Struct ServerCertIssuerData
pub struct ServerCertIssuerData { /* private fields */ }boring only.Expand description
Configures on-the-fly server certificate issuance and caching.
Clones share generated CA material and cached certificates. Changing the
issuer kind or cache kind starts a new runtime, while changing only the
fallback identity retains it. Use ServerCertIssuerData::new when an
independent runtime is required.
Implementations§
§impl ServerCertIssuerData
impl ServerCertIssuerData
pub fn new(kind: impl Into<ServerCertIssuerKind>) -> ServerCertIssuerData
pub fn new(kind: impl Into<ServerCertIssuerKind>) -> ServerCertIssuerData
Create an issuer configuration with the default in-memory cache.
pub const fn kind(&self) -> &ServerCertIssuerKind
pub fn with_kind(
self,
kind: impl Into<ServerCertIssuerKind>,
) -> ServerCertIssuerData
pub fn with_kind( self, kind: impl Into<ServerCertIssuerKind>, ) -> ServerCertIssuerData
Set the kind of server certificate issuer.
pub fn set_kind(
&mut self,
kind: impl Into<ServerCertIssuerKind>,
) -> &mut ServerCertIssuerData
pub fn set_kind( &mut self, kind: impl Into<ServerCertIssuerKind>, ) -> &mut ServerCertIssuerData
Set the kind of server certificate issuer.
pub const fn cache_kind(&self) -> &CacheKind
pub fn with_cache_kind(self, cache_kind: CacheKind) -> ServerCertIssuerData
pub fn with_cache_kind(self, cache_kind: CacheKind) -> ServerCertIssuerData
Set the cache used for issued certificates.
pub fn set_cache_kind(
&mut self,
cache_kind: CacheKind,
) -> &mut ServerCertIssuerData
pub fn set_cache_kind( &mut self, cache_kind: CacheKind, ) -> &mut ServerCertIssuerData
Set the cache used for issued certificates.
pub const fn fallback_identity(&self) -> Option<&CertificateIdentity>
pub fn maybe_with_fallback_identity(
self,
fallback_identity: Option<CertificateIdentity>,
) -> ServerCertIssuerData
pub fn maybe_with_fallback_identity( self, fallback_identity: Option<CertificateIdentity>, ) -> ServerCertIssuerData
Set the identity used when no SNI or target identity is available.
The default is the DNS identity localhost, matching the conventional
default-certificate behavior of TLS servers. Use
Self::without_fallback_identity to reject handshakes that provide
neither SNI nor a target identity.
pub fn maybe_set_fallback_identity(
&mut self,
fallback_identity: Option<CertificateIdentity>,
) -> &mut ServerCertIssuerData
pub fn maybe_set_fallback_identity( &mut self, fallback_identity: Option<CertificateIdentity>, ) -> &mut ServerCertIssuerData
Set the identity used when no SNI or target identity is available.
The default is the DNS identity localhost, matching the conventional
default-certificate behavior of TLS servers. Use
Self::without_fallback_identity to reject handshakes that provide
neither SNI nor a target identity.
pub fn with_fallback_identity(
self,
fallback_identity: CertificateIdentity,
) -> ServerCertIssuerData
pub fn with_fallback_identity( self, fallback_identity: CertificateIdentity, ) -> ServerCertIssuerData
Set the identity used when no SNI or target identity is available.
The default is the DNS identity localhost, matching the conventional
default-certificate behavior of TLS servers. Use
Self::without_fallback_identity to reject handshakes that provide
neither SNI nor a target identity.
pub fn set_fallback_identity(
&mut self,
fallback_identity: CertificateIdentity,
) -> &mut ServerCertIssuerData
pub fn set_fallback_identity( &mut self, fallback_identity: CertificateIdentity, ) -> &mut ServerCertIssuerData
Set the identity used when no SNI or target identity is available.
The default is the DNS identity localhost, matching the conventional
default-certificate behavior of TLS servers. Use
Self::without_fallback_identity to reject handshakes that provide
neither SNI nor a target identity.
pub fn without_fallback_identity(self) -> ServerCertIssuerData
pub fn without_fallback_identity(self) -> ServerCertIssuerData
Set the identity used when no SNI or target identity is available.
The default is the DNS identity localhost, matching the conventional
default-certificate behavior of TLS servers. Use
Self::without_fallback_identity to reject handshakes that provide
neither SNI nor a target identity.
pub fn unset_fallback_identity(&mut self) -> &mut ServerCertIssuerData
pub fn unset_fallback_identity(&mut self) -> &mut ServerCertIssuerData
Set the identity used when no SNI or target identity is available.
The default is the DNS identity localhost, matching the conventional
default-certificate behavior of TLS servers. Use
Self::without_fallback_identity to reject handshakes that provide
neither SNI nor a target identity.
Trait Implementations§
§impl Clone for ServerCertIssuerData
impl Clone for ServerCertIssuerData
§fn clone(&self) -> ServerCertIssuerData
fn clone(&self) -> ServerCertIssuerData
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more§impl Debug for ServerCertIssuerData
impl Debug for ServerCertIssuerData
§impl Default for ServerCertIssuerData
impl Default for ServerCertIssuerData
§fn default() -> ServerCertIssuerData
fn default() -> ServerCertIssuerData
Auto Trait Implementations§
impl !Freeze for ServerCertIssuerData
impl !RefUnwindSafe for ServerCertIssuerData
impl !UnwindSafe for ServerCertIssuerData
impl Send for ServerCertIssuerData
impl Sync for ServerCertIssuerData
impl Unpin for ServerCertIssuerData
impl UnsafeUnpin for ServerCertIssuerData
Blanket Implementations§
§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<T> FutureExt for T
impl<T> FutureExt for T
§fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
§fn with_current_context(self) -> WithContext<Self> ⓘ
fn with_current_context(self) -> WithContext<Self> ⓘ
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
T in a rama_grpc::Request§impl<T> Pointable for T
impl<T> Pointable for T
§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
§fn and<P, B, E>(self, other: P) -> And<T, P>
fn and<P, B, E>(self, other: P) -> And<T, P>
Policy that returns Action::Follow only if self and other return
Action::Follow. Read more