Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Research platform-native TLS trust configuration

オープン
#454 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
5/5
見積もり時間
1週間以上
初心者へのやさしさ
32/100
issue の種類
ドキュメント
明瞭さ
おおむね明確
活発さ
静か
技術スタック
rust

調査の方向性

src/http.rs と Cargo.toml を確認して現在のバンドルされた root の設定を確定し、その後、関連する issue #448、#438、#445 を読みます。サポート対象の target と指定された証明書ケース全体で、列挙された trust 戦略を比較します。文書化された推奨事項、根拠、実行可能な失敗時の動作、実装およびテストのフォローアップが示され、runtime のドキュメントが更新されていれば完了です。

索引モデルが issue の本文から書いたものです。

説明

Context

The HTTP host currently builds its TLS connector with with_webpki_roots() in src/http.rs, while Cargo.toml enables the webpki-tokio feature. This embeds the Mozilla root set in every basic-cli application and does not use trust configured by the operating system.

Bundled roots make static applications self-contained and allow public HTTPS to work in minimal environments without a system CA bundle. However, a general-purpose CLI may need to honor:

  • enterprise TLS interception and private certificate authorities;
  • locally trusted development certificates;
  • administrator trust and distrust policy;
  • operating-system certificate updates;
  • standard CA bundle overrides such as SSL_CERT_FILE and SSL_CERT_DIR.

Research questions

Investigate and document the tradeoffs between:

  • a platform verifier;
  • loading native roots into rustls;
  • retaining only bundled WebPKI roots;
  • combining or falling back between native and bundled roots;
  • exposing an application-level custom CA configuration.

The investigation should cover:

  • x64 and arm64 macOS, x64 Windows, and x64 and arm64 Linux musl;
  • static linking, cross-compilation, binary size, and startup/runtime cost;
  • minimal containers or hosts with no usable native certificate store;
  • whether fallback to bundled roots could bypass an intentional OS distrust decision;
  • actionable errors when roots cannot be loaded or a certificate is rejected;
  • private CA, public CA, missing-store, and invalid-store test cases.

Desired outcome

Record a recommended trust policy for basic-cli and the rationale behind it. If a change is recommended, define implementation and test follow-ups that provide predictable behavior on every supported target without requiring users to disable certificate verification.

Keep the public runtime documentation updated with the chosen behavior.

Related work

  • #448 documents the current bundled-root behavior.
  • #438 tracks stable HTTP transport error classification, including TLS failures.
  • #445 tracks dependency advisories and rebuild expectations for statically linked applications.
主要言語
Rust
スター
121
フォーク
45
平均マージ
19時間 1分
マージ済み PR(30日)
16

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

roc-lang/basic-cli のほかの issue

roc-lang/basic-cli の issue をすべて見る

似ている issue

Rust の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。