feat(tls/crate-init): initialize alknet-tls crate with Cargo.toml, deps, and module skeleton
Phase 1, Task 1 of crate extraction. Creates the alknet-tls crate with: - Cargo.toml with all dependencies and feature flags (quinn, tcp, acme) - Module skeleton: server.rs, client.rs, signing.rs, pem.rs - Workspace membership in root Cargo.toml - rustls-native-certs and webpki-roots always-present (not feature-gated) - alknet-core dependency via workspace path
This commit is contained in:
1 parent
9b527a888d
commit
44f5e32740
7 files changed
+66
No files matched your search
@@ -4,6 +4,7 @@ members = [
|
||||
"crates/alknet-core",
|
||||
"crates/alknet-call",
|
||||
"crates/alknet-http",
|
||||
"crates/alknet-tls",
|
||||
"crates/alknet-tty",
|
||||
"crates/alknet-tty-local",
|
||||
]
|
||||
|
||||
@@ -0,0 +1,35 @@
|
||||
[package]
|
||||
name = "alknet-tls"
|
||||
version.workspace = true
|
||||
edition.workspace = true
|
||||
license.workspace = true
|
||||
description = "TLS setup types for alknet — server config, client config, verifiers, cert resolvers, and shared signing helpers"
|
||||
repository.workspace = true
|
||||
|
||||
[lib]
|
||||
name = "alknet_tls"
|
||||
|
||||
[features]
|
||||
default = ["quinn"]
|
||||
quinn = ["dep:quinn"]
|
||||
tcp = ["dep:tokio-rustls"]
|
||||
acme = ["dep:rustls-acme"]
|
||||
|
||||
[dependencies]
|
||||
alknet-core = { path = "../alknet-core" }
|
||||
tokio = { version = "1", features = ["full"] }
|
||||
rustls = { version = "0.23", features = ["aws_lc_rs"] }
|
||||
rustls-pki-types = "1"
|
||||
rustls-pemfile = "2"
|
||||
rustls-native-certs = "0.8"
|
||||
webpki-roots = "1"
|
||||
rcgen = "0.13"
|
||||
tracing = "0.1"
|
||||
thiserror = "2"
|
||||
quinn = { version = "0.11", optional = true }
|
||||
tokio-rustls = { version = "0.26", optional = true }
|
||||
rustls-acme = { version = "0.12", optional = true, features = ["aws-lc-rs"] }
|
||||
|
||||
[dev-dependencies]
|
||||
tempfile = "3"
|
||||
hex = "0.4"
|
||||
@@ -0,0 +1,5 @@
|
||||
//! Client-side TLS configuration: `TlsClientConfig`, `FingerprintPinVerifier`,
|
||||
//! `RawKeyClientCertResolver`, `NoClientCertResolver`, `select_server_verifier`,
|
||||
//! `build_client_auth`, `load_platform_root_cert_store`.
|
||||
//!
|
||||
//! TODO: implement
|
||||
@@ -0,0 +1,11 @@
|
||||
//! alknet-tls: TLS setup types for alknet — server config, client config,
|
||||
//! verifiers, cert resolvers, and shared signing helpers.
|
||||
//!
|
||||
//! Provides `TlsServerConfig` (server-side TLS setup) and `TlsClientConfig`
|
||||
//! (client-side TLS setup), both transport-agnostic. Transport-specific
|
||||
//! conversion (e.g. `for_quinn()`) is feature-gated.
|
||||
|
||||
pub mod client;
|
||||
pub mod pem;
|
||||
pub mod server;
|
||||
pub mod signing;
|
||||
@@ -0,0 +1,4 @@
|
||||
//! PEM loading helpers: `load_cert_chain`, `load_private_key`.
|
||||
//! Consolidated — one copy used by both server and client.
|
||||
//!
|
||||
//! TODO: implement
|
||||
@@ -0,0 +1,5 @@
|
||||
//! Server-side TLS configuration: `TlsServerConfig`, `TlsSetup`,
|
||||
//! `RawKeyCertResolver`, `AcceptAnyCertVerifier`, `SelfSignedCert`,
|
||||
//! `generate_self_signed_cert`, and `build_iroh_endpoint`.
|
||||
//!
|
||||
//! TODO: implement
|
||||
@@ -0,0 +1,5 @@
|
||||
//! Ed25519 signing key usable as both a rustls `SigningKey` and `Signer`.
|
||||
//! Consolidated — one copy used by both server (`RawKeyCertResolver`) and
|
||||
//! client (`RawKeyClientCertResolver`).
|
||||
//!
|
||||
//! TODO: implement
|
||||
Reference in new issue
Block a user