code wiki / (root) / nx_acme_directory_live_real_ca_test.nx

nx_acme_directory_live_real_ca_test.nx

buildroot/runtime/nx_acme_directory_live_real_ca_test.nx

9215 B244 linesdepth 21pulls 128 transitivereach 0 importersview sourcekind gate/prooftopic acme
docsdependenciesstructsconstsfunctions

about

nx_acme_directory_live_real_ca_test.nx -- L11 step 2d. Live HTTPS GET against Let's Encrypt PRODUCTION /directory using the already-shipped modular pipeline (url_for_fetch -> url_connect -> tls13_client_session_run -> https_get_complete -> response_parse + dechunk) and the real Mozilla trust store. Production rather than staging: LE STAGING certs chain to the "(STAGING) Pretend Pear X1" root which is NOT in Mozilla's public trust store -- by design. Hitting production /directory is safe (GET, no order placed, no rate-limit consumption) AND validates the real ISRG Root X1 chain that Mozilla anchors. What this proves: - DNS resolves acme-v02.api.letsencrypt.org - TCP connects to LE production - TLS 1.3 handshake completes - LE's cert chain validates against our shipped Mozilla store (ISRG Root X1 is one of the 167 anchors loaded earlier) - HTTP/1.1 GET succeeds, response parses, body dechunks - JSON body contains the expected ACME endpoint keys What this does NOT prove: - any POST against LE (that's step 2e -- needs JOSE-signed body via nx_https_post_complete shipped in step 2c) - staging cert chain support (separate task: add the staging trust anchor or implement a staging trust mode) expect_exit: 0 license_tier: ORIGINAL

dependencies 10 imports · 0 importers

nx_syscalls.nx nx_x509_trust_store.nx nx_trust_store_load_from_certdata. nx_tls13_client_validate_certifica nx_tls13_client_session_run.nx nx_https_url_for_fetch.nx nx_https_url_connect.nx nx_https_get.nx nx_https_get_complete.nx nx_http_response_parse.nx nx_acme_directory_live_real_ca

imports: nx_syscalls.nxnx_x509_trust_store.nxnx_trust_store_load_from_certdata.nxnx_tls13_client_validate_certificate.nxnx_tls13_client_session_run.nxnx_https_url_for_fetch.nxnx_https_url_connect.nxnx_https_get.nxnx_https_get_complete.nxnx_http_response_parse.nx

imported by: nobody (leaf or entry point)

call flow from main pre-order; caps 40 nodes / depth 6 declared; ↻ = already shown

main sys_mmap nx_trust_store_load_from_c sys_mmap ↻ sys_read_file sys_openat_rd sys_lseek sys_mmap ↻ sys_read sys_close nx_nss_certdata_parse sys_mmap ↻ _pat_class_cert _pat_value_octal _pat_end _find_newline _starts_with _parse_octal_line sys_mmap ↻ _is_space _decode_octal_escape _is_octal trust_store_alloc sys_mmap ↻ nx_x509_trust_store_load sys_mmap ↻ x509_parse sys_mmap ↻ asn1_cursor_init asn1_expect_tag sys_mmap ↻ asn1_read_tlv_header asn1_read_tag asn1_read_length asn1_read_length ↻ x509_read_tlv sys_mmap ↻ asn1_expect_tag ↻ x509_read_alg_id sys_mmap ↻

structs

none

consts

none

functions

43func dump_dec(label0: i64, label1: i64, v: i64) -> i64
called by 1: main calls 2: sys_mmapsys_write
78func _contains(haystack: *u8, h: i64, needle: *u8, n: i64) -> i64
called by 1: main
95func main() -> i64