mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-08 06:13:14 +00:00
d74e6eb042
* refactor(targets): move notify net helpers from utils * refactor(tls): centralize runtime foundation * refactor(targets): move notify net helpers from utils * refactor(tls): centralize runtime foundation * feat(tls-runtime): add TLS debug state and admin handler * refactor(tls-runtime): unify TLS debug consumer status view * fix(tls): address PR3065 review feedback * refactor(tls): align debug status payload types * refactor(targets): harden TLS hot reload paths * fix(targets): resolve review-4348251652 findings * fix(targets): finalize tls runtime review follow-ups * fix(targets): harden tls reload and review follow-ups * fix(targets): align tls reload handling across targets * fix(targets): finalize tls reload state and metrics updates * chore(deps): trim unused TLS deps * style(targets): normalize TLS reload formatting * refactor(targets): introduce tls runtime adapter path * chore: update workspace manifests for tls refactor * fix(tls): stabilize material reload and audit workflow * fix(targets): refresh tls fingerprint flow across sinks * fix(tls): align runtime coordinator and http reader updates * fix(sftp): simplify protocol error mapping * fix(tls): harmonize material loading behavior * fix(server): finalize tls material wiring in startup flow * fix(protos): tighten tls generation cache and deps
49 lines
1.6 KiB
Rust
49 lines
1.6 KiB
Rust
// Copyright 2024 RustFS Team
|
|
//
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
// you may not use this file except in compliance with the License.
|
|
// You may obtain a copy of the License at
|
|
//
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
// See the License for the specific language governing permissions and
|
|
// limitations under the License.
|
|
|
|
use sha2::{Digest, Sha256};
|
|
|
|
#[derive(Debug, Clone, PartialEq, Eq, Default)]
|
|
pub struct TlsFingerprint {
|
|
pub server_sha256: Option<[u8; 32]>,
|
|
pub public_ca_sha256: Option<[u8; 32]>,
|
|
pub client_ca_sha256: Option<[u8; 32]>,
|
|
pub client_cert_sha256: Option<[u8; 32]>,
|
|
pub client_key_sha256: Option<[u8; 32]>,
|
|
}
|
|
|
|
fn digest_bytes(bytes: &[u8]) -> [u8; 32] {
|
|
let mut hasher = Sha256::new();
|
|
hasher.update(bytes);
|
|
hasher.finalize().into()
|
|
}
|
|
|
|
impl TlsFingerprint {
|
|
pub fn from_optional_bytes(
|
|
server: Option<&[u8]>,
|
|
public_ca: Option<&[u8]>,
|
|
client_ca: Option<&[u8]>,
|
|
client_cert: Option<&[u8]>,
|
|
client_key: Option<&[u8]>,
|
|
) -> Self {
|
|
Self {
|
|
server_sha256: server.map(digest_bytes),
|
|
public_ca_sha256: public_ca.map(digest_bytes),
|
|
client_ca_sha256: client_ca.map(digest_bytes),
|
|
client_cert_sha256: client_cert.map(digest_bytes),
|
|
client_key_sha256: client_key.map(digest_bytes),
|
|
}
|
|
}
|
|
}
|