Expand description
§x509-info
Owned X.509 certificate data for applications, bindings and reports. Read DER and PEM certificates, then emit text, JSON, JSON Lines, YAML, TOML, CBOR, MessagePack, DER or PEM output. Parse into names, algorithms, public-key components and decoded extensions, including FIDO identifiers. Unknown fields retain their original encodings and diagnostics.
The library performs no I/O, reads no clock, and verifies no signatures, trust chains or attestation policy. Callers own all inputs, results and OID overrides.
§Why this crate?
| Library | Focus |
|---|---|
x509-parser | Borrowed certificate types and low-level parsing; used internally |
x509-cert | RustCrypto ASN.1 structures and certificate construction; nested decoders reused here |
x509-certificate-printer | Formatted certificate text |
This crate: x509-info | Owned application data, field diagnostics, versioned reports and generated schemas |
See the ecosystem comparison for alternatives and dependency choices.
§Library
Requires Rust 1.85+.
[dependencies]
x509-info = { version = "0.1", features = ["serde"] }
serde_json = "1"fn main() -> Result<(), Box<dyn std::error::Error>> {
let pem = std::fs::read("certificate.pem")?;
let cert = x509_info::parse_pem(&pem, Default::default())?;
println!("{:#?}", cert.summary());
Ok(())
}Inputs are limited to one certificate and 1 MiB by default; use ParseOptions to
change the byte limit. The full result retains original bytes; summary() creates
an owned view without large raw buffers. Public-key and name details() accessors
provide additional decoded fields.
| Feature | Adds |
|---|---|
| Default | Parsing and owned Rust results |
serde | Serialization of library results |
schema | Schemars schemas for the library’s Serde model |
cli | Binary, format serializers and CLI report schemas |
Use cargo doc --all-features --no-deps --open for API documentation and
cargo run --example binding_dto for a binding example.
§CLI
cargo install x509-info --features cli --locked
x509-info certificate.pem
x509-info certificate.pem --format json --summary
x509-info certificate.pem --format yaml -o report.yaml
x509-info certificate.pem --format der -o certificate.der
x509-info --schema -o report.schema.json
x509-info --schema --summary -o summary.schema.jsonFormats: text, JSON, JSON Lines, YAML, TOML, CBOR, MessagePack, DER and PEM.
Omit the input path or use - for stdin. Textual reports use Base64 for raw blocks,
hex for numerical components and fingerprints, and UUID strings for AAGUIDs.
CBOR and MessagePack use native byte strings. DER/PEM conversion preserves the DER.
CLI usage · Report schemas and format contracts
§Layout and development
lib/ Parsing and models; names/, keys/ and extensions/ submodules
bin/ CLI, report formatting and schema generation
examples/ Binding DTO example
tests/ Integration tests and synthetic certificate fixturescargo fmt --all --check
cargo test --locked
cargo test --all-features --locked
cargo clippy --all-targets --all-features --locked -- -D warningsLicensed under Apache-2.0. Owned X.509 certificate inspection, independent of applets and transport.
This extracts the reusable DER/PEM inspection responsibility from Console’s
Rust api/crypto.rs. It uses the same x509-parser dependency, with owned
typed results and bounded, strict single-certificate inputs. This crate is
licensed under Apache-2.0.
Parsing is not signature verification, chain building, trust, revocation, or
application policy. No system clock or randomness is read. The caller supplies
a timestamp to Validity::contains if it wants a validity-period check.
Unknown algorithm/extension OIDs and their encoded data remain available.
CertificateInfo::summary provides owned application details, common decoded
extensions and a SHA-256 fingerprint without raw certificate/key/signature copies.
Enable serde for the versioned CertificateSummary serialization contract.
Full-result serialization remains available for diagnostics (raw bytes are octet
arrays). JSON belongs to callers; FRB can map these fields to its own DTOs.
No public result borrows backend types or requires a registry/handle lifecycle.
Enable schema for Schemars schemas of the library’s Serde result types.
These describe source representations. The optional CLI’s --schema command
additionally accounts for report field names, Base64 and UUID formatting.
See Ecosystem and dependency choices for comparisons with other X.509 libraries.
§Example
use x509_info::{parse_pem, ParseOptions};
let info = parse_pem(pem, ParseOptions::default())?;
assert_eq!(info.public_key.key_size_bits, Some(256));
assert_eq!(info.public_key.algorithm.oid, "1.2.840.10045.2.1");
let details = info.summary();
drop(info);
let subject = details.subject; // Owned independently of parser input/results.
assert!(subject.display.contains("libcanokey test certificate"));§Ecosystem and dependency choices
x509-info is an owned, transport-free projection for applications and reports.
It reuses established parsers and keeps unknown or malformed values with typed
diagnostics. It does not verify signatures, trust chains, identities or policy.
§Comparisons
| Project | Best fit | Why use x509-info instead |
|---|---|---|
| x509-parser | Borrowed parsing and low-level inspection | Owned results, stable summaries, diagnostics and report schemas |
| x509-cert | RustCrypto ASN.1 models, encoding and construction | Application-facing projection and CLI formats |
| x509-certificate | High-level owned certificates and crypto operations | Narrow inspection layer without I/O, clocks or verification |
| picky-asn1-x509 | Picky ASN.1 structures with Serde | Certificate reading and a versioned report contract |
| x509-certificate-printer | Human-readable certificate text | Library data for bindings plus text and machine-readable output |
| cert-dump | Scanning stores and producing inventory JSON | One certificate at a time, with no filesystem, database or scanner |
These projects overlap in certificate decoding or presentation, but their data
ownership, validation scope and output contracts differ. rcgen is for creating
certificates, while rustls-pki-types supplies shared PKI byte/time types; they
are complementary rather than replacements.
§Primary sources
Structs§
- Access
Description - An AIA/SIA access method and its location. This library never retrieves it.
- Algorithm
Info - Algorithm information with an optional common label and preserved parameters.
- Algorithm
Summary - Algorithm description without raw parameter bytes; see AlgorithmInfo for full data.
- Authority
KeyIdentifier - Authority key identifier components, as asserted by the certificate. Matching these fields does not establish an issuer relationship or trust.
- Certificate
Info - Owned certificate inspection result; no input lifetime or device state.
- Certificate
Policy - One asserted certificate policy; OID recognition never implies policy compliance.
- Certificate
Summary - Owned certificate details for UI/FFI and optional Serde export.
- Certificate
Template - Microsoft certificate-template fields without enrollment/template policy.
- Decode
Diagnostic - Caller-owned field decoding diagnostic; not a certificate validation error.
- Directory
Attribute - A subject directory attribute with its multi-valued ASN.1 SET preserved.
- Distinguished
Name - Owned distinguished name, retaining RDN grouping, repeated attributes and order.
- Distribution
Point - A CRL/freshest-CRL distribution point, without revocation processing or I/O.
- Extension
Info - An extension and its decoded information, retained in certificate order.
- Extension
Summary - Extension summary without raw extnValue bytes; unsupported values remain explicit.
- Fido
Transports - FIDO U2F transport assertions. Unknown bits are retained; no transport is selected.
- General
Subtree - One permitted/excluded subtree. This model does not evaluate name matching.
- Integer
Value - ASN.1 INTEGER value without a machine-integer truncation or sign guess.
- Invalid
Oid - A name lookup received an invalid or noncanonical dotted-decimal OID.
- KeyPurpose
- An Extended Key Usage purpose, preserving OIDs, order and repetitions.
- KeyUsage
- Decoded Key Usage bits. These describe assertions, not enforced permissions.
- Name
Attribute - One attribute in a relative distinguished name; no normalization or name matching.
- Name
Constraints - Encoded name constraints, with absent and present subtrees distinguished. The strict backend supports u32 distances and GeneralNames except X.400; values outside that representation yield a malformed extension finding.
- Name
Summary - Display-oriented name data without the complete Name DER.
- Netscape
Certificate Type - Legacy Netscape certificate-type assertions, not enforced permissions.
- Notice
Reference - Organization and referenced notice numbers; numbers are not range-checked.
- OidNames
- Caller-owned OID presentation names, independent of parsing or trust policy.
- Parse
Options - Limits for a single certificate input; defaults to 1 MiB.
- Policy
Constraints - Policy counters asserted by the certificate, without path-policy evaluation.
- Policy
Mapping - One issuer-to-subject policy mapping; order and duplicate pairs are retained.
- Policy
Qualifier - One policy qualifier with its original value representation retained.
- Private
KeyUsage Period - Optional private-key usage bounds. This does not change certificate validity. The backend accepts years 1970–9999; other encodings yield a malformed finding.
- PssParameters
- Decoded RSA-PSS parameters, including RFC 8017 defaults. No assertion is made that the parameters are secure or usable with a given key.
- Public
KeyInfo - Owned public-key algorithm and encoding, without performing key validation.
- Public
KeySummary - Public-key description without key/SPKI bytes.
- Signed
Certificate Timestamp - RFC 6962 v1 SCT fields, independent of the input certificate buffer.
- User
Notice - Certificate-policy notice, preserving optional fields without display policy.
- Validity
- Certificate validity interval as signed Unix seconds, independent of a clock.
Enums§
- Constraint
Name - A name-constraint base. IP constraints encode an address and mask, not a host.
- Decode
Issue - Why a field could not be decoded; none of these categories is a trust verdict.
- Distribution
Point Name - A CRL distribution-point name; relative RDNs are not resolved automatically.
- Error
- Typed local parsing failures, distinct from card status and transport errors.
- Extension
Details - Application-facing interpretation of a certificate extension. Malformed/unsupported values and duplicate extensions never disappear silently.
- General
Name - An owned GeneralName. Values are decoded, not validated as identities or URLs.
- KeyData
Status - Inspection state for public-key bytes, separate from algorithm parameters.
- Name
Details - Additional fields decoded from a GeneralName’s retained encoding.
- Parameter
Status - Parameter inspection state, separate from algorithm recognition and trust.
- Policy
Qualifier Details - Interpretation of a policy qualifier, without policy evaluation.
- Public
KeyDetails - Parsed public-key fields. This performs no arithmetic or mathematical validation.
- SctEntry
- One embedded SCT entry. No log lookup or signature verification is performed.
Functions§
- parse_
der - Inspect exactly one DER certificate, copying its fields into an owned result.
- parse_
der_ with_ names - Inspect one DER certificate using a caller-owned OID name table. Results copy names and do not retain the table. Overrides affect presentation only, never decoder selection, key sizes or validation.
- parse_
pem - Inspect one CERTIFICATE PEM block, permitting only surrounding ASCII whitespace.
- parse_
pem_ with_ names - Inspect one PEM certificate with caller-owned presentation names. The input and name table are borrowed only for this call; output owns all data.