Documentation
¶
Overview ¶
Package crlcache defines the Verifier interface used by transport.TLSInfo to check client certificates against a CRL or OCSP source. It contains no implementation; callers supply their own.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Verifier ¶
type Verifier interface {
// Update refreshes the underlying CRL/OCSP cache.
Update() error
// Verify returns OCSP status:
// ocsp.Revoked - the certificate found in CRL
// ocsp.Good - the certificate not found in a valid CRL
// ocsp.Unknown - no CRL or OCSP response found for the certificate
Verify(crt *x509.Certificate, issuer *x509.Certificate) (int, error)
}
Verifier checks the revocation status of a certificate against its issuer. Implementations must be safe for concurrent use: transport.NewTLSListener calls Verify from concurrent handshake goroutines.
Click to show internal directories.
Click to hide internal directories.