rustls

Enum CertificateError

Source
#[non_exhaustive]
pub enum CertificateError {
Show 13 variants BadEncoding, Expired, NotValidYet, Revoked, UnhandledCriticalExtension, UnknownIssuer, UnknownRevocationStatus, ExpiredRevocationList, BadSignature, NotValidForName, InvalidPurpose, ApplicationVerificationFailure, Other(OtherError),
}
Expand description

The ways in which certificate validators can express errors.

Note that the rustls TLS protocol code interprets specifically these error codes to send specific TLS alerts. Therefore, if a custom certificate validator uses incorrect errors the library as a whole will send alerts that do not match the standard (this is usually a minor issue, but could be misleading).

Variants (Non-exhaustive)§

This enum is marked as non-exhaustive
Non-exhaustive enums could have additional variants added in future. Therefore, when matching against variants of non-exhaustive enums, an extra wildcard arm must be added to account for any future variants.
§

BadEncoding

The certificate is not correctly encoded.

§

Expired

The current time is after the notAfter time in the certificate.

§

NotValidYet

The current time is before the notBefore time in the certificate.

§

Revoked

The certificate has been revoked.

§

UnhandledCriticalExtension

The certificate contains an extension marked critical, but it was not processed by the certificate validator.

§

UnknownIssuer

The certificate chain is not issued by a known root certificate.

§

UnknownRevocationStatus

The certificate’s revocation status could not be determined.

§

ExpiredRevocationList

The certificate’s revocation status could not be determined, because the CRL is expired.

§

BadSignature

A certificate is not correctly signed by the key of its alleged issuer.

§

NotValidForName

The subject names in an end-entity certificate do not include the expected name.

§

InvalidPurpose

The certificate is being used for a different purpose than allowed.

§

ApplicationVerificationFailure

The certificate is valid, but the handshake is rejected for other reasons.

§

Other(OtherError)

Any other error.

This can be used by custom verifiers to expose the underlying error (where they are not better described by the more specific errors above).

It is also used by the default verifier in case its error is not covered by the above common cases.

Enums holding this variant will never compare equal to each other.

Trait Implementations§

Source§

impl Clone for CertificateError

Source§

fn clone(&self) -> CertificateError

Returns a copy of the value. Read more
1.0.0 · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for CertificateError

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl From<CertificateError> for AlertDescription

Source§

fn from(e: CertificateError) -> Self

Converts to this type from the input type.
Source§

impl From<CertificateError> for Error

Source§

fn from(e: CertificateError) -> Self

Converts to this type from the input type.
Source§

impl PartialEq for CertificateError

Source§

fn eq(&self, other: &Self) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 · Source§

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dst: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dst. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.

Layout§

Note: Most layout information is completely unstable and may even differ between compilations. The only exception is types with certain repr(...) attributes. Please see the Rust Reference's “Type Layout” chapter for details on type layout guarantees.

Size: 24 bytes

Size for each variant:

  • BadEncoding: 0 bytes
  • Expired: 0 bytes
  • NotValidYet: 0 bytes
  • Revoked: 0 bytes
  • UnhandledCriticalExtension: 0 bytes
  • UnknownIssuer: 0 bytes
  • UnknownRevocationStatus: 0 bytes
  • ExpiredRevocationList: 0 bytes
  • BadSignature: 0 bytes
  • NotValidForName: 0 bytes
  • InvalidPurpose: 0 bytes
  • ApplicationVerificationFailure: 0 bytes
  • Other: 16 bytes