Skip to main content

Module tls

Module tls 

Source
Expand description

Shared TLS client policy — the one place that decides whether a server is trusted.

This lived inside src-tauri/src/lib.rs until Phase 17, which meant the desktop app pinned certificates and the CLI did not verify them at all. Two implementations of a trust decision is how one of them ends up accepting anything, so there is now exactly one, and both callers build their HTTP client from it.

Three policies, and the difference between them is the whole security model:

  • TlsPolicy::Ca — ordinary CA validation, for a server with a real certificate.
  • TlsPolicy::Pin — the leaf certificate must hash to a known SHA-256. Enforced during the handshake, before any request body is written, so a MITM is rejected before the master password reaches the socket.
  • TlsPolicy::PrivateCa — validate against a specific CA and only that CA. Narrower than adding a root to the system store, and deliberately so: a private CA should be able to vouch for your own server, not for the web.

capturing_config is separate and is not a policy. It accepts whatever the server presents and records the fingerprint — the trust-on-first-use bootstrap, which is only sound because it is confined to one unauthenticated request that sends no credentials.

Re-exports§

pub use rustls;

Enums§

TlsPolicy
How a client should decide whether to trust the server it reaches.

Functions§

capturing_config
Trust-on-first-use bootstrap: accept whatever is presented and record its fingerprint.
certs_from_pem
Parse a PEM bundle into certificates for TlsPolicy::PrivateCa.
client_config
Build a rustls client configuration for policy.
client_config_tls13
As client_config, but offering TLS 1.3 only. A node agent runs unattended on a host nobody is watching and carries rendered config, so it does not negotiate down (Phase 34).
fingerprint_of_der
SHA-256 of a certificate’s DER encoding, lower-case hex.
fingerprint_of_pem
The SHA-256 of the first certificate in a PEM file, as the pin form.
normalize_fingerprint
Normalise a user-supplied fingerprint for comparison.
self_signed
A fresh self-signed certificate for a listener that is reached by pin, not by name: (cert_pem, key_pem, fingerprint). The names go in the SAN list for tools that look; the pin ignores them.
server_config_tls13
A server configuration that speaks TLS 1.3 only and asks for no client certificate: the caller proves itself with a signature on the request.

Type Aliases§

ProbeConfig
What a fingerprint probe hands back: a client configuration, and the slot the observed fingerprint lands in once the handshake completes.