Nethermind.Libp2p.Protocols.AutoTls 1.0.3

dotnet add package Nethermind.Libp2p.Protocols.AutoTls --version 1.0.3
                    
NuGet\Install-Package Nethermind.Libp2p.Protocols.AutoTls -Version 1.0.3
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Nethermind.Libp2p.Protocols.AutoTls" Version="1.0.3" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Nethermind.Libp2p.Protocols.AutoTls" Version="1.0.3" />
                    
Directory.Packages.props
<PackageReference Include="Nethermind.Libp2p.Protocols.AutoTls" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Nethermind.Libp2p.Protocols.AutoTls --version 1.0.3
                    
#r "nuget: Nethermind.Libp2p.Protocols.AutoTls, 1.0.3"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Nethermind.Libp2p.Protocols.AutoTls@1.0.3
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Nethermind.Libp2p.Protocols.AutoTls&version=1.0.3
                    
Install as a Cake Addin
#tool nuget:?package=Nethermind.Libp2p.Protocols.AutoTls&version=1.0.3
                    
Install as a Cake Tool

AutoTLS

Automatic browser-trusted TLS certificates for libp2p nodes, via the p2p-forge registration broker and Let's Encrypt.

What this is (and isn't)

The libp2p TLS protocol (/tls/1.0.0, see Libp2p.Protocols.Tls) already encrypts every connection with self-signed, identity-derived certificates. That is not what AutoTLS replaces.

AutoTLS exists so a non-browser libp2p node can obtain a publicly-trusted wildcard certificate for *.<base36 PeerID CID>.libp2p.direct. With such a certificate, browsers can open Secure WebSocket (WSS) connections directly to your node, which the in-browser TLS stack would otherwise reject.

This module produces and renews the certificate. Libp2p.Protocols.WebSockets can consume ITlsCertificateProvider for /wss listeners.

Usage

using Microsoft.Extensions.DependencyInjection;
using Nethermind.Libp2p.Protocols.AutoTls;

services
    .AddLibp2p(builder => builder.WithWebSockets())
    .AddAutoTls(opts =>
    {
        opts.ContactEmail = "you@example.com";
        opts.AcmeDirectoryUrl = AutoTlsOptions.StagingAcmeDirectoryUrl; // for testing
    });

// After your peer starts listening:
var provider = serviceProvider.GetRequiredService<ITlsCertificateProvider>();
provider.Configure(localPeer.Identity, localPeer.ListenAddresses.ToArray());

provider.CertificateChanged += cert =>
{
    // The WSS listener picks up renewed certificates from ITlsCertificateProvider.
};

Behavior

  • On startup, a stored certificate (if any) is loaded from CertificateStorePath (default: <AppContext.BaseDirectory>/autotls).
  • If no stored cert, or its remaining validity is less than RenewBefore (default 30 days), an issuance is started: ACME order, DNS-01 challenge, broker submission, validation, finalize, save.
  • After issuance the manager sleeps until the next renewal window.
  • Failures back off exponentially up to MaxRetryDelay (default 1 hour).

Caveats

  • Public reachability is required. The p2p-forge broker probes the multiaddrs you supply before publishing the DNS-01 TXT record. Issuance will fail on unreachable nodes. There is no automatic reachability gate yet — only call Configure once you know the node is reachable.
  • Let's Encrypt rate limits apply (~50 certs / week / registered domain). The on-disk store prevents re-issuance churn across restarts; do not delete it casually.
  • HTTP peer-id auth is implemented to spec but unverified against a live broker in this PR. Test against staging (AutoTlsOptions.StagingAcmeDirectoryUrl) before pointing at production.
  • WSS requires a public WebSocket listen address. Configure the provider after the peer is listening on the addresses that the broker can probe.

References

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (1)

Showing the top 1 NuGet packages that depend on Nethermind.Libp2p.Protocols.AutoTls:

Package Downloads
Nethermind.Libp2p.Protocols.WebSockets

A libp2p implementation for .NET

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.0.3 0 10/6/2026
1.0.2 50 10/3/2026
1.0.1 55 10/2/2026
1.0.0 61 10/1/2026