pub enum Trust {
Pinned([u8; 32]),
WebPki,
Insecure,
}Expand description
How to trust whatever certificate the station presents. Mirrors the
three modes macula_quic’s own build_client_config supports — see
plans/PLAN_WIRE_PROTOCOL.md §2.
Clone, Copy: every variant is plain data (a bare [u8; 32] or
nothing at all), and pool.rs needs to redial a link — possibly
under a DIFFERENT per-link trust than the pool’s own configured
default, see pool::PooledLink’s own doc — more than once over a
link’s lifetime (initial dial, every respawn).
Variants§
Pinned([u8; 32])
Pin the station’s known Ed25519 pubkey (its macula NodeId). The right mode once a station’s identity is known — DHT-resolved, or configured directly, which is the normal case for a mobile client dialing a known station.
WebPki
Standard CA-bundle + hostname validation, for a station whose TLS is terminated by real PKI (e.g. Let’s Encrypt) rather than a self-signed macula identity cert.
Insecure
Skip verification entirely. Development/diagnostic only — see
crate::cert::SkipServerVerification’s own warning.