Uh oh!
There was an error while loading. Please reload this page.
x509-cert: adds a serial numbers generator - #1270
Merged
tarcieri merged 1 commit intoJan 5, 2024
Merged
Conversation
baloo
commented
Nov 26, 2023
Uh oh!
There was an error while loading. Please reload this page.
balooforce-pushed
the
baloo/x509-cert/serial-number-generate
branch
from
November 26, 2023 09:08
f78f6bc to
31a07a9Comparebalooforce-pushed
the
baloo/x509-cert/serial-number-generate
branch
3 times, most recently
from
December 3, 2023 01:28
a81e1ac to
38d4573Comparebalooforce-pushed
the
baloo/x509-cert/serial-number-generate
branch
from
December 4, 2023 20:40
38d4573 to
4ba6d43Comparebalooforce-pushed
the
baloo/x509-cert/serial-number-generate
branch
from
December 4, 2023 20:45
4ba6d43 to
f361e2eComparebalooforce-pushed
the
baloo/x509-cert/serial-number-generate
branch
2 times, most recently
from
December 13, 2023 22:46
8d6817b to
f3471e7CompareUh oh!
There was an error while loading. Please reload this page.
balooforce-pushed
the
baloo/x509-cert/serial-number-generate
branch
3 times, most recently
from
December 25, 2023 03:04
bae1b21 to
61f06d0Comparebalooforce-pushed
the
baloo/x509-cert/serial-number-generate
branch
from
January 5, 2024 00:00
61f06d0 to
86c086bCompareThis follows the CABF ballot 164 recommendation to have serials use 64 bits from a CSPRNG. This also provides the user with the option to prefix its values (for use of an instance id).
balooforce-pushed
the
baloo/x509-cert/serial-number-generate
branch
from
January 5, 2024 00:02
86c086b to
cb34750Comparebaloo
commented
Jan 5, 2024
Uh oh!
There was an error while loading. Please reload this page.
tarcieri
approved these changes
Jan 5, 2024
Uh oh!
There was an error while loading. Please reload this page.
baloo added a commit
to baloo/formats
that referenced
this pull request
Jul 6, 2026
Added - Serial number generator ([RustCrypto#1270]) - `DecodeValue` for `x509_cert::time::Time` ([RustCrypto#1986]) - `FromStr` for `x509_cert::time::Time` ([RustCrypto#1961]) - impl `Hash` for `Name` ([RustCrypto#1764]) - impl `Ord` for `CrlReason` ([RustCrypto#1869]) - `DirectoryString::BmpString` ([RustCrypto#1794]) - `Crl` builder ([RustCrypto#1759]) - `Time::now` method ([RustCrypto#1761]) - `Validity::infinity` helper ([RustCrypto#1528]) - `Validity::new` method ([RustCrypto#1529]) - Re-export `spki` types without `*Owned` suffixes ([RustCrypto#1534]) - `x509_cert::builder::AsyncBuilder` using `AsyncSigner` ([RustCrypto#1280]) Changed - Decompose `AsExtension` into `Criticality + AsExtension` ([RustCrypto#2109]) - Improve extension API flexibility and ergonomics ([RustCrypto#2120]) - Expose `Profile` in the `CrlBuilder` ([RustCrypto#1870]) - Ensure a serial number can be stored in a database ([RustCrypto#1868]) - Move the CSR builder `x509_cert::request` ([RustCrypto#1581]) - Rename `x509_cert::builder::Profile` to `BuilderProfile` ([RustCrypto#1514] && [RustCrypto#1517]) - `Name` is now a new type over `RdnSequence` ([RustCrypto#1499]) - make `RelativeDistinguishedName` fields private ([RustCrypto#1510]) - make `RdnSequence` fields private ([RustCrypto#1508]) - make (Tbs)`CertificateInner` fields private ([RustCrypto#1505]) - rename helpers to `get_extension`/`filter_extensions` ([RustCrypto#1497]) - `check_name_encoding` now allow extraneous components ([RustCrypto#1447]) - Accept RFC-invalid certificates as TrustAnchors ([RustCrypto#1403]) - Edition changed to 2024 and MSRV bumped to 1.85 ([RustCrypto#1689]) - Bump `rand` to `v0.10` ([RustCrypto#2212]) - Bump `der` to `v0.8` ([RustCrypto#2234]) - Bump `digest` to `v0.11` ([RustCrypto#2237]) - Bump `sha2` to `v0.11` ([RustCrypto#2273]) - Bump `spki` to `v0.8` ([RustCrypto#2277]) - Bump `signature` to `v3` ([RustCrypto#2326]) Fixed - Converting from `SystemTime` should use `UtcTime` if date <= 2049 ([RustCrypto#1969]) - Underflow on empty input in `Certificate::load_pem_chain` ([RustCrypto#1965]) - Domain validated should accept CNs ([RustCrypto#1815]) - Serialization of email addresses ([RustCrypto#1425]) Removed - Std requirement for `x509_cert::builder` ([RustCrypto#1709]) - `RelativeDistinguishedName::encode_from_string` ([RustCrypto#1509]) [RustCrypto#1270]: RustCrypto#1270 [RustCrypto#1280]: RustCrypto#1280 [RustCrypto#1403]: RustCrypto#1403 [RustCrypto#1425]: RustCrypto#1425 [RustCrypto#1447]: RustCrypto#1447 [RustCrypto#1497]: RustCrypto#1497 [RustCrypto#1499]: RustCrypto#1499 [RustCrypto#1505]: RustCrypto#1505 [RustCrypto#1508]: RustCrypto#1508 [RustCrypto#1509]: RustCrypto#1509 [RustCrypto#1510]: RustCrypto#1510 [RustCrypto#1514]: RustCrypto#1514 [RustCrypto#1517]: RustCrypto#1517 [RustCrypto#1528]: RustCrypto#1528 [RustCrypto#1529]: RustCrypto#1529 [RustCrypto#1534]: RustCrypto#1534 [RustCrypto#1581]: RustCrypto#1581 [RustCrypto#1689]: RustCrypto#1689 [RustCrypto#1709]: RustCrypto#1709 [RustCrypto#1759]: RustCrypto#1759 [RustCrypto#1761]: RustCrypto#1761 [RustCrypto#1764]: RustCrypto#1764 [RustCrypto#1794]: RustCrypto#1794 [RustCrypto#1815]: RustCrypto#1815 [RustCrypto#1868]: RustCrypto#1868 [RustCrypto#1869]: RustCrypto#1869 [RustCrypto#1870]: RustCrypto#1870 [RustCrypto#1961]: RustCrypto#1961 [RustCrypto#1965]: RustCrypto#1965 [RustCrypto#1969]: RustCrypto#1969 [RustCrypto#1986]: RustCrypto#1986 [RustCrypto#2109]: RustCrypto#2109 [RustCrypto#2120]: RustCrypto#2120 [RustCrypto#2212]: RustCrypto#2212 [RustCrypto#2234]: RustCrypto#2234 [RustCrypto#2237]: RustCrypto#2237 [RustCrypto#2273]: RustCrypto#2273 [RustCrypto#2277]: RustCrypto#2277 [RustCrypto#2326]: RustCrypto#2326
Merged
baloo added a commit
to baloo/formats
that referenced
this pull request
Jul 6, 2026
Added - Serial number generator ([RustCrypto#1270]) - `DecodeValue` for `x509_cert::time::Time` ([RustCrypto#1986]) - `FromStr` for `x509_cert::time::Time` ([RustCrypto#1961]) - impl `Hash` for `Name` ([RustCrypto#1764]) - impl `Ord` for `CrlReason` ([RustCrypto#1869]) - `DirectoryString::BmpString` ([RustCrypto#1794]) - `Crl` builder ([RustCrypto#1759]) - `Time::now` method ([RustCrypto#1761]) - `Validity::infinity` helper ([RustCrypto#1528]) - `Validity::new` method ([RustCrypto#1529]) - Re-export `spki` types without `*Owned` suffixes ([RustCrypto#1534]) - `x509_cert::builder::AsyncBuilder` using `AsyncSigner` ([RustCrypto#1280]) Changed - Decompose `AsExtension` into `Criticality + AsExtension` ([RustCrypto#2109]) - Improve extension API flexibility and ergonomics ([RustCrypto#2120]) - Expose `Profile` in the `CrlBuilder` ([RustCrypto#1870]) - Ensure a serial number can be stored in a database ([RustCrypto#1868]) - Move the CSR builder `x509_cert::request` ([RustCrypto#1581]) - Rename `x509_cert::builder::Profile` to `BuilderProfile` ([RustCrypto#1514] && [RustCrypto#1517]) - `Name` is now a new type over `RdnSequence` ([RustCrypto#1499]) - make `RelativeDistinguishedName` fields private ([RustCrypto#1510]) - make `RdnSequence` fields private ([RustCrypto#1508]) - make (Tbs)`CertificateInner` fields private ([RustCrypto#1505]) - rename helpers to `get_extension`/`filter_extensions` ([RustCrypto#1497]) - `check_name_encoding` now allow extraneous components ([RustCrypto#1447]) - Accept RFC-invalid certificates as TrustAnchors ([RustCrypto#1403]) - Edition changed to 2024 and MSRV bumped to 1.85 ([RustCrypto#1689]) - Bump `rand` to `v0.10` ([RustCrypto#2212]) - Bump `der` to `v0.8` ([RustCrypto#2234]) - Bump `digest` to `v0.11` ([RustCrypto#2237]) - Bump `sha2` to `v0.11` ([RustCrypto#2273]) - Bump `spki` to `v0.8` ([RustCrypto#2277]) - Bump `signature` to `v3` ([RustCrypto#2326]) Fixed - Converting from `SystemTime` should use `UtcTime` if date <= 2049 ([RustCrypto#1969]) - Underflow on empty input in `Certificate::load_pem_chain` ([RustCrypto#1965]) - Domain validated should accept CNs ([RustCrypto#1815]) - Serialization of email addresses ([RustCrypto#1425]) Removed - Std requirement for `x509_cert::builder` ([RustCrypto#1709]) - `RelativeDistinguishedName::encode_from_string` ([RustCrypto#1509]) [RustCrypto#1270]: RustCrypto#1270 [RustCrypto#1280]: RustCrypto#1280 [RustCrypto#1403]: RustCrypto#1403 [RustCrypto#1425]: RustCrypto#1425 [RustCrypto#1447]: RustCrypto#1447 [RustCrypto#1497]: RustCrypto#1497 [RustCrypto#1499]: RustCrypto#1499 [RustCrypto#1505]: RustCrypto#1505 [RustCrypto#1508]: RustCrypto#1508 [RustCrypto#1509]: RustCrypto#1509 [RustCrypto#1510]: RustCrypto#1510 [RustCrypto#1514]: RustCrypto#1514 [RustCrypto#1517]: RustCrypto#1517 [RustCrypto#1528]: RustCrypto#1528 [RustCrypto#1529]: RustCrypto#1529 [RustCrypto#1534]: RustCrypto#1534 [RustCrypto#1581]: RustCrypto#1581 [RustCrypto#1689]: RustCrypto#1689 [RustCrypto#1709]: RustCrypto#1709 [RustCrypto#1759]: RustCrypto#1759 [RustCrypto#1761]: RustCrypto#1761 [RustCrypto#1764]: RustCrypto#1764 [RustCrypto#1794]: RustCrypto#1794 [RustCrypto#1815]: RustCrypto#1815 [RustCrypto#1868]: RustCrypto#1868 [RustCrypto#1869]: RustCrypto#1869 [RustCrypto#1870]: RustCrypto#1870 [RustCrypto#1961]: RustCrypto#1961 [RustCrypto#1965]: RustCrypto#1965 [RustCrypto#1969]: RustCrypto#1969 [RustCrypto#1986]: RustCrypto#1986 [RustCrypto#2109]: RustCrypto#2109 [RustCrypto#2120]: RustCrypto#2120 [RustCrypto#2212]: RustCrypto#2212 [RustCrypto#2234]: RustCrypto#2234 [RustCrypto#2237]: RustCrypto#2237 [RustCrypto#2273]: RustCrypto#2273 [RustCrypto#2277]: RustCrypto#2277 [RustCrypto#2326]: RustCrypto#2326
tarcieri added a commit
that referenced
this pull request
Jul 9, 2026
## Added - Serial number generator (#1270) - `DecodeValue` for `x509_cert::time::Time` (#1986) - `FromStr` for `x509_cert::time::Time` (#1961) - impl `Hash` for `Name` (#1764) - impl `Ord` for `CrlReason` (#1869) - `DirectoryString::BmpString` (#1794) - `Crl` builder (#1759) - `Time::now` method (#1761) - `Validity::infinity` helper (#1528) - `Validity::new` method (#1529) - Re-export `spki` types without `*Owned` suffixes (#1534) - `x509_cert::builder::AsyncBuilder` using `AsyncSigner` (#1280) ## Changed - Decompose `AsExtension` into `Criticality + AsExtension` (#2109) - Improve extension API flexibility and ergonomics (#2120) - Expose `Profile` in the `CrlBuilder` (#1870) - Ensure a serial number can be stored in a database (#1868) - Move the CSR builder `x509_cert::request` (#1581) - Rename `x509_cert::builder::Profile` to `BuilderProfile` (#1514, #1517) - `Name` is now a new type over `RdnSequence` (#1499) - make `RelativeDistinguishedName` fields private (#1510) - make `RdnSequence` fields private (#1508) - make (Tbs)`CertificateInner` fields private (#1505) - rename helpers to `get_extension`/`filter_extensions` (#1497) - `check_name_encoding` now allow extraneous components (#1447) - Accept RFC-invalid certificates as TrustAnchors (#1403) - Edition changed to 2024 and MSRV bumped to 1.85 (#1689) - Bump `rand` to `v0.10` (#2212) - Bump `der` to `v0.8` (#2234) - Bump `digest` to `v0.11` (#2237) - Bump `sha2` to `v0.11` (#2273) - Bump `spki` to `v0.8` (#2277) - Bump `signature` to `v3` (#2326) ## Fixed - Converting from `SystemTime` should use `UtcTime` if date <= 2049 (#1969) - Underflow on empty input in `Certificate::load_pem_chain` (#1965) - Domain validated should accept CNs (#1815) - Serialization of email addresses (#1425) ## Removed - `std` requirement for `x509_cert::builder` (#1709) - `RelativeDistinguishedName::encode_from_string` (#1509) Co-authored-by: Tony Arcieri <bascule@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for freeto join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This follows the CABF ballot 164 recommendation to have serials use 64 bits from a CSPRNG.
https://cabforum.org/2016/03/31/ballot-164/
This also provides the user with the option to prefix its values (for use of an instance id).