tlsutil

package
v1.2.8 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 2, 2026 License: MIT Imports: 16 Imported by: 0

Documentation

Overview

Package tlsutil generates and manages TLS certificates for Pando's HTTP server.

A local certificate authority is created once in the user's profile and signs the short-lived server certificate Pando serves. The CA is what a user imports as trusted: it stays the same across projects, restarts and server certificate renewals, so the import is needed only once.

Index

Constants

View Source
const (

	// LoopbackServerName is the DNS name the generated certificate always
	// carries, so callers can pin it while connecting to 127.0.0.1.
	LoopbackServerName = "localhost"
)

Variables

This section is empty.

Functions

func LoadPinnedLoopbackTLSConfig added in v1.2.7

func LoadPinnedLoopbackTLSConfig(certPath string) (*tls.Config, error)

LoadPinnedLoopbackTLSConfig builds a TLS client config that trusts only the certificates stored at certPath and verifies the server against localhost while allowing the caller to connect to 127.0.0.1. For an auto-generated pair certPath holds the server certificate followed by the local CA, so a server certificate renewed by that CA keeps verifying.

Types

type CertPaths

type CertPaths struct {
	// CertFile holds the server certificate followed by the CA certificate.
	CertFile string
	KeyFile  string
	// CAFile is the local CA certificate, the file to import as trusted. It
	// is empty for a user-provided certificate.
	CAFile string
}

CertPaths holds the file paths for the TLS certificate and private key.

func EnsureCert

func EnsureCert(dir string) (CertPaths, error)

EnsureCert returns paths to a TLS cert/key pair inside dir, normally the user's profile directory.

The local CA is created once and reused until it nears expiry. The server certificate is reused while it is valid, signed by that CA and covers the host's current local addresses; otherwise it is reissued by the same CA, which does not affect a trust import of the CA.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL