pub struct Verifier { /* private fields */ }Expand description
A TLS certificate verifier that uses the system’s root store and WebPKI.
Implementations§
Source§impl Verifier
impl Verifier
Sourcepub fn new(crypto_provider: Arc<CryptoProvider>) -> Result<Self, TlsError>
Available on (Unix or WebAssembly) and non-Android and non-Apple only.
pub fn new(crypto_provider: Arc<CryptoProvider>) -> Result<Self, TlsError>
Creates a new verifier whose certificate validation is provided by WebPKI, using root certificates provided by the platform.
Sourcepub fn new_with_extra_roots(
extra_roots: impl IntoIterator<Item = CertificateDer<'static>>,
crypto_provider: Arc<CryptoProvider>,
) -> Result<Self, TlsError>
Available on (Unix or WebAssembly) and non-Android and non-Apple only.
pub fn new_with_extra_roots( extra_roots: impl IntoIterator<Item = CertificateDer<'static>>, crypto_provider: Arc<CryptoProvider>, ) -> Result<Self, TlsError>
Creates a new verifier whose certificate validation is provided by WebPKI, using root certificates provided by the platform and augmented by the provided extra root certificates.
Trait Implementations§
Source§impl Debug for Verifier
Available on (Unix or WebAssembly) and non-Android and non-Apple only.
impl Debug for Verifier
Available on (Unix or WebAssembly) and non-Android and non-Apple only.
Source§impl ServerCertVerifier for Verifier
Available on (Unix or WebAssembly) and non-Android and non-Apple only.
impl ServerCertVerifier for Verifier
Available on (Unix or WebAssembly) and non-Android and non-Apple only.
Source§fn verify_server_cert(
&self,
end_entity: &CertificateDer<'_>,
intermediates: &[CertificateDer<'_>],
server_name: &ServerName<'_>,
ocsp_response: &[u8],
now: UnixTime,
) -> Result<ServerCertVerified, TlsError>
fn verify_server_cert( &self, end_entity: &CertificateDer<'_>, intermediates: &[CertificateDer<'_>], server_name: &ServerName<'_>, ocsp_response: &[u8], now: UnixTime, ) -> Result<ServerCertVerified, TlsError>
Verify the end-entity certificate
end_entity is valid for the
hostname dns_name and chains to at least one trust anchor. Read moreSource§fn verify_tls12_signature(
&self,
message: &[u8],
cert: &CertificateDer<'_>,
dss: &DigitallySignedStruct,
) -> Result<HandshakeSignatureValid, TlsError>
fn verify_tls12_signature( &self, message: &[u8], cert: &CertificateDer<'_>, dss: &DigitallySignedStruct, ) -> Result<HandshakeSignatureValid, TlsError>
Verify a signature allegedly by the given server certificate. Read more
Source§fn verify_tls13_signature(
&self,
message: &[u8],
cert: &CertificateDer<'_>,
dss: &DigitallySignedStruct,
) -> Result<HandshakeSignatureValid, TlsError>
fn verify_tls13_signature( &self, message: &[u8], cert: &CertificateDer<'_>, dss: &DigitallySignedStruct, ) -> Result<HandshakeSignatureValid, TlsError>
Verify a signature allegedly by the given server certificate. Read more
Source§fn supported_verify_schemes(&self) -> Vec<SignatureScheme>
fn supported_verify_schemes(&self) -> Vec<SignatureScheme>
Return the list of SignatureSchemes that this verifier will handle,
in
verify_tls12_signature and verify_tls13_signature calls. Read moreSource§fn requires_raw_public_keys(&self) -> bool
fn requires_raw_public_keys(&self) -> bool
Returns whether this verifier requires raw public keys as defined
in RFC 7250.
Source§fn root_hint_subjects(&self) -> Option<&[DistinguishedName]>
fn root_hint_subjects(&self) -> Option<&[DistinguishedName]>
Return the
DistinguishedNames of certificate authorities that this verifier trusts. Read moreAuto Trait Implementations§
impl Freeze for Verifier
impl !RefUnwindSafe for Verifier
impl Send for Verifier
impl Sync for Verifier
impl Unpin for Verifier
impl !UnwindSafe for Verifier
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more