Skip to main content

nautilus_cryptography/
tls.rs

1// -------------------------------------------------------------------------------------------------
2//  Copyright (C) 2015-2026 Nautech Systems Pty Ltd. All rights reserved.
3//  https://nautechsystems.io
4//
5//  Licensed under the GNU Lesser General Public License Version 3.0 (the "License");
6//  You may not use this file except in compliance with the License.
7//  You may obtain a copy of the License at https://www.gnu.org/licenses/lgpl-3.0.en.html
8//
9//  Unless required by applicable law or agreed to in writing, software
10//  distributed under the License is distributed on an "AS IS" BASIS,
11//  WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12//  See the License for the specific language governing permissions and
13//  limitations under the License.
14// -------------------------------------------------------------------------------------------------
15
16use std::sync::Arc;
17
18use rustls::{ClientConfig, RootCertStore};
19use webpki_roots;
20
21use crate::providers::install_cryptographic_provider;
22
23/// Loads a TLS client configuration with certificates.
24#[must_use]
25pub fn create_tls_config() -> Arc<ClientConfig> {
26    install_cryptographic_provider();
27
28    log::debug!("Loading certificates");
29
30    let mut root_store = RootCertStore::empty();
31    root_store.extend(webpki_roots::TLS_SERVER_ROOTS.iter().cloned());
32
33    let config = ClientConfig::builder()
34        .with_root_certificates(root_store)
35        .with_no_client_auth();
36
37    Arc::new(config)
38}
39
40#[cfg(test)]
41mod tests {
42    use rstest::rstest;
43    use rustls::crypto::CryptoProvider;
44
45    use super::*;
46
47    #[rstest]
48    fn test_create_tls_config_installs_default_provider() {
49        // Must build without panicking and leave a usable process-default
50        // provider, even when called as the first rustls use in the process.
51        let _config = create_tls_config();
52        assert!(CryptoProvider::get_default().is_some());
53
54        // Second call exercises the idempotent install path
55        let _config = create_tls_config();
56        assert!(CryptoProvider::get_default().is_some());
57    }
58}