Skip to main content
This is unreleased documentation for the main (development) branch of crypto-glue.

x509_cert/builder/
profile.rs

1//! Certificate profiles
2//!
3//! Profiles need implement by the [`BuilderProfile`] trait.
4//! They may then be consumed by a [`builder::CertificateBuilder`].
5//!
6//!
7//! Multiple profiles are provided and you may select one depending on your use-case:
8//!  - [`cabf`] implements the Baseline Requirement from the CA Browser Forum as close as it can be
9//!    done.
10//!  - [`devid`] implements the specification for IEEE 802.1 AR. Certificates for Secure
11//!    Device Identity.
12//!
13//! Please follow each sub-module documentation and select a profile that may suit your needs, or
14//! you may implement your own profile, if need be.
15
16#[cfg(doc)]
17use crate::builder;
18
19use crate::{builder::Result, certificate::TbsCertificate, ext::Extension, name::Name};
20use alloc::vec;
21use spki::SubjectPublicKeyInfoRef;
22
23pub mod cabf;
24pub mod devid;
25
26/// Profile for certificates
27///
28/// The profile will define the various extensions to add to a certificate, this may be used to
29/// generate a [`cabf::Root`], or a TLS [`cabf::tls::Subscriber`] certificate.
30///
31/// See [implementors](#implementors) for a full list of existing profiles.
32pub trait BuilderProfile {
33    /// Issuer to be used for issued certificates
34    fn get_issuer(&self, subject: &Name) -> Name;
35
36    /// Subject for the certificate to be used.
37    fn get_subject(&self) -> Name;
38
39    /// X509v3 extensions to be added in the certificates.
40    fn build_extensions(
41        &self,
42        spk: SubjectPublicKeyInfoRef<'_>,
43        issuer_spk: SubjectPublicKeyInfoRef<'_>,
44        tbs: &TbsCertificate,
45    ) -> Result<vec::Vec<Extension>>;
46}