Expand description
TTKServer HTTP/3 (QUIC) Client implementation.
Connects to TTKServer running inside an AWS Nitro Enclave (or local testing environment) over QUIC and HTTP/3 (RFC 9114).
Handles:
- QUIC transport negotiation via
quinnwith ALPNh3 - RA-TLS verification of the enclave’s ephemeral self-signed certificate: the embedded TEE evidence (AWS Nitro, AMD SEV-SNP, Intel TDX or SGX) is verified against the vendor’s root and must bind to the SHA-256 of the certificate’s public key
- Sending HTTP/3 requests and receiving responses using
h3andh3-quinn
Re-exports§
pub use crate::verifier::nitro::AttestationDocument;
Structs§
- Client
Response - Represents the response received from the HTTP/3 server.
- Enclave
Cert Verifier - Custom certificate verifier for Remote Attestation TLS (RA-TLS).
- TtkClient
- HTTP/3 client for communicating with TTKServer over QUIC.
Functions§
- extract_
attestation_ doc - Extract raw attestation bytes from the leaf certificate
- hex_
encode - Helper function to format bytes as a hex string.