NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #599 most downloaded on crates.io
Parser for the X.509 v3 format (RFC 5280 certificates)
Last release 8 months ago
05 Feb 2026
Ships fairly regularly
a new release about every 5 months
Most releases are documented
notes for 31 of 35 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
39 releases · first in 2018
fix(verify): also enable all functions when using verify-aws, otherwise par of the API is missing
Release x509-parser-0.18.0
Release x509-parser-0.18.0
verify-aws to use aws-lc-rs as crypto provider instead of ring
aws-lc-rs is used (but both dependencies are included)as_raw methods to X509Certificate, CertificateRevocationList and X509CertificationRequest
Extensions:
SubjectInfoAccess extensionGeneralName: add a new variant Invalid so an invalid entry does not stop
parsing for the entire list of names (for ex in SAN)One column per quarter.
Upgrade asn1-rs to version 0.6.2.
Global:
asn1-rs to version 0.6.2. (#161)Code:
Updated asn1-rs to 0.6, der-parser and oid-registry
Global:
*ring* to 0.17.7 (#148)time to 0.3.20 (#148)time/ring) (#148)Code:
IssuingDistributionPoint extensions (#146)TbsCertificate::subject_alt_names function (#151)UniqueIdentifier fields to use implicit tagging
instead of explicit (#145)clippy::manual_try_fold findings (#147)Attribute: fix parsing of BmpString string type to use UTF-16 (Closes #143)
revocation_list: use correct OID for CRL number.AttributeTypeAndValueSet MSRV to 1.57 (due to ring/once_cell)
Global:
ring/once_cell)data-encoding crate (#136)Code:
verify feature to verify a certificate revocation list by a public keyDocs:
Add support for parsing signature parameters and value (closes #94)
Add support for parsing signature parameters and value (closes #94)
Change ASN1Time::to_rfc2822() to return a Result
ASN1Time: modify from_timestamp to return a Result
ASN1Time: implement Display
Upgrade versions of asn1-rs, oid-registry and der-parser
AlgorithmIdentifier: add const methods to create object/access fields
Globally: start using asn1-rs types, simplify parsers:
asn1_rs::FromDer (using X509Error)Fix panic in ASN1Time::to_rfc2822() when year is less than 1900
Fix regression with certificate verification for ECDSA signatures using the P-256 curve and SHA-384
time to 0.3.7 (#119)Add Validator trait and deprecate Validate
Crate:
Validators:
Deref<Target=TbsCertificate> trait to X509CertificateValidator trait and deprecate Validate
X509StructureValidatorX509CertificateValidatorExtensions:
TbsCertificate::find_extension() and add preferred method TbsCertificate::get_extension_unique():
the latter checks for duplicate extensions (#113)Signatures:
Public Keys:
### Added/Changed/Fixed - Upgrade to nom 7
Add SubjectPublicKeyInfo::raw field
Add the Validate trait to run post-parsing validations of X.509 structure
Validate trait to run post-parsing validations of X.509 structureFromDer trait to unify parsing methods and visibility (#85)X509Certificate::public_key() methodX509CertificateParser builder to allow specifying parsing options.extensions field is not public anymore, but methods .extensions() and .extensions_map()
have been addedClone for all types (when possible) (#89)X509Name (replaced by accessors)Remove der-oid-macro from dependencies, not used directly
Fix: X509Name::iter_state_or_province OID value
Add function parse_x509_pem and deprecate pem_to_der
Upgrade to nom 6.0
Upgrade to der-parser 5.0
Upgrade MSRV to 1.44.0
Re-export crates so crate users do not have to import them
Add function parse_x509_pem and deprecate pem_to_der (#53)
Add helper methods to X509Name and simplify accessing values
Add support for ReasonCode extension
Add support for InvalidityDate extension
Add support for CRL Number extension
Add support for Certificate Signing Request (#58)
Change type of X509Version (now directly using the u32 value)
X509Name: relax check, allow some non-rfc compliant strings (#50)
Relax some constraints for invalid dates
CRL: extract raw serial, and add methods to access it
CRL: add method to iterate revoked certificates
RevokedCertificate: convert extensions list to hashmap
Refactor crate modules and visibility
Rename top-level functions to parse_x509_certificate and parse_x509_crl`
Refactor error handling, return meaningful errors when possible
Make many more functions public (parse_tbs_certificate, etc.)
Nothing published for this version
Nothing published for this version
`time 0.1 is very old, and time 0.2 broke compatibility and cannot parse timezones
der-parser 4.0time to chrono
ASN1Time object to abstract implementationnot_before, not_after etc.nid2obj argument is now passed by copy, not referenceparse_x509_name public, for parsing distinguished namesverify feature to verify cryptographic signature by a public keyNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Expose raw bytes of the certificate serial number
Nothing published for this version
Fix infinite loop when certificate has no END mark
Fix infinite loop when reading non-pem data
Remove debug code left in Pem::read
Pem::readPEM: ignore lines before BEGIN label
Update to der-parser 3.0 and nom 5
Add time_to_expiration to Validity object
time_to_expiration to Validity objectPem object from BufRead + SeekPem to decode and extract certificate- Update to der-parser 2.0
Make parse_subject_public_key_info public
parse_subject_public_key_info publicsn2oid (get an OID by short name)Support GeneralizedTime conversion
Fix case where certificate has no extensions
Upgrade to der-parser 1.1, and Use num-bigint over num
- Upgrade to nom 4
Rewrite X.509 structures and parsing code to work in one pass Warning: this is a breaking change
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →