Struct TlsMitmClientAuthPlan
pub struct TlsMitmClientAuthPlan { /* private fields */ }boring only.Expand description
Second stage: configure ingress, then resolve the egress credential.
Returning None deliberately sends no certificate, which only optional
upstream authentication can accept. Errors reject the connection.
A credential returned when upstream requested none is rejected as a policy error.
Implementations§
§impl TlsMitmClientAuthPlan
impl TlsMitmClientAuthPlan
pub fn new<S>(resolver: S) -> TlsMitmClientAuthPlanwhere
S: Service<TlsMitmClientIdentity, Output = Option<SslCredential>>,
<S as Service<TlsMitmClientIdentity>>::Error: Into<Box<dyn Error + Sync + Send>>,
pub fn new<S>(resolver: S) -> TlsMitmClientAuthPlanwhere
S: Service<TlsMitmClientIdentity, Output = Option<SslCredential>>,
<S as Service<TlsMitmClientIdentity>>::Error: Into<Box<dyn Error + Sync + Send>>,
By default, ingress does not request a certificate.
pub fn fixed(credential: Option<SslCredential>) -> TlsMitmClientAuthPlan
pub fn fixed(credential: Option<SslCredential>) -> TlsMitmClientAuthPlan
Fixed egress identity, without requiring ingress authentication.
pub fn with_ingress_trust(self, store: X509Store) -> TlsMitmClientAuthPlan
pub fn with_ingress_trust(self, store: X509Store) -> TlsMitmClientAuthPlan
Require a client certificate trusted by this prebuilt store. The store is reference-counted by BoringSSL, so callers can cheaply clone and reuse it.
pub fn set_ingress_trust(
&mut self,
store: X509Store,
) -> &mut TlsMitmClientAuthPlan
pub fn set_ingress_trust( &mut self, store: X509Store, ) -> &mut TlsMitmClientAuthPlan
Require a client certificate trusted by this prebuilt store. The store is reference-counted by BoringSSL, so callers can cheaply clone and reuse it.
pub fn with_ingress(
self,
configure: impl FnOnce(&mut SslRef) -> Result<(), Box<dyn Error + Sync + Send>> + Send + 'static,
) -> TlsMitmClientAuthPlan
pub fn with_ingress( self, configure: impl FnOnce(&mut SslRef) -> Result<(), Box<dyn Error + Sync + Send>> + Send + 'static, ) -> TlsMitmClientAuthPlan
Configure native ingress authentication on this connection, after routing and before its handshake. Set verification mode, trust, CA hints and any custom verifier here. Calls compose in order. Never mutate a shared cached acceptor for flow policy.
pub fn set_ingress(
&mut self,
configure: impl FnOnce(&mut SslRef) -> Result<(), Box<dyn Error + Sync + Send>> + Send + 'static,
) -> &mut TlsMitmClientAuthPlan
pub fn set_ingress( &mut self, configure: impl FnOnce(&mut SslRef) -> Result<(), Box<dyn Error + Sync + Send>> + Send + 'static, ) -> &mut TlsMitmClientAuthPlan
Configure native ingress authentication on this connection, after routing and before its handshake. Set verification mode, trust, CA hints and any custom verifier here. Calls compose in order. Never mutate a shared cached acceptor for flow policy.
Trait Implementations§
Auto Trait Implementations§
impl !RefUnwindSafe for TlsMitmClientAuthPlan
impl !Sync for TlsMitmClientAuthPlan
impl !UnwindSafe for TlsMitmClientAuthPlan
impl Freeze for TlsMitmClientAuthPlan
impl Send for TlsMitmClientAuthPlan
impl Unpin for TlsMitmClientAuthPlan
impl UnsafeUnpin for TlsMitmClientAuthPlan
Blanket Implementations§
§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
§impl<T> FutureExt for T
impl<T> FutureExt for T
§fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
§fn with_current_context(self) -> WithContext<Self> ⓘ
fn with_current_context(self) -> WithContext<Self> ⓘ
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
T in a rama_grpc::Request§impl<T> Pointable for T
impl<T> Pointable for T
§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
§fn and<P, B, E>(self, other: P) -> And<T, P>
fn and<P, B, E>(self, other: P) -> And<T, P>
Policy that returns Action::Follow only if self and other return
Action::Follow. Read more