pub enum CertChainError {
BadSignature,
Absent,
Undecodable,
KeyMismatch,
Untrusted,
OrgMismatch,
}Expand description
Mirrors macula_record.erl’s six cert_chain_step_* failure atoms
(advertisement_bad_signature, no_cert_chain, cert_chain_undecodable,
cert_key_mismatch, cert_chain_untrusted/{bad_cert, _},
cert_org_mismatch) as distinguishable variants (test with
matches!/==) — never silently treat an unauthorized advertisement as
trusted.
Variants§
BadSignature
The advertisement’s own Ed25519 envelope signature does not verify —
checked BEFORE the cert chain is even examined, since nothing in an
unverified record can be trusted. Also covers the (practically
unreachable once the envelope verifies) case of a structurally
malformed procedure_advertisement payload — macula_record.erl
itself has no distinct atom for that case either, since it can’t
occur without the signer having signed garbage in the first place.
Absent
cert_chain is absent — the common, unmanaged-realm case. Not
itself a sign of tampering; callers that require managed-realm
authorization should treat this as “not authorized,” not as
evidence of an attack.
Undecodable
cert_chain is present but not a decodable PEM bundle containing at
least one certificate.
KeyMismatch
The leaf certificate’s Ed25519 subject public key does not match the advertisement’s own signing key — the chain does not actually belong to whoever signed this record.
Untrusted
The chain does not validate to the given realm CA (expired, wrong issuer, broken path, etc.).
OrgMismatch
The chain validates, but the leaf certificate’s Organization (O) does not match the procedure’s expected org segment — a validly-signed cert for the WRONG org, i.e. a squat.
Trait Implementations§
Source§impl Debug for CertChainError
impl Debug for CertChainError
Source§impl Display for CertChainError
impl Display for CertChainError
impl Eq for CertChainError
Source§impl Error for CertChainError
impl Error for CertChainError
1.30.0 · Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()