Skip to content

Opt-in auto-import of the host OS trust store into the extra-CA set (rustls-native-certs) #290

Description

@Lupus

What

Follow-up to #283, which ships the explicit host-only <data>/trust/extra/ directory only. If demand appears: an opt-in setting that additionally imports the host OS trust store (rustls-native-certs) into the same extra-CA set — both the guest bundle and izbad's upstream verifier — through the existing single loader so the two consumers can never disagree.

Why

Corporate machines often have the corporate root installed in the OS store already; auto-import would remove the copy step. Deliberately NOT default and NOT part of #283: the explicit directory is deterministic, reviewable, cross-platform, and never widens trust by surprise (the PM recommendation on #283).

In Scope

  • A host-only setting (e.g. <data>/trust/settings.json import_os_store: true, default false).
  • When enabled, OS roots are appended after the explicit files in the same ExtraCaFile list (same validation, same private-key refusal, same re-serialization to the guest).
  • izba daemon status shows the count of OS-imported roots separately.

Out of Scope

  • Per-sandbox CA sets; mTLS / client certs.

Acceptance Criteria

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions