feat(tls/crate-init): initialize alknet-tls crate with Cargo.toml, deps, and module skeleton

Phase 1, Task 1 of crate extraction. Creates the alknet-tls crate with:
- Cargo.toml with all dependencies and feature flags (quinn, tcp, acme)
- Module skeleton: server.rs, client.rs, signing.rs, pem.rs
- Workspace membership in root Cargo.toml
- rustls-native-certs and webpki-roots always-present (not feature-gated)
- alknet-core dependency via workspace path
This commit is contained in:
deepseek-v4-pro committed 2026-07-17 09:55:52 +00:00
1 parent 9b527a888d
commit 44f5e32740
7 files changed
+66

No files matched your search

+1
View File
@@ -4,6 +4,7 @@ members = [
"crates/alknet-core",
"crates/alknet-call",
"crates/alknet-http",
"crates/alknet-tls",
"crates/alknet-tty",
"crates/alknet-tty-local",
]
+35
View File
@@ -0,0 +1,35 @@
[package]
name = "alknet-tls"
version.workspace = true
edition.workspace = true
license.workspace = true
description = "TLS setup types for alknet — server config, client config, verifiers, cert resolvers, and shared signing helpers"
repository.workspace = true
[lib]
name = "alknet_tls"
[features]
default = ["quinn"]
quinn = ["dep:quinn"]
tcp = ["dep:tokio-rustls"]
acme = ["dep:rustls-acme"]
[dependencies]
alknet-core = { path = "../alknet-core" }
tokio = { version = "1", features = ["full"] }
rustls = { version = "0.23", features = ["aws_lc_rs"] }
rustls-pki-types = "1"
rustls-pemfile = "2"
rustls-native-certs = "0.8"
webpki-roots = "1"
rcgen = "0.13"
tracing = "0.1"
thiserror = "2"
quinn = { version = "0.11", optional = true }
tokio-rustls = { version = "0.26", optional = true }
rustls-acme = { version = "0.12", optional = true, features = ["aws-lc-rs"] }
[dev-dependencies]
tempfile = "3"
hex = "0.4"
+5
View File
@@ -0,0 +1,5 @@
//! Client-side TLS configuration: `TlsClientConfig`, `FingerprintPinVerifier`,
//! `RawKeyClientCertResolver`, `NoClientCertResolver`, `select_server_verifier`,
//! `build_client_auth`, `load_platform_root_cert_store`.
//!
//! TODO: implement
+11
View File
@@ -0,0 +1,11 @@
//! alknet-tls: TLS setup types for alknet — server config, client config,
//! verifiers, cert resolvers, and shared signing helpers.
//!
//! Provides `TlsServerConfig` (server-side TLS setup) and `TlsClientConfig`
//! (client-side TLS setup), both transport-agnostic. Transport-specific
//! conversion (e.g. `for_quinn()`) is feature-gated.
pub mod client;
pub mod pem;
pub mod server;
pub mod signing;
+4
View File
@@ -0,0 +1,4 @@
//! PEM loading helpers: `load_cert_chain`, `load_private_key`.
//! Consolidated — one copy used by both server and client.
//!
//! TODO: implement
+5
View File
@@ -0,0 +1,5 @@
//! Server-side TLS configuration: `TlsServerConfig`, `TlsSetup`,
//! `RawKeyCertResolver`, `AcceptAnyCertVerifier`, `SelfSignedCert`,
//! `generate_self_signed_cert`, and `build_iroh_endpoint`.
//!
//! TODO: implement
+5
View File
@@ -0,0 +1,5 @@
//! Ed25519 signing key usable as both a rustls `SigningKey` and `Signer`.
//! Consolidated — one copy used by both server (`RawKeyCertResolver`) and
//! client (`RawKeyClientCertResolver`).
//!
//! TODO: implement