Skip to main content

ensure_ca

Function ensure_ca 

Source
pub fn ensure_ca(
    cert_path: &Path,
    key_path: &Path,
    usable: impl FnOnce() -> bool,
) -> Result<bool>
Expand description

Generate the CA pair unless usable says the one on disk will do.

proxy setup and a starting supervisor can both find the CA missing and generate one at once. The cert and key are separate files, so two writers interleaving can leave one’s certificate beside the other’s key: a pair that trusts fine and then signs nothing that verifies. The check and the write happen under one lock so only the first generation happens.

Returns whether a new pair was written.