Struct rocket::mtls::Certificate

pub struct Certificate<'a> { /* private fields */ }
Available on crate feature mtls only.
Expand description

A request guard for validated, verified client certificates.

This type is a wrapper over x509::TbsCertificate with convenient methods and complete documentation. Should the data exposed by the inherent methods not suffice, this type derefs to x509::TbsCertificate.

§Request Guard

The request guard implementation succeeds if:

  • The client presents certificates.
  • The certificates are active and not yet expired.
  • The client’s certificate chain was signed by the CA identified by the configured ca_certs and with respect to SNI, if any. See module level docs for configuration details.

If the client does not present certificates, the guard forwards with a status of 401 Unauthorized.

If the certificate chain fails to validate or verify, the guard fails with the respective Error.


To implement roles, the Certificate guard can be wrapped with a more semantically meaningful type with extra validation. For example, if a certificate with a specific serial number is known to belong to an administrator, a CertifiedAdmin type can authorize as follow:

use rocket::mtls::{self, bigint::BigUint, Certificate};
use rocket::request::{Request, FromRequest, Outcome};
use rocket::outcome::try_outcome;
use rocket::http::Status;

// The serial number for the certificate issued to the admin.
const ADMIN_SERIAL: &str = "65828378108300243895479600452308786010218223563";

// A request guard that authenticates and authorizes an administrator.
struct CertifiedAdmin<'r>(Certificate<'r>);

impl<'r> FromRequest<'r> for CertifiedAdmin<'r> {
    type Error = mtls::Error;

    async fn from_request(req: &'r Request<'_>) -> Outcome<Self, Self::Error> {
        let cert = try_outcome!(req.guard::<Certificate<'r>>().await);
        if let Some(true) = cert.has_serial(ADMIN_SERIAL) {
        } else {

fn admin(admin: CertifiedAdmin<'_>) {
    // This handler can only execute if an admin is authenticated.

#[get("/admin", rank = 2)]
fn unauthorized(user: Option<Certificate<'_>>) {
    // This handler always executes, whether there's a non-admin user that's
    // authenticated (user = Some()) or not (user = None).


To retrieve certificate data in a route, use Certificate as a guard:

use rocket::mtls::{self, Certificate};

fn auth(cert: Certificate<'_>) {
    // This handler only runs when a valid certificate was presented.

fn maybe_auth(cert: Option<Certificate<'_>>) {
    // This handler runs even if no certificate was presented or an invalid
    // certificate was presented.

fn ok_auth(cert: mtls::Result<Certificate<'_>>) {
    // This handler does not run if a certificate was not presented but
    // _does_ run if a valid (Ok) or invalid (Err) one was presented.



impl<'a> Certificate<'a>

pub fn serial(&self) -> &BigUint

Returns the serial number of the X.509 certificate.

use rocket::mtls::Certificate;

fn auth(cert: Certificate<'_>) {
    let cert = cert.serial();

pub fn version(&self) -> u32

Returns the version of the X.509 certificate.

use rocket::mtls::Certificate;

fn auth(cert: Certificate<'_>) {
    let cert = cert.version();

pub fn subject(&self) -> &Name<'a>

Returns the subject (a “DN” or “Distinguished Name”) of the X.509 certificate.

use rocket::mtls::Certificate;

fn auth(cert: Certificate<'_>) {
    if let Some(name) = cert.subject().common_name() {
        println!("Hello, {}!", name);

pub fn issuer(&self) -> &Name<'a>

Returns the issuer (a “DN” or “Distinguished Name”) of the X.509 certificate.

use rocket::mtls::Certificate;

fn auth(cert: Certificate<'_>) {
    if let Some(name) = cert.issuer().common_name() {
        println!("Issued by: {}", name);

pub fn extensions(&self) -> &[X509Extension<'a>]

Returns a slice of the extensions in the X.509 certificate.

use rocket::mtls::{oid, x509, Certificate};

fn auth(cert: Certificate<'_>) {
    let subject_alt = cert.extensions().iter()
        .find(|e| e.oid == oid::OID_X509_EXT_SUBJECT_ALT_NAME)
        .and_then(|e| match e.parsed_extension() {
            x509::ParsedExtension::SubjectAlternativeName(s) => Some(s),
            _ => None

    if let Some(subject_alt) = subject_alt {
        for name in &subject_alt.general_names {
            if let x509::GeneralName::RFC822Name(name) = name {
                println!("An email, perhaps? {}", name);

pub fn has_serial(&self, number: &str) -> Option<bool>

Checks if the certificate has the serial number number.

If number is not a valid unsigned integer in base 10, returns None.

Otherwise, returns Some(true) if it does and Some(false) if it does not.

use rocket::mtls::Certificate;

const SERIAL: &str = "65828378108300243895479600452308786010218223563";

fn auth(cert: Certificate<'_>) {
    if cert.has_serial(SERIAL).unwrap_or(false) {
        println!("certificate has the expected serial number");

pub fn as_bytes(&self) -> &'a [u8]

Returns the raw, unmodified, DER-encoded X.509 certificate data bytes.

use rocket::mtls::Certificate;

const SHA256_FINGERPRINT: &str =
    "CE C2 4E 01 00 FF F7 78 CB A4 AA CB D2 49 DD 09 \
     02 EF 0E 9B DA 89 2A E4 0D F4 09 83 97 C1 97 0D";

fn auth(cert: Certificate<'_>) {
    if sha256_fingerprint(cert.as_bytes()) == SHA256_FINGERPRINT {
        println!("certificate fingerprint matched");

Methods from Deref<Target = TbsCertificate<'a>>§


pub fn version(&self) -> X509Version

Get the version of the encoded certificate


pub fn subject(&self) -> &X509Name<'_>

Get the certificate subject.


pub fn issuer(&self) -> &X509Name<'_>

Get the certificate issuer.


pub fn validity(&self) -> &Validity

Get the certificate validity.


pub fn public_key(&self) -> &SubjectPublicKeyInfo<'_>

Get the certificate public key information.


pub fn extensions(&self) -> &[X509Extension<'a>]

Returns the certificate extensions


pub fn iter_extensions(&self) -> impl Iterator<Item = &X509Extension<'a>>

Returns an iterator over the certificate extensions


pub fn get_extension_unique( &self, oid: &Oid<'_>, ) -> Result<Option<&X509Extension<'a>>, X509Error>

Searches for an extension with the given Oid.

Return Ok(Some(extension)) if exactly one was found, Ok(None) if none was found, or an error DuplicateExtensions if the extension is present twice or more.


pub fn find_extension(&self, oid: &Oid<'_>) -> Option<&X509Extension<'a>>

👎Deprecated since 0.13.0: Do not use this function (duplicate extensions are not checked), use get_extension_unique

Searches for an extension with the given Oid.

§Duplicate extensions

Note: if there are several extensions with the same Oid, the first one is returned, masking other values.

RFC5280 forbids having duplicate extensions, but does not specify how errors should be handled.

Because of this, the find_extension method is not safe and should not be used! The get_extension_unique method checks for duplicate extensions and should be preferred.


pub fn extensions_map( &self, ) -> Result<HashMap<Oid<'_>, &X509Extension<'a>>, X509Error>

Builds and returns a map of extensions.

If an extension is present twice, this will fail and return DuplicateExtensions.


pub fn basic_constraints( &self, ) -> Result<Option<BasicExtension<&BasicConstraints>>, X509Error>

Attempt to get the certificate Basic Constraints extension

Return Ok(Some(extension)) if exactly one was found, Ok(None) if none was found, or an error if the extension is present twice or more.


pub fn key_usage(&self) -> Result<Option<BasicExtension<&KeyUsage>>, X509Error>

Attempt to get the certificate Key Usage extension

Return Ok(Some(extension)) if exactly one was found, Ok(None) if none was found, or an error if the extension is invalid, or is present twice or more.


pub fn extended_key_usage( &self, ) -> Result<Option<BasicExtension<&ExtendedKeyUsage<'_>>>, X509Error>

Attempt to get the certificate Extended Key Usage extension

Return Ok(Some(extension)) if exactly one was found, Ok(None) if none was found, or an error if the extension is invalid, or is present twice or more.


pub fn policy_constraints( &self, ) -> Result<Option<BasicExtension<&PolicyConstraints>>, X509Error>

Attempt to get the certificate Policy Constraints extension

Return Ok(Some(extension)) if exactly one was found, Ok(None) if none was found, or an error if the extension is invalid, or is present twice or more.


pub fn inhibit_anypolicy( &self, ) -> Result<Option<BasicExtension<&InhibitAnyPolicy>>, X509Error>

Attempt to get the certificate Policy Constraints extension

Return Ok(Some(extension)) if exactly one was found, Ok(None) if none was found, or an error if the extension is invalid, or is present twice or more.


pub fn policy_mappings( &self, ) -> Result<Option<BasicExtension<&PolicyMappings<'_>>>, X509Error>

Attempt to get the certificate Policy Mappings extension

Return Ok(Some(extension)) if exactly one was found, Ok(None) if none was found, or an error if the extension is invalid, or is present twice or more.


pub fn subject_alternative_name( &self, ) -> Result<Option<BasicExtension<&SubjectAlternativeName<'_>>>, X509Error>

Attempt to get the certificate Subject Alternative Name extension

Return Ok(Some(extension)) if exactly one was found, Ok(None) if none was found, or an error if the extension is invalid, or is present twice or more.


pub fn name_constraints( &self, ) -> Result<Option<BasicExtension<&NameConstraints<'_>>>, X509Error>

Attempt to get the certificate Name Constraints extension

Return Ok(Some(extension)) if exactly one was found, Ok(None) if none was found, or an error if the extension is invalid, or is present twice or more.


pub fn is_ca(&self) -> bool

Returns true if certificate has basicConstraints CA:true


pub fn raw_serial(&self) -> &'a [u8]

Get the raw bytes of the certificate serial number


pub fn raw_serial_as_string(&self) -> String

Get a formatted string of the certificate serial number, separated by ‘:’

Trait Implementations§


impl<'a> Debug for Certificate<'a>


fn fmt(&self, f: &mut Formatter<'_>) -> Result<(), Error>

Formats the value using the given formatter. Read more

impl<'a> Deref for Certificate<'a>


type Target = TbsCertificate<'a>

The resulting type after dereferencing.

fn deref(&self) -> &<Certificate<'a> as Deref>::Target

Dereferences the value.

impl<'r> FromRequest<'r> for Certificate<'r>


type Error = Error

The associated error to be returned if derivation fails.

fn from_request<'life0, 'async_trait>( req: &'r Request<'life0>, ) -> Pin<Box<dyn Future<Output = Outcome<Self, Self::Error>> + Send + 'async_trait>>
where Self: 'async_trait, 'r: 'async_trait, 'life0: 'async_trait,

Derives an instance of Self from the incoming request metadata. Read more

impl<'a> PartialEq for Certificate<'a>


fn eq(&self, other: &Certificate<'a>) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 · source§

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.

impl<'a> StructuralPartialEq for Certificate<'a>

