3 ms·
In case anyone wants to learn about an effort to incrementally port some of the BoringSSL (fork of OpenSSL) primitives to Rust: https://github.com/briansmith/r
by frewsxcv 10y ago
In case anyone wants to learn about an effort to incrementally port some of the BoringSSL (fork of OpenSSL) primitives to Rust:
https://github.com/briansmith/ring https://github.com/briansmith/ring
If anyone is looking to contribute and wants a "good first task", here are some tasks:
https://github.com/briansmith/ring/issues?q=is%3Aopen+is%3Aissue+label%3Agood-first-bug https://github.com/briansmith/ring/issues?q=is%3Aopen+is%3Ai...
Help is greatly appreciated :)
- lambda 10y agoOf particular interest here is also webpki: https://github.com/briansmith/webpki https://github.com/briansmith/webpki Which is designed to validate TLS certificates. This is doing the ASN.1 parsing and signature verification in a zero-copy, memory safe way, built on top of ring for the core crypto primitives. Now, this isn't a full implementation of what you would need for replacing OpenSSL for certificate handling (and also isn't yet complete); in particular, this is extremely limited in scope as only being for client-side certificate verification. This particular OpenSSL issue was when parsing and re-encoding certificates, which is out of scope for webpki. But it is a good starting point for demonstrating memory-safe and efficient handling of complex tasks like parsing and verifying of TLS certificates.