Skip to content

x509-cert: adds a serial numbers generator - #1270

Merged
tarcieri merged 1 commit into
RustCrypto:masterfrom
baloo:baloo/x509-cert/serial-number-generate
Jan 5, 2024
Merged

x509-cert: adds a serial numbers generator#1270
tarcieri merged 1 commit into
RustCrypto:masterfrom
baloo:baloo/x509-cert/serial-number-generate

Conversation

@baloo

@baloobaloo commented Nov 26, 2023

Copy link
Copy Markdown
Member

This follows the CABF ballot 164 recommendation to have serials use 64 bits from a CSPRNG.
https://cabforum.org/2016/03/31/ballot-164/

This also provides the user with the option to prefix its values (for use of an instance id).

Comment threadx509-cert/src/serial_number.rs Outdated
@baloo
balooforce-pushed the baloo/x509-cert/serial-number-generate branch from f78f6bc to 31a07a9CompareNovember 26, 2023 09:08
@baloobaloo changed the title x509-cert: adds a convenience helper to generate serialsx509-cert: adds a helper to generate serial numbersNov 26, 2023
@baloobaloo changed the title x509-cert: adds a helper to generate serial numbersx509-cert: adds a serial numbers generatorNov 26, 2023
@baloo
balooforce-pushed the baloo/x509-cert/serial-number-generate branch 3 times, most recently from a81e1ac to 38d4573CompareDecember 3, 2023 01:28
@baloo
balooforce-pushed the baloo/x509-cert/serial-number-generate branch from 38d4573 to 4ba6d43CompareDecember 4, 2023 20:40
@baloo
balooforce-pushed the baloo/x509-cert/serial-number-generate branch from 4ba6d43 to f361e2eCompareDecember 4, 2023 20:45
@baloo
balooforce-pushed the baloo/x509-cert/serial-number-generate branch 2 times, most recently from 8d6817b to f3471e7CompareDecember 13, 2023 22:46
Comment threadx509-cert/src/serial_number.rs Outdated
@baloo
balooforce-pushed the baloo/x509-cert/serial-number-generate branch 3 times, most recently from bae1b21 to 61f06d0CompareDecember 25, 2023 03:04
@baloobaloo mentioned this pull request Jan 3, 2024
@baloo
balooforce-pushed the baloo/x509-cert/serial-number-generate branch from 61f06d0 to 86c086bCompareJanuary 5, 2024 00:00
This follows the CABF ballot 164 recommendation to have serials use 64
bits from a CSPRNG.
This also provides the user with the option to prefix its values (for
use of an instance id).
@baloo
balooforce-pushed the baloo/x509-cert/serial-number-generate branch from 86c086b to cb34750CompareJanuary 5, 2024 00:02
Comment threadx509-cert/src/serial_number.rs
@tarcieri
tarcieri merged commit efa381e into RustCrypto:masterJan 5, 2024
Comment threadx509-cert/src/serial_number.rs
@baloo
baloo deleted the baloo/x509-cert/serial-number-generate branch February 16, 2024 16:57
baloo added a commit to baloo/formats that referenced this pull request Jul 6, 2026
Added
- Serial number generator ([RustCrypto#1270])
- `DecodeValue` for `x509_cert::time::Time` ([RustCrypto#1986])
- `FromStr` for `x509_cert::time::Time` ([RustCrypto#1961])
- impl `Hash` for `Name` ([RustCrypto#1764])
- impl `Ord` for `CrlReason` ([RustCrypto#1869])
- `DirectoryString::BmpString` ([RustCrypto#1794])
- `Crl` builder ([RustCrypto#1759])
- `Time::now` method ([RustCrypto#1761])
- `Validity::infinity` helper ([RustCrypto#1528])
- `Validity::new` method ([RustCrypto#1529])
- Re-export `spki` types without `*Owned` suffixes ([RustCrypto#1534])
- `x509_cert::builder::AsyncBuilder` using `AsyncSigner` ([RustCrypto#1280])
Changed
- Decompose `AsExtension` into `Criticality + AsExtension` ([RustCrypto#2109])
- Improve extension API flexibility and ergonomics ([RustCrypto#2120])
- Expose `Profile` in the `CrlBuilder` ([RustCrypto#1870])
- Ensure a serial number can be stored in a database ([RustCrypto#1868])
- Move the CSR builder `x509_cert::request` ([RustCrypto#1581])
- Rename `x509_cert::builder::Profile` to `BuilderProfile` ([RustCrypto#1514] && [RustCrypto#1517])
- `Name` is now a new type over `RdnSequence` ([RustCrypto#1499])
- make `RelativeDistinguishedName` fields private ([RustCrypto#1510])
- make `RdnSequence` fields private ([RustCrypto#1508])
- make (Tbs)`CertificateInner` fields private ([RustCrypto#1505])
- rename helpers to `get_extension`/`filter_extensions` ([RustCrypto#1497])
- `check_name_encoding` now allow extraneous components ([RustCrypto#1447])
- Accept RFC-invalid certificates as TrustAnchors ([RustCrypto#1403])
- Edition changed to 2024 and MSRV bumped to 1.85 ([RustCrypto#1689])
- Bump `rand` to `v0.10` ([RustCrypto#2212])
- Bump `der` to `v0.8` ([RustCrypto#2234])
- Bump `digest` to `v0.11` ([RustCrypto#2237])
- Bump `sha2` to `v0.11` ([RustCrypto#2273])
- Bump `spki` to `v0.8` ([RustCrypto#2277])
- Bump `signature` to `v3` ([RustCrypto#2326])
Fixed
- Converting from `SystemTime` should use `UtcTime` if date <= 2049 ([RustCrypto#1969])
- Underflow on empty input in `Certificate::load_pem_chain` ([RustCrypto#1965])
- Domain validated should accept CNs ([RustCrypto#1815])
- Serialization of email addresses ([RustCrypto#1425])
Removed
- Std requirement for `x509_cert::builder` ([RustCrypto#1709])
- `RelativeDistinguishedName::encode_from_string` ([RustCrypto#1509])
[RustCrypto#1270]: RustCrypto#1270
[RustCrypto#1280]: RustCrypto#1280
[RustCrypto#1403]: RustCrypto#1403
[RustCrypto#1425]: RustCrypto#1425
[RustCrypto#1447]: RustCrypto#1447
[RustCrypto#1497]: RustCrypto#1497
[RustCrypto#1499]: RustCrypto#1499
[RustCrypto#1505]: RustCrypto#1505
[RustCrypto#1508]: RustCrypto#1508
[RustCrypto#1509]: RustCrypto#1509
[RustCrypto#1510]: RustCrypto#1510
[RustCrypto#1514]: RustCrypto#1514
[RustCrypto#1517]: RustCrypto#1517
[RustCrypto#1528]: RustCrypto#1528
[RustCrypto#1529]: RustCrypto#1529
[RustCrypto#1534]: RustCrypto#1534
[RustCrypto#1581]: RustCrypto#1581
[RustCrypto#1689]: RustCrypto#1689
[RustCrypto#1709]: RustCrypto#1709
[RustCrypto#1759]: RustCrypto#1759
[RustCrypto#1761]: RustCrypto#1761
[RustCrypto#1764]: RustCrypto#1764
[RustCrypto#1794]: RustCrypto#1794
[RustCrypto#1815]: RustCrypto#1815
[RustCrypto#1868]: RustCrypto#1868
[RustCrypto#1869]: RustCrypto#1869
[RustCrypto#1870]: RustCrypto#1870
[RustCrypto#1961]: RustCrypto#1961
[RustCrypto#1965]: RustCrypto#1965
[RustCrypto#1969]: RustCrypto#1969
[RustCrypto#1986]: RustCrypto#1986
[RustCrypto#2109]: RustCrypto#2109
[RustCrypto#2120]: RustCrypto#2120
[RustCrypto#2212]: RustCrypto#2212
[RustCrypto#2234]: RustCrypto#2234
[RustCrypto#2237]: RustCrypto#2237
[RustCrypto#2273]: RustCrypto#2273
[RustCrypto#2277]: RustCrypto#2277
[RustCrypto#2326]: RustCrypto#2326
@baloobaloo mentioned this pull request Jul 6, 2026
baloo added a commit to baloo/formats that referenced this pull request Jul 6, 2026
Added
- Serial number generator ([RustCrypto#1270])
- `DecodeValue` for `x509_cert::time::Time` ([RustCrypto#1986])
- `FromStr` for `x509_cert::time::Time` ([RustCrypto#1961])
- impl `Hash` for `Name` ([RustCrypto#1764])
- impl `Ord` for `CrlReason` ([RustCrypto#1869])
- `DirectoryString::BmpString` ([RustCrypto#1794])
- `Crl` builder ([RustCrypto#1759])
- `Time::now` method ([RustCrypto#1761])
- `Validity::infinity` helper ([RustCrypto#1528])
- `Validity::new` method ([RustCrypto#1529])
- Re-export `spki` types without `*Owned` suffixes ([RustCrypto#1534])
- `x509_cert::builder::AsyncBuilder` using `AsyncSigner` ([RustCrypto#1280])
Changed
- Decompose `AsExtension` into `Criticality + AsExtension` ([RustCrypto#2109])
- Improve extension API flexibility and ergonomics ([RustCrypto#2120])
- Expose `Profile` in the `CrlBuilder` ([RustCrypto#1870])
- Ensure a serial number can be stored in a database ([RustCrypto#1868])
- Move the CSR builder `x509_cert::request` ([RustCrypto#1581])
- Rename `x509_cert::builder::Profile` to `BuilderProfile` ([RustCrypto#1514] && [RustCrypto#1517])
- `Name` is now a new type over `RdnSequence` ([RustCrypto#1499])
- make `RelativeDistinguishedName` fields private ([RustCrypto#1510])
- make `RdnSequence` fields private ([RustCrypto#1508])
- make (Tbs)`CertificateInner` fields private ([RustCrypto#1505])
- rename helpers to `get_extension`/`filter_extensions` ([RustCrypto#1497])
- `check_name_encoding` now allow extraneous components ([RustCrypto#1447])
- Accept RFC-invalid certificates as TrustAnchors ([RustCrypto#1403])
- Edition changed to 2024 and MSRV bumped to 1.85 ([RustCrypto#1689])
- Bump `rand` to `v0.10` ([RustCrypto#2212])
- Bump `der` to `v0.8` ([RustCrypto#2234])
- Bump `digest` to `v0.11` ([RustCrypto#2237])
- Bump `sha2` to `v0.11` ([RustCrypto#2273])
- Bump `spki` to `v0.8` ([RustCrypto#2277])
- Bump `signature` to `v3` ([RustCrypto#2326])
Fixed
- Converting from `SystemTime` should use `UtcTime` if date <= 2049 ([RustCrypto#1969])
- Underflow on empty input in `Certificate::load_pem_chain` ([RustCrypto#1965])
- Domain validated should accept CNs ([RustCrypto#1815])
- Serialization of email addresses ([RustCrypto#1425])
Removed
- Std requirement for `x509_cert::builder` ([RustCrypto#1709])
- `RelativeDistinguishedName::encode_from_string` ([RustCrypto#1509])
[RustCrypto#1270]: RustCrypto#1270
[RustCrypto#1280]: RustCrypto#1280
[RustCrypto#1403]: RustCrypto#1403
[RustCrypto#1425]: RustCrypto#1425
[RustCrypto#1447]: RustCrypto#1447
[RustCrypto#1497]: RustCrypto#1497
[RustCrypto#1499]: RustCrypto#1499
[RustCrypto#1505]: RustCrypto#1505
[RustCrypto#1508]: RustCrypto#1508
[RustCrypto#1509]: RustCrypto#1509
[RustCrypto#1510]: RustCrypto#1510
[RustCrypto#1514]: RustCrypto#1514
[RustCrypto#1517]: RustCrypto#1517
[RustCrypto#1528]: RustCrypto#1528
[RustCrypto#1529]: RustCrypto#1529
[RustCrypto#1534]: RustCrypto#1534
[RustCrypto#1581]: RustCrypto#1581
[RustCrypto#1689]: RustCrypto#1689
[RustCrypto#1709]: RustCrypto#1709
[RustCrypto#1759]: RustCrypto#1759
[RustCrypto#1761]: RustCrypto#1761
[RustCrypto#1764]: RustCrypto#1764
[RustCrypto#1794]: RustCrypto#1794
[RustCrypto#1815]: RustCrypto#1815
[RustCrypto#1868]: RustCrypto#1868
[RustCrypto#1869]: RustCrypto#1869
[RustCrypto#1870]: RustCrypto#1870
[RustCrypto#1961]: RustCrypto#1961
[RustCrypto#1965]: RustCrypto#1965
[RustCrypto#1969]: RustCrypto#1969
[RustCrypto#1986]: RustCrypto#1986
[RustCrypto#2109]: RustCrypto#2109
[RustCrypto#2120]: RustCrypto#2120
[RustCrypto#2212]: RustCrypto#2212
[RustCrypto#2234]: RustCrypto#2234
[RustCrypto#2237]: RustCrypto#2237
[RustCrypto#2273]: RustCrypto#2273
[RustCrypto#2277]: RustCrypto#2277
[RustCrypto#2326]: RustCrypto#2326
tarcieri added a commit that referenced this pull request Jul 9, 2026
## Added
- Serial number generator (#1270)
- `DecodeValue` for `x509_cert::time::Time` (#1986)
- `FromStr` for `x509_cert::time::Time` (#1961)
- impl `Hash` for `Name` (#1764)
- impl `Ord` for `CrlReason` (#1869)
- `DirectoryString::BmpString` (#1794)
- `Crl` builder (#1759)
- `Time::now` method (#1761)
- `Validity::infinity` helper (#1528)
- `Validity::new` method (#1529)
- Re-export `spki` types without `*Owned` suffixes (#1534)
- `x509_cert::builder::AsyncBuilder` using `AsyncSigner` (#1280)
## Changed
- Decompose `AsExtension` into `Criticality + AsExtension` (#2109)
- Improve extension API flexibility and ergonomics (#2120)
- Expose `Profile` in the `CrlBuilder` (#1870)
- Ensure a serial number can be stored in a database (#1868)
- Move the CSR builder `x509_cert::request` (#1581)
- Rename `x509_cert::builder::Profile` to `BuilderProfile` (#1514, #1517)
- `Name` is now a new type over `RdnSequence` (#1499)
- make `RelativeDistinguishedName` fields private (#1510)
- make `RdnSequence` fields private (#1508)
- make (Tbs)`CertificateInner` fields private (#1505)
- rename helpers to `get_extension`/`filter_extensions` (#1497)
- `check_name_encoding` now allow extraneous components (#1447)
- Accept RFC-invalid certificates as TrustAnchors (#1403)
- Edition changed to 2024 and MSRV bumped to 1.85 (#1689)
- Bump `rand` to `v0.10` (#2212)
- Bump `der` to `v0.8` (#2234)
- Bump `digest` to `v0.11` (#2237)
- Bump `sha2` to `v0.11` (#2273)
- Bump `spki` to `v0.8` (#2277)
- Bump `signature` to `v3` (#2326)
## Fixed
- Converting from `SystemTime` should use `UtcTime` if date <= 2049 (#1969)
- Underflow on empty input in `Certificate::load_pem_chain` (#1965)
- Domain validated should accept CNs (#1815)
- Serialization of email addresses (#1425)
## Removed
- `std` requirement for `x509_cert::builder` (#1709)
- `RelativeDistinguishedName::encode_from_string` (#1509)
Co-authored-by: Tony Arcieri <bascule@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@baloo@tarcieri