ADR-007: RFC 7250 cert-type negotiation — the offer follows the identity (OQ-TLS-10 resolved)
Resolve the cert-type negotiation gap (review 001 §U-3, OQ-TLS-10) by deviation from alknet: the gap was a defect in the prior art (alknet's code never delivered its spec's raw-key-over-TCP promise — ADR-082 "works for both QUIC and TCP+TLS"), not behavior to preserve. - FingerprintPinVerifier::requires_raw_public_keys() derives from the pin format: ed25519: -> true (offer [RawPublicKey]), SHA256: -> false (X.509 offer). Crate pin client now completes against the crate raw-key server; SHA256: pins negotiate unchanged. - RawKeyClientCertResolver presents the SPKI under the X.509 offer (only_raw_public_keys() == false): a raw-only client offer can only negotiate against a requires_raw server verifier, and AcceptAnyCertVerifier correctly stays on the default (accepts both cert types). The server extracts the ed25519: fingerprint from the SPKI bytes either way. - Fail-closed preserved and strengthened: an ed25519: pin against an X.509 server now aborts at negotiation (suite 2b), never a downgrade; no API change (no public signature affected; the fix is invisible to consumers apart from working handshakes). - tests/handshake_behavior.rs: suite 3 now runs crate-native (no custom iroh-shaped verifier), new negotiation fail-closed suite, suite 3b inverted to end-to-end success; invariant_pins.rs resolver-offer assertions flipped; unused imports dropped. - Docs: ADR-007 written; OQ-TLS-10 -> resolved-by-deviation; client.md/server.md/overview/README/task postscript synced (incl. the strict-foreign-server limit in ADR-007 §Limits). Verification: cargo test 81 / --features tcp 94 / --all-features 105 green; clippy -D warnings clean (default + all-features); fmt clean; cargo doc warning-free.
This commit is contained in:
@@ -82,6 +82,29 @@ The four handshake-level gaps (review 001 §U-3):
|
||||
stays inside it)
|
||||
- tasks/integration-suite.md (the existing suite this extends)
|
||||
|
||||
## Postscript (2026-09-11 — the OQ-TLS-10 resolution)
|
||||
|
||||
The open gap above is now **resolved by ADR-007** (deviation from
|
||||
alknet; OQ-TLS-10 → resolved). The two gap premises this task pinned
|
||||
are no longer true:
|
||||
|
||||
- Suite 1's original premise (crate pin client ↔ raw-key server → ok)
|
||||
is now **true**: `FingerprintPinVerifier::requires_raw_public_keys()`
|
||||
derives from the pin format (`ed25519:` → `true`), so the crate's
|
||||
own pin client completes against the crate's raw-key server —
|
||||
`raw_key_server_path_completes_with_crate_pin_client` (no custom
|
||||
verifier needed anymore).
|
||||
- Suite 3b's premise is now **inverted**: a raw-key client identity
|
||||
presents its SPKI under the X.509 offer and
|
||||
`AcceptAnyCertVerifier` accepts it end-to-end
|
||||
(`raw_key_client_presents_spki_and_server_extracts_fingerprint`).
|
||||
- New pin: `ed25519_pin_against_x509_server_fails_closed_at_negotiation`
|
||||
— a pin-format/cert-kind mismatch aborts at negotiation, never a
|
||||
downgrade.
|
||||
|
||||
Rationale and limits (incl. the strict-foreign-server caveat) in
|
||||
ADR-007; client.md/server.md notes flipped accordingly.
|
||||
|
||||
## Notes
|
||||
|
||||
> **Major finding during implementation (recorded as OQ-TLS-10):** the
|
||||
|
||||
Reference in New Issue
Block a user