pub struct CaConfig {Show 25 fields
pub label: String,
pub bundle_file: Option<PathBuf>,
pub nonce_policy: String,
pub completeness: String,
pub issuer_name_hash: Option<String>,
pub issuer_key_hash: Option<String>,
pub forward_to: Option<String>,
pub forward_insecure: bool,
pub forward_ca: Option<PathBuf>,
pub source: Option<SourceConfig>,
pub batch_interval: u64,
pub validity_secs: u64,
pub jitter_secs: u64,
pub certid_compat: String,
pub max_age_fraction: f64,
pub archive_cutoff_secs: u64,
pub urgent_revocation: bool,
pub issuer_name_der_b64: Option<String>,
pub issuer_key_bytes_b64: Option<String>,
pub sig_alg: String,
pub signing_key: Option<SigningKeyConfig>,
pub responder_cert: Option<PathBuf>,
pub key_rotation: Option<KeyRotationConfigToml>,
pub seal_key: Option<PathBuf>,
pub seal_cert: Option<PathBuf>,
}Fields§
§label: String§bundle_file: Option<PathBuf>§nonce_policy: String§completeness: String§issuer_name_hash: Option<String>Hex-encoded issuerNameHash for explicit routing. If absent, extracted from the bundle manifest on load.
issuer_key_hash: Option<String>Hex-encoded issuerKeyHash for explicit routing. If absent, extracted from the bundle manifest on load.
forward_to: Option<String>URL to forward nonce-bearing requests to (for nonce_policy = “forward”).
Must be https:// (trusted channel, FTP_ITC.1) unless forward_insecure
is set.
forward_insecure: boolAllow a plaintext http:// forward_to target. Lab/testing only —
hoike check refuses a cleartext forward URL without this escape hatch.
forward_ca: Option<PathBuf>Optional PEM CA bundle for the forward target’s server certificate.
NOTE: per-target custom roots are not yet wired into the forward path.
The shared outbound client validates the forward target against the
system trust store, so this CA must currently be installed system-wide to
take effect; setting it alone does not change validation. hoike check
emits the same caveat. Retained as forward-looking config.
source: Option<SourceConfig>Revocation source (required for combined/signer mode)
batch_interval: u64Batch production interval in seconds (combined/signer mode)
validity_secs: u64OCSP response validity in seconds
jitter_secs: u64Upper bound (seconds) of randomized jitter added to nextUpdate so a
fleet’s responses do not all expire simultaneously (thundering-herd
avoidance). Bounded by the source’s own nextUpdate. Default 7200.
certid_compat: StringCertID hash coverage baked into produced bundles:
"dual" (both SHA-256 and SHA-1, default), "sha256", or "sha1".
max_age_fraction: f64Fraction of a response’s validity window advertised as HTTP
Cache-Control: max-age at the edge. Must be in (0, 1]. Default 0.5.
archive_cutoff_secs: u64Drop entries for certificates that expired more than this many seconds
ago, bounding bundle size. Requires per-certificate notAfter, which
only the 389 DS syncrepl source supplies — a no-op for CRL sources.
0 (default) disables pruning.
urgent_revocation: boolWhen true (default), the signer produces an off-cycle bundle immediately
upon detecting a newly revoked certificate, instead of waiting for the
next batch_interval.
issuer_name_der_b64: Option<String>DER bytes of the issuer DN (for CertID computation in signer mode). Base64-encoded in config, decoded on load.
issuer_key_bytes_b64: Option<String>Raw issuer public key bytes (for CertID computation in signer mode). Base64-encoded in config, decoded on load.
sig_alg: StringSigning algorithm: ecdsa-p256 (default), ml-dsa-44, ml-dsa-65, ml-dsa-87
signing_key: Option<SigningKeyConfig>Signing key configuration (required for signer/combined mode).
responder_cert: Option<PathBuf>Path to the delegated OCSP signing certificate (DER or PEM). Embedded in each OCSPResponse per RFC 9919 §3.2.2 so clients can validate the response without pre-caching the responder cert.
key_rotation: Option<KeyRotationConfigToml>Key rotation monitoring configuration.
seal_key: Option<PathBuf>Path to PKCS#8 PEM/DER key for bundle seal signing. If absent, falls back to the OCSP signing key (with a warning). The seal key SHOULD be different from the OCSP signing key.
seal_cert: Option<PathBuf>Path to the DER/PEM certificate for the seal signer. If absent, generates a self-signed cert (for testing only).