#![cfg_attr(docsrs, feature(doc_cfg, doc_auto_cfg))]
#[cfg(all(unix, not(target_os = "macos")))]
mod unix;
#[cfg(all(unix, not(target_os = "macos")))]
use unix as platform;
#[cfg(windows)]
mod windows;
#[cfg(windows)]
use windows as platform;
#[cfg(target_os = "macos")]
mod macos;
#[cfg(target_os = "macos")]
use macos as platform;
use std::env;
use std::fs::File;
use std::io::BufReader;
use std::io::{Error, ErrorKind};
use std::path::{Path, PathBuf};
use pki_types::CertificateDer;
pub fn load_native_certs() -> Result<Vec<CertificateDer<'static>>, Error> {
load_certs_from_env().unwrap_or_else(platform::load_native_certs)
}
const ENV_CERT_FILE: &str = "SSL_CERT_FILE";
fn load_certs_from_env() -> Option<Result<Vec<CertificateDer<'static>>, Error>> {
let cert_var_path = PathBuf::from(env::var_os(ENV_CERT_FILE)?);
Some(load_pem_certs(&cert_var_path))
}
fn load_pem_certs(path: &Path) -> Result<Vec<CertificateDer<'static>>, Error> {
let mut f = BufReader::new(File::open(path)?);
rustls_pemfile::certs(&mut f)
.map(|result| match result {
Ok(der) => Ok(der),
Err(err) => Err(Error::new(
ErrorKind::InvalidData,
format!("could not load PEM file {path:?}: {err}"),
)),
})
.collect()
}