courierust 1.0.0

no_std HTTP and gRPC engine with work-stealing, RFC 9218, and JA3/JA4 fingerprinting.
Documentation
//! Test-only TLS identity: an Ed25519 self-signed certificate for
//! `localhost` (valid 2026-08-20 .. 2036-08-17), generated with OpenSSL
//! 3.x. Used by the end-to-end TLS handshake and HTTPS integration tests.
//!
//! This is a test artifact only — it is never used as a default trust
//! anchor by the library.

/// DER-encoded self-signed certificate.
/// subject = CN=localhost, issuer = CN=localhost.
/// SAN: DNS:localhost, IP:127.0.0.1.
/// basicConstraints = critical, CA:TRUE; keyUsage = digitalSignature,
/// keyCertSign, cRLSign.
pub(crate) const SERVER_CERT_DER: &[u8] = &[
    0x30, 0x82, 0x01, 0x69, 0x30, 0x82, 0x01, 0x1b, 0xa0, 0x03, 0x02, 0x01, 0x02, 0x02, 0x14, 0x7b,
    0xa7, 0x64, 0x6f, 0x10, 0x02, 0x62, 0x8d, 0x15, 0x37, 0x61, 0xff, 0xd1, 0xa5, 0xba, 0x8b, 0x22,
    0x49, 0xab, 0x5d, 0x30, 0x05, 0x06, 0x03, 0x2b, 0x65, 0x70, 0x30, 0x14, 0x31, 0x12, 0x30, 0x10,
    0x06, 0x03, 0x55, 0x04, 0x03, 0x0c, 0x09, 0x6c, 0x6f, 0x63, 0x61, 0x6c, 0x68, 0x6f, 0x73, 0x74,
    0x30, 0x1e, 0x17, 0x0d, 0x32, 0x36, 0x30, 0x38, 0x32, 0x30, 0x31, 0x33, 0x32, 0x36, 0x35, 0x39,
    0x5a, 0x17, 0x0d, 0x33, 0x36, 0x30, 0x38, 0x31, 0x37, 0x31, 0x33, 0x32, 0x36, 0x35, 0x39, 0x5a,
    0x30, 0x14, 0x31, 0x12, 0x30, 0x10, 0x06, 0x03, 0x55, 0x04, 0x03, 0x0c, 0x09, 0x6c, 0x6f, 0x63,
    0x61, 0x6c, 0x68, 0x6f, 0x73, 0x74, 0x30, 0x2a, 0x30, 0x05, 0x06, 0x03, 0x2b, 0x65, 0x70, 0x03,
    0x21, 0x00, 0xc1, 0xc6, 0xfc, 0x0c, 0xe9, 0x2b, 0x4a, 0x7b, 0xc3, 0x43, 0xd6, 0x44, 0x5a, 0x54,
    0xdc, 0x8a, 0xf6, 0x86, 0x39, 0x0f, 0x5c, 0x4d, 0xc9, 0x79, 0x21, 0x98, 0x8b, 0xa3, 0xc8, 0x12,
    0x23, 0x30, 0xa3, 0x7f, 0x30, 0x7d, 0x30, 0x1d, 0x06, 0x03, 0x55, 0x1d, 0x0e, 0x04, 0x16, 0x04,
    0x14, 0x36, 0xa2, 0x38, 0x9e, 0x39, 0x4a, 0xa8, 0xf1, 0x9b, 0x60, 0xf6, 0x58, 0x4b, 0x5f, 0x2a,
    0x49, 0xaa, 0xbe, 0xe2, 0x0b, 0x30, 0x1f, 0x06, 0x03, 0x55, 0x1d, 0x23, 0x04, 0x18, 0x30, 0x16,
    0x80, 0x14, 0x36, 0xa2, 0x38, 0x9e, 0x39, 0x4a, 0xa8, 0xf1, 0x9b, 0x60, 0xf6, 0x58, 0x4b, 0x5f,
    0x2a, 0x49, 0xaa, 0xbe, 0xe2, 0x0b, 0x30, 0x1a, 0x06, 0x03, 0x55, 0x1d, 0x11, 0x04, 0x13, 0x30,
    0x11, 0x82, 0x09, 0x6c, 0x6f, 0x63, 0x61, 0x6c, 0x68, 0x6f, 0x73, 0x74, 0x87, 0x04, 0x7f, 0x00,
    0x00, 0x01, 0x30, 0x0f, 0x06, 0x03, 0x55, 0x1d, 0x13, 0x01, 0x01, 0xff, 0x04, 0x05, 0x30, 0x03,
    0x01, 0x01, 0xff, 0x30, 0x0e, 0x06, 0x03, 0x55, 0x1d, 0x0f, 0x01, 0x01, 0xff, 0x04, 0x04, 0x03,
    0x02, 0x01, 0x86, 0x30, 0x05, 0x06, 0x03, 0x2b, 0x65, 0x70, 0x03, 0x41, 0x00, 0xee, 0xd2, 0x7a,
    0x76, 0xff, 0x3d, 0xb9, 0xaf, 0xa9, 0x87, 0x68, 0xbd, 0x85, 0xf9, 0xf6, 0xff, 0xc8, 0x2b, 0xfb,
    0xd0, 0x48, 0x94, 0x69, 0x7a, 0x19, 0x94, 0x45, 0x09, 0x8a, 0x67, 0x4e, 0x8c, 0xec, 0x54, 0xab,
    0xaa, 0xa0, 0xba, 0xec, 0x12, 0xea, 0xfe, 0x12, 0xbf, 0xf8, 0x0e, 0x87, 0x96, 0xed, 0xd9, 0x48,
    0x65, 0xce, 0xf8, 0x48, 0xf6, 0x0c, 0x09, 0xa7, 0x5b, 0x50, 0x5e, 0x00, 0x02,
];

/// PKCS#8 DER-encoded Ed25519 private key matching [`SERVER_CERT_DER`].
pub(crate) const SERVER_KEY_DER: &[u8] = &[
    0x30, 0x2e, 0x02, 0x01, 0x00, 0x30, 0x05, 0x06, 0x03, 0x2b, 0x65, 0x70, 0x04, 0x22, 0x04, 0x20,
    0x18, 0xab, 0xee, 0xbf, 0x68, 0x5a, 0x04, 0x6a, 0xcb, 0xd0, 0x92, 0x42, 0x43, 0xaf, 0x2e, 0xe2,
    0x88, 0xb6, 0x91, 0x81, 0x91, 0xea, 0x18, 0x0e, 0x75, 0x6e, 0x62, 0xe6, 0x0e, 0x17, 0x4e, 0xd1,
];

/// A fixed Unix timestamp inside the certificate validity window, so the
/// tests are deterministic regardless of the machine clock.
pub(crate) const NOW: i64 = 1_800_000_000; // 2027-01-14T00:00:00Z

/// The server identity for the test certificate.
pub(crate) fn server_identity() -> crate::courierust_tls::Identity {
    crate::courierust_tls::Identity {
        cert_chain: vec![SERVER_CERT_DER.to_vec()],
        private_key: SERVER_KEY_DER.to_vec(),
        is_rsa: false,
    }
}

/// A root store that trusts the test certificate.
pub(crate) fn root_store() -> crate::courierust_tls::RootStore {
    let mut roots = crate::courierust_tls::RootStore::new();
    roots.add_der(SERVER_CERT_DER.to_vec());
    roots
}