Repository navigation
refactor(tsa)!: keep the RFC 3161 ASN.1 model private - #245
Merged
Merged
Conversation
The public `asn1` and `verify` modules exposed structs with public `der`, `cms`, `const-oid` and `x509-cert` fields and return types (`parse_timestamp_token` returned `cms::SignedData`). Those 0.x crates became part of sigstore-tsa's semver, so the planned ASN.1 dependency upgrade (#224) would have been a breaking change. - Make `asn1` and `verify` private and `parse_timestamp_token` crate-private; drop the re-exports of `AlgorithmIdentifier`, `Asn1MessageImprint`, `PkiStatus`, `TimeStampReq`, `TimeStampResp` and `TstInfo`, and remove helpers that only external callers used. - `verify_timestamp_for_authority` takes `&TimestampToken` and `&SignatureBytes` instead of two byte slices. - `TimestampClient`: add `TimestampClient::builder(url)` with `timeout` and `user_agent` (default `sigstore-rust/<version>`); `new` returns `Result` instead of panicking on HTTP client setup; remove `new_with_timeout` and the built-in `sigstore()` / `freetsa()` URLs; add `timestamp_digest(&ArtifactDigest)`. - `Error` is `#[non_exhaustive]`, and the duplicate `ParseError` variant is merged into `Parse`. BREAKING CHANGE: `sigstore_tsa::asn1` and `sigstore_tsa::verify` are no longer public; `verify_timestamp_for_authority` takes typed arguments; `TimestampClient::new` returns `Result`, and `new_with_timeout`, `sigstore` and `freetsa` are removed; `Error::ParseError` is merged into `Error::Parse`. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
baszalmstra
approved these changes
Sep 24, 2026
This was referenced Sep 24, 2026
Merged
jku
pushed a commit
that referenced
this pull request
Sep 30, 2026
The RFC 3161 request types and nonce generation are only used by the TSA client, and the Rekor v1 entry-response map only by the Rekor client. Since the ASN.1 module became private (#245) and the response map crate-private (#251), offline builds (default features off, as used by sigstore-verify) warned about them. Compile them only with the client feature or in tests. Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
1.0 API work, the TSA PR in the plan.
Why: the public
asn1andverifymodules exposed structs with public fields and return types fromder,cms,const-oidandx509-cert(for example,parse_timestamp_tokenreturned acms::SignedData). That made those 0.x crates part of sigstore-tsa's semver, so the planned ASN.1 upgrade (#224) would have been a breaking change after 1.0. With this PR (and the crypto counterpart, C-a) it can ship in a minor release.asn1andverifyare private, andparse_timestamp_tokenis crate-private. The re-exports ofAlgorithmIdentifier,Asn1MessageImprint,PkiStatus,TimeStampReq,TimeStampRespandTstInfoare dropped, along with helpers nothing internal usedTimestampClient/TimestampClientBuilder,verify_timestamp_for_authority,ErrorandTsaAuthorityverify_timestamp_for_authoritytakes&TimestampTokenand&SignatureBytesinstead of two&[u8]TimestampClient:TimestampClient::builder(url).timeout(..).user_agent(..).build(), with a default UA ofsigstore-rust/<version>newreturnsResultinstead of panicking on HTTP client setupnew_with_timeoutis removed, and so are the built-insigstore()/freetsa()URLs (same reasoning as refactor(rekor)!: remove built-in log URLs and fix stale docs #240)timestamp_digest(&ArtifactDigest)Erroris#[non_exhaustive], and the duplicateParseErroris merged intoParseValidation
cargo clippy --workspace --all-targets --all-features -- -D warningscargo test -p sigstore-tsa -p sigstore-verify -p sigstore-sign -p sigstore-conformance --all-featurescargo check --no-default-featuresfor tsa and verifySigned-off-by: Wolf Vollprecht w.vollprecht@gmail.com
🤖 Generated with Claude Code