Expand description
On-demand OCSP response signing with a client-supplied nonce.
Used by nonce_policy = "live" on signer/combined nodes. The signer
already has the certificate’s status (from the loaded bundle) and the
signing key — it re-signs a fresh response with the nonce embedded,
without round-tripping to the CA.
Structs§
- Live
Response Source - Status and authenticated freshness from exactly one matching SingleResponse.
- Live
Signing Material - Validated software-key material, shared by startup and rotation.
Enums§
- Live
Cert Status - Certificate status for live signing.
Functions§
- extract_
status_ for_ cert - extract_
status_ from_ response - Diagnostic compatibility API. Batched sources require explicit CertID selection.
- load_
live_ material - sign_
live_ response - Sign a fresh OCSP response on demand with the client’s nonce embedded.
- sign_
live_ response_ with_ window - Sign only within the authenticated source window; producedAt is signing time, thisUpdate remains the time the source actually established the status.