1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
//! [`TrustServiceHistory`] — what a trust service's status was at a past moment.
use ;
use ;
use TrustServiceStatus;
/// One status, and the moment it took effect.
///
/// TS 119 612 clause 5.5.5 ("Current status starting date and time") for the
/// present status, and clause 5.6 ("Service history instance") for each previous
/// one.
/// The status of one trust service over time.
///
/// # Why this is not a single current status
///
/// **The question the law asks is in the past tense.** Regulation (EU)
/// No 910/2014 Art. 40 applies Art. 32 *mutatis mutandis* to seals, and
/// Art. 32(1)(b) asks whether the qualified certificate *"was issued by a
/// qualified trust service provider and was valid **at the time of signing**"*.
/// Not now. At the time of sealing.
///
/// The difference is the whole point of this type, and it is the easy mistake to
/// make, because "is this provider on the trusted list?" is the question a person
/// naturally asks and it has an answer that looks right. Consider a passport
/// sealed in 2027 by a provider whose qualified status was withdrawn in 2029:
///
/// - asking *"is it granted?"* in 2030 answers **no**, and reports a sound seal
/// as unqualified;
/// - asking *"was it granted in 2027?"* answers **yes**, which is what
/// Art. 32(1)(b) requires.
///
/// The reverse error is worse. A provider granted in 2029 was not qualified in
/// 2027, and a present-tense check would certify a seal that never was.
///
/// Trusted lists are built for this. TS 119 612 clause 5.3.12 requires the
/// retention period for historical information to be `65535`, which the standard
/// defines as retained indefinitely, and clause 5.5.1 note adds that historical
/// information "shall be retained even if the service's present status would not
/// normally" require it. The history is there precisely so that a past question
/// can be answered.