x509_cert/builder/profile.rs
1//! Certificate profiles
2//!
3//! Profiles need implement by the [`BuilderProfile`] trait.
4//! They may then be consumed by a [`builder::CertificateBuilder`].
5//!
6//!
7//! Multiple profiles are provided and you may select one depending on your use-case:
8//! - [`cabf`] implements the Baseline Requirement from the CA Browser Forum as close as it can be
9//! done.
10//! - [`devid`] implements the specification for IEEE 802.1 AR. Certificates for Secure
11//! Device Identity.
12//!
13//! Please follow each sub-module documentation and select a profile that may suit your needs, or
14//! you may implement your own profile, if need be.
15
16#[cfg(doc)]
17use crate::builder;
18
19use crate::{builder::Result, certificate::TbsCertificate, ext::Extension, name::Name};
20use alloc::vec;
21use spki::SubjectPublicKeyInfoRef;
22
23pub mod cabf;
24pub mod devid;
25
26/// Profile for certificates
27///
28/// The profile will define the various extensions to add to a certificate, this may be used to
29/// generate a [`cabf::Root`], or a TLS [`cabf::tls::Subscriber`] certificate.
30///
31/// See [implementors](#implementors) for a full list of existing profiles.
32pub trait BuilderProfile {
33 /// Issuer to be used for issued certificates
34 fn get_issuer(&self, subject: &Name) -> Name;
35
36 /// Subject for the certificate to be used.
37 fn get_subject(&self) -> Name;
38
39 /// X509v3 extensions to be added in the certificates.
40 fn build_extensions(
41 &self,
42 spk: SubjectPublicKeyInfoRef<'_>,
43 issuer_spk: SubjectPublicKeyInfoRef<'_>,
44 tbs: &TbsCertificate,
45 ) -> Result<vec::Vec<Extension>>;
46}