Phase 1, Task 3 of crate extraction. Extracts client-side TLS setup code from alknet-call/call_client.rs into alknet-tls: - client.rs: TlsClientConfig, build_client_auth, select_server_verifier, load_platform_root_cert_store, FingerprintPinVerifier, RawKeyClientCertResolver, NoClientCertResolver - load_platform_root_cert_store includes webpki-roots fallback (ADR-088 §5) - Reuses shared Ed25519SigningKey from signing.rs and load_cert_chain/ load_private_key from pem.rs - All error returns use TlsError (not String) - webpki-roots 0.26 with TrustAnchor-based fallback Old code in call_client.rs stays (duplicated). No breakage.
37 lines
941 B
TOML
37 lines
941 B
TOML
[package]
|
|
name = "alknet-tls"
|
|
version.workspace = true
|
|
edition.workspace = true
|
|
license.workspace = true
|
|
description = "TLS setup types for alknet — server config, client config, verifiers, cert resolvers, and shared signing helpers"
|
|
repository.workspace = true
|
|
|
|
[lib]
|
|
name = "alknet_tls"
|
|
|
|
[features]
|
|
default = ["quinn"]
|
|
quinn = ["dep:quinn"]
|
|
tcp = ["dep:tokio-rustls"]
|
|
acme = ["dep:rustls-acme"]
|
|
|
|
[dependencies]
|
|
alknet-core = { path = "../alknet-core" }
|
|
tokio = { version = "1", features = ["full"] }
|
|
rustls = { version = "0.23", features = ["aws_lc_rs"] }
|
|
rustls-pki-types = "1"
|
|
rustls-pemfile = "2"
|
|
rustls-native-certs = "0.8"
|
|
webpki-roots = "0.26"
|
|
rcgen = "0.13"
|
|
tracing = "0.1"
|
|
thiserror = "2"
|
|
futures = "0.3"
|
|
quinn = { version = "0.11", optional = true }
|
|
tokio-rustls = { version = "0.26", optional = true }
|
|
rustls-acme = { version = "0.12", optional = true, features = ["aws-lc-rs"] }
|
|
|
|
[dev-dependencies]
|
|
tempfile = "3"
|
|
hex = "0.4"
|