Skip to content

feat: Add Signer.with_ocsp_response to staple OCSP responses - #334

Draft
byh-trufo wants to merge 1 commit into
contentauth:mainfrom
byh-trufo:feature/ocsp-stapling
Draft

byh-trufo wants to merge 1 commit into
contentauth:mainfrom
byh-trufo:feature/ocsp-stapling

Conversation

@byh-trufo

Copy link
Copy Markdown

Draft: blocked on contentauth/c2pa-rs#2725. Not ready for review until a c2pa-rs release includes c2pa_signer_with_ocsp_response and c2pa-native-version.txt is bumped to that release.

Changes in this pull request

Adds Signer.with_ocsp_response(ocsp_response), which staples a DER-encoded OCSP response into every signature the signer produces. Call it once per certificate along the chain, signing certificate first. It binds the new C function c2pa_signer_with_ocsp_response; on failure the signer is unchanged and still usable.

Checklist

  • This PR represents a single feature, fix, or change.
  • All applicable changes have been documented.
  • Any TO DO items (or similar) have been entered as GitHub issues and the link to that issue has been included in a comment.

Signatures made through the Python SDK could not carry rVals.ocspVals, so
validators had to fetch revocation status themselves. with_ocsp_response
binds c2pa_signer_with_ocsp_response, swapping in the stapling signer in
place so callback lifetimes and chaining work as before. Requires a native
library that exports the new function.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant