From 24bf2a395d6af479a93481eb699d6835e3c70e44 Mon Sep 17 00:00:00 2001 From: Tom Fay Date: Fri, 25 Sep 2026 09:23:10 +0100 Subject: [PATCH 1/3] doc: mention provider usage in docstring --- src/lib.rs | 18 +++++++++++++----- 1 file changed, 13 insertions(+), 5 deletions(-) diff --git a/src/lib.rs b/src/lib.rs index 6453dd8..914b492 100644 --- a/src/lib.rs +++ b/src/lib.rs @@ -59,8 +59,8 @@ //! //! ```toml //! [dependencies] -//! rustls = { version = "0.23.0", features = ["tls12", "std"], default-features = false } -//! rustls_openssl = "0.3" +//! rustls = { version = "0.23", features = ["tls12", "std"], default-features = false } +//! rustls_openssl = "0.4" //! ``` //! //! ### Configuration @@ -72,7 +72,13 @@ //! - `tls12`: Enables TLS 1.2 cipher suites. Enabled by default. //! - `prefer-post-quantum`: Enables X25519MLKEM768 as the first key exchange group. Enabled by default. //! - `vendored`: Enables vendored OpenSSL. Disabled by default. -//! - `fips`: No longer used. +//! - `fips`: No longer used. See [fips] for FIPS support. +//! +//! # OpenSSL API Usage +//! +//! When targeting OpenSSL 3.0 or later, this crate strictly uses modern, provider APIs (`EVP_*`). +//! Legacy cryptographic interfaces (e.g., direct `HMAC_*` or `RSA_*` functions) are used only when +//! targeting OpenSSL 1.1.1. #![warn(missing_docs)] use openssl::rand::rand_priv_bytes; use rustls::SupportedCipherSuite; @@ -181,8 +187,10 @@ fn cipher_suite_available(cipher_suite: &SupportedCipherSuite) -> bool { /// The specified cipher suites and key exchange groups should be defined in descending order of preference. /// i.e the first elements have the highest priority during negotiation. /// -/// If OpenSSL is running in FIPS mode, non-approved algorithms may be filtered -/// out by runtime availability checks. +/// INo runtime filtering is performed on the provided cipher suites and key exchange groups, +/// so the caller is responsible for ensuring that the provided algorithms are available at runtime, +/// by calling [available_cipher_suites()] and [kx_group::available_groups()]. +/// /// /// Sample usage: /// ```rust From 1a31b7b474d84e615781a41d4036ffa75cd8f72a Mon Sep 17 00:00:00 2001 From: Tom Fay Date: Fri, 25 Sep 2026 09:23:56 +0100 Subject: [PATCH 2/3] typo --- src/lib.rs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/lib.rs b/src/lib.rs index 914b492..e70dcb0 100644 --- a/src/lib.rs +++ b/src/lib.rs @@ -187,7 +187,7 @@ fn cipher_suite_available(cipher_suite: &SupportedCipherSuite) -> bool { /// The specified cipher suites and key exchange groups should be defined in descending order of preference. /// i.e the first elements have the highest priority during negotiation. /// -/// INo runtime filtering is performed on the provided cipher suites and key exchange groups, +/// No runtime filtering is performed on the provided cipher suites and key exchange groups, /// so the caller is responsible for ensuring that the provided algorithms are available at runtime, /// by calling [available_cipher_suites()] and [kx_group::available_groups()]. /// From 3f5f7d04db3d4ee7af89783cbf7c999bf2ae96be Mon Sep 17 00:00:00 2001 From: Tom Fay Date: Fri, 25 Sep 2026 09:25:49 +0100 Subject: [PATCH 3/3] reword --- src/lib.rs | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/src/lib.rs b/src/lib.rs index e70dcb0..f6d3848 100644 --- a/src/lib.rs +++ b/src/lib.rs @@ -76,7 +76,7 @@ //! //! # OpenSSL API Usage //! -//! When targeting OpenSSL 3.0 or later, this crate strictly uses modern, provider APIs (`EVP_*`). +//! When targeting OpenSSL 3.0 or later this crate uses OpenSSL's provider APIs (`EVP_*`). //! Legacy cryptographic interfaces (e.g., direct `HMAC_*` or `RSA_*` functions) are used only when //! targeting OpenSSL 1.1.1. #![warn(missing_docs)] @@ -187,9 +187,9 @@ fn cipher_suite_available(cipher_suite: &SupportedCipherSuite) -> bool { /// The specified cipher suites and key exchange groups should be defined in descending order of preference. /// i.e the first elements have the highest priority during negotiation. /// -/// No runtime filtering is performed on the provided cipher suites and key exchange groups, -/// so the caller is responsible for ensuring that the provided algorithms are available at runtime, -/// by calling [available_cipher_suites()] and [kx_group::available_groups()]. +/// No runtime filtering is performed on the provided cipher suites and key exchange groups +/// so the caller is responsible for ensuring that the provided algorithms are available at runtime. +/// This can be done by using [available_cipher_suites()] and [kx_group::available_groups()]. /// /// /// Sample usage: