Struct SslCredentialBuilder
pub struct SslCredentialBuilder(/* private fields */);boring only.Expand description
A builder for SslCredential.
Create it with SslCredential::builder. Building consumes the mutable
configuration so credentials added to contexts or SSL objects stay immutable.
Implementations§
§impl SslCredentialBuilder
impl SslCredentialBuilder
pub fn set_async_private_key_method(
&mut self,
method: impl AsyncPrivateKeyMethod,
) -> Result<(), ErrorStack>
pub fn set_async_private_key_method( &mut self, method: impl AsyncPrivateKeyMethod, ) -> Result<(), ErrorStack>
Configures an asynchronous signer on this credential.
Without a task waker, signing fails without calling the signer.
See AsyncPrivateKeyMethod and SslRef::set_task_waker.
§impl SslCredentialBuilder
impl SslCredentialBuilder
pub fn is_complete(&self) -> bool
pub fn is_complete(&self) -> bool
Whether the required certificate and private key material is configured.
pub fn set_certificate_chain<I, C>(
&mut self,
certificates: I,
) -> Result<(), ErrorStack>
pub fn set_certificate_chain<I, C>( &mut self, certificates: I, ) -> Result<(), ErrorStack>
Sets the certificate chain in leaf-first order, copying each certificate.
The chain must be non-empty. If a private key is already configured, the leaf’s public key must match it. On error, native configuration may have been partially updated; configure a valid chain before using the builder.
This corresponds to SSL_CREDENTIAL_set1_cert_chain.
pub fn set_signing_algorithm_prefs(
&mut self,
prefs: &[SslSignatureAlgorithm],
) -> Result<(), ErrorStack>
pub fn set_signing_algorithm_prefs( &mut self, prefs: &[SslSignatureAlgorithm], ) -> Result<(), ErrorStack>
Sets signing algorithm preferences for this credential’s private key.
This corresponds to SSL_CREDENTIAL_set1_signing_algorithm_prefs.
pub fn set_trust_anchor_id(&mut self, id: &[u8]) -> Result<(), ErrorStack>
pub fn set_trust_anchor_id(&mut self, id: &[u8]) -> Result<(), ErrorStack>
Sets the binary trust anchor ID of the issuer of the final certificate.
An empty slice clears it. Enable Self::set_must_match_issuer for this
metadata to affect selection. This does not establish trust in that issuer.
This corresponds to SSL_CREDENTIAL_set1_trust_anchor_id.
pub fn add_trust_anchor_group_inclusion(
&mut self,
base: &[u8],
min: u64,
max: u64,
) -> Result<(), ErrorStack>
pub fn add_trust_anchor_group_inclusion( &mut self, base: &[u8], min: u64, max: u64, ) -> Result<(), ErrorStack>
Adds a trust anchor group inclusion: base followed by a component in the
inclusive range min..=max. The base is a binary trust anchor ID.
Prefer CA-provided Self::set_certificate_properties when available.
This corresponds to SSL_CREDENTIAL_add1_trust_anchor_group_inclusion.
pub fn set_must_match_issuer(&mut self, enabled: bool)
pub fn set_must_match_issuer(&mut self, enabled: bool)
Conditions this credential on the peer’s requested CAs or trust anchor IDs.
Enabled credentials must have a correctly ordered chain. Put these before broadly usable fallback credentials in the context’s preference list.
This corresponds to SSL_CREDENTIAL_set_must_match_issuer.
pub fn set_certificate_properties(
&mut self,
properties: &[u8],
) -> Result<(), ErrorStack>
pub fn set_certificate_properties( &mut self, properties: &[u8], ) -> Result<(), ErrorStack>
Parses a serialized CertificatePropertyList and applies recognized metadata.
Uses the format supported by the bundled BoringSSL, including the outer u16 length. Does not enable issuer matching. On error, earlier properties may already have been applied; discard or reconfigure the builder.
This corresponds to SSL_CREDENTIAL_set1_certificate_properties.
pub fn set_ocsp_response(&mut self, response: &[u8]) -> Result<(), ErrorStack>
pub fn set_ocsp_response(&mut self, response: &[u8]) -> Result<(), ErrorStack>
Sets the stapled OCSP response for this credential, copying the bytes.
This corresponds to SSL_CREDENTIAL_set1_ocsp_response.
pub fn set_signed_cert_timestamp_list(
&mut self,
timestamps: &[u8],
) -> Result<(), ErrorStack>
pub fn set_signed_cert_timestamp_list( &mut self, timestamps: &[u8], ) -> Result<(), ErrorStack>
Sets this credential’s serialized SignedCertificateTimestampList. Includes the outer u16 length and each SCT’s u16 length; bytes are copied.
This corresponds to SSL_CREDENTIAL_set1_signed_cert_timestamp_list.
pub fn replace_ex_data<T>(
&mut self,
index: Index<SslCredential, T>,
data: T,
) -> Option<T>
pub fn replace_ex_data<T>( &mut self, index: Index<SslCredential, T>, data: T, ) -> Option<T>
Sets or overwrites the extra data at the specified index.
This can be used to provide data to callbacks registered with the context. Use the
SslCredential::new_ex_index method to create an Index.
Any previous value will be returned and replaced by the new one.
This corresponds to SSL_CREDENTIAL_set_ex_data.
pub fn set_private_key(
&mut self,
private_key: &PKeyRef<Private>,
) -> Result<(), ErrorStack>
pub fn set_private_key( &mut self, private_key: &PKeyRef<Private>, ) -> Result<(), ErrorStack>
Sets the private key of the credential.
This corresponds to SSL_CREDENTIAL_set1_private_key.
pub fn set_private_key_method<M>(&mut self, method: M) -> Result<(), ErrorStack>where
M: PrivateKeyMethod,
pub fn set_private_key_method<M>(&mut self, method: M) -> Result<(), ErrorStack>where
M: PrivateKeyMethod,
Configures a custom private key method on the credential.
See PrivateKeyMethod for more details.
This corresponds to SSL_CREDENTIAL_set_private_key_method.
pub fn build(self) -> SslCredential
Auto Trait Implementations§
impl Freeze for SslCredentialBuilder
impl RefUnwindSafe for SslCredentialBuilder
impl Send for SslCredentialBuilder
impl Sync for SslCredentialBuilder
impl Unpin for SslCredentialBuilder
impl UnsafeUnpin for SslCredentialBuilder
impl UnwindSafe for SslCredentialBuilder
Blanket Implementations§
§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
§impl<T> FutureExt for T
impl<T> FutureExt for T
§fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
§fn with_current_context(self) -> WithContext<Self> ⓘ
fn with_current_context(self) -> WithContext<Self> ⓘ
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
T in a rama_grpc::Request§impl<T> Pointable for T
impl<T> Pointable for T
§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
§fn and<P, B, E>(self, other: P) -> And<T, P>
fn and<P, B, E>(self, other: P) -> And<T, P>
Policy that returns Action::Follow only if self and other return
Action::Follow. Read more