Skip to main content

Module seal

Module seal 

Source
Expand description

CMS SignedData seal creation for ahu bundles.

Creates a detached CMS SignedData (RFC 5652) over the manifest bytes. The seal proves that a specific producer assembled the bundle; it does not make the OCSP responses more trustworthy (their own signatures do that).

Uses the der 0.8 ecosystem (via cms crate), separate from the OCSP-side der 0.7 types. The p256 signing key bridges between them.

Enums§

SealKey
Algorithm-agnostic seal signing key.

Functions§

create_cms_seal
Create a detached CMS SignedData seal over the manifest bytes.
generate_seal_cert
Generate a self-signed seal certificate for testing/demo use.
generate_seal_cert_for_key
Generate a self-signed seal certificate for any SealKey type.