pub struct TlsConfig {
pub cert: PathBuf,
pub key: PathBuf,
pub client_ca: Option<PathBuf>,
}Expand description
PEM certificate/key material for a TLS-terminated listener.
client_ca, when set, turns on mutual TLS: clients must present a
certificate chaining to one of these anchors (NIAP PPCA FCS_TLSS_EXT.2).
When absent, the listener does server-auth TLS only (FCS_TLSS_EXT.1) and
authentication falls to the existing bcrypt/RBAC login.
Fields§
§cert: PathBufPath to the server certificate chain (PEM, leaf first).
key: PathBufPath to the server private key (PKCS#8 or RSA/SEC1 PEM).
client_ca: Option<PathBuf>Optional PEM bundle of CAs trusted to sign client certificates. Presence enables mutual TLS (client-cert required).
Trait Implementations§
Source§impl<'de> Deserialize<'de> for TlsConfig
impl<'de> Deserialize<'de> for TlsConfig
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Deserialize this value from the given Serde deserializer. Read more
Auto Trait Implementations§
impl Freeze for TlsConfig
impl RefUnwindSafe for TlsConfig
impl Send for TlsConfig
impl Sync for TlsConfig
impl Unpin for TlsConfig
impl UnsafeUnpin for TlsConfig
impl UnwindSafe for TlsConfig
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more