Skip to main content

Module orchestrate

Module orchestrate 

Source
Expand description

Bundle-production orchestration shared by the CLI signer loop and the admin signing API.

This module turns a (Config, CaConfig, RevocationSource) into signed, CMS-sealed bundle bytes — handling revocation snapshotting, anti-rollback epoch derivation, signing-key source dispatch (ECDSA / ML-DSA × file / demo / PKCS#11), seal materials, and responder-cert loading.

It deliberately contains no interactive I/O: PKCS#11 PINs are resolved only from config or the environment, never a terminal prompt. The CLI keeps its own interactive PIN path for the one-shot hoike sign subcommand.

Structs§

SignedScope
Outcome of signing one CA scope.

Constants§

COMBINED_PRODUCER_ID
Producer ID stamped into combined-mode bundles.

Functions§

create_persistent_sources
Build the persistent revocation sources for a config. Only stateful sources (DogtagSync) are created here; stateless sources (CRL) are resolved fresh at signing time.
decode_issuer_key
Decode the issuer public-key bytes for a CA, falling back to a synthetic key.
decode_issuer_name
Decode the issuer DN (DER) for a CA, falling back to a synthetic CN=<label>.
load_responder_cert
Load and normalize a responder certificate to DER, if configured.
load_seal_materials
Load the seal key and certificate for CMS bundle sealing.
revoked_serials_for_scope
Snapshot a CA scope and return the set of currently-revoked serials, without signing or writing anything. Used by the signer loop’s urgent-revocation detector to diff against the previously-known revoked set between scheduled passes. Reuses the shared persistent source so a syncrepl cookie is not reset.
sign_and_write_all
Sign every configured CA that has a revocation source, writing each .ahu. CAs without a source are skipped. Returns the list of signed scopes.
sign_and_write_scope
Sign one CA scope by label, resolving its source, and write the resulting .ahu to the configured bundle directory. Used by the on-demand admin API.
sign_ca_scope
Produce a signed bundle for one CA scope from an already-resolved revocation source. Pure with respect to the filesystem for the bundle (does not write the .ahu); it does read the state store to derive the epoch.
write_bundle
Write bundle bytes to {bundle_dir}/{label}.ahu, creating the directory if needed. Returns the written path.
write_bundle_atomic
Durable replacement: readers see either complete old or complete new bytes.

Type Aliases§

PersistentSources
Map of CA label → persistent revocation source. Stateful sources (DogtagSync) retain their in-memory snapshot and sync cookie across signer passes and must be shared, not rebuilt, between the background loop and on-demand signing.