Skip to main content

ttk_server/service/
mod.rs

1//! Network services of the RA-TLS stack over QUIC / HTTP/3 (RFC 9114), plus the RA-TLS
2//! identity and attestation request parameters they share.
3//!
4//! - [`server`]: the RATS (RFC 9334) Attester endpoint, serving Evidence from inside the TEE.
5//! - [`router`]: the server's HTTP routes, including the `POST /faf` relay.
6//! - [`client`]: the Relying Party side, verifying the RA-TLS certificate's embedded Evidence.
7
8pub mod client;
9pub mod router;
10pub mod server;
11
12use rcgen::generate_simple_self_signed;
13use rustls_pki_types::{CertificateDer, PrivateKeyDer, PrivatePkcs8KeyDer};
14use sha2::{Digest, Sha256};
15
16/// Generates a self-signed ephemeral TLS certificate and private key for Remote Attestation TLS (RA-TLS).
17///
18/// Returns `(certificates, private_key, certificate_der_bytes)`.
19pub fn generate_identity() -> (
20    Vec<CertificateDer<'static>>,
21    PrivateKeyDer<'static>,
22    Vec<u8>,
23) {
24    let subject_alt_names = vec!["localhost".to_string(), "enclave.local".to_string()];
25    let certified_key = generate_simple_self_signed(subject_alt_names).unwrap();
26
27    let cert_der = certified_key.cert.der().to_vec();
28    let rustls_cert = certified_key.cert.der().clone();
29    let rustls_key = PrivateKeyDer::Pkcs8(PrivatePkcs8KeyDer::from(
30        certified_key.key_pair.serialize_der(),
31    ));
32
33    (vec![rustls_cert], rustls_key, cert_der)
34}
35
36/// Parameters for requesting an attestation document from the Nitro Security Module.
37#[derive(Debug, Clone, Default, PartialEq)]
38pub struct AttestationParams {
39    /// Optional user data to include in the attestation document (e.g. SHA-256 hash of TLS cert).
40    pub user_data: Option<Vec<u8>>,
41    /// Optional cryptographic nonce to prevent replay attacks.
42    pub nonce: Option<Vec<u8>>,
43    /// Optional public key (DER-encoded) for cryptographic sealing or key exchange.
44    pub public_key: Option<Vec<u8>>,
45}
46
47/// Builder-style setters and accessors for the attestation parameters.
48impl AttestationParams {
49    /// Creates a new, empty set of attestation parameters.
50    pub fn new() -> Self {
51        Self::default()
52    }
53
54    /// Sets user data bytes.
55    pub fn with_user_data(mut self, data: impl Into<Vec<u8>>) -> Self {
56        self.user_data = Some(data.into());
57        self
58    }
59
60    /// Computes the SHA-256 hash of the input data (such as a DER-encoded certificate)
61    /// and sets it as the `user_data` field for Remote Attestation TLS (RA-TLS).
62    pub fn with_user_data_hash(mut self, data: &[u8]) -> Self {
63        let hash = Sha256::digest(data);
64        self.user_data = Some(hash.to_vec());
65        self
66    }
67
68    /// Sets the cryptographic nonce.
69    pub fn with_nonce(mut self, nonce: impl Into<Vec<u8>>) -> Self {
70        self.nonce = Some(nonce.into());
71        self
72    }
73
74    /// Sets the DER-encoded public key.
75    pub fn with_public_key(mut self, public_key: impl Into<Vec<u8>>) -> Self {
76        self.public_key = Some(public_key.into());
77        self
78    }
79
80    /// Returns a reference to the user data, if set.
81    pub fn user_data(&self) -> Option<&[u8]> {
82        self.user_data.as_deref()
83    }
84
85    /// Returns a reference to the nonce, if set.
86    pub fn nonce(&self) -> Option<&[u8]> {
87        self.nonce.as_deref()
88    }
89
90    /// Returns a reference to the public key, if set.
91    pub fn public_key(&self) -> Option<&[u8]> {
92        self.public_key.as_deref()
93    }
94}