#![cfg(feature = "rustls")] //! Commonly used code in most examples. use iroh_quinn::{ClientConfig, Endpoint, ServerConfig}; use rustls::pki_types::{CertificateDer, PrivatePkcs8KeyDer}; use std::{error::Error, net::SocketAddr, sync::Arc}; /// Constructs a QUIC endpoint configured for use a client only. /// /// ## Args /// /// - server_certs: list of trusted certificates. #[allow(unused)] pub fn make_client_endpoint( bind_addr: SocketAddr, server_certs: &[&[u8]], ) -> Result> { let client_cfg = configure_client(server_certs)?; let mut endpoint = Endpoint::client(bind_addr)?; endpoint.set_default_client_config(client_cfg); Ok(endpoint) } /// Constructs a QUIC endpoint configured to listen for incoming connections on a certain address /// and port. /// /// ## Returns /// /// - a stream of incoming QUIC connections /// - server certificate serialized into DER format #[allow(unused)] pub fn make_server_endpoint( bind_addr: SocketAddr, ) -> Result<(Endpoint, CertificateDer<'static>), Box> { let (server_config, server_cert) = configure_server()?; let endpoint = Endpoint::server(server_config, bind_addr)?; Ok((endpoint, server_cert)) } /// Builds default quinn client config and trusts given certificates. /// /// ## Args /// /// - server_certs: a list of trusted certificates in DER format. fn configure_client( server_certs: &[&[u8]], ) -> Result> { let mut certs = rustls::RootCertStore::empty(); for cert in server_certs { certs.add(CertificateDer::from(*cert))?; } Ok(ClientConfig::with_root_certificates(Arc::new(certs))?) } /// Returns default server configuration along with its certificate. fn configure_server( ) -> Result<(ServerConfig, CertificateDer<'static>), Box> { let cert = rcgen::generate_simple_self_signed(vec!["localhost".into()]).unwrap(); let cert_der = CertificateDer::from(cert.cert); let priv_key = PrivatePkcs8KeyDer::from(cert.key_pair.serialize_der()); let mut server_config = ServerConfig::with_single_cert(vec![cert_der.clone()], priv_key.into())?; let transport_config = Arc::get_mut(&mut server_config.transport).unwrap(); transport_config.max_concurrent_uni_streams(0_u8.into()); Ok((server_config, cert_der)) } #[allow(unused)] pub const ALPN_QUIC_HTTP: &[&[u8]] = &[b"hq-29"];