1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
use std::future::Future;
use std::io;
use std::net::SocketAddr;
use std::pin::Pin;
use futures_util::TryFutureExt;
#[cfg(feature = "mtls")]
use openssl::pkcs12::Pkcs12;
use openssl::x509::X509;
use tokio_openssl::SslStream as TokioTlsStream;
use crate::error::ProtoError;
use crate::iocompat::AsyncIoStdAsTokio;
use crate::iocompat::AsyncIoTokioAsStd;
use crate::tcp::{Connect, TcpClientStream};
use crate::xfer::BufDnsStreamHandle;
use super::TlsStreamBuilder;
pub type TlsClientStream<S> =
TcpClientStream<AsyncIoTokioAsStd<TokioTlsStream<AsyncIoStdAsTokio<S>>>>;
pub struct TlsClientStreamBuilder<S>(TlsStreamBuilder<S>);
impl<S: Connect> TlsClientStreamBuilder<S> {
pub fn new() -> Self {
Self(TlsStreamBuilder::new())
}
pub fn add_ca(&mut self, ca: X509) {
self.0.add_ca(ca);
}
pub fn add_ca_der(&mut self, ca_der: &[u8]) -> io::Result<()> {
let ca = X509::from_der(ca_der)
.map_err(|e| io::Error::new(io::ErrorKind::InvalidData, e.to_string()))?;
self.add_ca(ca);
Ok(())
}
#[cfg(feature = "mtls")]
pub fn identity(&mut self, pkcs12: Pkcs12) {
self.0.identity(pkcs12);
}
pub fn bind_addr(&mut self, bind_addr: SocketAddr) {
self.0.bind_addr(bind_addr);
}
#[allow(clippy::type_complexity)]
pub fn build(
self,
name_server: SocketAddr,
dns_name: String,
) -> (
Pin<Box<dyn Future<Output = Result<TlsClientStream<S>, ProtoError>> + Send>>,
BufDnsStreamHandle,
) {
let (stream_future, sender) = self.0.build(name_server, dns_name);
let new_future = Box::pin(
stream_future
.map_ok(TcpClientStream::from_stream)
.map_err(ProtoError::from),
);
(new_future, sender)
}
}
impl<S: Connect> Default for TlsClientStreamBuilder<S> {
fn default() -> Self {
Self::new()
}
}