pub struct CustomScriptSigner { /* private fields */ }Expand description
Delegates issuance/revocation to an external script.
Implementations§
Source§impl CustomScriptSigner
impl CustomScriptSigner
Sourcepub fn from_config(cfg: &CustomSignerConfig) -> Result<Self>
pub fn from_config(cfg: &CustomSignerConfig) -> Result<Self>
Validates the configuration and creates the signer.
Trait Implementations§
Source§impl Debug for CustomScriptSigner
impl Debug for CustomScriptSigner
Source§impl SignerBackend for CustomScriptSigner
impl SignerBackend for CustomScriptSigner
Source§fn renewal_info<'life0, 'life1, 'async_trait>(
&'life0 self,
cert_der: &'life1 [u8],
) -> Pin<Box<dyn Future<Output = Result<Option<RenewalWindow>, SignerError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn renewal_info<'life0, 'life1, 'async_trait>(
&'life0 self,
cert_der: &'life1 [u8],
) -> Pin<Box<dyn Future<Output = Result<Option<RenewalWindow>, SignerError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Stdout contract: empty for “no opinion”, <start> <end> as epoch
seconds, or <start> <end> <explanationURL> to also supply RFC 9773
§4.2’s optional explanationURL. The URL is last and optional so an
existing two-token script keeps working unchanged.
Source§fn issue<'life0, 'life1, 'life2, 'life3, 'async_trait>(
&'life0 self,
order_id: &'life1 str,
csr_der: &'life2 [u8],
identifiers: &'life3 [Identifier],
validity: RequestedValidity,
) -> Pin<Box<dyn Future<Output = Result<IssueOutcome, SignerError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
'life2: 'async_trait,
'life3: 'async_trait,
fn issue<'life0, 'life1, 'life2, 'life3, 'async_trait>(
&'life0 self,
order_id: &'life1 str,
csr_der: &'life2 [u8],
identifiers: &'life3 [Identifier],
validity: RequestedValidity,
) -> Pin<Box<dyn Future<Output = Result<IssueOutcome, SignerError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
'life2: 'async_trait,
'life3: 'async_trait,
Issues a leaf certificate for the PKCS#10 CSR in
csr_der.
identifiers are the order’s identifiers, so the backend can check the
CSR requests exactly them. Read moreSource§fn revoke<'life0, 'life1, 'async_trait>(
&'life0 self,
cert_der: &'life1 [u8],
reason: Option<u32>,
) -> Pin<Box<dyn Future<Output = Result<(), SignerError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn revoke<'life0, 'life1, 'async_trait>(
&'life0 self,
cert_der: &'life1 [u8],
reason: Option<u32>,
) -> Pin<Box<dyn Future<Output = Result<(), SignerError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Revokes the certificate
cert_der (RFC 8555 §7.6), with an optional
RFC 5280 §5.3.1 CRLReason code. Must be idempotent: revoking an
already-revoked certificate is not an error. Read moreSource§fn crl_der<'life0, 'async_trait>(
&'life0 self,
) -> Pin<Box<dyn Future<Output = Option<Vec<u8>>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
fn crl_der<'life0, 'async_trait>(
&'life0 self,
) -> Pin<Box<dyn Future<Output = Option<Vec<u8>>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
The backend’s current certificate revocation list (RFC 5280), DER
encoded, if it maintains one servable here.
None means the backend
has no CRL of its own (e.g. a delegating backend whose CRL is only
ever published by the upstream CA it defers to, at a URL of the
upstream’s choosing).Source§fn ca_chain_pem<'life0, 'async_trait>(
&'life0 self,
) -> Pin<Box<dyn Future<Output = Option<String>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
fn ca_chain_pem<'life0, 'async_trait>(
&'life0 self,
) -> Pin<Box<dyn Future<Output = Option<String>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
The certificates a client needs to trust what this backend issues, PEM
encoded, anchor last — served unauthenticated at
GET /ca.pem. Read moreSource§fn jobs(&self) -> Vec<Arc<dyn JobHandler>>
fn jobs(&self) -> Vec<Arc<dyn JobHandler>>
The background work this backend needs a durable queue for. Read more
Source§fn http01_tokens(&self) -> Option<Arc<dyn Http01TokenStore>>
fn http01_tokens(&self) -> Option<Arc<dyn Http01TokenStore>>
The
http-01 token store this backend answers the upstream’s own
challenge from, if it has one. Read moreSource§fn crl_pruner(&self) -> Option<Arc<dyn CrlPruner>>
fn crl_pruner(&self) -> Option<Arc<dyn CrlPruner>>
This backend’s revocation ledger, if it keeps one that grows and can be
swept (RFC 5280 §3.3). Read more
Source§fn carried_state(&self) -> CarriedState
fn carried_state(&self) -> CarriedState
What this backend hands to whichever backend replaces it on a
configuration reload, keyed by the resource each piece describes. Read more
Auto Trait Implementations§
impl Freeze for CustomScriptSigner
impl RefUnwindSafe for CustomScriptSigner
impl Send for CustomScriptSigner
impl Sync for CustomScriptSigner
impl Unpin for CustomScriptSigner
impl UnsafeUnpin for CustomScriptSigner
impl UnwindSafe for CustomScriptSigner
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more