Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 21 additions & 6 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

72 changes: 44 additions & 28 deletions Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,5 +1,27 @@
[workspace]
members = [".", "attested-tls"]
members = [".", "attested-tls", "tcp-tunnel"]

[workspace.dependencies]
anyhow = "1.0.100"
attestation = { git = "https://github.com/flashbots/attested-tls", branch = "main" }
attested-tls = { path = "attested-tls", default-features = false }
bytes = "1.11.1"
clap = { version = "4.5.51", features = ["derive", "env"] }
h2 = "0.4.12"
http = "1.3.1"
http-body-util = "0.1.3"
hyper = { version = "1.7.0", features = ["http2"] }
hyper-util = { version = "0.1.17", features = ["tokio"] }
rcgen = "0.14.5"
rustls-pemfile = "2.2.0"
serde_json = "1.0.145"
tempfile = "3.23.0"
thiserror = "2.0.17"
tokio = "1.48.0"
tokio-rustls = { version = "0.26.4", default-features = false }
tracing = "0.1.41"
tracing-subscriber = { version = "0.3.20", features = ["env-filter", "json"] }
webpki-roots = "1.0.4"

[package]
name = "attested-tls-proxy"
Expand All @@ -11,45 +33,39 @@ repository = "https://github.com/flashbots/attested-tls-proxy"
keywords = ["attested-TLS", "CVM", "TDX"]

[dependencies]
attested-tls = { path = "attested-tls", default-features = false }
tokio = { version = "1.48.0", features = ["full"] }
tokio-rustls = { version = "0.26.4", default-features = false, features = [
"aws_lc_rs",
] }
x509-parser = { version = "0.18.0", features = ["verify"] }
thiserror = "2.0.17"
clap = { version = "4.5.51", features = ["derive", "env"] }
rustls-pemfile = "2.2.0"
anyhow = "1.0.100"
attested-tls = { workspace = true, features = ["self-signed"] }
tokio = { workspace = true, features = ["fs", "io-std", "io-util", "macros", "net", "rt-multi-thread", "sync", "time"] }
tokio-rustls = { workspace = true, features = ["aws_lc_rs"] }
thiserror.workspace = true
clap.workspace = true
rustls-pemfile.workspace = true
anyhow.workspace = true
pem-rfc7468 = { version = "0.7.0", features = ["std"] }
hyper = { version = "1.7.0", features = ["server", "http2"] }
h2 = "0.4.12"
hyper-util = { version = "0.1.17", features = ["tokio"] }
http-body-util = "0.1.3"
bytes = "1.11.1"
http = "1.3.1"
serde_json = "1.0.145"
hyper = { workspace = true, features = ["server"] }
h2.workspace = true
hyper-util.workspace = true
http-body-util.workspace = true
bytes.workspace = true
http.workspace = true
serde_json.workspace = true
serde = "1.0.228"
reqwest = { version = "0.13.4", default-features = false, features = [
"rustls-no-provider",
] }
webpki-roots = "1.0.4"
tracing = "0.1.41"
tracing-subscriber = { version = "0.3.20", features = ["env-filter", "json"] }
webpki-roots.workspace = true
tracing.workspace = true
tracing-subscriber.workspace = true
axum = "0.8.8"
tower-http = { version = "0.6.7", features = ["fs"] }
rsa = { version = "0.9", default-features = false }
p256 = { version = "0.13.2", features = ["pkcs8"] }
pkcs1 = "0.7.5"
pkcs8 = "0.10.2"
rcgen = "0.14.5"
pin-project-lite = "0.2.16"
pccs = { git = "https://github.com/flashbots/attested-tls", branch = "main" }

[dev-dependencies]
tempfile = "3.23.0"
tokio = { workspace = true, features = ["process"] }
rcgen.workspace = true
tempfile.workspace = true
tdx-quote = { version = "0.0.5", features = ["mock"] }
attested-tls = { path = "attested-tls", features = ["test-helpers", "mock"] }
attested-tls = { workspace = true, default-features = true, features = ["test-helpers", "mock"] }
jsonrpsee = { version = "0.26.0", features = ["server"] }

[features]
Expand Down
2 changes: 2 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,8 @@ It has five subcommands:
- `attested-tls-proxy attested-file-server` - serve files from a local filesystem path over an attested TLS channel.
- `attested-tls-proxy attested-get` - connect to a proxy server, verify its attestation, make a single HTTP GET request, and write the response body to standard output.

If you rather want opaque TCP forwarding, see [`attested-tls-tcp-tunnel`](tcp-tunnel/README.md). It provides a separate CLI and library with one attested connection per source TCP connection.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I like my human made grammatical errors actually


### How it works

This works as follows:
Expand Down
39 changes: 22 additions & 17 deletions attested-tls/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -8,17 +8,17 @@ repository = "https://github.com/flashbots/attested-tls-proxy"
keywords = ["attested-TLS", "CVM", "TDX"]

[dependencies]
tokio = { version = "1.48.0", features = ["full"] }
tokio-rustls = { version = "0.26.4", default-features = false }
tokio = { workspace = true, features = ["io-util", "net", "rt"] }

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not strictly related to PR - i pruned tokio features to only the required ones, not full

tokio-rustls.workspace = true
sha2 = "0.10.9"
x509-parser = "0.18.0"
thiserror = "2.0.17"
webpki-roots = "1.0.4"
http = "1.3.1"
serde_json = "1.0.145"
tracing = "0.1.41"
thiserror.workspace = true
webpki-roots.workspace = true
http.workspace = true
serde_json.workspace = true
tracing.workspace = true
parity-scale-codec = "3.7.5"
attestation = { git = "https://github.com/flashbots/attested-tls", branch = "main" }
attestation.workspace = true

# Used for websocket support
tokio-tungstenite = { version = "0.28.0", optional = true }
Expand All @@ -29,22 +29,26 @@ alloy-rpc-client = { version = "1.1.3", optional = true }
tower-service = { version = "0.3.3", optional = true }
alloy-transport-http = { version = "1.4.3", features = ["hyper"], optional = true }
url = { version = "2.5.7", optional = true }
hyper = { version = "1.7.0", features = ["client", "http2"], optional = true }
hyper-util = { version = "0.1.17", features = ["tokio"], optional = true }
bytes = { version = "1.11.1", optional = true }
http-body-util = { version = "0.1.3", optional = true }
hyper = { workspace = true, optional = true, features = ["client"] }
hyper-util = { workspace = true, optional = true }
bytes = { workspace = true, optional = true }
http-body-util = { workspace = true, optional = true }

# Used by test helpers
rcgen = { version = "0.14.5", optional = true }
# Used by test helpers and self-signed certificate support
rcgen = { workspace = true, optional = true }

[dev-dependencies]
rcgen = "0.14.5"
tempfile = "3.23.0"
attestation = { git = "https://github.com/flashbots/attested-tls", branch = "main", features = ["mock"] }
tokio = { workspace = true, features = ["macros", "time"] }
rcgen.workspace = true
tempfile.workspace = true
attestation = { workspace = true, features = ["mock"] }

[features]
default = ["ws", "rpc"]

# Self-signed certificate generation and verification.
self-signed = ["rcgen", "x509-parser/verify"]

# Adds support for Microsoft Azure attestation generation and verification
azure = ["attestation/azure"]

Expand All @@ -53,6 +57,7 @@ ws = ["tokio-tungstenite", "futures-util"]

# Adds JSON RPC support
rpc = [
"tokio/sync",
"alloy-rpc-client",
"tower-service",
"alloy-transport-http",
Expand Down
2 changes: 2 additions & 0 deletions attested-tls/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,8 @@ It uses session binding through exported key material from the TLS session. This

Attestation may be provided by either the server, or the client, or both.

The optional `self-signed` feature exposes the `self_signed` module for generating and verifying self-signed certificates.

## Protocol Specification

A TLS 1.3 handshake is made between server and client. The protocol name `flashbots-ratls/1` is included in ALPN. Future versions of the protocol may add additional protocol names which increment the number given after the slash, but backwards compatibility will be provided through also specifying `flashbots-ratls/1`.
Expand Down
3 changes: 3 additions & 0 deletions attested-tls/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,9 @@ pub mod attested_rpc;
#[cfg(any(test, feature = "test-helpers"))]
pub mod test_helpers;

#[cfg(feature = "self-signed")]
pub mod self_signed;

pub use attestation;

use attestation::{
Expand Down
Loading
Loading