Skip to main content

Crate x509_info

Crate x509_info 

Source
Expand description

§x509-info

CI crates.io docs.rs License: Apache-2.0

Owned X.509 certificate data for applications, bindings and reports. Read DER and PEM certificates, then emit text, JSON, JSON Lines, YAML, TOML, CBOR, MessagePack, DER or PEM output. Parse into names, algorithms, public-key components and decoded extensions, including FIDO identifiers. Unknown fields retain their original encodings and diagnostics.

The library performs no I/O, reads no clock, and verifies no signatures, trust chains or attestation policy. Callers own all inputs, results and OID overrides.

§Why this crate?

LibraryFocus
x509-parserBorrowed certificate types and low-level parsing; used internally
x509-certRustCrypto ASN.1 structures and certificate construction; nested decoders reused here
x509-certificate-printerFormatted certificate text
This crate: x509-infoOwned application data, field diagnostics, versioned reports and generated schemas

See the ecosystem comparison for alternatives and dependency choices.

§Library

Requires Rust 1.85+.

[dependencies]
x509-info = { version = "0.1", features = ["serde"] }
serde_json = "1"
fn main() -> Result<(), Box<dyn std::error::Error>> {
    let pem = std::fs::read("certificate.pem")?;
    let cert = x509_info::parse_pem(&pem, Default::default())?;
    println!("{:#?}", cert.summary());
    Ok(())
}

Inputs are limited to one certificate and 1 MiB by default; use ParseOptions to change the byte limit. The full result retains original bytes; summary() creates an owned view without large raw buffers. Public-key and name details() accessors provide additional decoded fields.

FeatureAdds
DefaultParsing and owned Rust results
serdeSerialization of library results
schemaSchemars schemas for the library’s Serde model
cliBinary, format serializers and CLI report schemas

Use cargo doc --all-features --no-deps --open for API documentation and cargo run --example binding_dto for a binding example.

§CLI

cargo install x509-info --features cli --locked
x509-info certificate.pem
x509-info certificate.pem --format json --summary
x509-info certificate.pem --format yaml -o report.yaml
x509-info certificate.pem --format der -o certificate.der
x509-info --schema -o report.schema.json
x509-info --schema --summary -o summary.schema.json

Formats: text, JSON, JSON Lines, YAML, TOML, CBOR, MessagePack, DER and PEM. Omit the input path or use - for stdin. Textual reports use Base64 for raw blocks, hex for numerical components and fingerprints, and UUID strings for AAGUIDs. CBOR and MessagePack use native byte strings. DER/PEM conversion preserves the DER.

CLI usage · Report schemas and format contracts

§Layout and development

lib/        Parsing and models; names/, keys/ and extensions/ submodules
bin/        CLI, report formatting and schema generation
examples/   Binding DTO example
tests/      Integration tests and synthetic certificate fixtures
cargo fmt --all --check
cargo test --locked
cargo test --all-features --locked
cargo clippy --all-targets --all-features --locked -- -D warnings

Licensed under Apache-2.0. Owned X.509 certificate inspection, independent of applets and transport.

This extracts the reusable DER/PEM inspection responsibility from Console’s Rust api/crypto.rs. It uses the same x509-parser dependency, with owned typed results and bounded, strict single-certificate inputs. This crate is licensed under Apache-2.0.

Parsing is not signature verification, chain building, trust, revocation, or application policy. No system clock or randomness is read. The caller supplies a timestamp to Validity::contains if it wants a validity-period check. Unknown algorithm/extension OIDs and their encoded data remain available.

CertificateInfo::summary provides owned application details, common decoded extensions and a SHA-256 fingerprint without raw certificate/key/signature copies. Enable serde for the versioned CertificateSummary serialization contract. Full-result serialization remains available for diagnostics (raw bytes are octet arrays). JSON belongs to callers; FRB can map these fields to its own DTOs. No public result borrows backend types or requires a registry/handle lifecycle.

Enable schema for Schemars schemas of the library’s Serde result types. These describe source representations. The optional CLI’s --schema command additionally accounts for report field names, Base64 and UUID formatting.

See Ecosystem and dependency choices for comparisons with other X.509 libraries.

§Example

use x509_info::{parse_pem, ParseOptions};
let info = parse_pem(pem, ParseOptions::default())?;
assert_eq!(info.public_key.key_size_bits, Some(256));
assert_eq!(info.public_key.algorithm.oid, "1.2.840.10045.2.1");
let details = info.summary();
drop(info);
let subject = details.subject; // Owned independently of parser input/results.
assert!(subject.display.contains("libcanokey test certificate"));

§Ecosystem and dependency choices

x509-info is an owned, transport-free projection for applications and reports. It reuses established parsers and keeps unknown or malformed values with typed diagnostics. It does not verify signatures, trust chains, identities or policy.

§Comparisons

ProjectBest fitWhy use x509-info instead
x509-parserBorrowed parsing and low-level inspectionOwned results, stable summaries, diagnostics and report schemas
x509-certRustCrypto ASN.1 models, encoding and constructionApplication-facing projection and CLI formats
x509-certificateHigh-level owned certificates and crypto operationsNarrow inspection layer without I/O, clocks or verification
picky-asn1-x509Picky ASN.1 structures with SerdeCertificate reading and a versioned report contract
x509-certificate-printerHuman-readable certificate textLibrary data for bindings plus text and machine-readable output
cert-dumpScanning stores and producing inventory JSONOne certificate at a time, with no filesystem, database or scanner

These projects overlap in certificate decoding or presentation, but their data ownership, validation scope and output contracts differ. rcgen is for creating certificates, while rustls-pki-types supplies shared PKI byte/time types; they are complementary rather than replacements.

§Primary sources

Structs§

AccessDescription
An AIA/SIA access method and its location. This library never retrieves it.
AlgorithmInfo
Algorithm information with an optional common label and preserved parameters.
AlgorithmSummary
Algorithm description without raw parameter bytes; see AlgorithmInfo for full data.
AuthorityKeyIdentifier
Authority key identifier components, as asserted by the certificate. Matching these fields does not establish an issuer relationship or trust.
CertificateInfo
Owned certificate inspection result; no input lifetime or device state.
CertificatePolicy
One asserted certificate policy; OID recognition never implies policy compliance.
CertificateSummary
Owned certificate details for UI/FFI and optional Serde export.
CertificateTemplate
Microsoft certificate-template fields without enrollment/template policy.
DecodeDiagnostic
Caller-owned field decoding diagnostic; not a certificate validation error.
DirectoryAttribute
A subject directory attribute with its multi-valued ASN.1 SET preserved.
DistinguishedName
Owned distinguished name, retaining RDN grouping, repeated attributes and order.
DistributionPoint
A CRL/freshest-CRL distribution point, without revocation processing or I/O.
ExtensionInfo
An extension and its decoded information, retained in certificate order.
ExtensionSummary
Extension summary without raw extnValue bytes; unsupported values remain explicit.
FidoTransports
FIDO U2F transport assertions. Unknown bits are retained; no transport is selected.
GeneralSubtree
One permitted/excluded subtree. This model does not evaluate name matching.
IntegerValue
ASN.1 INTEGER value without a machine-integer truncation or sign guess.
InvalidOid
A name lookup received an invalid or noncanonical dotted-decimal OID.
KeyPurpose
An Extended Key Usage purpose, preserving OIDs, order and repetitions.
KeyUsage
Decoded Key Usage bits. These describe assertions, not enforced permissions.
NameAttribute
One attribute in a relative distinguished name; no normalization or name matching.
NameConstraints
Encoded name constraints, with absent and present subtrees distinguished. The strict backend supports u32 distances and GeneralNames except X.400; values outside that representation yield a malformed extension finding.
NameSummary
Display-oriented name data without the complete Name DER.
NetscapeCertificateType
Legacy Netscape certificate-type assertions, not enforced permissions.
NoticeReference
Organization and referenced notice numbers; numbers are not range-checked.
OidNames
Caller-owned OID presentation names, independent of parsing or trust policy.
ParseOptions
Limits for a single certificate input; defaults to 1 MiB.
PolicyConstraints
Policy counters asserted by the certificate, without path-policy evaluation.
PolicyMapping
One issuer-to-subject policy mapping; order and duplicate pairs are retained.
PolicyQualifier
One policy qualifier with its original value representation retained.
PrivateKeyUsagePeriod
Optional private-key usage bounds. This does not change certificate validity. The backend accepts years 1970–9999; other encodings yield a malformed finding.
PssParameters
Decoded RSA-PSS parameters, including RFC 8017 defaults. No assertion is made that the parameters are secure or usable with a given key.
PublicKeyInfo
Owned public-key algorithm and encoding, without performing key validation.
PublicKeySummary
Public-key description without key/SPKI bytes.
SignedCertificateTimestamp
RFC 6962 v1 SCT fields, independent of the input certificate buffer.
UserNotice
Certificate-policy notice, preserving optional fields without display policy.
Validity
Certificate validity interval as signed Unix seconds, independent of a clock.

Enums§

ConstraintName
A name-constraint base. IP constraints encode an address and mask, not a host.
DecodeIssue
Why a field could not be decoded; none of these categories is a trust verdict.
DistributionPointName
A CRL distribution-point name; relative RDNs are not resolved automatically.
Error
Typed local parsing failures, distinct from card status and transport errors.
ExtensionDetails
Application-facing interpretation of a certificate extension. Malformed/unsupported values and duplicate extensions never disappear silently.
GeneralName
An owned GeneralName. Values are decoded, not validated as identities or URLs.
KeyDataStatus
Inspection state for public-key bytes, separate from algorithm parameters.
NameDetails
Additional fields decoded from a GeneralName’s retained encoding.
ParameterStatus
Parameter inspection state, separate from algorithm recognition and trust.
PolicyQualifierDetails
Interpretation of a policy qualifier, without policy evaluation.
PublicKeyDetails
Parsed public-key fields. This performs no arithmetic or mathematical validation.
SctEntry
One embedded SCT entry. No log lookup or signature verification is performed.

Functions§

parse_der
Inspect exactly one DER certificate, copying its fields into an owned result.
parse_der_with_names
Inspect one DER certificate using a caller-owned OID name table. Results copy names and do not retain the table. Overrides affect presentation only, never decoder selection, key sizes or validation.
parse_pem
Inspect one CERTIFICATE PEM block, permitting only surrounding ASCII whitespace.
parse_pem_with_names
Inspect one PEM certificate with caller-owned presentation names. The input and name table are borrowed only for this call; output owns all data.