swarmauri_certs_crlverifyservice
CRL-based certificate verification service for the Swarmauri SDK.
This package implements an ICertService that checks X.509 certificates
against Certificate Revocation Lists as described in
RFC 5280. It validates the
certificate's validity period, issuer, and revocation status.
Features
CrlVerifyServiceadapter dedicated to revocation-aware verification and parsing.- Accepts PEM or DER certificates/CRLs and normalizes them with
cryptography. - Returns structured validity metadata, revocation flags, issuers, and extension details.
- Focuses purely on verification; CSR and signing flows stay delegated to other Swarmauri services.
Prerequisites
- Python 3.10 or newer.
- Access to up-to-date CRLs for the certificate authorities you care about.
- Certificates and CRLs stored in PEM (Base64) or DER; the service can decode either.
- Optional: trusted root/intermediate certificates if you plan to record issuer context alongside revocation checks.
Installation
# pip
pip install swarmauri_certs_crlverifyservice
# poetry
poetry add swarmauri_certs_crlverifyservice
# uv (pyproject-based projects)
uv add swarmauri_certs_crlverifyservice
Quickstart: Revocation Check
Load a certificate and its corresponding CRL, then validate the revocation status and validity window:
import asyncio
from pathlib import Path
from swarmauri_certs_crlverifyservice import CrlVerifyService
async def main() -> None:
service = CrlVerifyService()
cert_bytes = Path("leaf.pem").read_bytes()
crl_bytes = Path("issuer.crl").read_bytes()
verification = await service.verify_cert(
cert=cert_bytes,
crls=[crl_bytes],
check_revocation=True,
)
if verification["valid"]:
print("Certificate is valid.")
elif verification.get("revoked"):
print("Certificate was revoked:", verification["reason"])
else:
print("Certificate failed validation:", verification["reason"])
if __name__ == "__main__":
asyncio.run(main())
Parsing Metadata
Use parse_cert to surface fields needed for logging, auditing, or dashboards:
import asyncio
from pathlib import Path
from swarmauri_certs_crlverifyservice import CrlVerifyService
async def describe() -> None:
service = CrlVerifyService()
cert_bytes = Path("leaf.pem").read_bytes()
metadata = await service.parse_cert(cert_bytes)
print("Subject:", metadata["subject"])
print("Valid until:", metadata["not_after"])
print("Key usage:", metadata.get("key_usage"))
if __name__ == "__main__":
asyncio.run(describe())
Best Practices
- Refresh CRLs frequently; RFC 5280
nextUpdatedictates how long a CRL should be considered valid. - Combine this service with Swarmauri signing services to perform a full lifecycle check (issue → deploy → monitor).
- Cache CRLs in memory or a fast datastore to avoid repeatedly downloading them when calling
verify_cert. - Log verification outputs (especially
reasonandrevoked) to your observability pipeline to catch trust issues early.
Metadata
Release files for swarmauri_certs_crlverifyservice 0.1.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| swarmauri_certs_crlverifyservice-0.1.3.tar.gz | 8.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| swarmauri_certs_crlverifyservice-0.1.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 18.5 kB
Release files / swarmauri_certs_crlverifyservice-0.1.3.tar.gz
| Download URL | swarmauri_certs_crlverifyservice-0.1.3.tar.gz |
|---|---|
| Size | 8.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d35a7a4a0dca153a93afeed0644e0704b7c2988e85e00bfd6e65586e5e009a83
|
|
BLAKE2b-256 checksum How to use checksums |
c45748ab9c4191119862380261fed8ea62ba3f5a9db1b431a135ccaf2e56ac32
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.0 {"installer":{"name":"uv","version":"0.11.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|
Release files / swarmauri_certs_crlverifyservice-0.1.3-py3-none-any.whl
| Download URL | swarmauri_certs_crlverifyservice-0.1.3-py3-none-any.whl |
|---|---|
| Size | 9.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a30deccaff8f7e761a8ff17eaa27c2d81a6107571f811c0b9ca3e5c98c4c5ba4
|
|
BLAKE2b-256 checksum How to use checksums |
70aaaceafcf0a27c7626b98a1cf7758262dfedfe6e3d49b476ee48f73b77d4d1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.0 {"installer":{"name":"uv","version":"0.11.0","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
|