Skip to main content

CaConfig

Struct CaConfig 

Source
pub struct CaConfig {
Show 25 fields pub label: String, pub bundle_file: Option<PathBuf>, pub nonce_policy: String, pub completeness: String, pub issuer_name_hash: Option<String>, pub issuer_key_hash: Option<String>, pub forward_to: Option<String>, pub forward_insecure: bool, pub forward_ca: Option<PathBuf>, pub source: Option<SourceConfig>, pub batch_interval: u64, pub validity_secs: u64, pub jitter_secs: u64, pub certid_compat: String, pub max_age_fraction: f64, pub archive_cutoff_secs: u64, pub urgent_revocation: bool, pub issuer_name_der_b64: Option<String>, pub issuer_key_bytes_b64: Option<String>, pub sig_alg: String, pub signing_key: Option<SigningKeyConfig>, pub responder_cert: Option<PathBuf>, pub key_rotation: Option<KeyRotationConfigToml>, pub seal_key: Option<PathBuf>, pub seal_cert: Option<PathBuf>,
}

Fields§

§label: String§bundle_file: Option<PathBuf>§nonce_policy: String§completeness: String§issuer_name_hash: Option<String>

Hex-encoded issuerNameHash for explicit routing. If absent, extracted from the bundle manifest on load.

§issuer_key_hash: Option<String>

Hex-encoded issuerKeyHash for explicit routing. If absent, extracted from the bundle manifest on load.

§forward_to: Option<String>

URL to forward nonce-bearing requests to (for nonce_policy = “forward”). Must be https:// (trusted channel, FTP_ITC.1) unless forward_insecure is set.

§forward_insecure: bool

Allow a plaintext http:// forward_to target. Lab/testing only — hoike check refuses a cleartext forward URL without this escape hatch.

§forward_ca: Option<PathBuf>

Optional PEM CA bundle for the forward target’s server certificate.

NOTE: per-target custom roots are not yet wired into the forward path. The shared outbound client validates the forward target against the system trust store, so this CA must currently be installed system-wide to take effect; setting it alone does not change validation. hoike check emits the same caveat. Retained as forward-looking config.

§source: Option<SourceConfig>

Revocation source (required for combined/signer mode)

§batch_interval: u64

Batch production interval in seconds (combined/signer mode)

§validity_secs: u64

OCSP response validity in seconds

§jitter_secs: u64

Upper bound (seconds) of randomized jitter added to nextUpdate so a fleet’s responses do not all expire simultaneously (thundering-herd avoidance). Bounded by the source’s own nextUpdate. Default 7200.

§certid_compat: String

CertID hash coverage baked into produced bundles: "dual" (both SHA-256 and SHA-1, default), "sha256", or "sha1".

§max_age_fraction: f64

Fraction of a response’s validity window advertised as HTTP Cache-Control: max-age at the edge. Must be in (0, 1]. Default 0.5.

§archive_cutoff_secs: u64

Drop entries for certificates that expired more than this many seconds ago, bounding bundle size. Requires per-certificate notAfter, which only the 389 DS syncrepl source supplies — a no-op for CRL sources. 0 (default) disables pruning.

§urgent_revocation: bool

When true (default), the signer produces an off-cycle bundle immediately upon detecting a newly revoked certificate, instead of waiting for the next batch_interval.

§issuer_name_der_b64: Option<String>

DER bytes of the issuer DN (for CertID computation in signer mode). Base64-encoded in config, decoded on load.

§issuer_key_bytes_b64: Option<String>

Raw issuer public key bytes (for CertID computation in signer mode). Base64-encoded in config, decoded on load.

§sig_alg: String

Signing algorithm: ecdsa-p256 (default), ml-dsa-44, ml-dsa-65, ml-dsa-87

§signing_key: Option<SigningKeyConfig>

Signing key configuration (required for signer/combined mode).

§responder_cert: Option<PathBuf>

Path to the delegated OCSP signing certificate (DER or PEM). Embedded in each OCSPResponse per RFC 9919 §3.2.2 so clients can validate the response without pre-caching the responder cert.

§key_rotation: Option<KeyRotationConfigToml>

Key rotation monitoring configuration.

§seal_key: Option<PathBuf>

Path to PKCS#8 PEM/DER key for bundle seal signing. If absent, falls back to the OCSP signing key (with a warning). The seal key SHOULD be different from the OCSP signing key.

§seal_cert: Option<PathBuf>

Path to the DER/PEM certificate for the seal signer. If absent, generates a self-signed cert (for testing only).

Implementations§

Source§

impl CaConfig

Source

pub fn is_ml_dsa(&self) -> bool

Returns true if the configured sig_alg is an ML-DSA variant.

Trait Implementations§

Source§

impl Clone for CaConfig

Source§

fn clone(&self) -> CaConfig

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for CaConfig

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for CaConfig

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,