diff --git a/kubert/Cargo.toml b/kubert/Cargo.toml index ec49c3c..ecdd46e 100644 --- a/kubert/Cargo.toml +++ b/kubert/Cargo.toml @@ -11,7 +11,7 @@ keywords = ["kubernetes", "client", "runtime", "server"] [features] _tls = [ - "dep:rustls-pemfile", + "dep:rustls-pki-types", "dep:tokio-rustls", "kube-client?/rustls-tls", ] @@ -194,7 +194,7 @@ once_cell = { version = "1", optional = true } parking_lot = { version = "0.12", optional = true } pin-project-lite = { version = "0.2", optional = true } prometheus-client = { workspace = true, optional = true } -rustls-pemfile = { version = "2", optional = true } +rustls-pki-types = { version = "1", optional = true } serde = { version = "1", optional = true } serde_json = { version = "1", optional = true } sha2 = { version = "0.10", optional = true } diff --git a/kubert/src/server/tls_rustls.rs b/kubert/src/server/tls_rustls.rs index 52e0354..ec34d70 100644 --- a/kubert/src/server/tls_rustls.rs +++ b/kubert/src/server/tls_rustls.rs @@ -1,4 +1,8 @@ use super::*; +use rustls_pki_types::{ + pem::{Error as PemError, PemObject as _}, + PrivatePkcs1KeyDer, PrivatePkcs8KeyDer, +}; use std::sync::Arc; use tokio_rustls::{ rustls::{ @@ -39,19 +43,23 @@ async fn load_certs( TlsCertPath(cp): &TlsCertPath, ) -> std::io::Result>> { let pem = tokio::fs::read(cp).await?; - rustls_pemfile::certs(&mut pem.as_slice()).collect() + CertificateDer::pem_slice_iter(pem.as_slice()) + .collect::, _>>() + .map_err(pem_error_into_io_error) } async fn load_private_key(TlsKeyPath(kp): &TlsKeyPath) -> std::io::Result> { let pem = tokio::fs::read(kp).await?; - let mut keys = rustls_pemfile::pkcs8_private_keys(&mut pem.as_slice()) + let mut keys = PrivatePkcs8KeyDer::pem_slice_iter(pem.as_slice()) .map(|res| res.map(PrivateKeyDer::from)) - .collect::, _>>()?; + .collect::, _>>() + .map_err(pem_error_into_io_error)?; if keys.is_empty() { - keys = rustls_pemfile::rsa_private_keys(&mut pem.as_slice()) + keys = PrivatePkcs1KeyDer::pem_slice_iter(pem.as_slice()) .map(|res| res.map(PrivateKeyDer::from)) - .collect::, _>>()?; + .collect::, _>>() + .map_err(pem_error_into_io_error)?; } let key = keys @@ -62,3 +70,34 @@ async fn load_private_key(TlsKeyPath(kp): &TlsKeyPath) -> std::io::Result std::io::Error { + use std::io::{self, ErrorKind}; + + match error { + PemError::MissingSectionEnd { end_marker } => io::Error::new( + ErrorKind::InvalidData, + format!( + "section end {:?} missing", + String::from_utf8_lossy(&end_marker) + ), + ), + + PemError::IllegalSectionStart { line } => io::Error::new( + ErrorKind::InvalidData, + format!( + "illegal section start: {:?}", + String::from_utf8_lossy(&line) + ), + ), + + PemError::Base64Decode(err) => io::Error::new(ErrorKind::InvalidData, err), + error => io::Error::other(error), + } +}