Skip to main content

Module cert_chain

Module cert_chain 

Source
Expand description

Direct-dial dual-trust (Slice 7c Direction B) — X.509 cert chain.

Managed realms root trust in the realm CA, not in the (keyless) realm tag. A provider embeds its own service-cert chain (leaf ++ org CA, PEM) in its procedure_advertisement; a verifying consumer chains it to the realm CA it received at its own issuance. No publisher records, no live authority — the trust material already travels with the advertisement.

Ported from macula_record.erl’s verify_advertisement_cert_chain/3 (and its cert_chain_step_*/pem_cert_ders/cert_subject_pubkey/ validate_path/cert_org helpers, in src/record/macula_record.erl) — same algorithm, using rustls-webpki’s native path validation instead of hand-rolling pkix_path_validation, and x509-parser (already used by crate::cert for the unrelated TLS pubkey-pinning tier) for field extraction. Cross-checked against macula-go’s own port (dht/cert_chain.go), which uses crypto/x509’s native path validation the same way. Opt-in: this has no effect on plain (non-cert-chain) direct-dial, which remains exactly as it was.

Not the same trust tier as crate::cert. That module verifies a TLS pubkey pin for dialing a KNOWN station — no CA chain, no org semantics, the pubkey IS the identity. This module verifies a resolved advertisement’s embedded X.509 chain proves its signer belongs to a specific org, authorized by a realm CA the caller already trusts — a higher, separate, opt-in tier that only matters once direct-dial itself exists.

Enums§

CertChainError
Mirrors macula_record.erl’s six cert_chain_step_* failure atoms (advertisement_bad_signature, no_cert_chain, cert_chain_undecodable, cert_key_mismatch, cert_chain_untrusted/{bad_cert, _}, cert_org_mismatch) as distinguishable variants (test with matches!/==) — never silently treat an unauthorized advertisement as trusted.

Functions§

verify_advertisement_cert_chain
Verifies a resolved procedure_advertisement record’s embedded X.509 service-cert chain against a trusted realm CA, for Slice 7c Direction B managed-realm authorization.