NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #4365 most downloaded on crates.io
Provides ASN1 types defined by X.509 related RFCs
Last release 7 days ago
01 Oct 2026
Release timing varies
gaps range from 2 weeks to 5 months
Most releases are documented
notes for 31 of 36 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
36 releases · first in 2020
One column per quarter.
chore: Release package picky-asn1-x509 version 0.15.5
chore: Release package picky-asn1-x509 version 0.15.5
IAKERB5 OID and its iakerb5() helper to picky_asn1_x509::oids (#531) (6f980446a3)chore: Release package picky-asn1-x509 version 0.15.4
chore: Release package picky-asn1-x509 version 0.15.4
### <!-- 7 -->Build - Update crypto dependencies
### <!-- 7 -->Build - Remove num-bigint-dig
Support parsing certs with MLDSA public keys
Improve support for SHA3 digests within EC and RSA certificates
### <!-- 1 -->Features - Add smart card logon oid
The Drop implementation of the RsaPrivateKey struct was only partially zeroizing the secrets.
Properly zeroize RsaPrivateKey (#386) (ace208d604)
The Drop implementation of the RsaPrivateKey struct was only partially zeroizing the secrets.
Invalid parameters for ecdsa with sha512 serialization
Symlinks to license files in packages
Symlinks to license files in packages (#339) (1834c04f39)
Use symlinks instead of copying files to avoid a “dirty” state during cargo publish and preserve VCS info. With #337 merged, CI handles publishing consistently, so developer environments no longer matter.
Add ContentInfo in pkcs7 module
AesAuthEncParams::new method (#336) (c33cf22bac)
Add enveloped-data oid (#335) (c077c72ee9)
Add ContentInfo in pkcs7 module (#334) (eaa43c36f6)
picky-test-data is a new dev-dependency.
picky-test-data is a new dev-dependency.EnvelopedData and related structures
EnvelopedData and related structuresNothing published for this version
Bump minimal rustc version to 1.61
Nothing published for this version
License files are now correctly included in the published package
Renamed oids::pkcs7 to correct oids::content_info_type_data
oids::pkcs7 to correct oids::content_info_type_dataFixed AlgorithmIdentifier parsing: made ECParameters non-optional for EC keys
AlgorithmIdentifier parsing: made ECParameters non-optional for EC keysECParameters - public_key now allowed to be optionaloid is now added as re-exportEcParameters::curve_oidPrivateKeyInfo::new_ec_encryptionsignature::EcdsaSignatureValueAlgorithmIdentifier::is_one_ofAlgorithmIdentifier::new_x25519AlgorithmIdentifier::new_ed448AlgorithmIdentifier::new_x448PrivateKeyInfo::new_ed_encryptionSubjectPublicKeyInfo::new_ed_keyprivate_key_info::PRIVATE_KEY_INFO_VERSION_1private_key_info::PRIVATE_KEY_INFO_VERSION_2AlgorithmIdentifier::new_elliptic_curve now accepts EcParameters instead of impl Into<Option<EcParameters>>AlgorithmIdentifierParameters::Ec now have EcParameters instead of Option<EcParameters>SubjectPublicKeyInfo::new_ec_key now accepts curve's ObjectIdentifier and point as BitStringPrivateKeyInfo structure now also could represent newer OneAsymmetricKey structure
(structures are backward-compatible). This allows to represent Ed keys with public key field setNothing published for this version
More OIDs such as PKINIT_AUTH_DATA and PKINIT_DH_KEY_DATA
Implement Zeroize on ECPrivateKey and RsaPrivateKey (behind feature zeroize)
Zeroize on ECPrivateKey and RsaPrivateKey (behind feature zeroize)### Added - OIDs used by NLA protocols
Support for Authenticode timestamp deserialization/serialization
ctl featureSpcSipInfo structTimestampRequestAttribute::new_content_type_pkcs7Attribute::new_signing_timeAttribute::new_message_digestEncapsulatedContentInfo::new_pkcs7_data methodShaVariant enum is extended for MD5 and SH1 algorithmsSpcStatementType variant in AttributeValues enumSigningTime variant in AttributeValues enumSpcAttributeAndOptionalValue now supports both SpcPeImageData and SpcSipInfo valuesRevocationInfoChoice field is now optional as specified by the RFCCertificateSet is now a Vec<CertificateChoices> which can accept both a normal Certificate and an other kind of certificate as specified by the RFCNothing published for this version
### Added - More ECC OIDs
Support for V1 and V2 X509 certificates
CrlNumber extension (#83)pkcs7 feature (#83)ContentType, MessageDigest and SpcSpOpusInfo (#83)ImplicitCurve from EcParameters enum (#85)Support for attributes in CertificationRequestInfo
CertificationRequestInfo (#78)Support for Ed25519 AlgorithmIdentifier and PublicKey
AlgorithmIdentifier parser has been made more lenient. For instance, rsa-export-0.1.1 crate does not serialize the "NULL" parameter with rsa encryptio
AlgorithmIdentifier parser has been made more lenient.
For instance, rsa-export-0.1.1 crate does not serialize the "NULL" parameter with rsa encryption OID.
Such input is not rejected anymore.### Added - Documentation on oids module.
oids module.legacy feature to support previously valid RSAPrivateKey with 6 components instead of 9 as specified by the RFC. Missing components are instead comput
legacy feature to support previously valid RSAPrivateKey with 6 components instead of 9 as specified by the RFC.
Missing components are instead computed on the fly as required.### Changed - Update dependencies
RSAPrivateKey getters are deprecated in favor of direct access of public fields
DigestInfo from RFC8017RSAPrivateKey fields are now pubPrivateKeyInfo::new_rsa_encryption takes 6 arguments instead of 8RSAPrivateKey getters are deprecated in favor of direct access of public fieldsAlgorithmIdentifier::new_sha3_384_with_rsa_encryption constructor
AlgorithmIdentifier::new_sha3_384_with_rsa_encryption constructorAlgorithmIdentifier::new_sha3_512_with_rsa_encryption constructorRSAPrivateKey is now RFC8017 compliantNothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →