Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Research platform-native TLS trust configuration

Abierto
#454 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
5/5
Tiempo estimado
Más de una semana
Aptitud para principiantes
32/100
Tipo de issue
Documentación
Claridad
Bastante claro
Estado de actividad
Tranquilo
Stack tecnológico
rust

Línea de trabajo

Revisa src/http.rs y Cargo.toml para confirmar la configuración actual de las raíces incluidas y, después, lee las issues relacionadas #448, #438 y #445. Compara las estrategias de confianza indicadas entre los targets compatibles y los casos de certificados especificados. Se considera terminado cuando haya una recomendación documentada, una justificación, un comportamiento accionable ante fallos y seguimientos de implementación y pruebas, con la documentación del runtime actualizada.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Context

The HTTP host currently builds its TLS connector with with_webpki_roots() in src/http.rs, while Cargo.toml enables the webpki-tokio feature. This embeds the Mozilla root set in every basic-cli application and does not use trust configured by the operating system.

Bundled roots make static applications self-contained and allow public HTTPS to work in minimal environments without a system CA bundle. However, a general-purpose CLI may need to honor:

  • enterprise TLS interception and private certificate authorities;
  • locally trusted development certificates;
  • administrator trust and distrust policy;
  • operating-system certificate updates;
  • standard CA bundle overrides such as SSL_CERT_FILE and SSL_CERT_DIR.

Research questions

Investigate and document the tradeoffs between:

  • a platform verifier;
  • loading native roots into rustls;
  • retaining only bundled WebPKI roots;
  • combining or falling back between native and bundled roots;
  • exposing an application-level custom CA configuration.

The investigation should cover:

  • x64 and arm64 macOS, x64 Windows, and x64 and arm64 Linux musl;
  • static linking, cross-compilation, binary size, and startup/runtime cost;
  • minimal containers or hosts with no usable native certificate store;
  • whether fallback to bundled roots could bypass an intentional OS distrust decision;
  • actionable errors when roots cannot be loaded or a certificate is rejected;
  • private CA, public CA, missing-store, and invalid-store test cases.

Desired outcome

Record a recommended trust policy for basic-cli and the rationale behind it. If a change is recommended, define implementation and test follow-ups that provide predictable behavior on every supported target without requiring users to disable certificate verification.

Keep the public runtime documentation updated with the chosen behavior.

Related work

  • #448 documents the current bundled-root behavior.
  • #438 tracks stable HTTP transport error classification, including TLS failures.
  • #445 tracks dependency advisories and rebuild expectations for statically linked applications.
Lenguaje dominante
Rust
Estrellas
121
Forks
45
Merge medio
19 h 1 min
PR fusionados (30 d)
16

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de roc-lang/basic-cli

Todos los issues de roc-lang/basic-cli

Issues similares

Más issues de Rust

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.