Expand description
Challenge validation as queued work.
POST /chall/{id} claims a challenge and enqueues one of these rows; the job
runner performs the outbound check. Validation reaches out to an address the
client named — over DNS, HTTP or TLS, to a host that may simply not answer
— so running it inside the request held an admission permit for the length of
challenge.timeout_ms and coupled that budget to
server.request_timeout_ms. RFC 8555 §7.1.6 already has the state this
needs: a challenge “transitions to the processing state when the client
responds to the challenge”, and §8.2 pairs that with a Retry-After.
One handler over every profile, the SignerRevokeJob shape: a row names
its challenge, the challenge walks up to its order, and the order names the
profile whose validators and notifier decide it. The registry refuses a
second handler for one kind, so one per profile could not be registered
anyway.
Structs§
- Challenge
Validate Job - Performs a claimed challenge validation and records its answer.
Constants§
- CHALLENGE_
VALIDATE_ KIND - The
jobs.kindone challenge validation is queued under.
Functions§
- challenge_
validate_ spec - The row asking a worker to validate the challenge
claim_challengejust claimed.