tls: expose verified peer certificate digest for server-side replica pinning #73
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/rustls-peer-cert-sha256"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Adds
rustls-peer-certificate-sha256to(std net tls-rustls)and nativejerboa_tls_peer_cert_sha256: the SHA-256 digest of the leaf certificate rustls already verified on a completed connection, retrievable from both client and server (mTLS) handles.Motivation
The existing pinning API (
rustls-connect-pinned) only covers the client connect path. Servers that authorize callers by per-certificate pinning (e.g. botcommons-store replica authorization over mTLS) currently have no way to learn which verified client certificate arrived — the only alternative is a CA-based model, which is a different security posture. This has forced downstream consumers to carry a private FFI fork of exactly this function (builder-lineage jerboa17c03773).Design
ring::digest::SHA256and writes exactly 32 bytes through the existing checked-output-buffer helper.-1with aset_last_errormessage; the Scheme wrapper raises.Testing
tests/test-tls-peer-certdriver (auto-discovered bymake testvia thetests/test-*wildcard) +tests/fixtures/tls-peer-certfixture: one self-signed cert serves as server cert, client cert, and CA; openssl independently computes the DER SHA-256; the fixture asserts both peers report exactly that digest after a completed mTLS roundtrip, and that an unknown handle raises.cargo checkclean on the native crate.Verification evidence
cargo check: passes (pre-existing warnings only).fbd78f32bcceb92f67c0Post-merge note: the
push-context ci.yaml run on57aa69e3(23:05) failed while the identical tree passed thepull_request-context run onceb92f67(22:47, all five checks green; freebsd/dtrace/gerbil-compat/version-policy also green on57aa69e3itself). Same content, ~20 min apart, single check diverging — this matches the timing-sensitive-test flake profile seen on master historically (e.g.e963f91f,143ba6ef,5905f56c). No content change is implicated; a re-run should settle it.Separately filed while debugging in this area: #76 (jerboa-prog-* temp artifacts leak on kill/crash — found after it filled a validation jail's /tmp with 61 GB and ENOSPC-truncated an unrelated DB).