Expand description
Dialing a macula 12 station over QUIC, as macula-go’s transport does.
Raw QUIC (RFC 9000) with the ALPN "macula", TLS 1.3 only, and the key
exchange macula-pqc fixes: SecP384r1MLKEM1024, then SecP256r1MLKEM768, and
nothing classical. A station’s certificate is self-signed, so it is not
checked against a CA: macula-pqc’s KeyPossessionVerifier accepts
exactly one certificate whose key is ML-DSA-87, then the station’s
handshake signature under that key. That proves the station holds the key,
not who it is: the handshake then checks the station’s TLS binding, which
ties this leaf to the identity key whose node_id the target pins (see
crate::handshake). A target without an expected node_id is refused before
anything is dialed.
quinn protects QUIC Initial packets with the suite it finds in the rustls
provider, and RFC 9001 fixes that suite at AES-128-GCM, which macula-pqc’s
provider does not offer for the handshake itself; the configuration is
therefore built with with_initial and macula-pqc’s quic_initial_suite.
Structs§
- Dialed
- A dialed station: the QUIC connection, the endpoint it runs on, the leaf certificate the station presented (DER), and the target it was dialed as. The endpoint must live as long as the connection.
- Target
- A station to dial: where it listens, the profile the node runs, and the node_id the station must prove in the handshake.
Enums§
- Dial
Error - Why a dial failed.
Constants§
- ALPN
- The ALPN macula stations listen for.
- IDLE_
TIMEOUT - macula’s QUIC idle timeout and keep-alive: long enough to tolerate a real gap between frames, with pings often enough that a healthy connection is never mistaken for a dead one.
- KEEP_
ALIVE_ INTERVAL
Functions§
- dial_
target - Dials
target: QUIC and TLS 1.3 with the post-quantum key exchange, the station’s certificate checked for an ML-DSA-87 key it holds.