Skip to main content

Module server

Module server 

Source
Expand description

RATS (RFC 9334) role mapping for this server:

  • Attester: this process, running inside a Nitro Enclave. It holds a hardware-rooted identity via the Nitro Security Module (NSM).
  • Evidence: the NSM Attestation Document produced by attestation::detect, with user_data bound to the SHA-256 hash of the ephemeral TLS key’s SubjectPublicKeyInfo so a Relying Party can tie the Evidence to the TLS session.
  • Endorsements: the AWS Nitro certificate chain embedded in the Attestation Document, rooted at the AWS Nitro Enclaves root certificate.
  • Verifier / Relying Party: the external client fetching Evidence as an RFC 9711 EAT over /evidence.eat (or from the RA-TLS certificate). Appraisal against Reference Values (expected PCR measurements) and issuance of an Attestation Result happen outside this server.

This module owns attestation, the RA-TLS certificate and the QUIC / HTTP/3 transport; the HTTP routes, including the POST /faf relay, live in super::router.

Re-exports§

pub use super::router::Evidence;

Structs§

Server
An attested HTTP/3 server bound to a QUIC endpoint.

Constants§

LISTEN_ADDR_ENV
Environment variable that overrides the default listen address 0.0.0.0:4433 (a socket address such as 127.0.0.1:4444).
MAX_REQUEST_BODY
Largest request body the server reads; larger requests get 413 Payload Too Large.

Functions§

create_cert_with_attestation
Creates a self-signed certificate for key_pair with attestation_doc embedded as a non-critical X.509 extension, and returns it PEM-encoded.
run
Runs the server: attests, builds the RA-TLS identity, then serves HTTP/3 on TTK_LISTEN_ADDR (default 0.0.0.0:4433) until the endpoint closes.