Skip to main content

Crate acme_proxy_core

Crate acme_proxy_core 

Source
Expand description

The bottom of acme-proxy’s crate graph: what every layer above it speaks.

Configuration (config), the ACME wire vocabulary (identifier, jws, error’s problem documents, routes), the nested-JWS surfaces that are pure verification (eab, key_change), certificate parsing (cert), the audit trail’s vocabulary (audit), where a request came from (client), and the small shared helpers (datetime, logfields, palette, pemfile, random, script_hook, templating).

Nothing here opens a database, dials a network or knows a signer; the crates that do are built on it. An internal crate of the acme-proxy binary, published in lockstep with it and with no semver promise of its own.

Modules§

audit
The vocabulary of the CA’s audit trail: who asked this server to sign or withdraw a certificate, from where, and how it ended.
cert
Small X.509 helpers shared by the certificate revocation paths: the ACME POST /revokeCert handler (handlers::post_revoke_cert) and the order revoke admin CLI command (admin::revoke_order). Both need to pull a certificate’s serial/public key out of raw DER, and pull the leaf back out of a stored leaf + CA PEM chain, so the parsing lives here once rather than twice.
client
Deciding which address a request actually came from.
config
The configuration: one Config, loaded once by Config::load and rebuilt on every reload.
datetime
Datetimes as the wire and the operator surfaces render them.
eab
External Account Binding (RFC 8555 §7.3.4): verification of the inner HMAC JWS a newAccount payload may carry, proving the client holds a pre-shared credential an operator issued out-of-band.
error
Problem: every error an ACME handler answers with, as the RFC 8555 §6.7 application/problem+json document a client parses.
identifier
The ACME identifier (RFC 8555 §7.1.4) — the name an order, an authorization, a filter check and a signer’s CSR check all speak about.
jws
JSON Web Signature, as RFC 8555 §6.2 uses it: the wire types (AcmeJwsRequest, ProtectedHeader, Jwk) and, in signature, the cryptography — including the DER-SPKI encoding by hand and the rule that the verification algorithm is never chosen from the client’s alg alone.
key_change
Account Key Rollover (RFC 8555 §7.3.5): verification of the nested inner JWS a keyChange request’s payload carries, proving simultaneous possession of both the old and new account keys.
logfields
Typed helpers for structured log fields, so a field has one spelling and one wire type wherever it is logged.
palette
Colour for the admin CLI’s human-readable output: whether it is on, and what each colour means.
pemfile
PEM material on disk: reading a certificate chain or a private key, and writing a key that is never briefly world-readable.
random
Random values from the system CSPRNG.
routes
The ACME resource paths, profile-relative, and the namespace every profile is mounted under.
script_hook
The contract every custom hook in this server runs under: one script, a cleared environment, JSON on stdin, an exit code for the verdict.
templating
The one thing the two minijinja environments in this crate share: how a template is found.