x509_cert/crl.rs
1//! Certificate Revocation List types
2
3use crate::{
4 AlgorithmIdentifier, Version,
5 certificate::{Profile, Rfc5280},
6 ext::Extensions,
7 name::Name,
8 serial_number::SerialNumber,
9 time::Time,
10};
11
12use alloc::vec::Vec;
13
14use der::asn1::BitString;
15use der::{Sequence, ValueOrd};
16
17#[cfg(feature = "pem")]
18use der::pem::PemLabel;
19
20/// `CertificateList` as defined in [RFC 5280 Section 5.1].
21///
22/// ```text
23/// CertificateList ::= SEQUENCE {
24/// tbsCertList TBSCertList,
25/// signatureAlgorithm AlgorithmIdentifier,
26/// signatureValue BIT STRING
27/// }
28/// ```
29///
30/// [RFC 5280 Section 5.1]: https://datatracker.ietf.org/doc/html/rfc5280#section-5.1
31#[derive(Clone, Debug, Eq, PartialEq, Sequence, ValueOrd)]
32#[allow(missing_docs)]
33pub struct CertificateList<P: Profile = Rfc5280> {
34 pub tbs_cert_list: TbsCertList<P>,
35 pub signature_algorithm: AlgorithmIdentifier,
36 pub signature: BitString,
37}
38
39#[cfg(feature = "pem")]
40impl<P: Profile> PemLabel for CertificateList<P> {
41 const PEM_LABEL: &'static str = "X509 CRL";
42}
43
44/// Implicit intermediate structure from the ASN.1 definition of `TBSCertList`.
45///
46/// This type is used for the `revoked_certificates` field of `TbsCertList`.
47/// See [RFC 5280 Section 5.1].
48///
49/// ```text
50/// RevokedCert ::= SEQUENCE {
51/// userCertificate CertificateSerialNumber,
52/// revocationDate Time,
53/// crlEntryExtensions Extensions OPTIONAL
54/// }
55/// ```
56///
57/// [RFC 5280 Section 5.1]: https://datatracker.ietf.org/doc/html/rfc5280#section-5.1
58#[derive(Clone, Debug, Eq, PartialEq, Sequence, ValueOrd)]
59#[allow(missing_docs)]
60pub struct RevokedCert<P: Profile = Rfc5280> {
61 pub serial_number: SerialNumber<P>,
62 pub revocation_date: Time,
63 pub crl_entry_extensions: Option<Extensions>,
64}
65
66/// `TbsCertList` as defined in [RFC 5280 Section 5.1].
67///
68/// ```text
69/// TBSCertList ::= SEQUENCE {
70/// version Version OPTIONAL, -- if present, MUST be v2
71/// signature AlgorithmIdentifier,
72/// issuer Name,
73/// thisUpdate Time,
74/// nextUpdate Time OPTIONAL,
75/// revokedCertificates SEQUENCE OF SEQUENCE {
76/// userCertificate CertificateSerialNumber,
77/// revocationDate Time,
78/// crlEntryExtensions Extensions OPTIONAL -- if present, version MUST be v2
79/// } OPTIONAL,
80/// crlExtensions [0] EXPLICIT Extensions OPTIONAL -- if present, version MUST be v2
81/// }
82/// ```
83///
84/// [RFC 5280 Section 5.1]: https://datatracker.ietf.org/doc/html/rfc5280#section-5.1
85#[derive(Clone, Debug, Eq, PartialEq, Sequence, ValueOrd)]
86#[allow(missing_docs)]
87pub struct TbsCertList<P: Profile = Rfc5280> {
88 pub version: Version,
89 pub signature: AlgorithmIdentifier,
90 pub issuer: Name,
91 pub this_update: Time,
92 pub next_update: Option<Time>,
93 pub revoked_certificates: Option<Vec<RevokedCert<P>>>,
94
95 #[asn1(context_specific = "0", tag_mode = "EXPLICIT", optional = "true")]
96 pub crl_extensions: Option<Extensions>,
97}