Async TLS for the Tokio runtime
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-05-04 20:01:31 +02:00
examples chore: sync dependencies (monorepo) 2026-03-25 17:28:58 +01:00
src chore: sync dependencies (monorepo) 2026-03-31 00:04:46 +02:00
tests chore: sync dependencies (monorepo) 2026-04-01 19:28:00 +02:00
.gitignore Clarify how to run the example server 2025-04-09 19:52:52 +02:00
Cargo.lock chore: sync dependencies (monorepo) 2026-04-06 15:17:26 +02:00
Cargo.toml Fix conflicting rustls-ring dependencies 2026-05-04 20:01:31 +02:00
LICENSE-APACHE Move tokio-rustls to top level 2023-05-31 17:09:52 +02:00
LICENSE-MIT Move tokio-rustls to top level 2023-05-31 17:09:52 +02:00
README.md Clarify how to run the example server 2025-04-09 19:52:52 +02:00

tokio-rustls

github actions crates license license docs.rs

Asynchronous TLS/SSL streams for Tokio using Rustls.

Basic Structure of a Client

use rustls_pki_types::ServerName;
use std::sync::Arc;
use tokio::net::TcpStream;
use tokio_rustls::rustls::{ClientConfig, RootCertStore};
use tokio_rustls::TlsConnector;

// ...

let mut root_cert_store = RootCertStore::empty();
root_cert_store.extend(webpki_roots::TLS_SERVER_ROOTS.iter().cloned());
let config = ClientConfig::builder()
    .with_root_certificates(root_cert_store)
    .with_no_client_auth();
let connector = TlsConnector::from(Arc::new(config));
let dnsname = ServerName::try_from("www.rust-lang.org").unwrap();

let stream = TcpStream::connect(&addr).await?;
let mut stream = connector.connect(dnsname, stream).await?;

// ...

Client Example Program

See examples/client.rs. You can run it with:

cargo run --example client -- hsts.badssl.com

Server Example Program

See examples/server.rs. You can run it with:

cargo run --example server -- 127.0.0.1:8000 --cert certs/cert.pem --key certs/cert.key.pem

If you don't have a certificate and key, you can generate a random key and self-signed certificate for testing with:

cargo install --locked rustls-cert-gen
rustls-cert-gen --output certs/ --san localhost

License & Origin

This project is licensed under either of

at your option.

This started as a fork of tokio-tls.

Contribution

Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in tokio-rustls by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.