Struct rustls::verify::WebPkiVerifier

source ·
pub struct WebPkiVerifier {
    roots: Arc<RootCertStore>,
    ct_policy: Option<CertificateTransparencyPolicy>,
}
Expand description

Default ServerCertVerifier, see the trait impl for more information.

Fields§

§roots: Arc<RootCertStore>§ct_policy: Option<CertificateTransparencyPolicy>

Implementations§

source§

impl WebPkiVerifier

source

pub fn new( roots: impl Into<Arc<RootCertStore>>, ct_policy: Option<CertificateTransparencyPolicy>, ) -> Self

Constructs a new WebPkiVerifier.

roots is the set of trust anchors to trust for issuing server certs.

ct_logs is the list of logs that are trusted for Certificate Transparency. Currently CT log enforcement is opportunistic; see https://github.com/rustls/rustls/issues/479.

source

pub fn verification_schemes() -> Vec<SignatureScheme>

Returns the signature verification methods supported by webpki.

Trait Implementations§

source§

impl ServerCertVerifier for WebPkiVerifier

source§

fn verify_server_cert( &self, end_entity: &Certificate, intermediates: &[Certificate], server_name: &ServerName, scts: &mut dyn Iterator<Item = &[u8]>, ocsp_response: &[u8], now: SystemTime, ) -> Result<ServerCertVerified, Error>

Will verify the certificate is valid in the following ways:

  • Signed by a trusted RootCertStore CA
  • Not Expired
  • Valid for DNS entry
source§

fn verify_tls12_signature( &self, message: &[u8], cert: &Certificate, dss: &DigitallySignedStruct, ) -> Result<HandshakeSignatureValid, Error>

Verify a signature allegedly by the given server certificate. Read more
source§

fn verify_tls13_signature( &self, message: &[u8], cert: &Certificate, dss: &DigitallySignedStruct, ) -> Result<HandshakeSignatureValid, Error>

Verify a signature allegedly by the given server certificate. Read more
source§

fn supported_verify_schemes(&self) -> Vec<SignatureScheme>

Return the list of SignatureSchemes that this verifier will handle, in verify_tls12_signature and verify_tls13_signature calls. Read more
source§

fn request_scts(&self) -> bool

Returns true if Rustls should ask the server to send SCTs. Read more

Auto Trait Implementations§

Blanket Implementations§

source§

impl<T> Any for T
where T: 'static + ?Sized,

source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
source§

impl<T> Borrow<T> for T
where T: ?Sized,

source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
source§

impl<T> From<T> for T

source§

fn from(t: T) -> T

Returns the argument unchanged.

source§

impl<T, U> Into<U> for T
where U: From<T>,

source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

§

type Error = Infallible

The type returned in the event of a conversion error.
source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.