Files
rustunnel/droid-wiki/systems/tls-stack.md
T
rootandfactory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com> 0166fb6511
CI / cargo fmt (push) Has been cancelled
CI / cargo clippy (macos-latest) (push) Has been cancelled
CI / cargo clippy (ubuntu-latest) (push) Has been cancelled
CI / cargo clippy (windows-latest) (push) Has been cancelled
CI / cargo test (macos-latest) (push) Has been cancelled
CI / cargo test (ubuntu-latest) (push) Has been cancelled
CI / cargo test (windows-latest) (push) Has been cancelled
CI / cargo build (macos-latest) (push) Has been cancelled
CI / cargo build (ubuntu-latest) (push) Has been cancelled
CI / cargo build (windows-latest) (push) Has been cancelled
CI / cargo build --release (macos-latest) (push) Has been cancelled
CI / cargo build --release (ubuntu-latest) (push) Has been cancelled
CI / cargo build --release (windows-latest) (push) Has been cancelled
CI / CLI smoke (macos-latest) (push) Has been cancelled
CI / CLI smoke (ubuntu-latest) (push) Has been cancelled
CI / CLI smoke (windows-latest) (push) Has been cancelled
CI / Minimal E2E (macos-latest) (push) Has been cancelled
CI / Minimal E2E (ubuntu-latest) (push) Has been cancelled
CI / Minimal E2E (windows-latest) (push) Has been cancelled
docs: add comprehensive project wiki for v1.0
Co-authored-by: factory-droid[bot] <138933559+factory-droid[bot]@users.noreply.github.com>
2026-06-04 14:07:55 -06:00

46 lines
2.1 KiB
Markdown

# TLS stack
The TLS stack in `src/tls.rs` configures rustls for both server (listener) and client (connector) roles with mutual TLS.
## Purpose
Provide safe, fail-closed TLS configuration builders that load certificates and keys, validate certificate identities, and support both secure and insecure (lab-only) modes.
## Key abstractions
| Type/Function | File | Description |
| ------------- | ---- | ----------- |
| `build_server_config` | `src/tls.rs` | Build a rustls `ServerConfig` with client certificate verification |
| `build_client_config` | `src/tls.rs` | Build a rustls `ClientConfig` with server certificate verification |
| `build_server_config_insecure` | `src/tls.rs` | Build a server config that skips client cert verification |
| `build_client_config_insecure` | `src/tls.rs` | Build a client config that skips server cert verification |
| `load_certs` | `src/tls.rs` | Load PEM-encoded certificates from a file |
| `load_key` | `src/tls.rs` | Load a PEM-encoded private key from a file |
| `validate_cert_identity` | `src/tls.rs` | Check SANs and CN against an expected hostname |
| `check_cert_not_expired` | `src/tls.rs` | Verify certificate validity period |
| `cert_fingerprint_sha256` | `src/tls.rs` | Compute SHA-256 fingerprint of a certificate |
| `InsecureServerCertVerifier` | `src/tls.rs` | Dangerous verifier that accepts any certificate |
## How it works
Server config building:
1. Load the server certificate chain and private key.
2. Load the CA certificate into a `RootCertStore`.
3. Build a `WebPkiClientVerifier` from the root store.
4. Use `ServerConfig::builder().with_client_cert_verifier(...).with_single_cert(...)`.
Client config building:
1. Load the client certificate chain and private key.
2. Load the CA certificate into a `RootCertStore`.
3. Use `ClientConfig::builder().with_root_certificates(...).with_client_auth_cert(...)`.
Identity validation uses `x509-parser` to extract Subject Alternative Names and the subject CN, matching against the expected hostname or IP address.
## Key source files
| File | Purpose |
| ---- | ------- |
| `src/tls.rs` | TLS configuration, certificate loading, identity validation |