) Has been cancelled
CI / Minimal E2E (windows-latest) (push) Has been cancelled
Co-authored-by: factory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com>
2.1 KiB
2.1 KiB
TLS stack
The TLS stack in src/tls.rs configures rustls for both server (listener) and client (connector) roles with mutual TLS.
Purpose
Provide safe, fail-closed TLS configuration builders that load certificates and keys, validate certificate identities, and support both secure and insecure (lab-only) modes.
Key abstractions
| Type/Function | File | Description |
|---|---|---|
build_server_config |
src/tls.rs |
Build a rustls ServerConfig with client certificate verification |
build_client_config |
src/tls.rs |
Build a rustls ClientConfig with server certificate verification |
build_server_config_insecure |
src/tls.rs |
Build a server config that skips client cert verification |
build_client_config_insecure |
src/tls.rs |
Build a client config that skips server cert verification |
load_certs |
src/tls.rs |
Load PEM-encoded certificates from a file |
load_key |
src/tls.rs |
Load a PEM-encoded private key from a file |
validate_cert_identity |
src/tls.rs |
Check SANs and CN against an expected hostname |
check_cert_not_expired |
src/tls.rs |
Verify certificate validity period |
cert_fingerprint_sha256 |
src/tls.rs |
Compute SHA-256 fingerprint of a certificate |
InsecureServerCertVerifier |
src/tls.rs |
Dangerous verifier that accepts any certificate |
How it works
Server config building:
- Load the server certificate chain and private key.
- Load the CA certificate into a
RootCertStore. - Build a
WebPkiClientVerifierfrom the root store. - Use
ServerConfig::builder().with_client_cert_verifier(...).with_single_cert(...).
Client config building:
- Load the client certificate chain and private key.
- Load the CA certificate into a
RootCertStore. - Use
ClientConfig::builder().with_root_certificates(...).with_client_auth_cert(...).
Identity validation uses x509-parser to extract Subject Alternative Names and the subject CN, matching against the expected hostname or IP address.
Key source files
| File | Purpose |
|---|---|
src/tls.rs |
TLS configuration, certificate loading, identity validation |