Skip to content

grpc-bssl: BoringSSL TLS implementation for grpc-rust - #2846

Open
geertj wants to merge 2 commits into
grpc:masterfrom
geertj:grpc-bssl
Open

grpc-bssl: BoringSSL TLS implementation for grpc-rust#2846
geertj wants to merge 2 commits into
grpc:masterfrom
geertj:grpc-bssl

Conversation

@geertj

@geertj geertj commented Sep 1, 2026

Copy link
Copy Markdown

Motivation

Grpc-rust currently supports rustls for transport security. Some environments want to use grpc-rust but standardize on other TLS libraries (such as BoringSSL).

Solution

This implements the ChannelCredentials and ServerCredentails trait for BoringSSL in a new grpc-bssl crate, enabling BoringSSL based transport security with grpc-rust.

Expose internal sealing type (Internal), credentials modules
(client, server, and common), and I/O and runtime adapters under the
__unstable feature flag.

This allows out-of-tree implementations of different TLS stacks through
the ChannelCredentials and ServerCredentials traits.
Add the grpc-bssl crate with client and server TLS credentials
(BsslChannelCredentials and BsslServerCredentials) built on bssl-tls and
bssl-tls-tokio. To let external crates provide custom credentials, this
exposes the internal token, EndpointIoStream, StreamEndpoint, and
default_runtime under the __unstable feature flag in grpc, and makes
credentials modules public. Also add setup-boringssl CI action and workflow
configuration for BoringSSL across Linux, macOS, and Windows.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant