Expand description
RATS (RFC 9334) role mapping for this server:
- Attester: this process, running inside a Nitro Enclave. It holds a hardware-rooted identity via the Nitro Security Module (NSM).
- Evidence: the NSM Attestation Document produced by
attestation::detect, withuser_databound to the SHA-256 hash of the ephemeral TLS key’s SubjectPublicKeyInfo so a Relying Party can tie the Evidence to the TLS session. - Endorsements: the AWS Nitro certificate chain embedded in the Attestation Document, rooted at the AWS Nitro Enclaves root certificate.
- Verifier / Relying Party: the external client fetching Evidence as an
RFC 9711 EAT over
/evidence.eat(or from the RA-TLS certificate). Appraisal against Reference Values (expected PCR measurements) and issuance of an Attestation Result happen outside this server.
This module owns attestation, the RA-TLS certificate and the QUIC / HTTP/3 transport; the
HTTP routes, including the POST /faf relay, live in super::router.
Re-exports§
pub use super::router::Evidence;
Structs§
- Server
- An attested HTTP/3 server bound to a QUIC endpoint.
Constants§
- LISTEN_
ADDR_ ENV - Environment variable that overrides the default listen address
0.0.0.0:4433(a socket address such as127.0.0.1:4444). - MAX_
REQUEST_ BODY - Largest request body the server reads; larger requests get
413 Payload Too Large.
Functions§
- create_
cert_ with_ attestation - Creates a self-signed certificate for
key_pairwithattestation_docembedded as a non-critical X.509 extension, and returns it PEM-encoded. - run
- Runs the server: attests, builds the RA-TLS identity, then serves HTTP/3 on
TTK_LISTEN_ADDR(default0.0.0.0:4433) until the endpoint closes.