Expand description
Bundle-production orchestration shared by the CLI signer loop and the admin signing API.
This module turns a (Config, CaConfig, RevocationSource) into signed,
CMS-sealed bundle bytes — handling revocation snapshotting, anti-rollback
epoch derivation, signing-key source dispatch (ECDSA / ML-DSA × file / demo /
PKCS#11), seal materials, and responder-cert loading.
It deliberately contains no interactive I/O: PKCS#11 PINs are resolved only
from config or the environment, never a terminal prompt. The CLI keeps its
own interactive PIN path for the one-shot hoike sign subcommand.
Structs§
- Signed
Scope - Outcome of signing one CA scope.
Constants§
- COMBINED_
PRODUCER_ ID - Producer ID stamped into combined-mode bundles.
Functions§
- create_
persistent_ sources - Build the persistent revocation sources for a config. Only stateful sources (DogtagSync) are created here; stateless sources (CRL) are resolved fresh at signing time.
- decode_
issuer_ key - Decode the issuer public-key bytes for a CA, falling back to a synthetic key.
- decode_
issuer_ name - Decode the issuer DN (DER) for a CA, falling back to a synthetic
CN=<label>. - load_
responder_ cert - Load and normalize a responder certificate to DER, if configured.
- load_
seal_ materials - Load the seal key and certificate for CMS bundle sealing.
- revoked_
serials_ for_ scope - Snapshot a CA scope and return the set of currently-revoked serials, without signing or writing anything. Used by the signer loop’s urgent-revocation detector to diff against the previously-known revoked set between scheduled passes. Reuses the shared persistent source so a syncrepl cookie is not reset.
- sign_
and_ write_ all - Sign every configured CA that has a revocation source, writing each
.ahu. CAs without a source are skipped. Returns the list of signed scopes. - sign_
and_ write_ scope - Sign one CA scope by label, resolving its source, and write the resulting
.ahuto the configured bundle directory. Used by the on-demand admin API. - sign_
ca_ scope - Produce a signed bundle for one CA scope from an already-resolved revocation
source. Pure with respect to the filesystem for the bundle (does not write
the
.ahu); it does read the state store to derive the epoch. - write_
bundle - Write bundle bytes to
{bundle_dir}/{label}.ahu, creating the directory if needed. Returns the written path. - write_
bundle_ atomic - Durable replacement: readers see either complete old or complete new bytes.
Type Aliases§
- Persistent
Sources - Map of CA label → persistent revocation source. Stateful sources (DogtagSync) retain their in-memory snapshot and sync cookie across signer passes and must be shared, not rebuilt, between the background loop and on-demand signing.