/** * Build a context-specific constructed tag byte — `[n] EXPLICIT` * from RFC 5280. * * @param {number} n */ export function contextTag(n: number): number; /** * A parsed TLV — `contents` is a view over the same buffer, no copy. * * @typedef {object} Tlv * @property {number} tag The full tag byte, class + P/C + number. * @property {number} tagClass Tag class 0..3 (universal/application/context/private). * @property {boolean} constructed True for constructed encoding (P/C bit set). * @property {number} tagNumber Bottom 5 bits of the tag byte. * @property {Uint8Array} contents Bytes carried by this TLV (no tag, no length). * @property {number} totalLength Total bytes consumed from the source, including tag + length. */ /** * Read one TLV starting at `offset` in `bytes`. * * @param {Uint8Array} bytes * @param {number} [offset=0] * @returns {Tlv} */ export function readTlv(bytes: Uint8Array, offset?: number): Tlv; /** * Read every child TLV inside a SEQUENCE / SET body. * * @param {Uint8Array} contents the `contents` slice of a SEQUENCE / SET TLV * @returns {Tlv[]} */ export function readChildren(contents: Uint8Array): Tlv[]; /** * Convenience: read a top-level TLV, assert its tag, return the * children of its contents. * * @param {Uint8Array} bytes * @param {number} expectedTag e.g. `TAG.SEQUENCE` or `contextTag(3)` * @returns {Tlv[]} */ export function intoSequence(bytes: Uint8Array, expectedTag?: number): Tlv[]; /** * Decode an OBJECT IDENTIFIER's contents into the dotted decimal * form used in RFCs (e.g. `"1.3.6.1.4.1.45724.1.1.4"`). * * X.690 §8.19: the first octet encodes the first two subidentifiers * as `40 * a + b` (where `a` is 0/1/2 and `b < 40` when `a < 2`); * subsequent subidentifiers are base-128, high bit set on all but * the final byte. * * @param {Uint8Array} contents the `contents` slice of an OID TLV * @returns {string} */ export function decodeOid(contents: Uint8Array): string; /** * Encode a dotted-decimal OID into its DER `contents` bytes. Handy * for compile-time OID tables and for tests; hot paths should just * compare the decoded string. * * @param {string} oid * @returns {Uint8Array} */ export function encodeOid(oid: string): Uint8Array; /** * Locate an extension by OID inside an X.509 certificate's raw DER * bytes and return its `extnValue` OCTET STRING contents — i.e. the * bytes typically parsed again as an inner ASN.1 structure per RFC * 5280 §4.2. * * Returns `null` when the extension is absent. Throws when the * certificate itself is malformed. * * Certificate structure (RFC 5280 §4.1): * * Certificate ::= SEQUENCE { * tbsCertificate TBSCertificate, * signatureAlgorithm AlgorithmIdentifier, * signature BIT STRING * } * * TBSCertificate ::= SEQUENCE { * version [0] EXPLICIT Version DEFAULT v1, * serialNumber CertificateSerialNumber, * signature AlgorithmIdentifier, * issuer Name, * validity Validity, * subject Name, * subjectPublicKeyInfo SubjectPublicKeyInfo, * issuerUniqueID [1] IMPLICIT UniqueIdentifier OPTIONAL, * subjectUniqueID [2] IMPLICIT UniqueIdentifier OPTIONAL, * extensions [3] EXPLICIT Extensions OPTIONAL * } * * Extension ::= SEQUENCE { * extnID OBJECT IDENTIFIER, * critical BOOLEAN DEFAULT FALSE, * extnValue OCTET STRING * } * * @param {Uint8Array} certDer raw DER-encoded certificate * @param {string} oid dotted-decimal OID to find * @returns {Uint8Array | null} */ export function findExtension(certDer: Uint8Array, oid: string): Uint8Array | null; export const TAG: Readonly<{ BOOLEAN: 1; INTEGER: 2; BIT_STRING: 3; OCTET_STRING: 4; NULL: 5; OBJECT_IDENTIFIER: 6; UTF8_STRING: 12; PRINTABLE_STRING: 19; IA5_STRING: 22; UTC_TIME: 23; GENERALIZED_TIME: 24; SEQUENCE: 48; SET: 49; }>; /** * A parsed TLV — `contents` is a view over the same buffer, no copy. */ export type Tlv = { /** * The full tag byte, class + P/C + number. */ tag: number; /** * Tag class 0..3 (universal/application/context/private). */ tagClass: number; /** * True for constructed encoding (P/C bit set). */ constructed: boolean; /** * Bottom 5 bits of the tag byte. */ tagNumber: number; /** * Bytes carried by this TLV (no tag, no length). */ contents: Uint8Array; /** * Total bytes consumed from the source, including tag + length. */ totalLength: number; };