pub struct EnclaveCertVerifier { /* private fields */ }Expand description
Custom certificate verifier for Remote Attestation TLS (RA-TLS).
The server presents an ephemeral self-signed certificate that carries an EAT with nested
TEE evidence (AWS Nitro, AMD SEV-SNP, Intel TDX or Intel SGX) in a custom X.509 extension.
Instead of a Web PKI CA chain, verify_server_cert
checks:
- the certificate itself: well-formed, within its validity period, correctly self-signed;
- the evidence: vendor signature chain up to a root in the
TrustStore(seettk_server::verifier), and that the TEE is not in debug mode; - the binding: the evidence’s report data equals the SHA-256 of the certificate’s SubjectPublicKeyInfo;
- any expected measurements configured with
with_expected_measurementorwith_expected_pcr.
The TLS handshake signature is verified against the same certificate, proving the peer holds the attested key.
Implementations§
Source§impl EnclaveCertVerifier
Construction, policy configuration and inspection of the verifier.
impl EnclaveCertVerifier
Construction, policy configuration and inspection of the verifier.
Sourcepub fn new() -> Self
pub fn new() -> Self
Creates a strict verifier: only genuine, vendor-signed evidence from a non-debug TEE is accepted, checked against the built-in vendor roots.
Sourcepub fn with_expected_measurement(
self,
name: impl Into<String>,
value: impl Into<Vec<u8>>,
) -> Self
pub fn with_expected_measurement( self, name: impl Into<String>, value: impl Into<Vec<u8>>, ) -> Self
Requires the evidence measurement name to equal value.
See VerifiedEvidence::measurements for the names each TEE reports. Evidence that
lacks the measurement (e.g. from a different TEE) is rejected.
Sourcepub fn with_expected_pcr(self, index: usize, value: impl Into<Vec<u8>>) -> Self
pub fn with_expected_pcr(self, index: usize, value: impl Into<Vec<u8>>) -> Self
Requires PCR index of a Nitro attestation document to equal value.
Sourcepub fn with_trust_store(self, trust: TrustStore) -> Self
pub fn with_trust_store(self, trust: TrustStore) -> Self
Replaces the built-in vendor roots, e.g. for testing or private deployments.
Sourcepub fn allow_mock(self) -> Self
pub fn allow_mock(self) -> Self
Accepts unsigned mock attestation documents (for local development only).
Skips the Nitro COSE signature and AWS certificate-chain checks; the certificate checks, the key binding and the measurement checks still apply. Never enable this in production.
Sourcepub fn allow_debug(self) -> Self
pub fn allow_debug(self) -> Self
Accepts evidence from TEEs running in debug mode, whose memory is not confidential.
Sourcepub fn received_certificate(&self) -> Option<CertificateDer<'static>>
pub fn received_certificate(&self) -> Option<CertificateDer<'static>>
Retrieve the server certificate DER bytes captured during a successful verification.
Sourcepub fn verified_evidence(&self) -> Option<VerifiedEvidence>
pub fn verified_evidence(&self) -> Option<VerifiedEvidence>
Returns the evidence accepted during the last successful verification.
Sourcepub fn verified_attestation(&self) -> Option<AttestationDocument>
pub fn verified_attestation(&self) -> Option<AttestationDocument>
Returns the Nitro attestation document accepted during the last successful verification, if the server attested with AWS Nitro.
Trait Implementations§
Source§impl Clone for EnclaveCertVerifier
impl Clone for EnclaveCertVerifier
Source§impl Debug for EnclaveCertVerifier
impl Debug for EnclaveCertVerifier
Source§impl Default for EnclaveCertVerifier
Default is equivalent to EnclaveCertVerifier::new.
impl Default for EnclaveCertVerifier
Default is equivalent to EnclaveCertVerifier::new.
Source§impl ServerCertVerifier for EnclaveCertVerifier
RA-TLS verification: the server is trusted because of its attestation, not a CA chain.
impl ServerCertVerifier for EnclaveCertVerifier
RA-TLS verification: the server is trusted because of its attestation, not a CA chain.
Source§fn verify_server_cert(
&self,
end_entity: &CertificateDer<'_>,
_intermediates: &[CertificateDer<'_>],
_server_name: &ServerName<'_>,
_ocsp_response: &[u8],
now: UnixTime,
) -> Result<ServerCertVerified, Error>
fn verify_server_cert( &self, end_entity: &CertificateDer<'_>, _intermediates: &[CertificateDer<'_>], _server_name: &ServerName<'_>, _ocsp_response: &[u8], now: UnixTime, ) -> Result<ServerCertVerified, Error>
Verifies the RA-TLS certificate and its embedded attestation document.
The hostname is not checked: the server’s identity is established by its attestation.
Source§fn verify_tls12_signature(
&self,
message: &[u8],
cert: &CertificateDer<'_>,
dss: &DigitallySignedStruct,
) -> Result<HandshakeSignatureValid, Error>
fn verify_tls12_signature( &self, message: &[u8], cert: &CertificateDer<'_>, dss: &DigitallySignedStruct, ) -> Result<HandshakeSignatureValid, Error>
Verifies the TLS 1.2 handshake signature with the server certificate’s key.
Source§fn verify_tls13_signature(
&self,
message: &[u8],
cert: &CertificateDer<'_>,
dss: &DigitallySignedStruct,
) -> Result<HandshakeSignatureValid, Error>
fn verify_tls13_signature( &self, message: &[u8], cert: &CertificateDer<'_>, dss: &DigitallySignedStruct, ) -> Result<HandshakeSignatureValid, Error>
Verifies the TLS 1.3 handshake signature with the server certificate’s key.
Source§fn supported_verify_schemes(&self) -> Vec<SignatureScheme>
fn supported_verify_schemes(&self) -> Vec<SignatureScheme>
Lists the signature schemes the verifier accepts.
Source§fn requires_raw_public_keys(&self) -> bool
fn requires_raw_public_keys(&self) -> bool
Source§fn root_hint_subjects(&self) -> Option<&[DistinguishedName]>
fn root_hint_subjects(&self) -> Option<&[DistinguishedName]>
DistinguishedNames of certificate authorities that this verifier trusts. Read more