NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #2024 most downloaded on crates.io
X.509 certificate parser and utility functionality
Last release 1 years ago
17 Aug 2025
Release timing varies
gaps range from 1 weeks to 12 months
Most releases are documented
notes for 23 of 27 stable releases
Nothing withdrawn
no release was ever pulled
5 years old
27 releases · first in 2021
One column per quarter.
x509-certificate: version 0.25.0
x509-certificate: version 0.25.0
Released on 2025-08-17.
thiserror 1.0 -> 2.0.x509-certificate: version 0.24.0
x509-certificate: version 0.24.0
Released on 2024-11-02.
bytes 1.5 -> 1.8.signature 2.1 -> 2.2.zeroize 1.6 -> 1.8.x509-certificate: version 0.23.1
x509-certificate: version 0.23.1
Released on 2023-11-16.
X509Certificate now has a tbs_certificate() to retrieve a reference to
the raw, main certificate data structure.From<T> implementations for asn1time::Time,
asn1time::GeneralizedTime, and asn1time::UtcTime that allow
conversion to chrono::DateTime<chrono::Utc>.X509Certificate now has validity_not_before() and validity_not_after()
methods to obtain a chrono::DateTime<chrono::Utc> corresponding to the
certificate's validity start and end times.X509Certificate now has a time_constraints_valid() to check whether the
time is between the validity constraints expressed in the certificate.x509-certificate: version 0.23.0
x509-certificate: version 0.23.0
Released on 2023-11-07.
InMemorySigningKeyPair now stores the private key as a
Zeroize<Vec<u8>> instead of a Vec<u8>.InMemorySigningKeyPair variants are now structs instead of
unnamed tuples.InMemorySigningKeyPair no longer implements
From<ring::signature::Ed25519KeyPair>.InMemorySigningKeyPair now has a to_pkcs8_one_asymmetric_key_der() method
to obtain this PKCS#8 DER representation of the key pair.X509CertificateBuilder::create_with_random_keypair() no longer returns
a ring::pkcs8::Document. (The PKCS#8 representation can now be obtained
from the returned InMemorySigningKeyPair.)InMemorySigningKeyPair::generate_random() no longer returns a
ring::pkcs8::Document. (The PKCS#8 representation can now be obtained
from the returned InMemorySigningKeyPair.)X509CertificateBuilder::new() no longer accepts a KeyAlgorithm argument.X509CertificateBuilder now implements Default. new() is deprecated
in favor of default().X509CertificateBuilder::create_with_random_keypair() now requires a
KeyAlgorithm argument.X509CertificateBuilder has gained a create_with_key_pair() method that
allows creating a certificate with a caller specified key pair.Sign::private_key_data() now returns a Zeroizing<Vec<u8>> instead of a
Vec<u8>.Sign::rsa_primes() now returns Zeroizing<Vec<u8>> instead of Vec<u8>.x509-certificate: version 0.22.1
x509-certificate: version 0.22.1
Released on 2023-11-05.
asn1time::UtcTime now implements From<chrono::DateTime<chrono::Utc>>
to facilitate constructing instances from arbitrary times.rfc5958::OneAsymmetricKey (PKCS#8) decoding now correctly handles the public key field. Before, it decoded the public key field as a constructed value
Released on 2023-11-03.
rfc5958::OneAsymmetricKey (PKCS#8) decoding now correctly handles the
public key field. Before, it decoded the public key field as a constructed
value when it should have been a regular tagged value. This bug was masked
by a bug in ring <0.17, which generated PKCS#8 documents incorrectly. The
new decoder only recognizes valid encoded PKCS#8 documents. Please open an
issue if you would like support for decoding the invalid format restored.pem 2.0 -> 3.0.ring 0.16 -> 0.17.GeneralizedTime implements From > (#13).
Released on 2023-07-24.
GeneralizedTime implements From<chrono::DateTime<chrono::Utc>> (#13).SignatureAlgorithm gained a NoSignature variant to express a a digest without a signature.
Released on 2023-06-03.
SignatureAlgorithm gained a NoSignature variant to express a
a digest without a signature. (#11)chrono compiled without default features (#12).Time now has a take_opt_from().
Released on 2023-03-19.
Time now has a take_opt_from().rfc5280::Version now has a take_opt_from().rfc5280::CertificateList now has a take_opt_from().rfc5280::TbsCertList now implements take_from().Released on 2023-01-21. * signature upgraded 1.6 -> 2.0.
Released on 2023-01-21.
Released on 2022-12-30. * pem upgraded 1.0 -> 1.1. * signature upgraded 1.3 -> 1.6.
Released on 2022-12-30.
Canonical home of project moved to https://github.com/indygreg/cryptography-rs.
Released on 2022-12-19.
der crate upgraded from 0.5 to 0.6.
(Released 2022-09-17)
bcder crate upgraded from 0.6.1 to 0.7.0. This entailed a lot of changes, mainly to error handling.
(Released 2022-08-07)
The Sign::sign() trait method is now marked as deprecated. Please switch to the signature::Signer trait.
X509Certificate now implements the spki::EncodePublicKey trait.
This change marks the beginning of a shift/intent to converge this
crate onto the interfaces defined by crates under the
RustCrypto umbrella for better
interop with the rest of the Rust ecosystem.KeyAlgorithm now implements conversion from/to spki::ObjectIdentifier.InMemorySigningKeyPair now implements signature::Signer. This
means there are now 2 implementations of sign() on this type. So
if both traits are in scope you will need to disambiguate the call.Sign::sign() trait method is now marked as deprecated. Please
switch to the signature::Signer trait.Defined a new Sign trait to indicate support for cryptographic signing. InMemorySigningKeyPair implements this trait and callers may need to use x509_
Sign trait to indicate support for cryptographic
signing. InMemorySigningKeyPair implements this trait and callers
may need to use x509_certificate::Sign to pull the trait into
scope.Result.InMemorySigningKeyPair now holds the the raw private key data.
This enables the content to be retrieved later.rfc2986 module.X509CertificateBuilder has a new
create_certificate_signing_request() method to create a
certificate signing request (CSR).Add some APIs on Name to retrieve additional well-known fields.
Name to retrieve additional well-known fields.Name::user_friendly_str() for obtaining a user-friendly string
from a series of attributes.CapturedX509Certificate has gained a verify_signed_data_with_algorithm() method that uses an explicit ring::VerificationAlgorithm for verification. Th
CapturedX509Certificate has gained a
verify_signed_data_with_algorithm() method that uses an explicit
ring::signature::VerificationAlgorithm for verification. The new
method allows verifying when using an alternative verification
algorithm. verify_signed_data() now internally calls into the new
function.Store version field of TbsCertificate as Option instead of Version. In 0.8.0 we interpreted a missing optional field as version 1. This was semantical
version field of TbsCertificate as Option<Version>
instead of Version. In 0.8.0 we interpreted a missing optional
field as version 1. This was semantically correct. However, when we
encoded the parsed data structure we would invent a new version
field where it didn't exist before. This mismatch is relevant for
operations like resolving the certificate fingerprint, as the extra
field would produce a different fingerprint result. Serializing now
omits the version field when it wasn't originally defined. (#525)Properly parse TbsCertificate that is missing a version field. Before, we\'d get a Malformed error if this optional field was missing. Now, we correct
TbsCertificate that is missing a version field.
Before, we'd get a Malformed error if this optional field was
missing. Now, we correctly interpret a missing field as version 1.
(#521)Refactor GeneralizedTime parsing to allow fractional seconds and timezones. Previously, only limited forms of GeneralizedTime were parsed.
GeneralizedTime parsing to allow fractional seconds and
timezones. Previously, only limited forms of GeneralizedTime were
parsed. (#482)Support parsing RSAPublicKey from RFC 8017.
RSAPublicKey from RFC 8017.* No changelog kept.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →