nx_acme_directory_live_real_ca_test.nx
buildroot/runtime/nx_acme_directory_live_real_ca_test.nx
about
nx_acme_directory_live_real_ca_test.nx -- L11 step 2d.
Live HTTPS GET against Let's Encrypt PRODUCTION /directory using the
already-shipped modular pipeline (url_for_fetch -> url_connect ->
tls13_client_session_run -> https_get_complete -> response_parse +
dechunk) and the real Mozilla trust store.
Production rather than staging: LE STAGING certs chain to the
"(STAGING) Pretend Pear X1" root which is NOT in Mozilla's public
trust store -- by design. Hitting production /directory is safe
(GET, no order placed, no rate-limit consumption) AND validates the
real ISRG Root X1 chain that Mozilla anchors.
What this proves:
- DNS resolves acme-v02.api.letsencrypt.org
- TCP connects to LE production
- TLS 1.3 handshake completes
- LE's cert chain validates against our shipped Mozilla store
(ISRG Root X1 is one of the 167 anchors loaded earlier)
- HTTP/1.1 GET succeeds, response parses, body dechunks
- JSON body contains the expected ACME endpoint keys
What this does NOT prove:
- any POST against LE (that's step 2e -- needs JOSE-signed body
via nx_https_post_complete shipped in step 2c)
- staging cert chain support (separate task: add the staging
trust anchor or implement a staging trust mode)
expect_exit: 0
license_tier: ORIGINAL
dependencies 10 imports · 0 importers
imports: nx_syscalls.nxnx_x509_trust_store.nxnx_trust_store_load_from_certdata.nxnx_tls13_client_validate_certificate.nxnx_tls13_client_session_run.nxnx_https_url_for_fetch.nxnx_https_url_connect.nxnx_https_get.nxnx_https_get_complete.nxnx_http_response_parse.nx
imported by: nobody (leaf or entry point)
call flow from main pre-order; caps 40 nodes / depth 6 declared; ↻ = already shown
structs
| none |
consts
| none |
functions
| 43 | func dump_dec(label0: i64, label1: i64, v: i64) -> i64 |
| 78 | func _contains(haystack: *u8, h: i64, needle: *u8, n: i64) -> i64 called by 1: main |
| 95 | func main() -> i64 |