oxedyne/fe2o3/fe2o3_net/src/acme/mod.rs
1.2 KiB, 11 runs
created by r1870400018:9523, which is this file's identity for as long as the history lasts, whatever it is later renamed to
download · who wrote it · its history
| 1 | //! ACME (Automatic Certificate Management Environment) client, RFC 8555. |
| 2 | //! |
| 3 | //! This module implements the subset of the ACME protocol needed to obtain and |
| 4 | //! renew TLS server certificates from a certificate authority such as Let's |
| 5 | //! Encrypt using the `tls-alpn-01` challenge type. |
| 6 | //! |
| 7 | //! The submodules are layered from low-level primitives upward: |
| 8 | //! |
| 9 | //! - [`jose`] provides the ES256 JSON Web Signature primitive that every ACME |
| 10 | //! request is wrapped in. |
| 11 | //! |
| 12 | //! Further submodules covering RFC 8555 message types, the ACME client state |
| 13 | //! machine, the TLS-ALPN-01 challenge cert generator and the renewal loop are |
| 14 | //! added incrementally on top of [`jose`]. |
| 15 | //! |
| 16 | //! [Written with AI entirely](https://need2know.ai/entirely-ai/code)\ |
| 17 | //! Anthropic Claude |
| 18 | |
| 19 | // `jose`, `cache` and `rfc8555` are tokio-free primitives (JWS, the on-disk cache |
| 20 | // and the RFC 8555 message types); `jose` in particular is reused by the |
| 21 | // tokio-free `webauthn` verifier. The client state machine, the renewal/trust |
| 22 | // TLS glue and the rcgen-backed challenge cert generator are the async/TLS half. |
| 23 | pub mod cache; |
| 24 | #[cfg(feature = "async")] |
| 25 | pub mod challenge; |
| 26 | #[cfg(feature = "async")] |
| 27 | pub mod client; |
| 28 | pub mod jose; |
| 29 | pub mod rfc8555; |
| 30 | #[cfg(feature = "async")] |
| 31 | pub mod trust; |