1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
//! JSON Web Signature, as RFC 8555 §6.2 uses it: the wire types ([`AcmeJwsRequest`],
//! [`ProtectedHeader`], [`Jwk`]) and, in [`signature`], the cryptography —
//! including the DER-SPKI encoding by hand and the rule that the verification
//! algorithm is never chosen from the client's `alg` alone.
//!
//! Free of any HTTP type: the axum extractors that run it on every request are
//! `extractors`, and the two nested-JWS surfaces ([`crate::eab`],
//! [`crate::key_change`]) and the relay's upstream client verify and sign with it
//! too.
use ;
/// Represents a JSON Web Signature (JWS) request structure used in ACME protocol.
/// Represents the JWK (JSON Web Key) structure used in ACME JWS headers.
/// Represents the protected header of an ACME JWS request.
///
/// Deliberately *not* `deny_unknown_fields`: RFC 8555 §6.2 enumerates the
/// fields it expects, but silently ignoring an extra member costs nothing and
/// refusing one would reject clients over a harmless addition. `crit` is the
/// exception — see the field below.