Skip to main content

Module identity

Module identity 

Source
Expand description

Peer identity: the fingerprint of a certificate’s public key.

weida names a peer by what it can prove it holds — a private key — rather than by what a certificate authority says about it. The fingerprint is the SHA-256 digest of the DER-encoded SubjectPublicKeyInfo of the leaf certificate, the same value openssl x509 -pubkey | openssl pkey -pubin -outform der | sha256sum prints and the one HPKP and curl --pinnedpubkey pin. Hashing the key rather than the certificate keeps the fingerprint stable across certificate renewals that reuse the key.

This module holds only the value type and its text form. Computing a fingerprint from certificate bytes needs a parser and a hash, both of which live in the transport crate.

Structs§

Fingerprint
SHA-256 digest of a peer’s public key.
LocalPrincipal
A principal the kernel proved, on a local transport.
WindowsPrincipal
A principal the kernel proved, on a Windows named pipe.

Enums§

PeerIdentity
Who the peer is, once it has been proved.