Feature analysis for Rust Rewrite #1

Open
opened 2026-08-31 06:31:34 +00:00 by fuxle · 0 comments
Owner

Java impl: ~/git/certgine

I want a detailed analysis of the used server feature for rewriting a faster and native version in rust with almost the same functionalities of the current Java version. However instead of GraphQL we do REST and OpenAPI with utopia and it's macros so it is convenient to use.

ACME Endpoints do not need OpenAPI doc

Currently the Java impl has its logic spread across modules -> each java module would be an rust crate and might be optional, e.g. build without TSA support.

Map out library equivalents. E.g.:

  • Jetty -> Axum 0.8x
  • BouncyCastle JSSE -> Rustls
  • BouncyCastle -> OpenSSL, rcgen, x509-generator, ...
  • JTE -> askama
  • ...

Also we have our own cryptography module so we have our common layer for certificate, key handling etc and it wraps that for interchange between modules. Just import cg-common-cryptography and u have all u need, no need to separate import openssl at some point. If something is missing, just add to cg-common-cryptography

Workspace Layout:

  • Cargo.toml (Workspace Root, Rust Edition 2024)
  • app/
    • certgined (main server)
    • certgine-transparencyd (CT-Server impl)
  • lib/
    • cg-common-cryptography (PKCS#11 is later added)
    • cg-common-types
    • cg-common-helpers
    • cg-auth (Local, OpenID)
    • cg-acme (if in server the ACME feature is enabled, cg-revocation is also required)
    • cg-revocation
    • cg-webui-legacy
    • cg-certificate-transparency
    • cg-tsa
    • cg-... modules

For DB we only support Postgres. AI Module is MUST NOT be ported for now.

Use your Forgejo MCP tools to create issues, labels, attach labels to issues and depend issues on abother

Java impl: ~/git/certgine I want a detailed analysis of the used server feature for rewriting a faster and native version in rust with almost the same functionalities of the current Java version. However instead of GraphQL we do REST and OpenAPI with utopia and it's macros so it is convenient to use. > ACME Endpoints do not need OpenAPI doc Currently the Java impl has its logic spread across modules -> each java module would be an rust crate and might be optional, e.g. build without TSA support. Map out library equivalents. E.g.: - Jetty -> Axum 0.8x - BouncyCastle JSSE -> Rustls - BouncyCastle -> OpenSSL, rcgen, x509-generator, ... - JTE -> askama - ... Also we have our own cryptography module so we have our common layer for certificate, key handling etc and it wraps that for interchange between modules. Just import cg-common-cryptography and u have all u need, no need to separate import openssl at some point. If something is missing, just add to cg-common-cryptography Workspace Layout: - Cargo.toml (Workspace Root, Rust Edition 2024) - app/ - certgined (main server) - certgine-transparencyd (CT-Server impl) - lib/ - cg-common-cryptography (PKCS#11 is later added) - cg-common-types - cg-common-helpers - cg-auth (Local, OpenID) - cg-acme (if in server the ACME feature is enabled, cg-revocation is also required) - cg-revocation - cg-webui-legacy - cg-certificate-transparency - cg-tsa - cg-... modules For DB we only support Postgres. AI Module is MUST NOT be ported for now. Use your Forgejo MCP tools to create issues, labels, attach labels to issues and depend issues on abother
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
fuxle/certgine#1
No description provided.