Skip to main content

Module transport

Module transport 

Source
Expand description

Dialing a macula 12 station over QUIC, as macula-go’s transport does.

Raw QUIC (RFC 9000) with the ALPN "macula", TLS 1.3 only, and the key exchange macula-pqc fixes: SecP384r1MLKEM1024, then SecP256r1MLKEM768, and nothing classical. A station’s certificate is self-signed, so it is not checked against a CA: macula-pqc’s KeyPossessionVerifier accepts exactly one certificate whose key is ML-DSA-87, then the station’s handshake signature under that key. That proves the station holds the key, not who it is: the handshake then checks the station’s TLS binding, which ties this leaf to the identity key whose node_id the target pins (see crate::handshake). A target without an expected node_id is refused before anything is dialed.

quinn protects QUIC Initial packets with the suite it finds in the rustls provider, and RFC 9001 fixes that suite at AES-128-GCM, which macula-pqc’s provider does not offer for the handshake itself; the configuration is therefore built with with_initial and macula-pqc’s quic_initial_suite.

Structs§

Dialed
A dialed station: the QUIC connection, the endpoint it runs on, the leaf certificate the station presented (DER), and the target it was dialed as. The endpoint must live as long as the connection.
Target
A station to dial: where it listens, the profile the node runs, and the node_id the station must prove in the handshake.

Enums§

DialError
Why a dial failed.

Constants§

ALPN
The ALPN macula stations listen for.
IDLE_TIMEOUT
macula’s QUIC idle timeout and keep-alive: long enough to tolerate a real gap between frames, with pings often enough that a healthy connection is never mistaken for a dead one.
KEEP_ALIVE_INTERVAL

Functions§

dial_target
Dials target: QUIC and TLS 1.3 with the post-quantum key exchange, the station’s certificate checked for an ML-DSA-87 key it holds.