Skip to main content

sign_live_response

Function sign_live_response 

Source
pub fn sign_live_response<S, Sig>(
    cert_id_der: &[u8],
    status: LiveCertStatus,
    nonce_bytes: &[u8],
    responder_key_bytes: &[u8],
    signer: &mut S,
    now: u64,
    validity_secs: u64,
    responder_cert_der: Option<&[u8]>,
) -> Result<Vec<u8>>
where S: Signer<Sig> + DynSignatureAlgorithmIdentifier, Sig: SignatureBitStringEncoding,
Expand description

Sign a fresh OCSP response on demand with the client’s nonce embedded.

This is the hot path for nonce_policy = "live". It builds a BasicOCSPResponse containing one SingleResponse for the requested CertID, adds the nonce as a response extension, and signs it.