Skip to main content

Module client

Module client 

Source
Expand description

TTKServer HTTP/3 (QUIC) Client implementation.

Connects to TTKServer running inside an AWS Nitro Enclave (or local testing environment) over QUIC and HTTP/3 (RFC 9114).

Handles:

  • QUIC transport negotiation via quinn with ALPN h3
  • RA-TLS verification of the enclave’s ephemeral self-signed certificate: the embedded TEE evidence (AWS Nitro, AMD SEV-SNP, Intel TDX or SGX) is verified against the vendor’s root and must bind to the SHA-256 of the certificate’s public key
  • Sending HTTP/3 requests and receiving responses using h3 and h3-quinn

Re-exports§

pub use crate::verifier::nitro::AttestationDocument;

Structs§

ClientResponse
Represents the response received from the HTTP/3 server.
EnclaveCertVerifier
Custom certificate verifier for Remote Attestation TLS (RA-TLS).
TtkClient
HTTP/3 client for communicating with TTKServer over QUIC.

Functions§

extract_attestation_doc
Extract raw attestation bytes from the leaf certificate
hex_encode
Helper function to format bytes as a hex string.