Skip to main content

ServerTlsConfig

Struct ServerTlsConfig 

Source
pub struct ServerTlsConfig {
    pub cert: PemSource,
    pub key: PemSource,
    pub client_ca: Option<PemSource>,
    pub alpn: Vec<Vec<u8>>,
}
Expand description

Server-side TLS configuration.

Construct via ServerTlsConfig::builder.

§Security

key (and cert/client_ca) are held as PemSource; the Bytes variant keeps the raw private key. The derived Debug redacts those bytes (see PemSource), so logging this struct will not leak the key, but the key is not zeroed while the config is alive.

§Also

Fields§

§cert: PemSource

Server certificate chain (leaf first).

§key: PemSource

Server private key (PKCS#8, PKCS#1, or SEC1).

§client_ca: Option<PemSource>

Trusted CA bundle for verifying client certificates (mTLS). None = standard TLS (no client cert required).

§alpn: Vec<Vec<u8>>

ALPN protocol list, in preference order (e.g. [b"h2"] for gRPC). Empty = no ALPN negotiation requested.

Implementations§

Source§

impl ServerTlsConfig

Source

pub fn builder() -> ServerTlsConfigBuilder

Start a new builder.

Source

pub fn into_rustls_config(self) -> Result<ServerConfig, TlsError>

Build a rustls::ServerConfig from this configuration.

Reads the PEM sources (disk or memory), parses the cert chain and key, optionally constructs a WebPkiClientVerifier for mTLS, and applies ALPN. Auto-installs the ring CryptoProvider if none is set process-wide.

§Security

The server always presents cert + key. If client_ca is set, client authentication is mandatory: the server demands a client certificate chaining to that CA and rejects unauthenticated clients at the handshake (WebPkiClientVerifier defaults to deny-anonymous).

Server hostname is not this method’s concern: it is the client that verifies the server’s identity.

§Errors

Trait Implementations§

Source§

impl Clone for ServerTlsConfig

Source§

fn clone(&self) -> ServerTlsConfig

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for ServerTlsConfig

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.