NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #837 most downloaded on crates.io
Rust X.509 certificate generator
Last release 1 months ago
28 Aug 2026
Ships fairly regularly
a new release about every 2 months
Nearly every release is documented
notes for 46 of 50 stable releases
3 versions withdrawn
withdrawn after publishing
8 years old
53 releases · first in 2019
Spec compliance bug fixes by @cpu in #445
Previous versions generated DER that is strictly incompatible with the spec, writing an explicit false value for IsCa::ExplicitNoCa where this should
Previous versions generated DER that is strictly incompatible with the spec, writing an explicit false value for IsCa::ExplicitNoCa where this should be omitted (as it's the default).
One column per quarter.
Fix incorrect identifier for ML-DSA signature algorithms by @DarkmatterVale in #412
Implement From<KeyPair> for PrivateKeyDer<'static> by @LebedevRI in #403
From<KeyPair> for PrivateKeyDer<'static> by @LebedevRI in #403Use private cfg for docs.rs-like builds by @ctz in #384
Implement SigningKey for &impl SigningKey to make Issuer more broadly useful.
docs: fix typo in PKCS_RSA_SHA384 doc comment by @Bravo555 in #367
Declare 1.71 rust-version and check MSRV in CI.
0.14.0 contains a number of potentially breaking API changes, though hopefully the rate of API change should slow down after this. Here is a summary o
0.14.0 contains a number of potentially breaking API changes, though hopefully the rate of API change should slow down after this. Here is a summary of the most noticeable changes you might run into:
signed_by() methods now take a reference to an &Issuer type that contains both the issuer's relevant certificate parameters and the signing key (see #356). The from_ca_cert_der() and from_ca_cert_pem() constructors that were previously attached to CertificateParams are now attached to Issuer instead, removing a number of documented caveats.RemoteKeyPair trait is now called SigningKey and instead of KeyPair being an enum that contains a Remote variant, that variant has been removed in favor of KeyPair implementing the trait (see #328). To align with this change, the CertifiedKey::key_pair field is now called signing_key, and CertifiedKey is generic over the signing key type.KeyPair::public_key_der() method has moved to PublicKeyData::subject_public_key_info() (see #328).Certificate no longer contain their originating CertificateParams. Instead, signed_by() and self_signed() now take &self, allowing the caller to retain access to the input parameters (see #328). In order to make this possible, Certificate::key_identifier() can now be accessed via CertificateParams directly..gitignore to be more specific by @Rynibami in #342Debug trait by @Rynibami in #343PartialEq and Eq traits by @Rynibami in #344Nothing published for this version
Nothing published for this version
Fixed incorrect usage of the subject certificate's parameter's key identifier method when computing the key identifier of the issuer for the subject's
Fixed:
The API used to create/issue key pairs, certificates, certificate signing requests (CSRs), and certificate revocation lists (CRLs) has been restructur
Breaking changes:
The API used to create/issue key pairs, certificates, certificate signing requests (CSRs), and certificate revocation lists (CRLs) has been restructured to emphasize consistency and avoid common errors with serialization.
For each concrete type (cert, CSR, CRL) the process is now the same:
fn on the parameters, providing subject key pair and
issuer information and as appropriate.fns on the finalized type, obtaining DER or PEM.For more information, see [rcgen/docs/0.12-to-0.13.md].
Throughout the API DER inputs are now represented using types from the Rustls
rustls-pki-types crate, e.g. PrivateKeyDer, CertificateDer,
CertificateSigningRequestDer. Contributed by
Tudyx.
String types used in SanType and DnValue enums for non-UTF8 string types
have been replaced with more specific types that prevent representation of
illegal values. E.g. Ia5String, BmpString, PrintableString,
TeletexString, and UniversalString. Contributed by
Tudyx.
Method names starting with get_ have been renamed to match Rust convention:
CertificateRevocationList::get_params() -> params()
Certificate::get_params() -> params()
Certificate::get_key_identifier() -> Certificate::key_identifier()
Certificate::get_times() -> Certificate::times()
Added:
RSA key generation support has been added. This support requires using the
aws-lc-rs feature. By default using KeyPair::generate_for() with
an RSA SignatureAlgorithm will generate an RSA 2048 keypair. See
KeyPair::generate_rsa_for() for support for RSA 2048, 3072 and 4096 key sizes.
Support for ECDSA P521 signatures and key generation has been added when using
the aws-lc-rs feature. Contributed by Alvenix.
Support for loading private keys that may be PKCS8, PKCS1, or SEC1 has been
added when using the aws-lc-rs feature. Without this feature private keys
must be PKCS8. See KeyPair::from_pem_and_sign_algo() and
KeyPair::from_der_and_sign_algo() for more information. Contributed by
Alvenix.
Support has been added for Subject Alternative Name (SAN) names of type
OtherName. Contributed by Tudyx.
Support has been added for specifying custom "other" OIDs in extended key usage. Contributed by Tudyx.
Support has been added for building rcgen without cryptography by omitting
the new (default-enabled) crypto feature flag. Contributed by
corrideat.
Support for using aws-lc-rs in fips mode can now be activated by using the
fips feature in combination with the aws-lc-rs feature. Contributed by
BiagioFesta.
A small command-line tool for certificate generation (rustls-cert-gen) was
added. Contributed by tbro.
RFC 5280 specifies that a serial number must not be larger than 20 octets in length. Prior to this release an unintended interaction between rcgen and
pem feature was
omitted has been fixed.Rename RcgenError to Error. Contributed by thomaseizinger.
RcgenError to Error. Contributed by thomaseizinger.Error has been made not expose external library types: Error::PemError now holds a String value, and the Error type doesn't support From<_> based conversion any more. This allows rcgen to update dependencies without impacting downstream users.ring v0.17. Contributed by thomaseizinger.ring optional and allow usage of aws-lc-rs via a cargo feature. Ring remains the default. Contributed by BiagioFesta.Ia5String support for DistinguishedNames.KeyIdMethod::PreSpecified variant to set, and not generate the SKI. CertificateParams::from_ca_cert_pem now uses it when building params from an existing CA certificate. Contributed by Brocar.Fix for import errors building without the optional pem feature.
pem feature.rcgen has joined the umbrella of the rustls organization.
rcgen has joined the umbrella of the rustls organization.KeyPairs. Contributed by tindzk.ExtendedKeyUsagePurpose::Any. Contributed by jgallagher.Make botan a dev-dependency again. Contributed by mbrubeck.
Parse IP-address subject alternative names. Contributed by iamjpotts.
SanType::IpAddress when calling CertificateParams::new or generate_simple_self_signed. Contributed by rukai.Increase minimum supported Rust version to 1.58.1.
IsCa enum to have NoCa and ExplicitNoCa and Ca(...). Contributed by doraneko94.yanked due to breaking API changes, see 0.10.0 instead.
Add a KeyPair::serialized_der function. Contributed by jean-airoldie.
KeyPair::serialized_der function. Contributed by jean-airoldie.Update x509-parser to 0.13. Contributed by matze.
Change edition to 2018 in order to support Rust 1.53.0.
Add RemoteKeyError for usage by remote keys.
- Update pem to 1.0. - Update x509-parser to 0.12.
Bugfix release to make Certificate Send and Sync again.
Send and Sync again.Use public key as default serial number. Contributed by jpastuszek.
PKCS_RSA_SHA512 and PKCS_RSA_SHA384 signature algorithms.Add getters for the criticality, content, and oid_components of a CustomExtension
oid_components of a CustomExtensionImplement some additional traits for some of the types. Contributed by zurborg.
Strip nanos from DateTime as well. Contributed by @trevor-crypto.
DateTime as well. Contributed by @trevor-crypto.Turn botan back into a dev-dependency. Contributed by @nthuemmel.
botan back into a dev-dependency. Contributed by @nthuemmel.Add botan based test to the testsuite
Add some more DnTypes: OrganizationalUnitName, LocalityName, StateOrProvinceName
DnTypes: OrganizationalUnitName, LocalityName, StateOrProvinceNameremove function to DistinguishedNameNameConstraintsImprove spec compliance in the notBefore/notAfter fields generated by using UTCTime if needed
notBefore/notAfter fields generated by using UTCTime if neededFix regression of 0.8.1 that generated standards non compliant CSRs and broke Go toolchain parsers. Contributed by @thomastaylor312.
0.8.1 that generated standards non compliant CSRs
and broke Go toolchain parsers. Contributed by @thomastaylor312.Disable chrono default features to get rid of time crate
chrono default features to get rid of time crateopenssl tests to do a full handshake with the generated certFix non-standard-compliant SubjectKeyIdentifier X.509v3 extension format
Correct number of nanoseconds per second. Contributed by @samlich.
non_exhaustive feature in the APIBugfix release for ip address subject alternative names. Turns out they aren't CIDR subnets after all :)
Support for email and cidr subnet (ip address) subject alternative names
- Update to x509-parser 0.6
Update to ring 0.16 and webpki 0.21
Allow inspection of DistinguishedName via iterators and get functions
Support for user supplied keypairs. Contributed by @fzgregor.
Result and our own Error typeAbility to disable the dependency on the pem crate
pem crateacmeIdentifier extensionsSupport for CA certificate generation. Contributed by @djc.
- Updated to pem 0.6
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →