pub struct TlsConfig { /* private fields */ }Expand description
Parsed and validated before binding or atomic replacement. Private keys are never rendered in diagnostics. Optional client authentication permits bearer users and unauthenticated health probes on the same encrypted listener.
Implementations§
Source§impl TlsConfig
impl TlsConfig
Sourcepub fn from_pem(
certificates: &[u8],
private_key: &[u8],
client_ca: Option<&[u8]>,
) -> Result<Self, SecurityError>
pub fn from_pem( certificates: &[u8], private_key: &[u8], client_ca: Option<&[u8]>, ) -> Result<Self, SecurityError>
Builds a server configuration from the PEM certificate chain, its PEM private key and, optionally, a PEM bundle of client CAs.
The server uses rustls’s safe default protocol versions and offers
only HTTP/1.1. It accepts no 0-RTT data and does not resume sessions.
With a client CA, the handshake requests a client certificate and
verifies any that is presented, but does not require one, so bearer
callers and probes share the listener. A verified certificate grants
nothing until its leaf fingerprint is mapped to an identity with
SecurityPolicy::with_certificate.
Handshake limits default to five seconds and 128 pending handshakes;
see with_handshake_limits.
§Errors
Returns a SecurityError for empty or malformed PEM, an invalid
client CA, or a private key that does not match the certificate. The
error never contains key material.
Sourcepub fn with_handshake_limits(
self,
timeout: Duration,
max_pending: NonZeroUsize,
) -> Result<Self, SecurityError>
pub fn with_handshake_limits( self, timeout: Duration, max_pending: NonZeroUsize, ) -> Result<Self, SecurityError>
A configurable connection-burst budget, independent of accounts or body sizes. Excess connections wait in the OS backlog rather than spawning unbounded handshake tasks. Each task has its own deadline.