hoike_core/response.rs
1//! Static DER-encoded OCSP error responses.
2//!
3//! These are constant byte arrays because error responses contain only
4//! a responseStatus ENUMERATED and no responseBytes — they never change
5//! and never need signing.
6//!
7//! ```asn1
8//! OCSPResponse ::= SEQUENCE {
9//! responseStatus OCSPResponseStatus, -- ENUMERATED
10//! responseBytes [0] EXPLICIT ResponseBytes OPTIONAL
11//! }
12//! ```
13
14/// responseStatus = unauthorized (6)
15/// Used when the responder has no entry for the requested CertID.
16/// RFC 9919 §3.2.3: a mirror that misses a lookup MUST answer unauthorized.
17pub const UNAUTHORIZED: &[u8] = &[0x30, 0x03, 0x0A, 0x01, 0x06];
18
19/// responseStatus = malformedRequest (1)
20/// Used when the request cannot be parsed or violates profile rules.
21pub const MALFORMED_REQUEST: &[u8] = &[0x30, 0x03, 0x0A, 0x01, 0x01];
22
23/// responseStatus = internalError (2)
24pub const INTERNAL_ERROR: &[u8] = &[0x30, 0x03, 0x0A, 0x01, 0x02];
25
26/// responseStatus = tryLater (3)
27pub const TRY_LATER: &[u8] = &[0x30, 0x03, 0x0A, 0x01, 0x03];
28
29/// Content-Type for all OCSP responses (success and error alike).
30pub const CONTENT_TYPE_OCSP_RESPONSE: &str = "application/ocsp-response";
31
32/// Content-Type expected on POST requests.
33pub const CONTENT_TYPE_OCSP_REQUEST: &str = "application/ocsp-request";