pub struct TbsCertificateInner<P: Profile = Rfc5280> { /* private fields */ }Expand description
X.509 TbsCertificate as defined in RFC 5280 Section 4.1
ASN.1 structure containing the names of the subject and issuer, a public key associated with the subject, a validity period, and other associated information.
TBSCertificate ::= SEQUENCE {
version [0] EXPLICIT Version DEFAULT v1,
serialNumber CertificateSerialNumber,
signature AlgorithmIdentifier,
issuer Name,
validity Validity,
subject Name,
subjectPublicKeyInfo SubjectPublicKeyInfo,
issuerUniqueID [1] IMPLICIT UniqueIdentifier OPTIONAL,
-- If present, version MUST be v2 or v3
subjectUniqueID [2] IMPLICIT UniqueIdentifier OPTIONAL,
-- If present, version MUST be v2 or v3
extensions [3] Extensions OPTIONAL
-- If present, version MUST be v3 --
}Implementations§
Source§impl<P: Profile> TbsCertificateInner<P>
impl<P: Profile> TbsCertificateInner<P>
Sourcepub fn serial_number(&self) -> &SerialNumber<P>
pub fn serial_number(&self) -> &SerialNumber<P>
Serial number of this certificate.
X.509 serial numbers are used to uniquely identify certificates issued by a given
Certificate Authority (CA) identified in the issuer field.
Sourcepub fn signature(&self) -> &AlgorithmIdentifier
pub fn signature(&self) -> &AlgorithmIdentifier
Identifies the signature algorithm that this TBSCertificate should be signed with.
In a signed certificate, matches CertificateInner::signature_algorithm.
Sourcepub fn issuer(&self) -> &Name
pub fn issuer(&self) -> &Name
Certificate issuer: Name of the Certificate Authority (CA) which issued this
certificate.
Sourcepub fn validity(&self) -> &Validity<P>
pub fn validity(&self) -> &Validity<P>
Validity period for this certificate: time range in which a certificate is considered valid, after which it expires.
Sourcepub fn subject(&self) -> &Name
pub fn subject(&self) -> &Name
Subject of this certificate: entity that the certificate is intended to represent or authenticate, e.g. an individual, a device, or an organization.
Sourcepub fn subject_public_key_info(&self) -> &SubjectPublicKeyInfo
pub fn subject_public_key_info(&self) -> &SubjectPublicKeyInfo
Subject Public Key Info (SPKI): public key information about this certificate including algorithm identifier and key data.
Sourcepub fn issuer_unique_id(&self) -> &Option<BitString>
pub fn issuer_unique_id(&self) -> &Option<BitString>
Issuer unique ID: unique identifier representing the issuing CA, as defined by the issuing CA.
(NOTE: added in X.509 v2)
Sourcepub fn subject_unique_id(&self) -> &Option<BitString>
pub fn subject_unique_id(&self) -> &Option<BitString>
Subject unique ID: unique identifier representing the certificate subject, as defined by the issuing CA.
(NOTE: added in X.509 v2)
Sourcepub fn extensions(&self) -> Option<&Extensions>
pub fn extensions(&self) -> Option<&Extensions>
Certificate extensions.
Additional fields in a digital certificate that provide extra information beyond the standard fields. These extensions enhance the functionality and flexibility of certificates, allowing them to convey more specific details about the certificate’s usage and constraints.
(NOTE: added in X.509 v3)
Sourcepub fn get_extension<'a, T: Decode<'a> + AssociatedOid>(
&'a self,
) -> Result<Option<(bool, T)>, <T as Decode<'a>>::Error>
pub fn get_extension<'a, T: Decode<'a> + AssociatedOid>( &'a self, ) -> Result<Option<(bool, T)>, <T as Decode<'a>>::Error>
Decodes a single extension.
Returns Ok(None) if the extension is not present.
Otherwise, returns the extension, and indicates if the extension was marked critical in the boolean.
use x509_cert::{der::DecodePem, ext::pkix::BasicConstraints, Certificate};
let certificate = Certificate::from_pem(CERT_PEM.as_bytes()).expect("parse certificate");
let (critical, constraints) = certificate.tbs_certificate().get_extension::<BasicConstraints>()
.expect("Failed to parse extension")
.expect("Basic constraints expected");§Errors
Returns an error if multiple of these extensions are present.
Returns a decoding error if decoding failed.
Sourcepub fn filter_extensions<'a, T: Decode<'a> + AssociatedOid>(
&'a self,
) -> impl 'a + Iterator<Item = Result<(bool, T), <T as Decode<'a>>::Error>>
pub fn filter_extensions<'a, T: Decode<'a> + AssociatedOid>( &'a self, ) -> impl 'a + Iterator<Item = Result<(bool, T), <T as Decode<'a>>::Error>>
Filters extensions by an associated OID
Returns a filtered iterator over all the extensions with the OID.
use x509_cert::{der::DecodePem, ext::pkix::BasicConstraints, Certificate};
let certificate = Certificate::from_pem(CERT_PEM.as_bytes()).expect("parse certificate");
let mut extensions_found = certificate.tbs_certificate().filter_extensions::<BasicConstraints>();
while let Some(Ok((critical, extension))) = extensions_found.next() {
println!("Found (critical={critical}): {extension:?}");
}§Safety
According to RFC 5290 section 4.2, extensions should not appear more than once.
A better alternative is to use TbsCertificateInner::get_extension instead.