Skip to main content
This is unreleased documentation for the main (development) branch of crypto-glue.

x509_cert/ext/pkix/
crl.rs

1//! PKIX Certificate Revocation List extensions
2
3pub mod dp;
4
5use const_oid::db::rfc5280::{
6    ID_CE_CRL_DISTRIBUTION_POINTS, ID_CE_CRL_NUMBER, ID_CE_CRL_REASONS, ID_CE_DELTA_CRL_INDICATOR,
7    ID_CE_FRESHEST_CRL,
8};
9use const_oid::{AssociatedOid, ObjectIdentifier};
10pub use dp::IssuingDistributionPoint;
11
12use alloc::vec::Vec;
13
14use der::{Enumerated, asn1::Uint};
15
16/// CrlNumber as defined in [RFC 5280 Section 5.2.3].
17///
18/// ```text
19/// CRLNumber ::= INTEGER (0..MAX)
20/// ```
21///
22/// [RFC 5280 Section 5.2.3]: https://datatracker.ietf.org/doc/html/rfc5280#section-5.2.3
23#[derive(Clone, Debug, PartialEq, Eq)]
24pub struct CrlNumber(pub Uint);
25
26impl AssociatedOid for CrlNumber {
27    const OID: ObjectIdentifier = ID_CE_CRL_NUMBER;
28}
29
30impl_newtype!(CrlNumber, Uint);
31impl_extension!(CrlNumber, critical = false);
32
33macro_rules! impl_from_traits {
34    ($($uint:ty),+) => {
35        $(
36            impl TryFrom<$uint> for CrlNumber {
37                type Error = der::Error;
38
39                fn try_from(value: $uint) -> der::Result<Self> {
40                    Uint::try_from(value).map(Self)
41                }
42            }
43        )+
44    }
45}
46
47impl_from_traits!(u8, u16, u32, u64, u128);
48
49/// BaseCRLNumber as defined in [RFC 5280 Section 5.2.4].
50///
51/// ```text
52/// BaseCRLNumber ::= CRLNumber
53/// ```
54///
55/// [RFC 5280 Section 5.2.4]: https://datatracker.ietf.org/doc/html/rfc5280#section-5.2.4
56#[derive(Clone, Debug, PartialEq, Eq)]
57pub struct BaseCrlNumber(pub Uint);
58
59impl AssociatedOid for BaseCrlNumber {
60    const OID: ObjectIdentifier = ID_CE_DELTA_CRL_INDICATOR;
61}
62
63impl_newtype!(BaseCrlNumber, Uint);
64impl_extension!(BaseCrlNumber, critical = true);
65
66/// CrlDistributionPoints as defined in [RFC 5280 Section 4.2.1.13].
67///
68/// ```text
69/// CRLDistributionPoints ::= SEQUENCE SIZE (1..MAX) OF DistributionPoint
70/// ```
71///
72/// [RFC 5280 Section 4.2.1.13]: https://datatracker.ietf.org/doc/html/rfc5280#section-4.2.1.13
73#[derive(Clone, Debug, Default, PartialEq, Eq)]
74pub struct CrlDistributionPoints(pub Vec<dp::DistributionPoint>);
75
76impl AssociatedOid for CrlDistributionPoints {
77    const OID: ObjectIdentifier = ID_CE_CRL_DISTRIBUTION_POINTS;
78}
79
80impl_newtype!(CrlDistributionPoints, Vec<dp::DistributionPoint>);
81impl_extension!(CrlDistributionPoints, critical = false);
82
83/// FreshestCrl as defined in [RFC 5280 Section 5.2.6].
84///
85/// ```text
86/// FreshestCRL ::= CRLDistributionPoints
87/// ```
88///
89/// [RFC 5280 Section 5.2.6]: https://datatracker.ietf.org/doc/html/rfc5280#section-5.2.6
90#[derive(Clone, Debug, Default, PartialEq, Eq)]
91pub struct FreshestCrl(pub Vec<dp::DistributionPoint>);
92
93impl AssociatedOid for FreshestCrl {
94    const OID: ObjectIdentifier = ID_CE_FRESHEST_CRL;
95}
96
97impl_newtype!(FreshestCrl, Vec<dp::DistributionPoint>);
98impl_extension!(FreshestCrl, critical = false);
99
100/// CRLReason as defined in [RFC 5280 Section 5.3.1].
101///
102/// ```text
103/// CRLReason ::= ENUMERATED {
104///     unspecified             (0),
105///     keyCompromise           (1),
106///     cACompromise            (2),
107///     affiliationChanged      (3),
108///     superseded              (4),
109///     cessationOfOperation    (5),
110///     certificateHold         (6),
111///     removeFromCRL           (8),
112///     privilegeWithdrawn      (9),
113///     aACompromise           (10)
114/// }
115/// ```
116///
117/// [RFC 5280 Section 5.3.1]: https://datatracker.ietf.org/doc/html/rfc5280#section-5.3.1
118#[derive(Copy, Clone, Debug, Eq, PartialEq, Enumerated, Ord, PartialOrd)]
119#[allow(missing_docs)]
120#[repr(u32)]
121pub enum CrlReason {
122    Unspecified = 0,
123    KeyCompromise = 1,
124    CaCompromise = 2,
125    AffiliationChanged = 3,
126    Superseded = 4,
127    CessationOfOperation = 5,
128    CertificateHold = 6,
129    RemoveFromCRL = 8,
130    PrivilegeWithdrawn = 9,
131    AaCompromise = 10,
132}
133
134impl AssociatedOid for CrlReason {
135    const OID: ObjectIdentifier = ID_CE_CRL_REASONS;
136}
137
138impl_extension!(CrlReason, critical = false);