Decision records
ADR-0002: rustls with the aws-lc-rs crypto provider
- Status: Accepted (2026-10-05)
Context
TLS must use a mature library. Options: OpenSSL bindings, rustls+ring, rustls+aws-lc-rs.
Decision
rustls 0.23 with its default aws-lc-rs provider, installed explicitly as the process
default at startup. TLS 1.2 and 1.3 enabled; rustls defaults for suites and key exchange
(including the hybrid post-quantum X25519MLKEM768 group).
Consequences
- Memory-safe TLS state machine; no OpenSSL runtime dependency in packages.
- aws-lc-sys needs a C toolchain (and CMake/NASM on some hosts) at build time.
- A FIPS build is possible later via
aws-lc-rsFIPS feature. - Certificate material is PEM on disk; SNI resolution is ours (exact + single-label
wildcard), with SAN coverage verified by
rustls-webpkiat config prepare time.