Skip to content

refactor(tsa)!: keep the RFC 3161 ASN.1 model private - #245

Merged
baszalmstra merged 1 commit into
mainfrom
refactor/tsa-private-asn1
Sep 24, 2026
Merged

baszalmstra merged 1 commit into
mainfrom
refactor/tsa-private-asn1

Conversation

@wolfv

@wolfv wolfv commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

Summary

1.0 API work, the TSA PR in the plan.

Why: the public asn1 and verify modules exposed structs with public fields and return types from der, cms, const-oid and x509-cert (for example, parse_timestamp_token returned a cms::SignedData). That made those 0.x crates part of sigstore-tsa's semver, so the planned ASN.1 upgrade (#224) would have been a breaking change after 1.0. With this PR (and the crypto counterpart, C-a) it can ship in a minor release.

  • asn1 and verify are private, and parse_timestamp_token is crate-private. The re-exports of AlgorithmIdentifier, Asn1MessageImprint, PkiStatus, TimeStampReq, TimeStampResp and TstInfo are dropped, along with helpers nothing internal used
  • the public API is now TimestampClient / TimestampClientBuilder, verify_timestamp_for_authority, Error and TsaAuthority
  • verify_timestamp_for_authority takes &TimestampToken and &SignatureBytes instead of two &[u8]
  • TimestampClient:
    • TimestampClient::builder(url).timeout(..).user_agent(..).build(), with a default UA of sigstore-rust/<version>
    • new returns Result instead of panicking on HTTP client setup
    • new_with_timeout is removed, and so are the built-in sigstore() / freetsa() URLs (same reasoning as refactor(rekor)!: remove built-in log URLs and fix stale docs #240)
    • new timestamp_digest(&ArtifactDigest)
  • Error is #[non_exhaustive], and the duplicate ParseError is merged into Parse

Validation

  • cargo clippy --workspace --all-targets --all-features -- -D warnings
  • cargo test -p sigstore-tsa -p sigstore-verify -p sigstore-sign -p sigstore-conformance --all-features
  • cargo check --no-default-features for tsa and verify

Signed-off-by: Wolf Vollprecht w.vollprecht@gmail.com

🤖 Generated with Claude Code

The public `asn1` and `verify` modules exposed structs with public `der`,
`cms`, `const-oid` and `x509-cert` fields and return types
(`parse_timestamp_token` returned `cms::SignedData`). Those 0.x crates
became part of sigstore-tsa's semver, so the planned ASN.1 dependency
upgrade (#224) would have been a breaking change.

- Make `asn1` and `verify` private and `parse_timestamp_token`
  crate-private; drop the re-exports of `AlgorithmIdentifier`,
  `Asn1MessageImprint`, `PkiStatus`, `TimeStampReq`, `TimeStampResp`
  and `TstInfo`, and remove helpers that only external callers used.
- `verify_timestamp_for_authority` takes `&TimestampToken` and
  `&SignatureBytes` instead of two byte slices.
- `TimestampClient`: add `TimestampClient::builder(url)` with `timeout`
  and `user_agent` (default `sigstore-rust/<version>`); `new` returns
  `Result` instead of panicking on HTTP client setup; remove
  `new_with_timeout` and the built-in `sigstore()` / `freetsa()` URLs; add
  `timestamp_digest(&ArtifactDigest)`.
- `Error` is `#[non_exhaustive]`, and the duplicate `ParseError` variant
  is merged into `Parse`.

BREAKING CHANGE: `sigstore_tsa::asn1` and `sigstore_tsa::verify` are no
longer public; `verify_timestamp_for_authority` takes typed arguments;
`TimestampClient::new` returns `Result`, and `new_with_timeout`,
`sigstore` and `freetsa` are removed; `Error::ParseError` is merged into
`Error::Parse`.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
@baszalmstra
baszalmstra merged commit c3231d5 into main Sep 24, 2026
19 checks passed
@baszalmstra
baszalmstra deleted the refactor/tsa-private-asn1 branch September 24, 2026 16:01
jku pushed a commit that referenced this pull request Sep 30, 2026
The RFC 3161 request types and nonce generation are only used by the TSA
client, and the Rekor v1 entry-response map only by the Rekor client.
Since the ASN.1 module became private (#245) and the response map
crate-private (#251), offline builds (default features off, as used by
sigstore-verify) warned about them. Compile them only with the client
feature or in tests.

Signed-off-by: Wolf Vollprecht <w.vollprecht@gmail.com>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants