Skip to content

Support new rustls KernelConnection API, and thence TLS1.3 KeyUpdates #59

Description

@ctz

See rustls/rustls#2362 for background. I plan to work on this as part of integrating KTLS into https://github.com/rustls/rustls-openssl-compat.

Activity

  1. self-assigned this
    on Apr 11, 2025
  2. swlynch99 commented on Apr 18, 2025

    @swlynch99
    Contributor

    I was planning on taking a shot at this once rustls/rustls#2370 ends up getting merged. I already have code written for a sync version, and translating that to async should be pretty straightforward. However, if you would prefer to do this yourself then that is fine as well and I'll hold off from making a PR.

  3. ctz commented on Apr 30, 2025

    @ctz
    MemberAuthor

    Please do if you have work in flight!

  4. removed their assignment
    on Apr 30, 2025
  5. marcus-sa commented on Jun 11, 2026

    @marcus-sa

    Cross-linking from a downstream consumer: I'm building Overdrive, which does transparent kernel mTLS (eBPF sockops + kTLS with per-workload SPIFFE SVIDs). TLS 1.3 KeyUpdate support here is the blocker for in-place SVID rekey on long-lived connections — without it, rotation falls back to teardown + reconnect when a workload's short-lived SVID expires. I'm tracking it at overdrive-sh/overdrive#229.

    The rustls::kernel rewrite in #62 looks like the right path. Happy to help: I can test against real kTLS east-west workloads on a pinned 6.18 kernel, and review once it's split into smaller PRs. Is #62 still the active line of work, or would a smaller KeyUpdate-only PR on top of the current crate be preferred?

  6. djc commented on Jun 11, 2026

    @djc
    Member

    Is #62 still the active line of work, or would a smaller KeyUpdate-only PR on top of the current crate be preferred?

    I don't think there is an active line of work right now, the maintainers are also kind of busy with other stuff (working on rustls 0.24) so I'm not sure we'll be able to make progress on this in the short term.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions