-
Notifications
You must be signed in to change notification settings - Fork 1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat: optional SSLKEYLOGFILE
support
#1539
base: master
Are you sure you want to change the base?
Conversation
Since this is mostly config wiring and relies on the already existing rustls features, does this need a test? If so, where should this test be placed? |
2d9fb99
to
66aa283
Compare
Seems to be related to #893. |
The solution there seems to be: just bypass |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This option is useful in terms of providing debuggability, and I think the benefits are worth the additional cost of adding this option. However, @LucioFranco has already rejected adding this feature in #893 and #1102, so we need his approval.
@LucioFranco As it's been a while since your previous review, I ask you if you've changed your mind and made this acceptable. If you accept it, I think it would be good to include this in the next v0.13 release.
will rebase... |
961f8ac
to
7bb05e8
Compare
Add a `use_key_log` option to server and client TLS configs that -- when set -- will enable rustls's `SSLKEYLOGFILE` handling. This is helpful when you want to intercept TLS traffic for debugging and is generally supported by many libraries and browsers. Also see: https://wiki.wireshark.org/TLS#using-the-pre-master-secret
7bb05e8
to
0c576da
Compare
@@ -26,12 +26,14 @@ pub(crate) struct TlsConnector { | |||
} | |||
|
|||
impl TlsConnector { | |||
#[allow(clippy::too_many_arguments)] |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
That's a bit cheating. If you want, I can refactor this, either using a parameter structure like
TlsConnectorParameters<'a> {
ca_certs: Vec<Certificate>,
trust_anchors: Vec<TrustAnchor<'static>>,
identity: Option<Identity>,
domain: &'a str,
assume_http2: bool,
use_key_log: bool,
}
or a builder pattern.
Motivation
Using
SSLKEYLOGFILE
is helpful when you want to intercept TLS traffic for debugging and is generally supported by many libraries and browsers. Also see: https://wiki.wireshark.org/TLS#using-the-pre-master-secretSolution
Add a
use_key_log
option to server and client TLS configs that -- when set -- will enable rustls'sSSLKEYLOGFILE
handling.