Skip to main content

TlsServer

Struct TlsServer 

Source
pub struct TlsServer { /* private fields */ }
Expand description

A TLS server address under construction, returned by Server::tls.

Carries the options that only make sense for a TLS connection. Convert it into a Server with From — which happens automatically wherever an impl Into<Server> is accepted, so the builder chain can be passed directly to connect.

Implementations§

Source§

impl TlsServer

Source

pub fn with_sni(self, hostname: impl Into<String>) -> Self

Override the hostname used for SNI and certificate verification.

By default the host part of the address is used. Set this when connecting to an IP address whose certificate names a hostname, or when going through a tunnel that changes the address.

Source

pub fn with_extra_root_pem(self, pem: impl Into<Vec<u8>>) -> Self

Trust an additional root certificate, in PEM form, alongside the platform’s native roots.

This is the supported way to connect to a network using a private CA or a self-signed certificate: trust exactly that certificate rather than disabling verification wholesale. May be called repeatedly; every certificate found in each PEM blob is added.

The PEM is parsed when the connection is made, so a malformed blob surfaces as a connect error rather than a panic here.

Source

pub fn with_client_cert_pem(self, pem: impl Into<Vec<u8>>) -> Self

Present a client certificate, in PEM form, for CertFP / SASL EXTERNAL authentication.

pem must contain the private key and the certificate chain concatenated — the single-file form produced by, for example:

openssl req -x509 -newkey rsa:4096 -sha256 -days 3650 \
    -nodes -keyout bot.pem -out bot.pem -subj "/CN=mybot"

The bytes are parsed when the connection is made, so a malformed or key-less blob surfaces as a connect error rather than a panic here.

Calling this more than once replaces the previous certificate.

Source

pub fn danger_accept_invalid_certs(self) -> Self

Dangerous. Accept any server certificate without verifying it.

This disables certificate and hostname verification entirely, which removes the protection TLS provides against an active machine-in-the-middle: traffic is still encrypted, but you have no assurance about who it is encrypted to. Passwords sent to the server — PASS, NickServ IDENTIFY, SASL — become interceptable.

It exists for talking to a development server on localhost and for tests. For a real network using a self-signed or private-CA certificate, use with_extra_root_pem instead: it keeps verification on and trusts exactly the one certificate you intend to trust.

Enabling this logs a warning on every connection.

Trait Implementations§

Source§

impl Clone for TlsServer

Source§

fn clone(&self) -> TlsServer

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for TlsServer

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl From<TlsServer> for Server

Available on crate feature tls only.
Source§

fn from(tls: TlsServer) -> Self

Converts to this type from the input type.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more