This sample code is designed to demonstrate how reqwest behaves with and without the rustls-tls-native-roots feature when attempting to connect to an HTTPS server that uses a custom Certificate Authority (CA) trusted at the operating system level. Custom root CAs are common in strict corporate network environments, both for private internal CAs or for outbound "man-in-the-middle" secure internet gateways such as Zscaler or Cloudflare Warp.
- Rust and Cargo installed (see rustup.rs)
- (Optional but recommended for full testing) An HTTPS server endpoint that is:
- Signed by a custom CA.
- The custom CA certificate must be installed and trusted in your operating system's native certificate store.
src/main.rs: Contains the Rust code that usesreqwestto fetch a URL.Cargo.toml: The project manifest. You will modify this file to switch betweenreqwest's TLS features.
-
Clone this repository (if you haven't already):
# git clone <repository-url> # cd repro-custom-ca
-
Modify
src/main.rs(Optional but Recommended for Real Test): Opensrc/main.rsand change theurl_to_fetchvariable to point to your HTTPS server that uses a custom CA.// src/main.rs let url_to_fetch = "https://your-custom-ca-protected-server.example.com/";
If you don't have such a server, you can use the default
https://self-signed.badssl.com/or any public URL, but the specific CA issue won't be directly observable without a custom CA setup. -
Configure
reqwestfeatures inCargo.toml:-
Scenario 1: Simulating the issue (without native roots) Edit
Cargo.tomlto use only therustls-tlsfeature:# Cargo.toml [dependencies] tokio = { version = "1", features = ["full"] } reqwest = { version = "0.11", features = ["rustls-tls"], default-features = false } # Comment out or remove other reqwest lines
-
Scenario 2: Simulating the fix (with native roots) Edit
Cargo.tomlto use therustls-tls-native-rootsfeature:# Cargo.toml [dependencies] tokio = { version = "1", features = ["full"] } reqwest = { version = "0.11", features = ["rustls-tls-native-roots"], default-features = false } # Comment out or remove other reqwest lines
-
-
Build and Run: In your terminal, from the
repro-custom-cadirectory, run:cargo run
-
Scenario 1 (with
rustls-tlsonly): Ifurl_to_fetchpoints to a server protected by a custom CA (that is trusted by your OS but not inwebpki-roots), the program is expected to fail with a certificate validation error. This is becauserustlsby default doesn't check the OS native certificate store. -
Scenario 2 (with
rustls-tls-native-roots): Ifurl_to_fetchpoints to the same server, the program is expected to succeed. Therustls-tls-native-rootsfeature enablesreqwest(viarustls) to load CAs from the OS native certificate store, thus trusting your custom CA.
This sample helps illustrate why the rustls-tls-native-roots feature is important for applications like Next.js/Turbopack that need to operate correctly in diverse network environments, including those with custom CAs (e.g., corporate proxies or internal services).