Files
tlsn/src/tlsn_core/config/tls.rs.html
2025-11-28 13:35:06 +00:00

112 lines
12 KiB
HTML

<!DOCTYPE html><html lang="en"><head><meta charset="utf-8"><meta name="viewport" content="width=device-width, initial-scale=1.0"><meta name="generator" content="rustdoc"><meta name="description" content="Source of the Rust file `crates/core/src/config/tls.rs`."><title>tls.rs - source</title><script>if(window.location.protocol!=="file:")document.head.insertAdjacentHTML("beforeend","SourceSerif4-Regular-6b053e98.ttf.woff2,FiraSans-Italic-81dc35de.woff2,FiraSans-Regular-0fe48ade.woff2,FiraSans-MediumItalic-ccf7e434.woff2,FiraSans-Medium-e1aa3f0a.woff2,SourceCodePro-Regular-8badfe75.ttf.woff2,SourceCodePro-Semibold-aa29a496.ttf.woff2".split(",").map(f=>`<link rel="preload" as="font" type="font/woff2"href="../../../static.files/${f}">`).join(""))</script><link rel="stylesheet" href="../../../static.files/normalize-9960930a.css"><link rel="stylesheet" href="../../../static.files/rustdoc-ca0dd0c4.css"><meta name="rustdoc-vars" data-root-path="../../../" data-static-root-path="../../../static.files/" data-current-crate="tlsn_core" data-themes="" data-resource-suffix="" data-rustdoc-version="1.93.0-nightly (c86564c41 2025-11-27)" data-channel="nightly" data-search-js="search-b9c1cd9b.js" data-stringdex-js="stringdex-a3946164.js" data-settings-js="settings-c38705f0.js" ><script src="../../../static.files/storage-e2aeef58.js"></script><script defer src="../../../static.files/src-script-813739b1.js"></script><script defer src="../../../src-files.js"></script><script defer src="../../../static.files/main-a410ff4d.js"></script><noscript><link rel="stylesheet" href="../../../static.files/noscript-263c88ec.css"></noscript><link rel="alternate icon" type="image/png" href="../../../static.files/favicon-32x32-eab170b8.png"><link rel="icon" type="image/svg+xml" href="../../../static.files/favicon-044be391.svg"></head><body class="rustdoc src"><!--[if lte IE 11]><div class="warning">This old browser is unsupported and will most likely display funky things.</div><![endif]--><nav class="sidebar"><div class="src-sidebar-title"><h2>Files</h2></div></nav><div class="sidebar-resizer" title="Drag to resize sidebar"></div><main><section id="main-content" class="content"><div class="main-heading"><h1><div class="sub-heading">tlsn_core/config/</div>tls.rs</h1><rustdoc-toolbar></rustdoc-toolbar></div><div class="example-wrap digits-3"><pre class="rust"><code><a href=#1 id=1 data-nosnippet>1</a><span class="doccomment">//! TLS client configuration.
<a href=#2 id=2 data-nosnippet>2</a>
<a href=#3 id=3 data-nosnippet>3</a></span><span class="kw">use </span>serde::{Deserialize, Serialize};
<a href=#4 id=4 data-nosnippet>4</a>
<a href=#5 id=5 data-nosnippet>5</a><span class="kw">use crate</span>::{
<a href=#6 id=6 data-nosnippet>6</a> connection::ServerName,
<a href=#7 id=7 data-nosnippet>7</a> webpki::{CertificateDer, PrivateKeyDer, RootCertStore},
<a href=#8 id=8 data-nosnippet>8</a>};
<a href=#9 id=9 data-nosnippet>9</a>
<a href=#10 id=10 data-nosnippet>10</a><span class="doccomment">/// TLS client configuration.
<a href=#11 id=11 data-nosnippet>11</a></span><span class="attr">#[derive(Debug, Clone, Serialize, Deserialize)]
<a href=#12 id=12 data-nosnippet>12</a></span><span class="kw">pub struct </span>TlsClientConfig {
<a href=#13 id=13 data-nosnippet>13</a> server_name: ServerName,
<a href=#14 id=14 data-nosnippet>14</a> <span class="doccomment">/// Root certificates.
<a href=#15 id=15 data-nosnippet>15</a> </span>root_store: RootCertStore,
<a href=#16 id=16 data-nosnippet>16</a> <span class="doccomment">/// Certificate chain and a matching private key for client
<a href=#17 id=17 data-nosnippet>17</a> /// authentication.
<a href=#18 id=18 data-nosnippet>18</a> </span>client_auth: <span class="prelude-ty">Option</span>&lt;(Vec&lt;CertificateDer&gt;, PrivateKeyDer)&gt;,
<a href=#19 id=19 data-nosnippet>19</a>}
<a href=#20 id=20 data-nosnippet>20</a>
<a href=#21 id=21 data-nosnippet>21</a><span class="kw">impl </span>TlsClientConfig {
<a href=#22 id=22 data-nosnippet>22</a> <span class="doccomment">/// Creates a new builder.
<a href=#23 id=23 data-nosnippet>23</a> </span><span class="kw">pub fn </span>builder() -&gt; TlsConfigBuilder {
<a href=#24 id=24 data-nosnippet>24</a> TlsConfigBuilder::default()
<a href=#25 id=25 data-nosnippet>25</a> }
<a href=#26 id=26 data-nosnippet>26</a>
<a href=#27 id=27 data-nosnippet>27</a> <span class="doccomment">/// Returns the server name.
<a href=#28 id=28 data-nosnippet>28</a> </span><span class="kw">pub fn </span>server_name(<span class="kw-2">&amp;</span><span class="self">self</span>) -&gt; <span class="kw-2">&amp;</span>ServerName {
<a href=#29 id=29 data-nosnippet>29</a> <span class="kw-2">&amp;</span><span class="self">self</span>.server_name
<a href=#30 id=30 data-nosnippet>30</a> }
<a href=#31 id=31 data-nosnippet>31</a>
<a href=#32 id=32 data-nosnippet>32</a> <span class="doccomment">/// Returns the root certificates.
<a href=#33 id=33 data-nosnippet>33</a> </span><span class="kw">pub fn </span>root_store(<span class="kw-2">&amp;</span><span class="self">self</span>) -&gt; <span class="kw-2">&amp;</span>RootCertStore {
<a href=#34 id=34 data-nosnippet>34</a> <span class="kw-2">&amp;</span><span class="self">self</span>.root_store
<a href=#35 id=35 data-nosnippet>35</a> }
<a href=#36 id=36 data-nosnippet>36</a>
<a href=#37 id=37 data-nosnippet>37</a> <span class="doccomment">/// Returns a certificate chain and a matching private key for client
<a href=#38 id=38 data-nosnippet>38</a> /// authentication.
<a href=#39 id=39 data-nosnippet>39</a> </span><span class="kw">pub fn </span>client_auth(<span class="kw-2">&amp;</span><span class="self">self</span>) -&gt; <span class="prelude-ty">Option</span>&lt;<span class="kw-2">&amp;</span>(Vec&lt;CertificateDer&gt;, PrivateKeyDer)&gt; {
<a href=#40 id=40 data-nosnippet>40</a> <span class="self">self</span>.client_auth.as_ref()
<a href=#41 id=41 data-nosnippet>41</a> }
<a href=#42 id=42 data-nosnippet>42</a>}
<a href=#43 id=43 data-nosnippet>43</a>
<a href=#44 id=44 data-nosnippet>44</a><span class="doccomment">/// Builder for [`TlsClientConfig`].
<a href=#45 id=45 data-nosnippet>45</a></span><span class="attr">#[derive(Debug, Default)]
<a href=#46 id=46 data-nosnippet>46</a></span><span class="kw">pub struct </span>TlsConfigBuilder {
<a href=#47 id=47 data-nosnippet>47</a> server_name: <span class="prelude-ty">Option</span>&lt;ServerName&gt;,
<a href=#48 id=48 data-nosnippet>48</a> root_store: <span class="prelude-ty">Option</span>&lt;RootCertStore&gt;,
<a href=#49 id=49 data-nosnippet>49</a> client_auth: <span class="prelude-ty">Option</span>&lt;(Vec&lt;CertificateDer&gt;, PrivateKeyDer)&gt;,
<a href=#50 id=50 data-nosnippet>50</a>}
<a href=#51 id=51 data-nosnippet>51</a>
<a href=#52 id=52 data-nosnippet>52</a><span class="kw">impl </span>TlsConfigBuilder {
<a href=#53 id=53 data-nosnippet>53</a> <span class="doccomment">/// Sets the server name.
<a href=#54 id=54 data-nosnippet>54</a> </span><span class="kw">pub fn </span>server_name(<span class="kw-2">mut </span><span class="self">self</span>, server_name: ServerName) -&gt; <span class="self">Self </span>{
<a href=#55 id=55 data-nosnippet>55</a> <span class="self">self</span>.server_name = <span class="prelude-val">Some</span>(server_name);
<a href=#56 id=56 data-nosnippet>56</a> <span class="self">self
<a href=#57 id=57 data-nosnippet>57</a> </span>}
<a href=#58 id=58 data-nosnippet>58</a>
<a href=#59 id=59 data-nosnippet>59</a> <span class="doccomment">/// Sets the root certificates to use for verifying the server's
<a href=#60 id=60 data-nosnippet>60</a> /// certificate.
<a href=#61 id=61 data-nosnippet>61</a> </span><span class="kw">pub fn </span>root_store(<span class="kw-2">mut </span><span class="self">self</span>, store: RootCertStore) -&gt; <span class="self">Self </span>{
<a href=#62 id=62 data-nosnippet>62</a> <span class="self">self</span>.root_store = <span class="prelude-val">Some</span>(store);
<a href=#63 id=63 data-nosnippet>63</a> <span class="self">self
<a href=#64 id=64 data-nosnippet>64</a> </span>}
<a href=#65 id=65 data-nosnippet>65</a>
<a href=#66 id=66 data-nosnippet>66</a> <span class="doccomment">/// Sets a DER-encoded certificate chain and a matching private key for
<a href=#67 id=67 data-nosnippet>67</a> /// client authentication.
<a href=#68 id=68 data-nosnippet>68</a> ///
<a href=#69 id=69 data-nosnippet>69</a> /// Often the chain will consist of a single end-entity certificate.
<a href=#70 id=70 data-nosnippet>70</a> ///
<a href=#71 id=71 data-nosnippet>71</a> /// # Arguments
<a href=#72 id=72 data-nosnippet>72</a> ///
<a href=#73 id=73 data-nosnippet>73</a> /// * `cert_key` - A tuple containing the certificate chain and the private
<a href=#74 id=74 data-nosnippet>74</a> /// key.
<a href=#75 id=75 data-nosnippet>75</a> ///
<a href=#76 id=76 data-nosnippet>76</a> /// - Each certificate in the chain must be in the X.509 format.
<a href=#77 id=77 data-nosnippet>77</a> /// - The key must be in the ASN.1 format (either PKCS#8 or PKCS#1).
<a href=#78 id=78 data-nosnippet>78</a> </span><span class="kw">pub fn </span>client_auth(<span class="kw-2">mut </span><span class="self">self</span>, cert_key: (Vec&lt;CertificateDer&gt;, PrivateKeyDer)) -&gt; <span class="self">Self </span>{
<a href=#79 id=79 data-nosnippet>79</a> <span class="self">self</span>.client_auth = <span class="prelude-val">Some</span>(cert_key);
<a href=#80 id=80 data-nosnippet>80</a> <span class="self">self
<a href=#81 id=81 data-nosnippet>81</a> </span>}
<a href=#82 id=82 data-nosnippet>82</a>
<a href=#83 id=83 data-nosnippet>83</a> <span class="doccomment">/// Builds the TLS configuration.
<a href=#84 id=84 data-nosnippet>84</a> </span><span class="kw">pub fn </span>build(<span class="self">self</span>) -&gt; <span class="prelude-ty">Result</span>&lt;TlsClientConfig, TlsConfigError&gt; {
<a href=#85 id=85 data-nosnippet>85</a> <span class="kw">let </span>server_name = <span class="self">self</span>.server_name.ok_or(ErrorRepr::MissingField {
<a href=#86 id=86 data-nosnippet>86</a> field: <span class="string">"server_name"</span>,
<a href=#87 id=87 data-nosnippet>87</a> })<span class="question-mark">?</span>;
<a href=#88 id=88 data-nosnippet>88</a>
<a href=#89 id=89 data-nosnippet>89</a> <span class="kw">let </span>root_store = <span class="self">self</span>.root_store.ok_or(ErrorRepr::MissingField {
<a href=#90 id=90 data-nosnippet>90</a> field: <span class="string">"root_store"</span>,
<a href=#91 id=91 data-nosnippet>91</a> })<span class="question-mark">?</span>;
<a href=#92 id=92 data-nosnippet>92</a>
<a href=#93 id=93 data-nosnippet>93</a> <span class="prelude-val">Ok</span>(TlsClientConfig {
<a href=#94 id=94 data-nosnippet>94</a> server_name,
<a href=#95 id=95 data-nosnippet>95</a> root_store,
<a href=#96 id=96 data-nosnippet>96</a> client_auth: <span class="self">self</span>.client_auth,
<a href=#97 id=97 data-nosnippet>97</a> })
<a href=#98 id=98 data-nosnippet>98</a> }
<a href=#99 id=99 data-nosnippet>99</a>}
<a href=#100 id=100 data-nosnippet>100</a>
<a href=#101 id=101 data-nosnippet>101</a><span class="doccomment">/// TLS configuration error.
<a href=#102 id=102 data-nosnippet>102</a></span><span class="attr">#[derive(Debug, thiserror::Error)]
<a href=#103 id=103 data-nosnippet>103</a>#[error(transparent)]
<a href=#104 id=104 data-nosnippet>104</a></span><span class="kw">pub struct </span>TlsConfigError(<span class="attr">#[from] </span>ErrorRepr);
<a href=#105 id=105 data-nosnippet>105</a>
<a href=#106 id=106 data-nosnippet>106</a><span class="attr">#[derive(Debug, thiserror::Error)]
<a href=#107 id=107 data-nosnippet>107</a>#[error(<span class="string">"tls config error"</span>)]
<a href=#108 id=108 data-nosnippet>108</a></span><span class="kw">enum </span>ErrorRepr {
<a href=#109 id=109 data-nosnippet>109</a> <span class="attr">#[error(<span class="string">"missing required field: {field}"</span>)]
<a href=#110 id=110 data-nosnippet>110</a> </span>MissingField { field: <span class="kw-2">&amp;</span><span class="lifetime">'static </span>str },
<a href=#111 id=111 data-nosnippet>111</a>}
</code></pre></div></section></main></body></html>