Skip to main content

Commands

Enum Commands 

Source
pub(crate) enum Commands {
    Serve {
        config: PathBuf,
    },
    Check {
        config: PathBuf,
    },
    Sign {
Show 15 fields ca: String, crl: PathBuf, output: PathBuf, issuer: Option<PathBuf>, epoch: u64, certid_compat: String, good_serials: Option<PathBuf>, sig_alg: String, issuer_name_b64: Option<String>, issuer_key_b64: Option<String>, signing_key: Option<PathBuf>, seal_key: Option<PathBuf>, dual_alg: Option<String>, pq_signing_key: Option<PathBuf>, demo_key: bool,
}, Query { url: String, serial: String, issuer_name_b64: String, issuer_key_b64: String, prefer: Option<String>, }, Import { bundle: PathBuf, config: PathBuf, force: bool, }, }

Variants§

§

Serve

Start the OCSP responder

Fields

§config: PathBuf

Config file path

§

Check

Validate configuration, bundle, and connectivity

Fields

§config: PathBuf

Config file path

§

Sign

Produce a signed ahu bundle from a revocation source

Fields

§ca: String

CA label

§crl: PathBuf

CRL file to ingest (DER or PEM)

§output: PathBuf

Output bundle path

§issuer: Option<PathBuf>

Issuer certificate (DER) for CertID computation

§epoch: u64

Epoch number for this generation

§certid_compat: String

CertID compatibility mode

§good_serials: Option<PathBuf>

Include known-good serials from a file (one hex serial per line)

§sig_alg: String

Signing algorithm: ecdsa-p256 (default), ml-dsa-44, ml-dsa-65, ml-dsa-87

§issuer_name_b64: Option<String>

Base64-encoded DER issuer name (for correct CertID hashes)

§issuer_key_b64: Option<String>

Base64-encoded issuer public key bytes (for correct CertID hashes)

§signing_key: Option<PathBuf>

Path to PKCS#8 PEM or DER signing key file

§seal_key: Option<PathBuf>

Path to PKCS#8 PEM or DER P-256 seal key file (separate from signing key)

§dual_alg: Option<String>

Produce a dual-algorithm bundle: –sig-alg is the classical algorithm, –dual-alg is the post-quantum algorithm (e.g. ml-dsa-87)

§pq_signing_key: Option<PathBuf>

Path to PKCS#8 PEM or DER PQ signing key file (for –dual-alg)

§demo_key: bool

Use an ephemeral demo key (NOT FOR PRODUCTION)

§

Query

Query a running OCSP responder with optional algorithm preference

Fields

§url: String

Responder URL (e.g. http://localhost:2560)

§serial: String

Hex-encoded serial number

§issuer_name_b64: String

Base64-encoded DER issuer name

§issuer_key_b64: String

Base64-encoded issuer public key bytes

§prefer: Option<String>

Preferred signature algorithms (comma-separated, e.g. “ml-dsa-87,ecdsa-p256”)

§

Import

Import a bundle into the responder’s bundle directory (for enclave/air-gap deployments)

Fields

§bundle: PathBuf

Path to the .ahu bundle to import

§config: PathBuf

Config file (to determine bundle_dir)

§force: bool

Skip anti-rollback check (for first import into a fresh enclave)

Trait Implementations§

Source§

impl FromArgMatches for Commands

Source§

fn from_arg_matches(__clap_arg_matches: &ArgMatches) -> Result<Self, Error>

Instantiate Self from [ArgMatches], parsing the arguments as needed. Read more
Source§

fn from_arg_matches_mut( __clap_arg_matches: &mut ArgMatches, ) -> Result<Self, Error>

Instantiate Self from [ArgMatches], parsing the arguments as needed. Read more
Source§

fn update_from_arg_matches( &mut self, __clap_arg_matches: &ArgMatches, ) -> Result<(), Error>

Assign values from ArgMatches to self.
Source§

fn update_from_arg_matches_mut<'b>( &mut self, __clap_arg_matches: &mut ArgMatches, ) -> Result<(), Error>

Assign values from ArgMatches to self.
Source§

impl Subcommand for Commands

Source§

fn augment_subcommands<'b>(__clap_app: Command) -> Command

Append to [Command] so it can instantiate Self via [FromArgMatches::from_arg_matches_mut] Read more
Source§

fn augment_subcommands_for_update<'b>(__clap_app: Command) -> Command

Append to [Command] so it can instantiate self via [FromArgMatches::update_from_arg_matches_mut] Read more
Source§

fn has_subcommand(__clap_name: &str) -> bool

Test whether Self can parse a specific subcommand

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

§

impl<T> PolicyExt for T
where T: ?Sized,

§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns [Action::Follow] only if self and other return Action::Follow. Read more
§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns [Action::Follow] if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

§

fn vzip(self) -> V

§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<A, B, T> HttpServerConnExec<A, B> for T
where B: Body,

§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,