Feature: Certificate policies - #406

Open
Gabgobie wants to merge 2 commits into
rustls:mainfrom
Gabgobie:certificate-policies
Open

Feature: Certificate policies#406
Gabgobie wants to merge 2 commits into
rustls:mainfrom
Gabgobie:certificate-policies

Conversation

@Gabgobie

@GabgobieGabgobie commented Jan 16, 2026

Copy link
Copy Markdown

Thanks for offering to review the PR @djc

Adds the following extensions

This PR handles two of the extensions listed/requested in #370

Compatibility check screenshots

Requested Screenshots

OpenSSL (WSL)

  • cd certs
  • openssl x509 --in cert.pem --text --noout
grafik

Windows "Krypto-Shellerweiterungen"

Ausstellerklärung:

grafik

Unfortunately the window can't be resized

grafikgrafikgrafik

Browsers

Minimal webserver

fromuvicornimportrunfromfastapiimportFastAPIrun(
FastAPI(),
host="127.0.0.1",
port=443,
ssl_certfile="certs/cert.pem",
ssl_keyfile="certs/key.pem",
)

Firefox

grafik

Chromium (Edge)

grafikgrafik

ASN.1 JavaScript decoder

Decode of a generated cert by cargo run --example certificate_policies

grafik

@Gabgobie

Copy link
Copy Markdown
Author

I'll take another look at test coverage and the pipeline checks in the coming days but wanted to get this out here since the output seems to at least be valid.

@Gabgobie
Gabgobie marked this pull request as draft January 16, 2026 18:18
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from fd4cb64 to 64ee5b1CompareJanuary 17, 2026 09:04
@Gabgobie
Gabgobie marked this pull request as ready for review January 18, 2026 18:43
@Gabgobie

Copy link
Copy Markdown
Author

Suppose this is about as ready for review as it can get. There are still changes to be made but I'll need to know which direction they should go in.

@djcdjc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1200 lines of code is a lot. I added a bunch of notes on how to pare that down.

Comment threadrcgen/Cargo.toml Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment on lines +841 to +842
/// ```rust
/// use rcgen::{CertificatePolicies, PolicyInformation, Error};

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Also too much.

Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
@cpu

cpu commented Jan 19, 2026

Copy link
Copy Markdown
Member

For whatever it's worth I remain not keen on supporting certificate policies and don't plan to try to review this work.

@Gabgobie
Gabgobieforce-pushed the certificate-policies branch 3 times, most recently from 86d4652 to 275c30cCompareJanuary 19, 2026 17:51
@Gabgobie

Copy link
Copy Markdown
Author

My apologies. I just took a look at the PR from a private window and noticed that my replies were never published. PR inexperience...

I thought you were just busy! I'll look into what it takes to publish a response.


@cpu Should I take your comment as active opposition to this PR? I'll be happy to make more changes but it would have been nice if you were clear about that beforehand. I interpreted your previous comment as indifference/approval. I also found more use-cases for policies aside from user notices, some of which I posted in the original issue.

I'm not strictly opposed to support if you can write a clean PR with appropriate test coverage without a lot of guidance1 but I'm having a hard time seeing this as a genuine use case that will benefit a large enough number of people to be worth the ongoing maintenance.

@cpu

cpu commented Feb 12, 2026

Copy link
Copy Markdown
Member

@cpu Should I take your comment as active opposition to this PR?

No, I wouldn't characterize it as active opposition in the sense that I would be in favour of blocking a PR that other maintainers wanted to approve or something like that. If you can get approvals, I won't stand in the way :-)

it would have been nice if you were clear about that beforehand. I interpreted your previous comment as indifference/approval.

My previous comment also emphasized a desire for a clean PR with appropriate test coverage. I haven't looked at the substance of the diff, but the commit history is pretty messy in the current state. Apologies if I misrepresented my interest/availability for reviewing the work in general, but I think you still have a path forward with djc/est31.

@Gabgobie

Copy link
Copy Markdown
Author

Thank you for clarifying. I am trying to do as much on my own as possible but this being my first larger PR I am not sure about the design decisions you - as in all maintainers of this project - would prefer. Maybe it would be better if I just make a decision over trying to add suggestions to pick from.

I wasn't aware that a clean history is valuable since it will be squashed on merge anyways. I will look into cleaning that up as well.

I'll also give reviewing my own changes another try. Not having looked at it for ~3 weeks I should have a fresh pair of eyes.

@Gabgobie
Gabgobie marked this pull request as draft February 12, 2026 23:40
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch 2 times, most recently from 2992e38 to a80f896CompareFebruary 27, 2026 13:43
@Gabgobie

Gabgobie commented Feb 27, 2026

Copy link
Copy Markdown
Author

If the checks pass, which I'd expect after having them run locally, I'll look into ergonomics when consuming my fork and mark this ready for review afterwards.

#406 (comment)

Let's avoid adding any particular policies for this PR.

Would you like a separate PR or commit with constructors for commonly used/standardized policies or should I implement them on the consumer side? Without these constructors, the consumer needs to know OIDs and in some cases encode their own DER. rcgen generally abstracts this low-level stuff so this would feel out of place to me.

@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from a80f896 to d6bb0d4CompareMarch 13, 2026 16:10
Comment on lines +750 to +753
/// Returns the contained sequence of one or more policy information terms
pub fn policy_information(&self) -> &[PolicyInformation] {
&self.policy_information
}

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I somehow just now noticed that - aside from testing - from_x509 is useless anyways, see also:

Should I remove this getter and the pub on critical entirely?

Comment threadrcgen/src/certificate.rs Outdated
InhibitAnyPolicy is used to limit the use of the special policy anypolicy that circumvents validation. Policies must be validated for example when deciding the level of trust to put into a certificate. Common policies include 2.23.140.1.2 which denotes the validation procedure. 2.23.140.1.2.1 for example is "Domain Validation"
See also https://oid-base.com/get/2.23.140.1.2.1 or inspect a LetsEncrypt certificate
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from d6bb0d4 to af5b4c0CompareApril 2, 2026 21:44
@Gabgobie
Gabgobie marked this pull request as ready for review April 2, 2026 23:19
@Gabgobie

Copy link
Copy Markdown
Author

Cleaned the history, rebased and tried reviewing the proposed changes again. I think it's ready for another review at your leisure :D

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Gabgobie@cpu@djc
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Feature: Certificate policies - #406

Open
Gabgobie wants to merge 2 commits into
rustls:mainfrom
Gabgobie:certificate-policies
Open

Feature: Certificate policies#406
Gabgobie wants to merge 2 commits into
rustls:mainfrom
Gabgobie:certificate-policies

Conversation

@Gabgobie

@GabgobieGabgobie commented Jan 16, 2026

Copy link
Copy Markdown

Thanks for offering to review the PR @djc

Adds the following extensions

This PR handles two of the extensions listed/requested in #370

Compatibility check screenshots

Requested Screenshots

OpenSSL (WSL)

  • cd certs
  • openssl x509 --in cert.pem --text --noout
grafik

Windows "Krypto-Shellerweiterungen"

Ausstellerklärung:

grafik

Unfortunately the window can't be resized

grafikgrafikgrafik

Browsers

Minimal webserver

fromuvicornimportrunfromfastapiimportFastAPIrun(
FastAPI(),
host="127.0.0.1",
port=443,
ssl_certfile="certs/cert.pem",
ssl_keyfile="certs/key.pem",
)

Firefox

grafik

Chromium (Edge)

grafikgrafik

ASN.1 JavaScript decoder

Decode of a generated cert by cargo run --example certificate_policies

grafik

@Gabgobie

Copy link
Copy Markdown
Author

I'll take another look at test coverage and the pipeline checks in the coming days but wanted to get this out here since the output seems to at least be valid.

@Gabgobie
Gabgobie marked this pull request as draft January 16, 2026 18:18
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from fd4cb64 to 64ee5b1CompareJanuary 17, 2026 09:04
@Gabgobie
Gabgobie marked this pull request as ready for review January 18, 2026 18:43
@Gabgobie

Copy link
Copy Markdown
Author

Suppose this is about as ready for review as it can get. There are still changes to be made but I'll need to know which direction they should go in.

@djcdjc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1200 lines of code is a lot. I added a bunch of notes on how to pare that down.

Comment threadrcgen/Cargo.toml Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment on lines +841 to +842
/// ```rust
/// use rcgen::{CertificatePolicies, PolicyInformation, Error};

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Also too much.

Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
@cpu

cpu commented Jan 19, 2026

Copy link
Copy Markdown
Member

For whatever it's worth I remain not keen on supporting certificate policies and don't plan to try to review this work.

@Gabgobie
Gabgobieforce-pushed the certificate-policies branch 3 times, most recently from 86d4652 to 275c30cCompareJanuary 19, 2026 17:51
@Gabgobie

Copy link
Copy Markdown
Author

My apologies. I just took a look at the PR from a private window and noticed that my replies were never published. PR inexperience...

I thought you were just busy! I'll look into what it takes to publish a response.


@cpu Should I take your comment as active opposition to this PR? I'll be happy to make more changes but it would have been nice if you were clear about that beforehand. I interpreted your previous comment as indifference/approval. I also found more use-cases for policies aside from user notices, some of which I posted in the original issue.

I'm not strictly opposed to support if you can write a clean PR with appropriate test coverage without a lot of guidance1 but I'm having a hard time seeing this as a genuine use case that will benefit a large enough number of people to be worth the ongoing maintenance.

@cpu

cpu commented Feb 12, 2026

Copy link
Copy Markdown
Member

@cpu Should I take your comment as active opposition to this PR?

No, I wouldn't characterize it as active opposition in the sense that I would be in favour of blocking a PR that other maintainers wanted to approve or something like that. If you can get approvals, I won't stand in the way :-)

it would have been nice if you were clear about that beforehand. I interpreted your previous comment as indifference/approval.

My previous comment also emphasized a desire for a clean PR with appropriate test coverage. I haven't looked at the substance of the diff, but the commit history is pretty messy in the current state. Apologies if I misrepresented my interest/availability for reviewing the work in general, but I think you still have a path forward with djc/est31.

@Gabgobie

Copy link
Copy Markdown
Author

Thank you for clarifying. I am trying to do as much on my own as possible but this being my first larger PR I am not sure about the design decisions you - as in all maintainers of this project - would prefer. Maybe it would be better if I just make a decision over trying to add suggestions to pick from.

I wasn't aware that a clean history is valuable since it will be squashed on merge anyways. I will look into cleaning that up as well.

I'll also give reviewing my own changes another try. Not having looked at it for ~3 weeks I should have a fresh pair of eyes.

@Gabgobie
Gabgobie marked this pull request as draft February 12, 2026 23:40
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch 2 times, most recently from 2992e38 to a80f896CompareFebruary 27, 2026 13:43
@Gabgobie

Gabgobie commented Feb 27, 2026

Copy link
Copy Markdown
Author

If the checks pass, which I'd expect after having them run locally, I'll look into ergonomics when consuming my fork and mark this ready for review afterwards.

#406 (comment)

Let's avoid adding any particular policies for this PR.

Would you like a separate PR or commit with constructors for commonly used/standardized policies or should I implement them on the consumer side? Without these constructors, the consumer needs to know OIDs and in some cases encode their own DER. rcgen generally abstracts this low-level stuff so this would feel out of place to me.

@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from a80f896 to d6bb0d4CompareMarch 13, 2026 16:10
Comment on lines +750 to +753
/// Returns the contained sequence of one or more policy information terms
pub fn policy_information(&self) -> &[PolicyInformation] {
&self.policy_information
}

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I somehow just now noticed that - aside from testing - from_x509 is useless anyways, see also:

Should I remove this getter and the pub on critical entirely?

Comment threadrcgen/src/certificate.rs Outdated
InhibitAnyPolicy is used to limit the use of the special policy anypolicy that circumvents validation. Policies must be validated for example when deciding the level of trust to put into a certificate. Common policies include 2.23.140.1.2 which denotes the validation procedure. 2.23.140.1.2.1 for example is "Domain Validation"
See also https://oid-base.com/get/2.23.140.1.2.1 or inspect a LetsEncrypt certificate
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from d6bb0d4 to af5b4c0CompareApril 2, 2026 21:44
@Gabgobie
Gabgobie marked this pull request as ready for review April 2, 2026 23:19
@Gabgobie

Copy link
Copy Markdown
Author

Cleaned the history, rebased and tried reviewing the proposed changes again. I think it's ready for another review at your leisure :D

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Gabgobie@cpu@djc
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Feature: Certificate policies - #406

Open
Gabgobie wants to merge 2 commits into
rustls:mainfrom
Gabgobie:certificate-policies
Open

Feature: Certificate policies#406
Gabgobie wants to merge 2 commits into
rustls:mainfrom
Gabgobie:certificate-policies

Conversation

@Gabgobie

@GabgobieGabgobie commented Jan 16, 2026

Copy link
Copy Markdown

Thanks for offering to review the PR @djc

Adds the following extensions

This PR handles two of the extensions listed/requested in #370

Compatibility check screenshots

Requested Screenshots

OpenSSL (WSL)

  • cd certs
  • openssl x509 --in cert.pem --text --noout
grafik

Windows "Krypto-Shellerweiterungen"

Ausstellerklärung:

grafik

Unfortunately the window can't be resized

grafikgrafikgrafik

Browsers

Minimal webserver

fromuvicornimportrunfromfastapiimportFastAPIrun(
FastAPI(),
host="127.0.0.1",
port=443,
ssl_certfile="certs/cert.pem",
ssl_keyfile="certs/key.pem",
)

Firefox

grafik

Chromium (Edge)

grafikgrafik

ASN.1 JavaScript decoder

Decode of a generated cert by cargo run --example certificate_policies

grafik

@Gabgobie

Copy link
Copy Markdown
Author

I'll take another look at test coverage and the pipeline checks in the coming days but wanted to get this out here since the output seems to at least be valid.

@Gabgobie
Gabgobie marked this pull request as draft January 16, 2026 18:18
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from fd4cb64 to 64ee5b1CompareJanuary 17, 2026 09:04
@Gabgobie
Gabgobie marked this pull request as ready for review January 18, 2026 18:43
@Gabgobie

Copy link
Copy Markdown
Author

Suppose this is about as ready for review as it can get. There are still changes to be made but I'll need to know which direction they should go in.

@djcdjc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1200 lines of code is a lot. I added a bunch of notes on how to pare that down.

Comment threadrcgen/Cargo.toml Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment on lines +841 to +842
/// ```rust
/// use rcgen::{CertificatePolicies, PolicyInformation, Error};

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Also too much.

Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
@cpu

cpu commented Jan 19, 2026

Copy link
Copy Markdown
Member

For whatever it's worth I remain not keen on supporting certificate policies and don't plan to try to review this work.

@Gabgobie
Gabgobieforce-pushed the certificate-policies branch 3 times, most recently from 86d4652 to 275c30cCompareJanuary 19, 2026 17:51
@Gabgobie

Copy link
Copy Markdown
Author

My apologies. I just took a look at the PR from a private window and noticed that my replies were never published. PR inexperience...

I thought you were just busy! I'll look into what it takes to publish a response.


@cpu Should I take your comment as active opposition to this PR? I'll be happy to make more changes but it would have been nice if you were clear about that beforehand. I interpreted your previous comment as indifference/approval. I also found more use-cases for policies aside from user notices, some of which I posted in the original issue.

I'm not strictly opposed to support if you can write a clean PR with appropriate test coverage without a lot of guidance1 but I'm having a hard time seeing this as a genuine use case that will benefit a large enough number of people to be worth the ongoing maintenance.

@cpu

cpu commented Feb 12, 2026

Copy link
Copy Markdown
Member

@cpu Should I take your comment as active opposition to this PR?

No, I wouldn't characterize it as active opposition in the sense that I would be in favour of blocking a PR that other maintainers wanted to approve or something like that. If you can get approvals, I won't stand in the way :-)

it would have been nice if you were clear about that beforehand. I interpreted your previous comment as indifference/approval.

My previous comment also emphasized a desire for a clean PR with appropriate test coverage. I haven't looked at the substance of the diff, but the commit history is pretty messy in the current state. Apologies if I misrepresented my interest/availability for reviewing the work in general, but I think you still have a path forward with djc/est31.

@Gabgobie

Copy link
Copy Markdown
Author

Thank you for clarifying. I am trying to do as much on my own as possible but this being my first larger PR I am not sure about the design decisions you - as in all maintainers of this project - would prefer. Maybe it would be better if I just make a decision over trying to add suggestions to pick from.

I wasn't aware that a clean history is valuable since it will be squashed on merge anyways. I will look into cleaning that up as well.

I'll also give reviewing my own changes another try. Not having looked at it for ~3 weeks I should have a fresh pair of eyes.

@Gabgobie
Gabgobie marked this pull request as draft February 12, 2026 23:40
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch 2 times, most recently from 2992e38 to a80f896CompareFebruary 27, 2026 13:43
@Gabgobie

Gabgobie commented Feb 27, 2026

Copy link
Copy Markdown
Author

If the checks pass, which I'd expect after having them run locally, I'll look into ergonomics when consuming my fork and mark this ready for review afterwards.

#406 (comment)

Let's avoid adding any particular policies for this PR.

Would you like a separate PR or commit with constructors for commonly used/standardized policies or should I implement them on the consumer side? Without these constructors, the consumer needs to know OIDs and in some cases encode their own DER. rcgen generally abstracts this low-level stuff so this would feel out of place to me.

@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from a80f896 to d6bb0d4CompareMarch 13, 2026 16:10
Comment on lines +750 to +753
/// Returns the contained sequence of one or more policy information terms
pub fn policy_information(&self) -> &[PolicyInformation] {
&self.policy_information
}

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I somehow just now noticed that - aside from testing - from_x509 is useless anyways, see also:

Should I remove this getter and the pub on critical entirely?

Comment threadrcgen/src/certificate.rs Outdated
InhibitAnyPolicy is used to limit the use of the special policy anypolicy that circumvents validation. Policies must be validated for example when deciding the level of trust to put into a certificate. Common policies include 2.23.140.1.2 which denotes the validation procedure. 2.23.140.1.2.1 for example is "Domain Validation"
See also https://oid-base.com/get/2.23.140.1.2.1 or inspect a LetsEncrypt certificate
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from d6bb0d4 to af5b4c0CompareApril 2, 2026 21:44
@Gabgobie
Gabgobie marked this pull request as ready for review April 2, 2026 23:19
@Gabgobie

Copy link
Copy Markdown
Author

Cleaned the history, rebased and tried reviewing the proposed changes again. I think it's ready for another review at your leisure :D

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Gabgobie@cpu@djc
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Feature: Certificate policies - #406

Open
Gabgobie wants to merge 2 commits into
rustls:mainfrom
Gabgobie:certificate-policies
Open

Feature: Certificate policies#406
Gabgobie wants to merge 2 commits into
rustls:mainfrom
Gabgobie:certificate-policies

Conversation

@Gabgobie

@GabgobieGabgobie commented Jan 16, 2026

Copy link
Copy Markdown

Thanks for offering to review the PR @djc

Adds the following extensions

This PR handles two of the extensions listed/requested in #370

Compatibility check screenshots

Requested Screenshots

OpenSSL (WSL)

  • cd certs
  • openssl x509 --in cert.pem --text --noout
grafik

Windows "Krypto-Shellerweiterungen"

Ausstellerklärung:

grafik

Unfortunately the window can't be resized

grafikgrafikgrafik

Browsers

Minimal webserver

fromuvicornimportrunfromfastapiimportFastAPIrun(
FastAPI(),
host="127.0.0.1",
port=443,
ssl_certfile="certs/cert.pem",
ssl_keyfile="certs/key.pem",
)

Firefox

grafik

Chromium (Edge)

grafikgrafik

ASN.1 JavaScript decoder

Decode of a generated cert by cargo run --example certificate_policies

grafik

@Gabgobie

Copy link
Copy Markdown
Author

I'll take another look at test coverage and the pipeline checks in the coming days but wanted to get this out here since the output seems to at least be valid.

@Gabgobie
Gabgobie marked this pull request as draft January 16, 2026 18:18
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from fd4cb64 to 64ee5b1CompareJanuary 17, 2026 09:04
@Gabgobie
Gabgobie marked this pull request as ready for review January 18, 2026 18:43
@Gabgobie

Copy link
Copy Markdown
Author

Suppose this is about as ready for review as it can get. There are still changes to be made but I'll need to know which direction they should go in.

@djcdjc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1200 lines of code is a lot. I added a bunch of notes on how to pare that down.

Comment threadrcgen/Cargo.toml Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment on lines +841 to +842
/// ```rust
/// use rcgen::{CertificatePolicies, PolicyInformation, Error};

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Also too much.

Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
@cpu

cpu commented Jan 19, 2026

Copy link
Copy Markdown
Member

For whatever it's worth I remain not keen on supporting certificate policies and don't plan to try to review this work.

@Gabgobie
Gabgobieforce-pushed the certificate-policies branch 3 times, most recently from 86d4652 to 275c30cCompareJanuary 19, 2026 17:51
@Gabgobie

Copy link
Copy Markdown
Author

My apologies. I just took a look at the PR from a private window and noticed that my replies were never published. PR inexperience...

I thought you were just busy! I'll look into what it takes to publish a response.


@cpu Should I take your comment as active opposition to this PR? I'll be happy to make more changes but it would have been nice if you were clear about that beforehand. I interpreted your previous comment as indifference/approval. I also found more use-cases for policies aside from user notices, some of which I posted in the original issue.

I'm not strictly opposed to support if you can write a clean PR with appropriate test coverage without a lot of guidance1 but I'm having a hard time seeing this as a genuine use case that will benefit a large enough number of people to be worth the ongoing maintenance.

@cpu

cpu commented Feb 12, 2026

Copy link
Copy Markdown
Member

@cpu Should I take your comment as active opposition to this PR?

No, I wouldn't characterize it as active opposition in the sense that I would be in favour of blocking a PR that other maintainers wanted to approve or something like that. If you can get approvals, I won't stand in the way :-)

it would have been nice if you were clear about that beforehand. I interpreted your previous comment as indifference/approval.

My previous comment also emphasized a desire for a clean PR with appropriate test coverage. I haven't looked at the substance of the diff, but the commit history is pretty messy in the current state. Apologies if I misrepresented my interest/availability for reviewing the work in general, but I think you still have a path forward with djc/est31.

@Gabgobie

Copy link
Copy Markdown
Author

Thank you for clarifying. I am trying to do as much on my own as possible but this being my first larger PR I am not sure about the design decisions you - as in all maintainers of this project - would prefer. Maybe it would be better if I just make a decision over trying to add suggestions to pick from.

I wasn't aware that a clean history is valuable since it will be squashed on merge anyways. I will look into cleaning that up as well.

I'll also give reviewing my own changes another try. Not having looked at it for ~3 weeks I should have a fresh pair of eyes.

@Gabgobie
Gabgobie marked this pull request as draft February 12, 2026 23:40
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch 2 times, most recently from 2992e38 to a80f896CompareFebruary 27, 2026 13:43
@Gabgobie

Gabgobie commented Feb 27, 2026

Copy link
Copy Markdown
Author

If the checks pass, which I'd expect after having them run locally, I'll look into ergonomics when consuming my fork and mark this ready for review afterwards.

#406 (comment)

Let's avoid adding any particular policies for this PR.

Would you like a separate PR or commit with constructors for commonly used/standardized policies or should I implement them on the consumer side? Without these constructors, the consumer needs to know OIDs and in some cases encode their own DER. rcgen generally abstracts this low-level stuff so this would feel out of place to me.

@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from a80f896 to d6bb0d4CompareMarch 13, 2026 16:10
Comment on lines +750 to +753
/// Returns the contained sequence of one or more policy information terms
pub fn policy_information(&self) -> &[PolicyInformation] {
&self.policy_information
}

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I somehow just now noticed that - aside from testing - from_x509 is useless anyways, see also:

Should I remove this getter and the pub on critical entirely?

Comment threadrcgen/src/certificate.rs Outdated
InhibitAnyPolicy is used to limit the use of the special policy anypolicy that circumvents validation. Policies must be validated for example when deciding the level of trust to put into a certificate. Common policies include 2.23.140.1.2 which denotes the validation procedure. 2.23.140.1.2.1 for example is "Domain Validation"
See also https://oid-base.com/get/2.23.140.1.2.1 or inspect a LetsEncrypt certificate
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from d6bb0d4 to af5b4c0CompareApril 2, 2026 21:44
@Gabgobie
Gabgobie marked this pull request as ready for review April 2, 2026 23:19
@Gabgobie

Copy link
Copy Markdown
Author

Cleaned the history, rebased and tried reviewing the proposed changes again. I think it's ready for another review at your leisure :D

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Gabgobie@cpu@djc
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Feature: Certificate policies - #406

Open
Gabgobie wants to merge 2 commits into
rustls:mainfrom
Gabgobie:certificate-policies
Open

Feature: Certificate policies#406
Gabgobie wants to merge 2 commits into
rustls:mainfrom
Gabgobie:certificate-policies

Conversation

@Gabgobie

@GabgobieGabgobie commented Jan 16, 2026

Copy link
Copy Markdown

Thanks for offering to review the PR @djc

Adds the following extensions

This PR handles two of the extensions listed/requested in #370

Compatibility check screenshots

Requested Screenshots

OpenSSL (WSL)

  • cd certs
  • openssl x509 --in cert.pem --text --noout
grafik

Windows "Krypto-Shellerweiterungen"

Ausstellerklärung:

grafik

Unfortunately the window can't be resized

grafikgrafikgrafik

Browsers

Minimal webserver

fromuvicornimportrunfromfastapiimportFastAPIrun(
FastAPI(),
host="127.0.0.1",
port=443,
ssl_certfile="certs/cert.pem",
ssl_keyfile="certs/key.pem",
)

Firefox

grafik

Chromium (Edge)

grafikgrafik

ASN.1 JavaScript decoder

Decode of a generated cert by cargo run --example certificate_policies

grafik

@Gabgobie

Copy link
Copy Markdown
Author

I'll take another look at test coverage and the pipeline checks in the coming days but wanted to get this out here since the output seems to at least be valid.

@Gabgobie
Gabgobie marked this pull request as draft January 16, 2026 18:18
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from fd4cb64 to 64ee5b1CompareJanuary 17, 2026 09:04
@Gabgobie
Gabgobie marked this pull request as ready for review January 18, 2026 18:43
@Gabgobie

Copy link
Copy Markdown
Author

Suppose this is about as ready for review as it can get. There are still changes to be made but I'll need to know which direction they should go in.

@djcdjc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1200 lines of code is a lot. I added a bunch of notes on how to pare that down.

Comment threadrcgen/Cargo.toml Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment on lines +841 to +842
/// ```rust
/// use rcgen::{CertificatePolicies, PolicyInformation, Error};

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Also too much.

Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
@cpu

cpu commented Jan 19, 2026

Copy link
Copy Markdown
Member

For whatever it's worth I remain not keen on supporting certificate policies and don't plan to try to review this work.

@Gabgobie
Gabgobieforce-pushed the certificate-policies branch 3 times, most recently from 86d4652 to 275c30cCompareJanuary 19, 2026 17:51
@Gabgobie

Copy link
Copy Markdown
Author

My apologies. I just took a look at the PR from a private window and noticed that my replies were never published. PR inexperience...

I thought you were just busy! I'll look into what it takes to publish a response.


@cpu Should I take your comment as active opposition to this PR? I'll be happy to make more changes but it would have been nice if you were clear about that beforehand. I interpreted your previous comment as indifference/approval. I also found more use-cases for policies aside from user notices, some of which I posted in the original issue.

I'm not strictly opposed to support if you can write a clean PR with appropriate test coverage without a lot of guidance1 but I'm having a hard time seeing this as a genuine use case that will benefit a large enough number of people to be worth the ongoing maintenance.

@cpu

cpu commented Feb 12, 2026

Copy link
Copy Markdown
Member

@cpu Should I take your comment as active opposition to this PR?

No, I wouldn't characterize it as active opposition in the sense that I would be in favour of blocking a PR that other maintainers wanted to approve or something like that. If you can get approvals, I won't stand in the way :-)

it would have been nice if you were clear about that beforehand. I interpreted your previous comment as indifference/approval.

My previous comment also emphasized a desire for a clean PR with appropriate test coverage. I haven't looked at the substance of the diff, but the commit history is pretty messy in the current state. Apologies if I misrepresented my interest/availability for reviewing the work in general, but I think you still have a path forward with djc/est31.

@Gabgobie

Copy link
Copy Markdown
Author

Thank you for clarifying. I am trying to do as much on my own as possible but this being my first larger PR I am not sure about the design decisions you - as in all maintainers of this project - would prefer. Maybe it would be better if I just make a decision over trying to add suggestions to pick from.

I wasn't aware that a clean history is valuable since it will be squashed on merge anyways. I will look into cleaning that up as well.

I'll also give reviewing my own changes another try. Not having looked at it for ~3 weeks I should have a fresh pair of eyes.

@Gabgobie
Gabgobie marked this pull request as draft February 12, 2026 23:40
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch 2 times, most recently from 2992e38 to a80f896CompareFebruary 27, 2026 13:43
@Gabgobie

Gabgobie commented Feb 27, 2026

Copy link
Copy Markdown
Author

If the checks pass, which I'd expect after having them run locally, I'll look into ergonomics when consuming my fork and mark this ready for review afterwards.

#406 (comment)

Let's avoid adding any particular policies for this PR.

Would you like a separate PR or commit with constructors for commonly used/standardized policies or should I implement them on the consumer side? Without these constructors, the consumer needs to know OIDs and in some cases encode their own DER. rcgen generally abstracts this low-level stuff so this would feel out of place to me.

@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from a80f896 to d6bb0d4CompareMarch 13, 2026 16:10
Comment on lines +750 to +753
/// Returns the contained sequence of one or more policy information terms
pub fn policy_information(&self) -> &[PolicyInformation] {
&self.policy_information
}

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I somehow just now noticed that - aside from testing - from_x509 is useless anyways, see also:

Should I remove this getter and the pub on critical entirely?

Comment threadrcgen/src/certificate.rs Outdated
InhibitAnyPolicy is used to limit the use of the special policy anypolicy that circumvents validation. Policies must be validated for example when deciding the level of trust to put into a certificate. Common policies include 2.23.140.1.2 which denotes the validation procedure. 2.23.140.1.2.1 for example is "Domain Validation"
See also https://oid-base.com/get/2.23.140.1.2.1 or inspect a LetsEncrypt certificate
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from d6bb0d4 to af5b4c0CompareApril 2, 2026 21:44
@Gabgobie
Gabgobie marked this pull request as ready for review April 2, 2026 23:19
@Gabgobie

Copy link
Copy Markdown
Author

Cleaned the history, rebased and tried reviewing the proposed changes again. I think it's ready for another review at your leisure :D

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Gabgobie@cpu@djc
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Feature: Certificate policies - #406

Open
Gabgobie wants to merge 2 commits into
rustls:mainfrom
Gabgobie:certificate-policies
Open

Feature: Certificate policies#406
Gabgobie wants to merge 2 commits into
rustls:mainfrom
Gabgobie:certificate-policies

Conversation

@Gabgobie

@GabgobieGabgobie commented Jan 16, 2026

Copy link
Copy Markdown

Thanks for offering to review the PR @djc

Adds the following extensions

This PR handles two of the extensions listed/requested in #370

Compatibility check screenshots

Requested Screenshots

OpenSSL (WSL)

  • cd certs
  • openssl x509 --in cert.pem --text --noout
grafik

Windows "Krypto-Shellerweiterungen"

Ausstellerklärung:

grafik

Unfortunately the window can't be resized

grafikgrafikgrafik

Browsers

Minimal webserver

fromuvicornimportrunfromfastapiimportFastAPIrun(
FastAPI(),
host="127.0.0.1",
port=443,
ssl_certfile="certs/cert.pem",
ssl_keyfile="certs/key.pem",
)

Firefox

grafik

Chromium (Edge)

grafikgrafik

ASN.1 JavaScript decoder

Decode of a generated cert by cargo run --example certificate_policies

grafik

@Gabgobie

Copy link
Copy Markdown
Author

I'll take another look at test coverage and the pipeline checks in the coming days but wanted to get this out here since the output seems to at least be valid.

@Gabgobie
Gabgobie marked this pull request as draft January 16, 2026 18:18
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from fd4cb64 to 64ee5b1CompareJanuary 17, 2026 09:04
@Gabgobie
Gabgobie marked this pull request as ready for review January 18, 2026 18:43
@Gabgobie

Copy link
Copy Markdown
Author

Suppose this is about as ready for review as it can get. There are still changes to be made but I'll need to know which direction they should go in.

@djcdjc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1200 lines of code is a lot. I added a bunch of notes on how to pare that down.

Comment threadrcgen/Cargo.toml Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment on lines +841 to +842
/// ```rust
/// use rcgen::{CertificatePolicies, PolicyInformation, Error};

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Also too much.

Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
@cpu

cpu commented Jan 19, 2026

Copy link
Copy Markdown
Member

For whatever it's worth I remain not keen on supporting certificate policies and don't plan to try to review this work.

@Gabgobie
Gabgobieforce-pushed the certificate-policies branch 3 times, most recently from 86d4652 to 275c30cCompareJanuary 19, 2026 17:51
@Gabgobie

Copy link
Copy Markdown
Author

My apologies. I just took a look at the PR from a private window and noticed that my replies were never published. PR inexperience...

I thought you were just busy! I'll look into what it takes to publish a response.


@cpu Should I take your comment as active opposition to this PR? I'll be happy to make more changes but it would have been nice if you were clear about that beforehand. I interpreted your previous comment as indifference/approval. I also found more use-cases for policies aside from user notices, some of which I posted in the original issue.

I'm not strictly opposed to support if you can write a clean PR with appropriate test coverage without a lot of guidance1 but I'm having a hard time seeing this as a genuine use case that will benefit a large enough number of people to be worth the ongoing maintenance.

@cpu

cpu commented Feb 12, 2026

Copy link
Copy Markdown
Member

@cpu Should I take your comment as active opposition to this PR?

No, I wouldn't characterize it as active opposition in the sense that I would be in favour of blocking a PR that other maintainers wanted to approve or something like that. If you can get approvals, I won't stand in the way :-)

it would have been nice if you were clear about that beforehand. I interpreted your previous comment as indifference/approval.

My previous comment also emphasized a desire for a clean PR with appropriate test coverage. I haven't looked at the substance of the diff, but the commit history is pretty messy in the current state. Apologies if I misrepresented my interest/availability for reviewing the work in general, but I think you still have a path forward with djc/est31.

@Gabgobie

Copy link
Copy Markdown
Author

Thank you for clarifying. I am trying to do as much on my own as possible but this being my first larger PR I am not sure about the design decisions you - as in all maintainers of this project - would prefer. Maybe it would be better if I just make a decision over trying to add suggestions to pick from.

I wasn't aware that a clean history is valuable since it will be squashed on merge anyways. I will look into cleaning that up as well.

I'll also give reviewing my own changes another try. Not having looked at it for ~3 weeks I should have a fresh pair of eyes.

@Gabgobie
Gabgobie marked this pull request as draft February 12, 2026 23:40
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch 2 times, most recently from 2992e38 to a80f896CompareFebruary 27, 2026 13:43
@Gabgobie

Gabgobie commented Feb 27, 2026

Copy link
Copy Markdown
Author

If the checks pass, which I'd expect after having them run locally, I'll look into ergonomics when consuming my fork and mark this ready for review afterwards.

#406 (comment)

Let's avoid adding any particular policies for this PR.

Would you like a separate PR or commit with constructors for commonly used/standardized policies or should I implement them on the consumer side? Without these constructors, the consumer needs to know OIDs and in some cases encode their own DER. rcgen generally abstracts this low-level stuff so this would feel out of place to me.

@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from a80f896 to d6bb0d4CompareMarch 13, 2026 16:10
Comment on lines +750 to +753
/// Returns the contained sequence of one or more policy information terms
pub fn policy_information(&self) -> &[PolicyInformation] {
&self.policy_information
}

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I somehow just now noticed that - aside from testing - from_x509 is useless anyways, see also:

Should I remove this getter and the pub on critical entirely?

Comment threadrcgen/src/certificate.rs Outdated
InhibitAnyPolicy is used to limit the use of the special policy anypolicy that circumvents validation. Policies must be validated for example when deciding the level of trust to put into a certificate. Common policies include 2.23.140.1.2 which denotes the validation procedure. 2.23.140.1.2.1 for example is "Domain Validation"
See also https://oid-base.com/get/2.23.140.1.2.1 or inspect a LetsEncrypt certificate
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from d6bb0d4 to af5b4c0CompareApril 2, 2026 21:44
@Gabgobie
Gabgobie marked this pull request as ready for review April 2, 2026 23:19
@Gabgobie

Copy link
Copy Markdown
Author

Cleaned the history, rebased and tried reviewing the proposed changes again. I think it's ready for another review at your leisure :D

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Gabgobie@cpu@djc
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Feature: Certificate policies - #406

Open
Gabgobie wants to merge 2 commits into
rustls:mainfrom
Gabgobie:certificate-policies
Open

Feature: Certificate policies#406
Gabgobie wants to merge 2 commits into
rustls:mainfrom
Gabgobie:certificate-policies

Conversation

@Gabgobie

@GabgobieGabgobie commented Jan 16, 2026

Copy link
Copy Markdown

Thanks for offering to review the PR @djc

Adds the following extensions

This PR handles two of the extensions listed/requested in #370

Compatibility check screenshots

Requested Screenshots

OpenSSL (WSL)

  • cd certs
  • openssl x509 --in cert.pem --text --noout
grafik

Windows "Krypto-Shellerweiterungen"

Ausstellerklärung:

grafik

Unfortunately the window can't be resized

grafikgrafikgrafik

Browsers

Minimal webserver

fromuvicornimportrunfromfastapiimportFastAPIrun(
FastAPI(),
host="127.0.0.1",
port=443,
ssl_certfile="certs/cert.pem",
ssl_keyfile="certs/key.pem",
)

Firefox

grafik

Chromium (Edge)

grafikgrafik

ASN.1 JavaScript decoder

Decode of a generated cert by cargo run --example certificate_policies

grafik

@Gabgobie

Copy link
Copy Markdown
Author

I'll take another look at test coverage and the pipeline checks in the coming days but wanted to get this out here since the output seems to at least be valid.

@Gabgobie
Gabgobie marked this pull request as draft January 16, 2026 18:18
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from fd4cb64 to 64ee5b1CompareJanuary 17, 2026 09:04
@Gabgobie
Gabgobie marked this pull request as ready for review January 18, 2026 18:43
@Gabgobie

Copy link
Copy Markdown
Author

Suppose this is about as ready for review as it can get. There are still changes to be made but I'll need to know which direction they should go in.

@djcdjc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1200 lines of code is a lot. I added a bunch of notes on how to pare that down.

Comment threadrcgen/Cargo.toml Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment on lines +841 to +842
/// ```rust
/// use rcgen::{CertificatePolicies, PolicyInformation, Error};

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Also too much.

Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
@cpu

cpu commented Jan 19, 2026

Copy link
Copy Markdown
Member

For whatever it's worth I remain not keen on supporting certificate policies and don't plan to try to review this work.

@Gabgobie
Gabgobieforce-pushed the certificate-policies branch 3 times, most recently from 86d4652 to 275c30cCompareJanuary 19, 2026 17:51
@Gabgobie

Copy link
Copy Markdown
Author

My apologies. I just took a look at the PR from a private window and noticed that my replies were never published. PR inexperience...

I thought you were just busy! I'll look into what it takes to publish a response.


@cpu Should I take your comment as active opposition to this PR? I'll be happy to make more changes but it would have been nice if you were clear about that beforehand. I interpreted your previous comment as indifference/approval. I also found more use-cases for policies aside from user notices, some of which I posted in the original issue.

I'm not strictly opposed to support if you can write a clean PR with appropriate test coverage without a lot of guidance1 but I'm having a hard time seeing this as a genuine use case that will benefit a large enough number of people to be worth the ongoing maintenance.

@cpu

cpu commented Feb 12, 2026

Copy link
Copy Markdown
Member

@cpu Should I take your comment as active opposition to this PR?

No, I wouldn't characterize it as active opposition in the sense that I would be in favour of blocking a PR that other maintainers wanted to approve or something like that. If you can get approvals, I won't stand in the way :-)

it would have been nice if you were clear about that beforehand. I interpreted your previous comment as indifference/approval.

My previous comment also emphasized a desire for a clean PR with appropriate test coverage. I haven't looked at the substance of the diff, but the commit history is pretty messy in the current state. Apologies if I misrepresented my interest/availability for reviewing the work in general, but I think you still have a path forward with djc/est31.

@Gabgobie

Copy link
Copy Markdown
Author

Thank you for clarifying. I am trying to do as much on my own as possible but this being my first larger PR I am not sure about the design decisions you - as in all maintainers of this project - would prefer. Maybe it would be better if I just make a decision over trying to add suggestions to pick from.

I wasn't aware that a clean history is valuable since it will be squashed on merge anyways. I will look into cleaning that up as well.

I'll also give reviewing my own changes another try. Not having looked at it for ~3 weeks I should have a fresh pair of eyes.

@Gabgobie
Gabgobie marked this pull request as draft February 12, 2026 23:40
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch 2 times, most recently from 2992e38 to a80f896CompareFebruary 27, 2026 13:43
@Gabgobie

Gabgobie commented Feb 27, 2026

Copy link
Copy Markdown
Author

If the checks pass, which I'd expect after having them run locally, I'll look into ergonomics when consuming my fork and mark this ready for review afterwards.

#406 (comment)

Let's avoid adding any particular policies for this PR.

Would you like a separate PR or commit with constructors for commonly used/standardized policies or should I implement them on the consumer side? Without these constructors, the consumer needs to know OIDs and in some cases encode their own DER. rcgen generally abstracts this low-level stuff so this would feel out of place to me.

@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from a80f896 to d6bb0d4CompareMarch 13, 2026 16:10
Comment on lines +750 to +753
/// Returns the contained sequence of one or more policy information terms
pub fn policy_information(&self) -> &[PolicyInformation] {
&self.policy_information
}

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I somehow just now noticed that - aside from testing - from_x509 is useless anyways, see also:

Should I remove this getter and the pub on critical entirely?

Comment threadrcgen/src/certificate.rs Outdated
InhibitAnyPolicy is used to limit the use of the special policy anypolicy that circumvents validation. Policies must be validated for example when deciding the level of trust to put into a certificate. Common policies include 2.23.140.1.2 which denotes the validation procedure. 2.23.140.1.2.1 for example is "Domain Validation"
See also https://oid-base.com/get/2.23.140.1.2.1 or inspect a LetsEncrypt certificate
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from d6bb0d4 to af5b4c0CompareApril 2, 2026 21:44
@Gabgobie
Gabgobie marked this pull request as ready for review April 2, 2026 23:19
@Gabgobie

Copy link
Copy Markdown
Author

Cleaned the history, rebased and tried reviewing the proposed changes again. I think it's ready for another review at your leisure :D

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Gabgobie@cpu@djc
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Feature: Certificate policies - #406

Open
Gabgobie wants to merge 2 commits into
rustls:mainfrom
Gabgobie:certificate-policies
Open

Feature: Certificate policies#406
Gabgobie wants to merge 2 commits into
rustls:mainfrom
Gabgobie:certificate-policies

Conversation

@Gabgobie

@GabgobieGabgobie commented Jan 16, 2026

Copy link
Copy Markdown

Thanks for offering to review the PR @djc

Adds the following extensions

This PR handles two of the extensions listed/requested in #370

Compatibility check screenshots

Requested Screenshots

OpenSSL (WSL)

  • cd certs
  • openssl x509 --in cert.pem --text --noout
grafik

Windows "Krypto-Shellerweiterungen"

Ausstellerklärung:

grafik

Unfortunately the window can't be resized

grafikgrafikgrafik

Browsers

Minimal webserver

fromuvicornimportrunfromfastapiimportFastAPIrun(
FastAPI(),
host="127.0.0.1",
port=443,
ssl_certfile="certs/cert.pem",
ssl_keyfile="certs/key.pem",
)

Firefox

grafik

Chromium (Edge)

grafikgrafik

ASN.1 JavaScript decoder

Decode of a generated cert by cargo run --example certificate_policies

grafik

@Gabgobie

Copy link
Copy Markdown
Author

I'll take another look at test coverage and the pipeline checks in the coming days but wanted to get this out here since the output seems to at least be valid.

@Gabgobie
Gabgobie marked this pull request as draft January 16, 2026 18:18
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from fd4cb64 to 64ee5b1CompareJanuary 17, 2026 09:04
@Gabgobie
Gabgobie marked this pull request as ready for review January 18, 2026 18:43
@Gabgobie

Copy link
Copy Markdown
Author

Suppose this is about as ready for review as it can get. There are still changes to be made but I'll need to know which direction they should go in.

@djcdjc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

1200 lines of code is a lot. I added a bunch of notes on how to pare that down.

Comment threadrcgen/Cargo.toml Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment on lines +841 to +842
/// ```rust
/// use rcgen::{CertificatePolicies, PolicyInformation, Error};

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Also too much.

Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
@cpu

cpu commented Jan 19, 2026

Copy link
Copy Markdown
Member

For whatever it's worth I remain not keen on supporting certificate policies and don't plan to try to review this work.

@Gabgobie
Gabgobieforce-pushed the certificate-policies branch 3 times, most recently from 86d4652 to 275c30cCompareJanuary 19, 2026 17:51
@Gabgobie

Copy link
Copy Markdown
Author

My apologies. I just took a look at the PR from a private window and noticed that my replies were never published. PR inexperience...

I thought you were just busy! I'll look into what it takes to publish a response.


@cpu Should I take your comment as active opposition to this PR? I'll be happy to make more changes but it would have been nice if you were clear about that beforehand. I interpreted your previous comment as indifference/approval. I also found more use-cases for policies aside from user notices, some of which I posted in the original issue.

I'm not strictly opposed to support if you can write a clean PR with appropriate test coverage without a lot of guidance1 but I'm having a hard time seeing this as a genuine use case that will benefit a large enough number of people to be worth the ongoing maintenance.

@cpu

cpu commented Feb 12, 2026

Copy link
Copy Markdown
Member

@cpu Should I take your comment as active opposition to this PR?

No, I wouldn't characterize it as active opposition in the sense that I would be in favour of blocking a PR that other maintainers wanted to approve or something like that. If you can get approvals, I won't stand in the way :-)

it would have been nice if you were clear about that beforehand. I interpreted your previous comment as indifference/approval.

My previous comment also emphasized a desire for a clean PR with appropriate test coverage. I haven't looked at the substance of the diff, but the commit history is pretty messy in the current state. Apologies if I misrepresented my interest/availability for reviewing the work in general, but I think you still have a path forward with djc/est31.

@Gabgobie

Copy link
Copy Markdown
Author

Thank you for clarifying. I am trying to do as much on my own as possible but this being my first larger PR I am not sure about the design decisions you - as in all maintainers of this project - would prefer. Maybe it would be better if I just make a decision over trying to add suggestions to pick from.

I wasn't aware that a clean history is valuable since it will be squashed on merge anyways. I will look into cleaning that up as well.

I'll also give reviewing my own changes another try. Not having looked at it for ~3 weeks I should have a fresh pair of eyes.

@Gabgobie
Gabgobie marked this pull request as draft February 12, 2026 23:40
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
Comment threadrcgen/src/certificate.rs Outdated
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch 2 times, most recently from 2992e38 to a80f896CompareFebruary 27, 2026 13:43
@Gabgobie

Gabgobie commented Feb 27, 2026

Copy link
Copy Markdown
Author

If the checks pass, which I'd expect after having them run locally, I'll look into ergonomics when consuming my fork and mark this ready for review afterwards.

#406 (comment)

Let's avoid adding any particular policies for this PR.

Would you like a separate PR or commit with constructors for commonly used/standardized policies or should I implement them on the consumer side? Without these constructors, the consumer needs to know OIDs and in some cases encode their own DER. rcgen generally abstracts this low-level stuff so this would feel out of place to me.

@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from a80f896 to d6bb0d4CompareMarch 13, 2026 16:10
Comment on lines +750 to +753
/// Returns the contained sequence of one or more policy information terms
pub fn policy_information(&self) -> &[PolicyInformation] {
&self.policy_information
}

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I somehow just now noticed that - aside from testing - from_x509 is useless anyways, see also:

Should I remove this getter and the pub on critical entirely?

Comment threadrcgen/src/certificate.rs Outdated
InhibitAnyPolicy is used to limit the use of the special policy anypolicy that circumvents validation. Policies must be validated for example when deciding the level of trust to put into a certificate. Common policies include 2.23.140.1.2 which denotes the validation procedure. 2.23.140.1.2.1 for example is "Domain Validation"
See also https://oid-base.com/get/2.23.140.1.2.1 or inspect a LetsEncrypt certificate
@Gabgobie
Gabgobieforce-pushed the certificate-policies branch from d6bb0d4 to af5b4c0CompareApril 2, 2026 21:44
@Gabgobie
Gabgobie marked this pull request as ready for review April 2, 2026 23:19
@Gabgobie

Copy link
Copy Markdown
Author

Cleaned the history, rebased and tried reviewing the proposed changes again. I think it's ready for another review at your leisure :D

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Gabgobie@cpu@djc