pub fn sign_live_response<S, Sig>(
cert_id_der: &[u8],
status: LiveCertStatus,
nonce_bytes: &[u8],
responder_key_bytes: &[u8],
signer: &mut S,
now: u64,
validity_secs: u64,
responder_cert_der: Option<&[u8]>,
) -> Result<Vec<u8>>where
S: Signer<Sig> + DynSignatureAlgorithmIdentifier,
Sig: SignatureBitStringEncoding,Expand description
Sign a fresh OCSP response on demand with the client’s nonce embedded.
This is the hot path for nonce_policy = "live". It builds a
BasicOCSPResponse containing one SingleResponse for the requested
CertID, adds the nonce as a response extension, and signs it.