Skip to main content

EnclaveCertVerifier

Struct EnclaveCertVerifier 

Source
pub struct EnclaveCertVerifier { /* private fields */ }
Expand description

Custom certificate verifier for Remote Attestation TLS (RA-TLS).

The server presents an ephemeral self-signed certificate that carries an EAT with nested TEE evidence (AWS Nitro, AMD SEV-SNP, Intel TDX or Intel SGX) in a custom X.509 extension. Instead of a Web PKI CA chain, verify_server_cert checks:

  1. the certificate itself: well-formed, within its validity period, correctly self-signed;
  2. the evidence: vendor signature chain up to a root in the TrustStore (see ttk_server::verifier), and that the TEE is not in debug mode;
  3. the binding: the evidence’s report data equals the SHA-256 of the certificate’s SubjectPublicKeyInfo;
  4. any expected measurements configured with with_expected_measurement or with_expected_pcr.

The TLS handshake signature is verified against the same certificate, proving the peer holds the attested key.

Implementations§

Source§

impl EnclaveCertVerifier

Construction, policy configuration and inspection of the verifier.

Source

pub fn new() -> Self

Creates a strict verifier: only genuine, vendor-signed evidence from a non-debug TEE is accepted, checked against the built-in vendor roots.

Source

pub fn with_expected_measurement( self, name: impl Into<String>, value: impl Into<Vec<u8>>, ) -> Self

Requires the evidence measurement name to equal value.

See VerifiedEvidence::measurements for the names each TEE reports. Evidence that lacks the measurement (e.g. from a different TEE) is rejected.

Source

pub fn with_expected_pcr(self, index: usize, value: impl Into<Vec<u8>>) -> Self

Requires PCR index of a Nitro attestation document to equal value.

Source

pub fn with_trust_store(self, trust: TrustStore) -> Self

Replaces the built-in vendor roots, e.g. for testing or private deployments.

Source

pub fn allow_mock(self) -> Self

Accepts unsigned mock attestation documents (for local development only).

Skips the Nitro COSE signature and AWS certificate-chain checks; the certificate checks, the key binding and the measurement checks still apply. Never enable this in production.

Source

pub fn allow_debug(self) -> Self

Accepts evidence from TEEs running in debug mode, whose memory is not confidential.

Source

pub fn received_certificate(&self) -> Option<CertificateDer<'static>>

Retrieve the server certificate DER bytes captured during a successful verification.

Source

pub fn verified_evidence(&self) -> Option<VerifiedEvidence>

Returns the evidence accepted during the last successful verification.

Source

pub fn verified_attestation(&self) -> Option<AttestationDocument>

Returns the Nitro attestation document accepted during the last successful verification, if the server attested with AWS Nitro.

Trait Implementations§

Source§

impl Clone for EnclaveCertVerifier

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for EnclaveCertVerifier

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for EnclaveCertVerifier

Default is equivalent to EnclaveCertVerifier::new.

Source§

fn default() -> Self

Creates a new strict verifier.

Source§

impl ServerCertVerifier for EnclaveCertVerifier

RA-TLS verification: the server is trusted because of its attestation, not a CA chain.

Source§

fn verify_server_cert( &self, end_entity: &CertificateDer<'_>, _intermediates: &[CertificateDer<'_>], _server_name: &ServerName<'_>, _ocsp_response: &[u8], now: UnixTime, ) -> Result<ServerCertVerified, Error>

Verifies the RA-TLS certificate and its embedded attestation document.

The hostname is not checked: the server’s identity is established by its attestation.

Source§

fn verify_tls12_signature( &self, message: &[u8], cert: &CertificateDer<'_>, dss: &DigitallySignedStruct, ) -> Result<HandshakeSignatureValid, Error>

Verifies the TLS 1.2 handshake signature with the server certificate’s key.

Source§

fn verify_tls13_signature( &self, message: &[u8], cert: &CertificateDer<'_>, dss: &DigitallySignedStruct, ) -> Result<HandshakeSignatureValid, Error>

Verifies the TLS 1.3 handshake signature with the server certificate’s key.

Source§

fn supported_verify_schemes(&self) -> Vec<SignatureScheme>

Lists the signature schemes the verifier accepts.

Source§

fn requires_raw_public_keys(&self) -> bool

Returns whether this verifier requires raw public keys as defined in RFC 7250.
Source§

fn root_hint_subjects(&self) -> Option<&[DistinguishedName]>

Return the DistinguishedNames of certificate authorities that this verifier trusts. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

Source§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

Source§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

Source§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<A, B, T> HttpServerConnExec<A, B> for T
where B: Body,

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more