pub struct OrderConfig {
pub validity_seconds: u64,
pub max_identifiers: usize,
pub retention_days: u64,
}Expand description
Order object configuration.
Fields§
§validity_seconds: u64§max_identifiers: usizeMost identifiers one newOrder may name.
The only other bound is server.max_body_bytes (128 KiB), which at the
~30 bytes an identifier costs lets a single request ask for some four
thousand names — and each one becomes an authorization plus a challenge
per offered type, all inserted in one transaction. SQLite has a
single writer, so that transaction stalls every other write in the
process for as long as it runs, and the response is four thousand
authorization URLs.
100 is what Let’s Encrypt allows, and is far above what a real client
asks for; the point is a ceiling, not a policy. A refusal is
malformed, not rateLimited — the order is malformed for this server
whenever it is sent, and §6.6’s retry-later reading would be a lie.
retention_days: u64Days an order is kept after it expires, before the retention sweep
deletes it. 0 keeps everything for ever.
Nothing pruned orders before this, so the table and the
authorizations and challenges that cascade from it grew for the life
of a deployment — one order plus N authorizations plus N×M challenges
per newOrder, on a default configuration where newAccount is open to
anyone.
A valid order is never swept, whatever its age. Its row is what
revokeCert and the CRL find a certificate by serial through, and what
RFC 9773 renewal information is derived from; deleting one would make an
issued certificate unrevokable. Only orders that ended some other way —
invalid, or abandoned pending/ready/processing — are eligible,
and only once their own expires is retention_days behind, at which
point no client can act on them either.
Per-profile like the rest of [order]: the sweep is one handler that
applies each mounted profile’s own value to that profile’s rows.
Trait Implementations§
Source§impl Clone for OrderConfig
impl Clone for OrderConfig
Source§fn clone(&self) -> OrderConfig
fn clone(&self) -> OrderConfig
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for OrderConfig
impl Debug for OrderConfig
Source§impl Default for OrderConfig
impl Default for OrderConfig
Source§impl<'de> Deserialize<'de> for OrderConfigwhere
OrderConfig: Default,
impl<'de> Deserialize<'de> for OrderConfigwhere
OrderConfig: Default,
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Auto Trait Implementations§
impl Freeze for OrderConfig
impl RefUnwindSafe for OrderConfig
impl Send for OrderConfig
impl Sync for OrderConfig
impl Unpin for OrderConfig
impl UnsafeUnpin for OrderConfig
impl UnwindSafe for OrderConfig
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more