import { canonicalDnKey, compareDistinguishedNames, isWithinDirectoryNameSubtree } from "../internal/shared/dn.js"; //#region src/x509/name.d.ts /** Machine-readable reason a distinguished-name encoder rejected its construction input. */ type NameEncoderErrorCode = "relative_distinguished_name_empty" | "unsupported_name_field" | "name_attribute_empty" | "name_attribute_too_long" | "invalid_country_code"; /** * Union of recognized distinguished-name attribute type shorthand names. * * Each key maps to an OID + ASN.1 string encoding in `NAME_FIELD_DEFINITIONS`. */ type NameFieldKey = "commonName" | "surname" | "serialNumber" | "country" | "locality" | "state" | "street" | "organization" | "organizationalUnit" | "title" | "givenName" | "emailAddress"; /** * Convenience object form of an X.501 distinguished name. * * Populated fields are emitted in the order defined by * `NAME_OBJECT_ORDER`.\ * Each populated field becomes its own single-attribute RDN. * * For caller-controlled ordering, pass a {@linkcode NameAttribute} array to {@linkcode encodeName}.\ * For multi-valued RDNs, use {@linkcode encodeRelativeDistinguishedName}. */ interface NameObject { /** Subject or issuer common name (CN). */ readonly commonName?: string; /** Subject surname (SN). */ readonly surname?: string; /** Device or entity serial number — not the certificate serial. */ readonly serialNumber?: string; /** ISO 3166 two-letter country code (C). Must be exactly 2 characters. */ readonly country?: string; /** City or locality (L). */ readonly locality?: string; /** State or province (ST). */ readonly state?: string; /** Street address. */ readonly street?: string; /** Organization name (O). */ readonly organization?: string; /** Organizational unit (OU). Deprecated in modern CA practice. */ readonly organizationalUnit?: string; /** Job title or functional designation. */ readonly title?: string; /** First / given name (GN). */ readonly givenName?: string; /** PKCS #9 emailAddress attribute (RFC 2985 §5.2.1). Encoded as IA5String, not UTF-8. RFC 5280 §4.1.2.6 deprecates it in favour of a subjectAltName rfc822Name. */ readonly emailAddress?: string; } /** * Single name attribute within a distinguished name. * * RFC 5280 / X.501 call this structure an `AttributeTypeAndValue`. * * @see {@link https://datatracker.ietf.org/doc/html/rfc5280#appendix-A.1 RFC 5280 Appendix A.1} * {@linkcode encodeName} places each attribute in its own single-attribute RDN.\ * {@linkcode encodeRelativeDistinguishedName} packs several attributes into one RDN. */ interface NameAttribute { /** Which attribute type this pair represents. */ readonly type: NameFieldKey; /** The string value for this attribute (encoding chosen per field definition). */ readonly value: string; } /** * Input for {@linkcode encodeName}. * * Accepts either a {@linkcode NameObject} convenience shape or an ordered array of {@linkcode NameAttribute} pairs.\ * Both forms encode one attribute per RDN. */ type NameInput = NameObject | readonly NameAttribute[]; /** * Input for {@linkcode encodeRelativeDistinguishedName}. * * Each entry becomes one name attribute inside the RDN's `SET OF`.\ * Use this shape for multi-valued RDNs. * * @see {@link https://datatracker.ietf.org/doc/html/rfc5280#appendix-A.1 RFC 5280 Appendix A.1} */ type RelativeDistinguishedNameInput = readonly NameAttribute[]; /** * DER-encodes an X.509 `Name`. * * Returns a DER `SEQUENCE` of RelativeDistinguishedNames (RDNs).\ * Each RDN emitted by this helper contains exactly one name attribute. * * @see {@link https://datatracker.ietf.org/doc/html/rfc5280#appendix-A.1 RFC 5280 Appendix A.1} * * {@linkcode NameObject} input emits populated fields in the canonical order from `NAME_OBJECT_ORDER`.\ * {@linkcode NameAttribute} array input preserves caller-supplied ordering, * but each entry still becomes its own single-attribute RDN. * * Attribute OIDs and ASN.1 string encodings come from `NAME_FIELD_DEFINITIONS`.\ * Empty strings and `undefined` fields are ignored when the input is a {@linkcode NameObject}. * * @example * ```ts * const der = encodeName({ country: 'US', commonName: 'example.com' }); * * // emits two single-attribute RDNs: C=US, then CN=example.com * ``` * * @example * ```ts * const der = encodeName([ * { type: 'country', value: 'US' }, * { type: 'commonName', value: 'example.com' }, * ]); * * // preserves caller order: C first, then CN * ``` * * @param input Name fields in convenience-object form or caller-ordered attribute form. * @returns DER-encoded X.509 `Name` bytes. * @throws {ResultError} If a value exceeds its RFC 5280 A.1 bound, an ordered attribute value is empty, a field key is unsupported, or a country code is not two characters. An input with no attributes encodes an empty Name (`30 00`) rather than throwing. */ declare function encodeName(input: NameInput): Uint8Array; /** * DER-encodes a single RelativeDistinguishedName (RDN). * * Returns a DER `SET OF` name attributes for one X.509 name segment.\ * Use this when you need a multi-valued RDN. * * @see {@link https://datatracker.ietf.org/doc/html/rfc5280#appendix-A.1 RFC 5280 Appendix A.1} * * Attribute OIDs and ASN.1 string encodings come from * `NAME_FIELD_DEFINITIONS`. * * @example * ```ts * const rdn = encodeRelativeDistinguishedName([ * { type: 'commonName', value: 'example.com' }, * { type: 'serialNumber', value: 'device-7' }, * ]); * * // emits one RDN with both attributes in the same SET * ``` * * @param attributes Attribute list to encode inside one RDN. * @returns DER-encoded RelativeDistinguishedName bytes. * @throws {ResultError} If the attribute list is empty, contains an unsupported field key, an empty or over-long value, or an invalid country code. */ declare function encodeRelativeDistinguishedName(attributes: RelativeDistinguishedNameInput): Uint8Array; //#endregion export { NameAttribute, NameEncoderErrorCode, NameFieldKey, NameInput, NameObject, RelativeDistinguishedNameInput, canonicalDnKey, compareDistinguishedNames, encodeName, encodeRelativeDistinguishedName, isWithinDirectoryNameSubtree }; //# sourceMappingURL=name.d.ts.map