Skip to main content
This is unreleased documentation for the main (development) branch of crypto-glue.

TbsCertificateInner

Struct TbsCertificateInner 

Source
pub struct TbsCertificateInner<P: Profile = Rfc5280> { /* private fields */ }
Expand description

X.509 TbsCertificate as defined in RFC 5280 Section 4.1

ASN.1 structure containing the names of the subject and issuer, a public key associated with the subject, a validity period, and other associated information.

TBSCertificate  ::=  SEQUENCE  {
    version         [0]  EXPLICIT Version DEFAULT v1,
    serialNumber         CertificateSerialNumber,
    signature            AlgorithmIdentifier,
    issuer               Name,
    validity             Validity,
    subject              Name,
    subjectPublicKeyInfo SubjectPublicKeyInfo,
    issuerUniqueID  [1]  IMPLICIT UniqueIdentifier OPTIONAL,
                         -- If present, version MUST be v2 or v3
    subjectUniqueID [2]  IMPLICIT UniqueIdentifier OPTIONAL,
                         -- If present, version MUST be v2 or v3
    extensions      [3]  Extensions OPTIONAL
                         -- If present, version MUST be v3 --
}

Implementations§

Source§

impl<P: Profile> TbsCertificateInner<P>

Source

pub fn version(&self) -> Version

Version of this certificate (v1/v2/v3).

Source

pub fn serial_number(&self) -> &SerialNumber<P>

Serial number of this certificate.

X.509 serial numbers are used to uniquely identify certificates issued by a given Certificate Authority (CA) identified in the issuer field.

Source

pub fn signature(&self) -> &AlgorithmIdentifier

Identifies the signature algorithm that this TBSCertificate should be signed with.

In a signed certificate, matches CertificateInner::signature_algorithm.

Source

pub fn issuer(&self) -> &Name

Certificate issuer: Name of the Certificate Authority (CA) which issued this certificate.

Source

pub fn validity(&self) -> &Validity<P>

Validity period for this certificate: time range in which a certificate is considered valid, after which it expires.

Source

pub fn subject(&self) -> &Name

Subject of this certificate: entity that the certificate is intended to represent or authenticate, e.g. an individual, a device, or an organization.

Source

pub fn subject_public_key_info(&self) -> &SubjectPublicKeyInfo

Subject Public Key Info (SPKI): public key information about this certificate including algorithm identifier and key data.

Source

pub fn issuer_unique_id(&self) -> &Option<BitString>

Issuer unique ID: unique identifier representing the issuing CA, as defined by the issuing CA.

(NOTE: added in X.509 v2)

Source

pub fn subject_unique_id(&self) -> &Option<BitString>

Subject unique ID: unique identifier representing the certificate subject, as defined by the issuing CA.

(NOTE: added in X.509 v2)

Source

pub fn extensions(&self) -> Option<&Extensions>

Certificate extensions.

Additional fields in a digital certificate that provide extra information beyond the standard fields. These extensions enhance the functionality and flexibility of certificates, allowing them to convey more specific details about the certificate’s usage and constraints.

(NOTE: added in X.509 v3)

Source

pub fn get_extension<'a, T: Decode<'a> + AssociatedOid>( &'a self, ) -> Result<Option<(bool, T)>, <T as Decode<'a>>::Error>

Decodes a single extension.

Returns Ok(None) if the extension is not present.

Otherwise, returns the extension, and indicates if the extension was marked critical in the boolean.

use x509_cert::{der::DecodePem, ext::pkix::BasicConstraints, Certificate};
let certificate = Certificate::from_pem(CERT_PEM.as_bytes()).expect("parse certificate");

let (critical, constraints) = certificate.tbs_certificate().get_extension::<BasicConstraints>()
    .expect("Failed to parse extension")
    .expect("Basic constraints expected");
§Errors

Returns an error if multiple of these extensions are present.

Returns a decoding error if decoding failed.

Source

pub fn filter_extensions<'a, T: Decode<'a> + AssociatedOid>( &'a self, ) -> impl 'a + Iterator<Item = Result<(bool, T), <T as Decode<'a>>::Error>>

Filters extensions by an associated OID

Returns a filtered iterator over all the extensions with the OID.

use x509_cert::{der::DecodePem, ext::pkix::BasicConstraints, Certificate};
let certificate = Certificate::from_pem(CERT_PEM.as_bytes()).expect("parse certificate");

let mut extensions_found = certificate.tbs_certificate().filter_extensions::<BasicConstraints>();
while let Some(Ok((critical, extension))) = extensions_found.next() {
    println!("Found (critical={critical}): {extension:?}");
}
§Safety

According to RFC 5290 section 4.2, extensions should not appear more than once. A better alternative is to use TbsCertificateInner::get_extension instead.

Trait Implementations§

Source§

impl<P: Clone + Profile> Clone for TbsCertificateInner<P>

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl<P: Debug + Profile> Debug for TbsCertificateInner<P>

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'__der_lifetime, P: Profile> DecodeValue<'__der_lifetime> for TbsCertificateInner<P>

Source§

type Error = Error

Type returned in the event of a decoding error.
Source§

fn decode_value<R: Reader<'__der_lifetime>>( reader: &mut R, header: Header, ) -> Result<Self, Error>

Attempt to decode this value using the provided Reader. Read more
Source§

impl<P: Profile> EncodeValue for TbsCertificateInner<P>

Source§

fn value_len(&self) -> Result<Length>

Compute the length of this value (sans [Tag]+Length header) when encoded as ASN.1 DER. Read more
Source§

fn encode_value(&self, writer: &mut impl Writer) -> Result<()>

Encode value (sans [Tag]+Length header) as ASN.1 DER using the provided Writer. Read more
Source§

fn header(&self) -> Result<Header, Error>
where Self: Tagged,

Get the Header used to encode this value. Read more
Source§

impl<P: Eq + Profile> Eq for TbsCertificateInner<P>

Source§

impl<P: PartialEq + Profile> PartialEq for TbsCertificateInner<P>

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl<'__der_lifetime, P: Profile> Sequence<'__der_lifetime> for TbsCertificateInner<P>

Source§

impl<P: PartialEq + Profile> StructuralPartialEq for TbsCertificateInner<P>

Source§

impl<P: Profile> ValueOrd for TbsCertificateInner<P>

Source§

fn value_cmp(&self, other: &Self) -> Result<Ordering>

Return an Ordering between value portion of TLV-encoded self and other when serialized as ASN.1 DER. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<'a, T> Choice<'a> for T
where T: Decode<'a> + FixedTag,

Source§

fn can_decode(tag: Tag) -> bool

Is the provided Tag decodable as a variant of this CHOICE?
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<'a, T> Decode<'a> for T
where T: DecodeValue<'a> + FixedTag + 'a,

Source§

type Error = <T as DecodeValue<'a>>::Error

Type returned in the event of a decoding error.
Source§

fn decode<R>(reader: &mut R) -> Result<T, <T as DecodeValue<'a>>::Error>
where R: Reader<'a>,

Attempt to decode this TLV message using the provided decoder. Read more
Source§

fn from_der(bytes: &'a [u8]) -> Result<Self, Self::Error>

Parse Self from the provided DER-encoded byte slice. Read more
Source§

fn from_der_partial(bytes: &'a [u8]) -> Result<(Self, &'a [u8]), Self::Error>

Parse Self from the provided DER-encoded byte slice. Read more
Source§

impl<T> DecodeOwned for T
where T: for<'a> Decode<'a>,

Source§

impl<T> DerOrd for T

Source§

fn der_cmp(&self, other: &T) -> Result<Ordering, Error>

Return an Ordering between self and other when serialized as ASN.1 DER. Read more
Source§

impl<T> Encode for T
where T: EncodeValue + Tagged + ?Sized,

Source§

fn encoded_len(&self) -> Result<Length, Error>

Compute the length of this TLV object in bytes when encoded as ASN.1 DER. Read more
Source§

fn encode(&self, writer: &mut impl Writer) -> Result<(), Error>

Encode this TLV object as ASN.1 DER using the provided Writer. Read more
Source§

fn encode_to_slice<'a>(&self, buf: &'a mut [u8]) -> Result<&'a [u8], Error>

Encode this TLV object to the provided byte slice, returning a sub-slice containing the encoded message. Read more
Source§

fn encode_to_vec(&self, buf: &mut Vec<u8>) -> Result<Length, Error>

Encode this TLV object as ASN.1 DER, appending it to the provided byte vector. Read more
Source§

fn to_der(&self) -> Result<Vec<u8>, Error>

Encode this TLV object as ASN.1 DER, returning a byte vector. Read more
Source§

impl<'a, S> FixedTag for S
where S: Sequence<'a>,

Source§

const TAG: Tag = Tag::Sequence

ASN.1 tag
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IsConstructed for T
where T: FixedTag + ?Sized,

Source§

const CONSTRUCTED: bool

ASN.1 constructed bit
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> Tagged for T
where T: FixedTag + ?Sized,

Source§

fn tag(&self) -> Tag

Get the ASN.1 tag that this type is encoded with.
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.