Skip to main content

EnrollRequest

Struct EnrollRequest 

Source
pub struct EnrollRequest { /* private fields */ }
Expand description

Enrollment request containing a PKCS#10 CSR (RFC 7030 §4.2.1).

The CSR must include:

  • Subject public key (ML-DSA, ML-KEM, or traditional)
  • Subject distinguished name
  • Signature proving possession of the private key (POP)

For ML-DSA CSRs, the signature algorithm OID indicates the ML-DSA level. For ML-KEM CSRs, a separate ML-DSA signature is required for POP.

The wire format is a DER-encoded CertificationRequest per RFC 2986. Use CertificationRequest for parsed/structured access to CSR fields.

Implementations§

Source§

impl EnrollRequest

Source

pub fn new(csr_der: Vec<u8>) -> Self

Creates a new enrollment request from a DER-encoded PKCS#10 CSR.

Source

pub fn csr_der(&self) -> &[u8]

Returns the raw DER-encoded CSR.

Source

pub fn into_csr_der(self) -> Vec<u8>

Consumes self and returns the DER-encoded CSR.

Source

pub fn to_base64(&self) -> String

Encodes the request as base64 for HTTP transport.

Source

pub fn from_base64(base64_data: &str) -> EstResult<Self>

Decodes a base64-encoded enrollment request.

Source

pub fn validate(&self) -> EstResult<()>

Validates the CSR structure and proof-of-possession.

This performs basic DER validation. Full cryptographic validation (signature verification) is delegated to the CA module.

Source

pub fn detect_signature_algorithm(&self) -> Option<String>

Detects the signature algorithm OID from the CSR.

Returns the OID string if found, or None if parsing fails. This is used to route CSRs to the appropriate CA signing key (ML-DSA-44/65/87, composite, or traditional).

Note: This is a simple heuristic parser. Full ASN.1 parsing is performed by the CA module.

Source

pub fn contains_ml_dsa(&self) -> bool

Checks if the CSR appears to contain an ML-DSA public key.

Searches for ML-DSA OID prefixes in the DER structure.

Source

pub fn contains_ml_kem(&self) -> bool

Checks if the CSR appears to contain an ML-KEM public key.

Searches for ML-KEM OID prefixes in the DER structure.

Source

pub fn to_certification_request(&self) -> CertificationRequest

Returns a parsed CertificationRequest from the DER-encoded CSR.

This is a placeholder that creates a CertificationRequest with default/empty fields. Full ASN.1 parsing of the RFC 2986 structure is performed by the CA module using synta.

Callers should use this to get the struct, then have the CA module populate the fields from actual DER parsing.

Trait Implementations§

Source§

impl Clone for EnrollRequest

Source§

fn clone(&self) -> EnrollRequest

Returns a duplicate of the value. Read more
1.0.0 · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for EnrollRequest

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for EnrollRequest

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl PartialEq for EnrollRequest

Source§

fn eq(&self, other: &EnrollRequest) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 · Source§

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.
Source§

impl Serialize for EnrollRequest

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl Eq for EnrollRequest

Source§

impl StructuralPartialEq for EnrollRequest

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,