pub enum CertOverrideDecision {
Deny,
SoftDenied,
AllowHostPinned,
AllowSessionOnce,
CandidateCustomRoots,
AllowChainVerified,
AllowSpkiPinned,
}Expand description
Host / session / chain policy decision for cert-override (swarm-2).
Security model: host-pin (A) by default path; chain vs enabled PEMs (B) only after cryptographic verify; never auto-allow solely because PEMs exist.
Variants§
Deny
No policy match — deny by default.
SoftDenied
Soft sticky deny (principal chose Deny and asked not to re-prompt).
AllowHostPinned
Explicit host allow entry (policy label host-allow:example.com) — A.
AllowSessionOnce
Session allow-once (process memory; not a permanent pin).
CandidateCustomRoots
PEM roots enabled: platform must call chain verify; without cert material → deny. This is not an automatic allow.
AllowChainVerified
Chain verified against enabled PEMs (B accepted).
AllowSpkiPinned
SPKI pin matched.
Trait Implementations§
Source§impl Clone for CertOverrideDecision
impl Clone for CertOverrideDecision
Source§fn clone(&self) -> CertOverrideDecision
fn clone(&self) -> CertOverrideDecision
Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
Performs copy-assignment from
source. Read moreSource§impl Debug for CertOverrideDecision
impl Debug for CertOverrideDecision
Source§impl PartialEq for CertOverrideDecision
impl PartialEq for CertOverrideDecision
Source§fn eq(&self, other: &CertOverrideDecision) -> bool
fn eq(&self, other: &CertOverrideDecision) -> bool
Tests for
self and other values to be equal, and is used by ==.impl Copy for CertOverrideDecision
impl Eq for CertOverrideDecision
impl StructuralPartialEq for CertOverrideDecision
Auto Trait Implementations§
impl Freeze for CertOverrideDecision
impl RefUnwindSafe for CertOverrideDecision
impl Send for CertOverrideDecision
impl Sync for CertOverrideDecision
impl Unpin for CertOverrideDecision
impl UnsafeUnpin for CertOverrideDecision
impl UnwindSafe for CertOverrideDecision
Blanket Implementations§
§impl<S, A> Aggregate<Result<S, Error>> for Awhere
A: Aggregate<S>,
impl<S, A> Aggregate<Result<S, Error>> for Awhere
A: Aggregate<S>,
Aggregate shares in an MPC protocol.
§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
Checks if this value is equivalent to the given key. Read more
§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
Compare self to
key and return true if they are equal.§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
Checks if this value is equivalent to the given key. Read more
§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
Checks if this value is equivalent to the given key. Read more
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more