Struct TlsMitmRelay
pub struct TlsMitmRelay<Issuer> { /* private fields */ }boring only.Expand description
A utility that can be used by MITM services such as transparent proxies, in order to relay (and MITM a TLS connection between a client and server, as part of a deep protocol inspection protocol (DPI) flow.
With the http feature, a per-flow TargetHttpVersion is a best-effort
preference. The relay narrows its upstream ALPN offer only when a peeked
ingress ClientHello can negotiate the same protocol (or when HTTP/1.1 is
its natural no-ALPN fallback). Otherwise the preference is ignored because
this TLS relay does not translate HTTP versions and the intercepted client
remains authoritative. Upstream negotiation may also decline the preferred
protocol. Without an applicable preference, normal ClientHello mirroring
and upstream negotiation decide the concrete HTTP version.
Implementations§
§impl<Issuer> TlsMitmRelay<Issuer>
impl<Issuer> TlsMitmRelay<Issuer>
pub fn new(issuer: Issuer) -> TlsMitmRelay<Issuer>
pub fn new(issuer: Issuer) -> TlsMitmRelay<Issuer>
Create a new TlsMitmRelay.
pub fn with_grease_enabled(self, enabled: bool) -> TlsMitmRelay<Issuer>
pub fn with_grease_enabled(self, enabled: bool) -> TlsMitmRelay<Issuer>
Set whether GREASE should be enabled for the ingress-side TLS acceptor.
By default is is enabled (true).
pub fn set_grease_enabled(&mut self, enabled: bool) -> &mut TlsMitmRelay<Issuer>
pub fn set_grease_enabled(&mut self, enabled: bool) -> &mut TlsMitmRelay<Issuer>
Set whether GREASE should be enabled for the ingress-side TLS acceptor.
By default is is enabled (true).
pub fn with_keylog_intent(self, intent: KeyLogIntent) -> TlsMitmRelay<Issuer>
pub fn with_keylog_intent(self, intent: KeyLogIntent) -> TlsMitmRelay<Issuer>
Set the KeyLogIntent.
Default is KeyLogIntent::Environment, matching Chrome,
Firefox, curl, and most TLS stacks: a non-empty
SSLKEYLOGFILE env var enables key logging. In a MITM
relay this exports session keys for both the ingress
(relay-mirrored) and egress (upstream) sides, so anyone
with read access to the keylog file can decrypt every
relayed flow. Treat the file as security-sensitive
(restricted dir, rotate, delete when done) and pick
KeyLogIntent::Disabled if your deployment shouldn’t
honour the env var at all.
pub fn set_keylog_intent(
&mut self,
intent: KeyLogIntent,
) -> &mut TlsMitmRelay<Issuer>
pub fn set_keylog_intent( &mut self, intent: KeyLogIntent, ) -> &mut TlsMitmRelay<Issuer>
Set the KeyLogIntent.
Default is KeyLogIntent::Environment, matching Chrome,
Firefox, curl, and most TLS stacks: a non-empty
SSLKEYLOGFILE env var enables key logging. In a MITM
relay this exports session keys for both the ingress
(relay-mirrored) and egress (upstream) sides, so anyone
with read access to the keylog file can decrypt every
relayed flow. Treat the file as security-sensitive
(restricted dir, rotate, delete when done) and pick
KeyLogIntent::Disabled if your deployment shouldn’t
honour the env var at all.
pub fn keylog_intent_ref(&self) -> &KeyLogIntent
pub fn keylog_intent_ref(&self) -> &KeyLogIntent
Borrow the currently-configured KeyLogIntent. Useful when
constructing a sibling relay (e.g. after a CA rotation) that
should share the same sink — a Custom(Arc<dyn KeyLogSink>)
cloned this way keeps writing through the same backing toggle.
pub fn maybe_with_egress_server_auth(
self,
policy: Option<TlsMitmEgressServerAuth>,
) -> TlsMitmRelay<Issuer>
pub fn maybe_with_egress_server_auth( self, policy: Option<TlsMitmEgressServerAuth>, ) -> TlsMitmRelay<Issuer>
Set the optional server-authentication policy for upstream TLS.
This policy controls only upstream certificate and identity verification. It cannot override the ClientHello fingerprint, protocol negotiation, client authentication, or key logging.
Upstream certificate verification is disabled by default, both with
no policy and for TlsMitmEgressServerAuth::default. This preserves
transparent relay behavior for certificates the intercepted client
may choose to accept. Select
rama_tls::client::ServerVerifyMode::Auto explicitly to enforce
upstream certificate and hostname verification.
Direct Self::handshake calls apply this policy when their
connector_data argument is None. Explicit connector data is
authoritative because it is already a fully-resolved backend
configuration; TlsMitmRelayService supplies such data only after
applying this policy itself.
pub fn maybe_set_egress_server_auth(
&mut self,
policy: Option<TlsMitmEgressServerAuth>,
) -> &mut TlsMitmRelay<Issuer>
pub fn maybe_set_egress_server_auth( &mut self, policy: Option<TlsMitmEgressServerAuth>, ) -> &mut TlsMitmRelay<Issuer>
Set the optional server-authentication policy for upstream TLS.
This policy controls only upstream certificate and identity verification. It cannot override the ClientHello fingerprint, protocol negotiation, client authentication, or key logging.
Upstream certificate verification is disabled by default, both with
no policy and for TlsMitmEgressServerAuth::default. This preserves
transparent relay behavior for certificates the intercepted client
may choose to accept. Select
rama_tls::client::ServerVerifyMode::Auto explicitly to enforce
upstream certificate and hostname verification.
Direct Self::handshake calls apply this policy when their
connector_data argument is None. Explicit connector data is
authoritative because it is already a fully-resolved backend
configuration; TlsMitmRelayService supplies such data only after
applying this policy itself.
pub fn with_egress_server_auth(
self,
policy: TlsMitmEgressServerAuth,
) -> TlsMitmRelay<Issuer>
pub fn with_egress_server_auth( self, policy: TlsMitmEgressServerAuth, ) -> TlsMitmRelay<Issuer>
Set the optional server-authentication policy for upstream TLS.
This policy controls only upstream certificate and identity verification. It cannot override the ClientHello fingerprint, protocol negotiation, client authentication, or key logging.
Upstream certificate verification is disabled by default, both with
no policy and for TlsMitmEgressServerAuth::default. This preserves
transparent relay behavior for certificates the intercepted client
may choose to accept. Select
rama_tls::client::ServerVerifyMode::Auto explicitly to enforce
upstream certificate and hostname verification.
Direct Self::handshake calls apply this policy when their
connector_data argument is None. Explicit connector data is
authoritative because it is already a fully-resolved backend
configuration; TlsMitmRelayService supplies such data only after
applying this policy itself.
pub fn set_egress_server_auth(
&mut self,
policy: TlsMitmEgressServerAuth,
) -> &mut TlsMitmRelay<Issuer>
pub fn set_egress_server_auth( &mut self, policy: TlsMitmEgressServerAuth, ) -> &mut TlsMitmRelay<Issuer>
Set the optional server-authentication policy for upstream TLS.
This policy controls only upstream certificate and identity verification. It cannot override the ClientHello fingerprint, protocol negotiation, client authentication, or key logging.
Upstream certificate verification is disabled by default, both with
no policy and for TlsMitmEgressServerAuth::default. This preserves
transparent relay behavior for certificates the intercepted client
may choose to accept. Select
rama_tls::client::ServerVerifyMode::Auto explicitly to enforce
upstream certificate and hostname verification.
Direct Self::handshake calls apply this policy when their
connector_data argument is None. Explicit connector data is
authoritative because it is already a fully-resolved backend
configuration; TlsMitmRelayService supplies such data only after
applying this policy itself.
pub fn without_egress_server_auth(self) -> TlsMitmRelay<Issuer>
pub fn without_egress_server_auth(self) -> TlsMitmRelay<Issuer>
Set the optional server-authentication policy for upstream TLS.
This policy controls only upstream certificate and identity verification. It cannot override the ClientHello fingerprint, protocol negotiation, client authentication, or key logging.
Upstream certificate verification is disabled by default, both with
no policy and for TlsMitmEgressServerAuth::default. This preserves
transparent relay behavior for certificates the intercepted client
may choose to accept. Select
rama_tls::client::ServerVerifyMode::Auto explicitly to enforce
upstream certificate and hostname verification.
Direct Self::handshake calls apply this policy when their
connector_data argument is None. Explicit connector data is
authoritative because it is already a fully-resolved backend
configuration; TlsMitmRelayService supplies such data only after
applying this policy itself.
pub fn unset_egress_server_auth(&mut self) -> &mut TlsMitmRelay<Issuer>
pub fn unset_egress_server_auth(&mut self) -> &mut TlsMitmRelay<Issuer>
Set the optional server-authentication policy for upstream TLS.
This policy controls only upstream certificate and identity verification. It cannot override the ClientHello fingerprint, protocol negotiation, client authentication, or key logging.
Upstream certificate verification is disabled by default, both with
no policy and for TlsMitmEgressServerAuth::default. This preserves
transparent relay behavior for certificates the intercepted client
may choose to accept. Select
rama_tls::client::ServerVerifyMode::Auto explicitly to enforce
upstream certificate and hostname verification.
Direct Self::handshake calls apply this policy when their
connector_data argument is None. Explicit connector data is
authoritative because it is already a fully-resolved backend
configuration; TlsMitmRelayService supplies such data only after
applying this policy itself.
pub fn egress_server_auth_ref(&self) -> Option<&TlsMitmEgressServerAuth>
pub fn egress_server_auth_ref(&self) -> Option<&TlsMitmEgressServerAuth>
Borrow the configured upstream server-authentication policy, if any.
§impl<Issuer> TlsMitmRelay<CachedBoringMitmCertIssuer<Issuer>>
impl<Issuer> TlsMitmRelay<CachedBoringMitmCertIssuer<Issuer>>
pub fn new_with_cached_issuer(
issuer: Issuer,
) -> TlsMitmRelay<CachedBoringMitmCertIssuer<Issuer>>
pub fn new_with_cached_issuer( issuer: Issuer, ) -> TlsMitmRelay<CachedBoringMitmCertIssuer<Issuer>>
Create a new TlsMitmRelay,
with a cache layer on top top of the provided issuer
toprovide reuse functionality of previously issued certs.
pub fn new_with_cached_issuer_and_config(
issuer: Issuer,
cfg: BoringMitmCertIssuerCacheConfig,
) -> TlsMitmRelay<CachedBoringMitmCertIssuer<Issuer>>
pub fn new_with_cached_issuer_and_config( issuer: Issuer, cfg: BoringMitmCertIssuerCacheConfig, ) -> TlsMitmRelay<CachedBoringMitmCertIssuer<Issuer>>
Create a new TlsMitmRelay,
with a cache layer (created by given config)
on top of the provided issuer to provide reuse functionality of previously issued certs.
§impl TlsMitmRelay<InMemoryBoringMitmCertIssuer>
impl TlsMitmRelay<InMemoryBoringMitmCertIssuer>
pub fn try_new_with_self_signed_issuer(
data: &SelfSignedCaConfig,
) -> Result<TlsMitmRelay<InMemoryBoringMitmCertIssuer>, Box<dyn Error + Send + Sync>>
pub fn try_new_with_self_signed_issuer( data: &SelfSignedCaConfig, ) -> Result<TlsMitmRelay<InMemoryBoringMitmCertIssuer>, Box<dyn Error + Send + Sync>>
Create a new TlsMitmRelay with self-signed CA using the given data.
pub fn new_in_memory(
crt: X509,
key: PKey<Private>,
) -> TlsMitmRelay<InMemoryBoringMitmCertIssuer>
pub fn new_in_memory( crt: X509, key: PKey<Private>, ) -> TlsMitmRelay<InMemoryBoringMitmCertIssuer>
Create a new TlsMitmRelay with the provided CA pair.
§impl TlsMitmRelay<CachedBoringMitmCertIssuer<InMemoryBoringMitmCertIssuer>>
impl TlsMitmRelay<CachedBoringMitmCertIssuer<InMemoryBoringMitmCertIssuer>>
pub fn try_new_with_cached_self_signed_issuer(
data: &SelfSignedCaConfig,
) -> Result<TlsMitmRelay<CachedBoringMitmCertIssuer<InMemoryBoringMitmCertIssuer>>, Box<dyn Error + Send + Sync>>
pub fn try_new_with_cached_self_signed_issuer( data: &SelfSignedCaConfig, ) -> Result<TlsMitmRelay<CachedBoringMitmCertIssuer<InMemoryBoringMitmCertIssuer>>, Box<dyn Error + Send + Sync>>
Create a new TlsMitmRelay with self-signed CA using the given data,
with a cache layer on top to provide reuse functionality of previously issued certs.
pub fn try_new_with_cached_self_signed_issuer_and_config(
data: &SelfSignedCaConfig,
cfg: BoringMitmCertIssuerCacheConfig,
) -> Result<TlsMitmRelay<CachedBoringMitmCertIssuer<InMemoryBoringMitmCertIssuer>>, Box<dyn Error + Send + Sync>>
pub fn try_new_with_cached_self_signed_issuer_and_config( data: &SelfSignedCaConfig, cfg: BoringMitmCertIssuerCacheConfig, ) -> Result<TlsMitmRelay<CachedBoringMitmCertIssuer<InMemoryBoringMitmCertIssuer>>, Box<dyn Error + Send + Sync>>
Create a new TlsMitmRelay with self-signed CA using the given data,
with a cache layer (created by given config)
on top to provide reuse functionality of previously issued certs.
pub fn new_cached_in_memory(
crt: X509,
key: PKey<Private>,
) -> TlsMitmRelay<CachedBoringMitmCertIssuer<InMemoryBoringMitmCertIssuer>>
pub fn new_cached_in_memory( crt: X509, key: PKey<Private>, ) -> TlsMitmRelay<CachedBoringMitmCertIssuer<InMemoryBoringMitmCertIssuer>>
Create a new TlsMitmRelay with the provided CA pair,
with a cache layer on top to provide reuse functionality of previously issued certs.
pub fn new_cached_in_memory_with_config(
crt: X509,
key: PKey<Private>,
cfg: BoringMitmCertIssuerCacheConfig,
) -> TlsMitmRelay<CachedBoringMitmCertIssuer<InMemoryBoringMitmCertIssuer>>
pub fn new_cached_in_memory_with_config( crt: X509, key: PKey<Private>, cfg: BoringMitmCertIssuerCacheConfig, ) -> TlsMitmRelay<CachedBoringMitmCertIssuer<InMemoryBoringMitmCertIssuer>>
Create a new TlsMitmRelay with the provided CA pair,
with a cache layer (created by given config)
on top to provide reuse functionality of previously issued certs.
§impl<Issuer> TlsMitmRelay<Issuer>where
Issuer: BoringMitmCertIssuer,
<Issuer as BoringMitmCertIssuer>::Error: Into<Box<dyn Error + Send + Sync>>,
impl<Issuer> TlsMitmRelay<Issuer>where
Issuer: BoringMitmCertIssuer,
<Issuer as BoringMitmCertIssuer>::Error: Into<Box<dyn Error + Send + Sync>>,
pub async fn handshake<Ingress, Egress>(
&self,
input: BridgeIo<Ingress, Egress>,
connector_data: Option<TlsConnectorData>,
) -> Result<BridgeIo<TlsStream<Ingress>, TlsStream<Egress>>, TlsMitmRelayError>
pub async fn handshake<Ingress, Egress>( &self, input: BridgeIo<Ingress, Egress>, connector_data: Option<TlsConnectorData>, ) -> Result<BridgeIo<TlsStream<Ingress>, TlsStream<Egress>>, TlsMitmRelayError>
Establish and MITM a handshake between the client (ingress) and server (egress).
When connector_data is None, the relay derives it from its key-log
intent and TlsMitmEgressServerAuth. With no authentication policy,
upstream verification remains disabled to preserve transparent relay
behavior. The direct handshake has no peeked ClientHello to mirror; it
can use a ConnectorTarget from the ingress extensions as a fallback
identity only when verification or pinning requires one.
Explicit connector_data is authoritative. This is primarily used by
TlsMitmRelayService, which has already combined the relay policy with
the peeked ClientHello and per-flow preferences.
Trait Implementations§
§impl<Issuer> Clone for TlsMitmRelay<Issuer>where
Issuer: Clone,
impl<Issuer> Clone for TlsMitmRelay<Issuer>where
Issuer: Clone,
§fn clone(&self) -> TlsMitmRelay<Issuer>
fn clone(&self) -> TlsMitmRelay<Issuer>
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more§impl<Issuer> Debug for TlsMitmRelay<Issuer>where
Issuer: Debug,
impl<Issuer> Debug for TlsMitmRelay<Issuer>where
Issuer: Debug,
§impl<S, Issuer> Layer<S> for TlsMitmRelay<Issuer>where
Issuer: Clone,
impl<S, Issuer> Layer<S> for TlsMitmRelay<Issuer>where
Issuer: Clone,
§type Service = TlsMitmRelayService<Issuer, S>
type Service = TlsMitmRelayService<Issuer, S>
§fn layer(&self, inner: S) -> <TlsMitmRelay<Issuer> as Layer<S>>::Service
fn layer(&self, inner: S) -> <TlsMitmRelay<Issuer> as Layer<S>>::Service
§fn into_layer(self, inner: S) -> <TlsMitmRelay<Issuer> as Layer<S>>::Service
fn into_layer(self, inner: S) -> <TlsMitmRelay<Issuer> as Layer<S>>::Service
layer but consuming self after the service was created. Read moreAuto Trait Implementations§
impl<Issuer> !RefUnwindSafe for TlsMitmRelay<Issuer>
impl<Issuer> !UnwindSafe for TlsMitmRelay<Issuer>
impl<Issuer> Freeze for TlsMitmRelay<Issuer>where
Issuer: Freeze,
impl<Issuer> Send for TlsMitmRelay<Issuer>where
Issuer: Send,
impl<Issuer> Sync for TlsMitmRelay<Issuer>where
Issuer: Sync,
impl<Issuer> Unpin for TlsMitmRelay<Issuer>where
Issuer: Unpin,
impl<Issuer> UnsafeUnpin for TlsMitmRelay<Issuer>where
Issuer: UnsafeUnpin,
Blanket Implementations§
§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<T> FutureExt for T
impl<T> FutureExt for T
§fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
§fn with_current_context(self) -> WithContext<Self> ⓘ
fn with_current_context(self) -> WithContext<Self> ⓘ
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
T in a rama_grpc::Request§impl<T> Pointable for T
impl<T> Pointable for T
§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
§fn and<P, B, E>(self, other: P) -> And<T, P>
fn and<P, B, E>(self, other: P) -> And<T, P>
Policy that returns Action::Follow only if self and other return
Action::Follow. Read more