Close review 001 §S-1: the default client-cert verifier never checked
the client's CertificateVerify, so anyone holding a peer's *public*
cert/SPKI bytes (public by design — peers publish them to be dialable)
could complete a handshake as that peer, and the auth layer could not
detect it. The consumer designs are known (X.509 and raw-key TCP/QUIC
endpoints with identity-bearing clients), so implementing now — the
zero-consumer moment — avoids the guaranteed breaking republish of
flipping the default later.
- VerifyPresentedCertVerifier (new): request, don't require, verify
possession — permissive verify_client_cert (self-signed chains and
bare SPKIs stay valid presentation) + CertificateVerify routing by
presented cert kind (Ed25519 SPKI -> verify_tls13_signature_with_
raw_key both TLS versions; X.509 -> standard route), the same
routing FingerprintPinVerifier implements. Nine-scheme list
verbatim (shared fn, exact-list pin covers both).
- Default on every TlsServerConfig path — X509 / RawKey / SelfSigned
/ ACME (the verifier install is crate-side rustls in new_acme, not
rustls-acme's).
- AcceptAnyCertVerifier stays public as the explicit no-pop escape
hatch, no longer installed by any crate path.
- tests/impersonation_posture.rs: four pins — default rejects the
attacker (X.509: UnsupportedSignatureAlgorithmForPublicKeyContext;
raw-key: BadSignature), escape hatch still accepts + extracts the
victim's fingerprint (both cert types).
- tests/handshake_behavior.rs: suites 4/4b — possession-checked legit
clients (raw-key pin vs raw-key server; X.509 client vs X.509
server) complete and the server extracts the fingerprint; suite 3b
doc updated.
- Docs: ADR-008 written; OQ-TLS-09 -> resolved (option (b));
ADR-007 §Limits deferral retired to not-planned; server.md/client.md
invariants/README/overview synced.
Verification: cargo test 81 / --features tcp 95 / --all-features 104
green; clippy -D warnings clean (default + all-features); fmt clean;
cargo doc warning-free.
Resolve the cert-type negotiation gap (review 001 §U-3, OQ-TLS-10) by
deviation from alknet: the gap was a defect in the prior art (alknet's
code never delivered its spec's raw-key-over-TCP promise — ADR-082
"works for both QUIC and TCP+TLS"), not behavior to preserve.
- FingerprintPinVerifier::requires_raw_public_keys() derives from the
pin format: ed25519: -> true (offer [RawPublicKey]), SHA256: ->
false (X.509 offer). Crate pin client now completes against the
crate raw-key server; SHA256: pins negotiate unchanged.
- RawKeyClientCertResolver presents the SPKI under the X.509 offer
(only_raw_public_keys() == false): a raw-only client offer can only
negotiate against a requires_raw server verifier, and
AcceptAnyCertVerifier correctly stays on the default (accepts both
cert types). The server extracts the ed25519: fingerprint from the
SPKI bytes either way.
- Fail-closed preserved and strengthened: an ed25519: pin against an
X.509 server now aborts at negotiation (suite 2b), never a
downgrade; no API change (no public signature affected; the fix is
invisible to consumers apart from working handshakes).
- tests/handshake_behavior.rs: suite 3 now runs crate-native (no
custom iroh-shaped verifier), new negotiation fail-closed suite,
suite 3b inverted to end-to-end success; invariant_pins.rs
resolver-offer assertions flipped; unused imports dropped.
- Docs: ADR-007 written; OQ-TLS-10 -> resolved-by-deviation;
client.md/server.md/overview/README/task postscript synced
(incl. the strict-foreign-server limit in ADR-007 §Limits).
Verification: cargo test 81 / --features tcp 94 / --all-features
105 green; clippy -D warnings clean (default + all-features); fmt
clean; cargo doc warning-free.