2018-08-07 22:34:16 -07:00
|
|
|
# tls example
|
|
|
|
|
|
|
|
## Usage
|
|
|
|
|
2020-05-19 12:46:00 +09:00
|
|
|
### Certificate
|
|
|
|
|
2020-10-03 18:31:58 +02:00
|
|
|
We put the self-signed certificate in this directory as an example
|
2020-05-19 12:46:00 +09:00
|
|
|
but your browser would complain that it isn't secure.
|
|
|
|
So we recommend to use [`mkcert`] to trust it. To use local CA, you should run:
|
|
|
|
|
|
|
|
```bash
|
|
|
|
mkcert -install
|
|
|
|
```
|
|
|
|
|
|
|
|
If you want to generate your own cert/private key file, then run:
|
|
|
|
|
|
|
|
```bash
|
|
|
|
mkcert 127.0.0.1
|
|
|
|
```
|
|
|
|
|
2020-07-19 00:57:15 +03:00
|
|
|
If your key doesn't work, convert it to rsa:
|
|
|
|
```bash
|
|
|
|
openssl rsa -in key.pem -out key-rsa.pem
|
|
|
|
```
|
|
|
|
|
2020-05-19 12:46:00 +09:00
|
|
|
[`mkcert`]: https://github.com/FiloSottile/mkcert
|
|
|
|
|
2018-08-07 22:34:16 -07:00
|
|
|
### server
|
|
|
|
|
|
|
|
```bash
|
|
|
|
cd examples/rustls
|
|
|
|
cargo run (or ``cargo watch -x run``)
|
|
|
|
# Started http server: 127.0.0.1:8443
|
|
|
|
```
|
|
|
|
|
|
|
|
### web client
|
|
|
|
|
|
|
|
- curl: ``curl -v https://127.0.0.1:8443/index.html --compressed -k``
|
|
|
|
- browser: [https://127.0.0.1:8443/index.html](https://127.0.0.1:8443/index.html)
|