Skip to main content
This is unreleased documentation for the main (development) branch of crypto-glue.

x509_cert/
crl.rs

1//! Certificate Revocation List types
2
3use crate::{
4    AlgorithmIdentifier, Version,
5    certificate::{Profile, Rfc5280},
6    ext::Extensions,
7    name::Name,
8    serial_number::SerialNumber,
9    time::Time,
10};
11
12use alloc::vec::Vec;
13
14use der::asn1::BitString;
15use der::{Sequence, ValueOrd};
16
17#[cfg(feature = "pem")]
18use der::pem::PemLabel;
19
20/// `CertificateList` as defined in [RFC 5280 Section 5.1].
21///
22/// ```text
23/// CertificateList  ::=  SEQUENCE  {
24///     tbsCertList          TBSCertList,
25///     signatureAlgorithm   AlgorithmIdentifier,
26///     signatureValue       BIT STRING
27/// }
28/// ```
29///
30/// [RFC 5280 Section 5.1]: https://datatracker.ietf.org/doc/html/rfc5280#section-5.1
31#[derive(Clone, Debug, Eq, PartialEq, Sequence, ValueOrd)]
32#[allow(missing_docs)]
33pub struct CertificateList<P: Profile = Rfc5280> {
34    pub tbs_cert_list: TbsCertList<P>,
35    pub signature_algorithm: AlgorithmIdentifier,
36    pub signature: BitString,
37}
38
39#[cfg(feature = "pem")]
40impl<P: Profile> PemLabel for CertificateList<P> {
41    const PEM_LABEL: &'static str = "X509 CRL";
42}
43
44/// Implicit intermediate structure from the ASN.1 definition of `TBSCertList`.
45///
46/// This type is used for the `revoked_certificates` field of `TbsCertList`.
47/// See [RFC 5280 Section 5.1].
48///
49/// ```text
50/// RevokedCert ::= SEQUENCE {
51///     userCertificate         CertificateSerialNumber,
52///     revocationDate          Time,
53///     crlEntryExtensions      Extensions OPTIONAL
54/// }
55/// ```
56///
57/// [RFC 5280 Section 5.1]: https://datatracker.ietf.org/doc/html/rfc5280#section-5.1
58#[derive(Clone, Debug, Eq, PartialEq, Sequence, ValueOrd)]
59#[allow(missing_docs)]
60pub struct RevokedCert<P: Profile = Rfc5280> {
61    pub serial_number: SerialNumber<P>,
62    pub revocation_date: Time,
63    pub crl_entry_extensions: Option<Extensions>,
64}
65
66/// `TbsCertList` as defined in [RFC 5280 Section 5.1].
67///
68/// ```text
69/// TBSCertList  ::=  SEQUENCE  {
70///      version                 Version OPTIONAL, -- if present, MUST be v2
71///      signature               AlgorithmIdentifier,
72///      issuer                  Name,
73///      thisUpdate              Time,
74///      nextUpdate              Time OPTIONAL,
75///      revokedCertificates     SEQUENCE OF SEQUENCE  {
76///           userCertificate         CertificateSerialNumber,
77///           revocationDate          Time,
78///           crlEntryExtensions      Extensions OPTIONAL -- if present, version MUST be v2
79///      }  OPTIONAL,
80///      crlExtensions           [0]  EXPLICIT Extensions OPTIONAL -- if present, version MUST be v2
81/// }
82/// ```
83///
84/// [RFC 5280 Section 5.1]: https://datatracker.ietf.org/doc/html/rfc5280#section-5.1
85#[derive(Clone, Debug, Eq, PartialEq, Sequence, ValueOrd)]
86#[allow(missing_docs)]
87pub struct TbsCertList<P: Profile = Rfc5280> {
88    pub version: Version,
89    pub signature: AlgorithmIdentifier,
90    pub issuer: Name,
91    pub this_update: Time,
92    pub next_update: Option<Time>,
93    pub revoked_certificates: Option<Vec<RevokedCert<P>>>,
94
95    #[asn1(context_specific = "0", tag_mode = "EXPLICIT", optional = "true")]
96    pub crl_extensions: Option<Extensions>,
97}