Decision records

ADR-0002: rustls with the aws-lc-rs crypto provider

  • Status: Accepted (2026-10-05)

Context

TLS must use a mature library. Options: OpenSSL bindings, rustls+ring, rustls+aws-lc-rs.

Decision

rustls 0.23 with its default aws-lc-rs provider, installed explicitly as the process default at startup. TLS 1.2 and 1.3 enabled; rustls defaults for suites and key exchange (including the hybrid post-quantum X25519MLKEM768 group).

Consequences

  • Memory-safe TLS state machine; no OpenSSL runtime dependency in packages.
  • aws-lc-sys needs a C toolchain (and CMake/NASM on some hosts) at build time.
  • A FIPS build is possible later via aws-lc-rs FIPS feature.
  • Certificate material is PEM on disk; SNI resolution is ours (exact + single-label wildcard), with SAN coverage verified by rustls-webpki at config prepare time.