Skip to main content

EnrollServer

Struct EnrollServer 

pub struct EnrollServer {
    pub bind_addr: SocketAddr,
    pub acceptor: TlsAcceptor,
    pub ca_cert_pem: String,
    pub ca_key_pem: Zeroizing<String>,
    pub ledger: Arc<CertLedger>,
    pub pairing: Arc<PairingGuard>,
    pub static_client_pins_configured: bool,
    pub allow_unpaired_until: Option<DateTime<Utc>>,
    pub relay_profile: RelayProfile,
    pub bridge_ports: Option<BridgePortSet>,
    pub relay_attempt_bucket: RelayAttemptBucket,
    pub paircode_admin_data_dir: Option<PathBuf>,
}

Fields§

§bind_addr: SocketAddr§acceptor: TlsAcceptor

Server-authentication-only TLS acceptor (no client cert; this is the bootstrap surface, not the mTLS RPC plane).

§ca_cert_pem: String

CA cert PEM (returned to the client and used for the SAS fingerprint).

§ca_key_pem: Zeroizing<String>

CA key PEM (decrypted), used only to sign CSRs. Held in memory for the endpoint’s lifetime; never written or returned.

§ledger: Arc<CertLedger>§pairing: Arc<PairingGuard>§static_client_pins_configured: bool

Static WSS pin allowlists cannot admit freshly issued in-band certs unless the operator updates the canonical pin source out of band.

§allow_unpaired_until: Option<DateTime<Utc>>

RFC3339 instant before which a code-less (“unpaired”) enrollment is accepted - the time-boxed migration window. None means closed.

§relay_profile: RelayProfile

Relay coordinates to hand back, when the relay bridge is configured.

§bridge_ports: Option<BridgePortSet>

Data dir used for local operator requests to mint additional pairing codes. This is intentionally not exposed through the public enrollment HTTP route because relay traffic reaches this listener over loopback. Ports the relay bridge dials enrollment from (None = no relay bridge).

§relay_attempt_bucket: RelayAttemptBucket

Class-wide attempt budget for relay-routed enrollment.

§paircode_admin_data_dir: Option<PathBuf>

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
§

impl<T> PolicyExt for T
where T: ?Sized,

§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns [Action::Follow] only if self and other return Action::Follow. Read more
§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns [Action::Follow] if either self or other returns Action::Follow. Read more
§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

§

fn vzip(self) -> V

§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more