Skip to main content

SslCredentialBuilder

Struct SslCredentialBuilder 

pub struct SslCredentialBuilder(/* private fields */);
Available on crate feature boring only.
Expand description

A builder for SslCredential.

Create it with SslCredential::builder. Building consumes the mutable configuration so credentials added to contexts or SSL objects stay immutable.

Implementations§

§

impl SslCredentialBuilder

pub fn set_async_private_key_method( &mut self, method: impl AsyncPrivateKeyMethod, ) -> Result<(), ErrorStack>

Configures an asynchronous signer on this credential. Without a task waker, signing fails without calling the signer. See AsyncPrivateKeyMethod and SslRef::set_task_waker.

§

impl SslCredentialBuilder

pub fn is_complete(&self) -> bool

Whether the required certificate and private key material is configured.

pub fn set_certificate_chain<I, C>( &mut self, certificates: I, ) -> Result<(), ErrorStack>
where I: IntoIterator<Item = C>, C: AsRef<X509Ref>,

Sets the certificate chain in leaf-first order, copying each certificate.

The chain must be non-empty. If a private key is already configured, the leaf’s public key must match it. On error, native configuration may have been partially updated; configure a valid chain before using the builder.

This corresponds to SSL_CREDENTIAL_set1_cert_chain.

pub fn set_signing_algorithm_prefs( &mut self, prefs: &[SslSignatureAlgorithm], ) -> Result<(), ErrorStack>

Sets signing algorithm preferences for this credential’s private key.

This corresponds to SSL_CREDENTIAL_set1_signing_algorithm_prefs.

pub fn set_trust_anchor_id(&mut self, id: &[u8]) -> Result<(), ErrorStack>

Sets the binary trust anchor ID of the issuer of the final certificate. An empty slice clears it. Enable Self::set_must_match_issuer for this metadata to affect selection. This does not establish trust in that issuer.

This corresponds to SSL_CREDENTIAL_set1_trust_anchor_id.

pub fn add_trust_anchor_group_inclusion( &mut self, base: &[u8], min: u64, max: u64, ) -> Result<(), ErrorStack>

Adds a trust anchor group inclusion: base followed by a component in the inclusive range min..=max. The base is a binary trust anchor ID. Prefer CA-provided Self::set_certificate_properties when available.

This corresponds to SSL_CREDENTIAL_add1_trust_anchor_group_inclusion.

pub fn set_must_match_issuer(&mut self, enabled: bool)

Conditions this credential on the peer’s requested CAs or trust anchor IDs.

Enabled credentials must have a correctly ordered chain. Put these before broadly usable fallback credentials in the context’s preference list.

This corresponds to SSL_CREDENTIAL_set_must_match_issuer.

pub fn set_certificate_properties( &mut self, properties: &[u8], ) -> Result<(), ErrorStack>

Parses a serialized CertificatePropertyList and applies recognized metadata.

Uses the format supported by the bundled BoringSSL, including the outer u16 length. Does not enable issuer matching. On error, earlier properties may already have been applied; discard or reconfigure the builder.

This corresponds to SSL_CREDENTIAL_set1_certificate_properties.

pub fn set_ocsp_response(&mut self, response: &[u8]) -> Result<(), ErrorStack>

Sets the stapled OCSP response for this credential, copying the bytes.

This corresponds to SSL_CREDENTIAL_set1_ocsp_response.

pub fn set_signed_cert_timestamp_list( &mut self, timestamps: &[u8], ) -> Result<(), ErrorStack>

Sets this credential’s serialized SignedCertificateTimestampList. Includes the outer u16 length and each SCT’s u16 length; bytes are copied.

This corresponds to SSL_CREDENTIAL_set1_signed_cert_timestamp_list.

pub fn replace_ex_data<T>( &mut self, index: Index<SslCredential, T>, data: T, ) -> Option<T>

Sets or overwrites the extra data at the specified index.

This can be used to provide data to callbacks registered with the context. Use the SslCredential::new_ex_index method to create an Index.

Any previous value will be returned and replaced by the new one.

This corresponds to SSL_CREDENTIAL_set_ex_data.

pub fn set_private_key( &mut self, private_key: &PKeyRef<Private>, ) -> Result<(), ErrorStack>

Sets the private key of the credential.

This corresponds to SSL_CREDENTIAL_set1_private_key.

pub fn set_private_key_method<M>(&mut self, method: M) -> Result<(), ErrorStack>

Configures a custom private key method on the credential.

See PrivateKeyMethod for more details.

This corresponds to SSL_CREDENTIAL_set_private_key_method.

pub fn build(self) -> SslCredential

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> FutureExt for T

§

fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ

Attaches the provided Context to this type, returning a WithContext wrapper. Read more
§

fn with_current_context(self) -> WithContext<Self> ⓘ

Attaches the current Context to this type, returning a WithContext wrapper. Read more
§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
§

impl<T> IntoRequest<T> for T

§

fn into_request(self) -> Request<T>

Wrap the input message T in a rama_grpc::Request
§

impl<L> LayerExt<L> for L

§

fn named_layer<S>(&self, service: S) -> Layered<<L as Layer<S>>::Service, S>
where L: Layer<S>,

Applies the layer to a service and wraps it in Layered.
§

impl<T> Pointable for T

§

const ALIGN: usize

The alignment of pointer.
§

type Init = T

The type for initializers.
§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
§

impl<T> PolicyExt for T
where T: ?Sized,

§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
§

impl<T, U> RamaFrom<T> for U
where U: From<T>,

§

fn rama_from(value: T) -> U

§

impl<T, U, CrateMarker> RamaInto<U, CrateMarker> for T
where U: RamaFrom<T, CrateMarker>,

§

fn rama_into(self) -> U

§

impl<T, U> RamaTryFrom<T> for U
where U: TryFrom<T>,

§

type Error = <U as TryFrom<T>>::Error

§

fn rama_try_from(value: T) -> Result<U, <U as RamaTryFrom<T>>::Error>

§

impl<T, U, CrateMarker> RamaTryInto<U, CrateMarker> for T
where U: RamaTryFrom<T, CrateMarker>,

§

type Error = <U as RamaTryFrom<T, CrateMarker>>::Error

§

fn rama_try_into(self) -> Result<U, <U as RamaTryFrom<T, CrateMarker>>::Error>

§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

§

fn vzip(self) -> V

§

impl<V, F> ValueFormatter<&V> for F
where F: ValueFormatter<V> + ?Sized, V: ?Sized,

§

const SHAPE: FieldShape<'static>

Available on non-metrique_require_explicit_impls only.
The shape of values produced by this formatter. Read more
§

fn format_value(writer: impl ValueWriter, value: &&V)

Write value to writer
§

impl<V, F> ValueFormatter<Arc<V>> for F
where F: ValueFormatter<V> + ?Sized, V: ?Sized,

§

const SHAPE: FieldShape<'static>

Available on non-metrique_require_explicit_impls only.
The shape of values produced by this formatter. Read more
§

fn format_value(writer: impl ValueWriter, value: &Arc<V>)

Write value to writer
§

impl<V, F> ValueFormatter<Box<V>> for F
where F: ValueFormatter<V> + ?Sized, V: ?Sized,

§

const SHAPE: FieldShape<'static>

Available on non-metrique_require_explicit_impls only.
The shape of values produced by this formatter. Read more
§

fn format_value(writer: impl ValueWriter, value: &Box<V>)

Write value to writer
§

impl<V, F> ValueFormatter<Cow<'_, V>> for F
where V: ToOwned + ?Sized, F: ValueFormatter<V> + ?Sized,

§

const SHAPE: FieldShape<'static>

Available on non-metrique_require_explicit_impls only.
The shape of values produced by this formatter. Read more
§

fn format_value(writer: impl ValueWriter, value: &Cow<'_, V>)

Write value to writer
§

impl<V, F> ValueFormatter<Option<V>> for F
where F: ValueFormatter<V> + ?Sized,

§

const SHAPE: FieldShape<'static>

Available on non-metrique_require_explicit_impls only.
The shape of values produced by this formatter. Read more
§

fn format_value(writer: impl ValueWriter, value: &Option<V>)

Write value to writer
§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more