Skip to main content

Module live

Module live 

Source
Expand description

On-demand OCSP response signing with a client-supplied nonce.

Used by nonce_policy = "live" on signer/combined nodes. The signer already has the certificate’s status (from the loaded bundle) and the signing key — it re-signs a fresh response with the nonce embedded, without round-tripping to the CA.

Structs§

LiveResponseSource
Status and authenticated freshness from exactly one matching SingleResponse.
LiveSigningMaterial
Validated software-key material, shared by startup and rotation.

Enums§

LiveCertStatus
Certificate status for live signing.

Functions§

extract_status_for_cert
extract_status_from_response
Diagnostic compatibility API. Batched sources require explicit CertID selection.
load_live_material
sign_live_response
Sign a fresh OCSP response on demand with the client’s nonce embedded.
sign_live_response_with_window
Sign only within the authenticated source window; producedAt is signing time, thisUpdate remains the time the source actually established the status.