struct ObservingVerifier {
inner: Arc<dyn ServerCertVerifier>,
hook: CertificateHook,
}Expand description
A verifier that writes down the chain it was shown, then defers to another.
It exists because the interesting certificates are the rejected ones. A relay with an expired certificate, a private CA, or a name that does not match never completes a handshake, so nothing is left afterwards to read the chain off — and “the handshake failed for a certificate reason” without the certificate is exactly the report a relay operator cannot act on.
It observes unconditionally and judges not at all. The inner verifier’s verdict is returned untouched, so wrapping cannot turn a rejection into an acceptance however the observation goes.
Fields§
§inner: Arc<dyn ServerCertVerifier>§hook: CertificateHookTrait Implementations§
Source§impl Debug for ObservingVerifier
impl Debug for ObservingVerifier
Source§impl ServerCertVerifier for ObservingVerifier
impl ServerCertVerifier for ObservingVerifier
Source§fn verify_server_cert(
&self,
end_entity: &CertificateDer<'_>,
intermediates: &[CertificateDer<'_>],
server_name: &ServerName<'_>,
ocsp_response: &[u8],
now: UnixTime,
) -> Result<ServerCertVerified, Error>
fn verify_server_cert( &self, end_entity: &CertificateDer<'_>, intermediates: &[CertificateDer<'_>], server_name: &ServerName<'_>, ocsp_response: &[u8], now: UnixTime, ) -> Result<ServerCertVerified, Error>
Verify the end-entity certificate
end_entity is valid for the
hostname dns_name and chains to at least one trust anchor. Read moreSource§fn verify_tls12_signature(
&self,
message: &[u8],
cert: &CertificateDer<'_>,
dss: &DigitallySignedStruct,
) -> Result<HandshakeSignatureValid, Error>
fn verify_tls12_signature( &self, message: &[u8], cert: &CertificateDer<'_>, dss: &DigitallySignedStruct, ) -> Result<HandshakeSignatureValid, Error>
Verify a signature allegedly by the given server certificate. Read more
Source§fn verify_tls13_signature(
&self,
message: &[u8],
cert: &CertificateDer<'_>,
dss: &DigitallySignedStruct,
) -> Result<HandshakeSignatureValid, Error>
fn verify_tls13_signature( &self, message: &[u8], cert: &CertificateDer<'_>, dss: &DigitallySignedStruct, ) -> Result<HandshakeSignatureValid, Error>
Verify a signature allegedly by the given server certificate. Read more
Source§fn supported_verify_schemes(&self) -> Vec<SignatureScheme>
fn supported_verify_schemes(&self) -> Vec<SignatureScheme>
Return the list of SignatureSchemes that this verifier will handle,
in
verify_tls12_signature and verify_tls13_signature calls. Read more§fn requires_raw_public_keys(&self) -> bool
fn requires_raw_public_keys(&self) -> bool
Returns whether this verifier requires raw public keys as defined
in RFC 7250.
§fn root_hint_subjects(&self) -> Option<&[DistinguishedName]>
fn root_hint_subjects(&self) -> Option<&[DistinguishedName]>
Return the [
DistinguishedName]s of certificate authorities that this verifier trusts. Read moreAuto Trait Implementations§
impl !RefUnwindSafe for ObservingVerifier
impl !UnwindSafe for ObservingVerifier
impl Freeze for ObservingVerifier
impl Send for ObservingVerifier
impl Sync for ObservingVerifier
impl Unpin for ObservingVerifier
impl UnsafeUnpin for ObservingVerifier
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more