# TLS fixtures Certificates are generated **in process** by `TlsFixture`, not checked in. A committed private key is a private key that leaks, and design §21.2 forbids key material in the repository. `TlsFixture` produces, from a throwaway CA created per test run: | Fixture | Purpose | |---|---| | `TlsFixture.trusted()` | a server certificate valid for the loopback host | | `TlsFixture.hostnameMismatch()` | a certificate whose SAN does not match the connection host | | `TlsFixture.expired()` | an already-expired certificate | | `clientHandshake(true)` | client key material for the mTLS lane | All three failure cases must classify as permanent (design §21.3) — never retried, never downgraded to plaintext.