Skip to main content

Certificate verification against CRLs

Project description

Swarmauri Logo

PyPI - Downloads Hits PyPI - Python Version PyPI - License PyPI - swarmauri_certs_crlverifyservice


swarmauri_certs_crlverifyservice

CRL-based certificate verification service for the Swarmauri SDK.

This package implements an ICertService that checks X.509 certificates against Certificate Revocation Lists as described in RFC 5280. It validates the certificate's validity period, issuer, and revocation status.

Features

  • CrlVerifyService adapter dedicated to revocation-aware verification and parsing.
  • Accepts PEM or DER certificates/CRLs and normalizes them with cryptography.
  • Returns structured validity metadata, revocation flags, issuers, and extension details.
  • Focuses purely on verification; CSR and signing flows stay delegated to other Swarmauri services.

Prerequisites

  • Python 3.10 or newer.
  • Access to up-to-date CRLs for the certificate authorities you care about.
  • Certificates and CRLs stored in PEM (Base64) or DER; the service can decode either.
  • Optional: trusted root/intermediate certificates if you plan to record issuer context alongside revocation checks.

Installation

# pip
pip install swarmauri_certs_crlverifyservice

# poetry
poetry add swarmauri_certs_crlverifyservice

# uv (pyproject-based projects)
uv add swarmauri_certs_crlverifyservice

Quickstart: Revocation Check

Load a certificate and its corresponding CRL, then validate the revocation status and validity window:

import asyncio
from pathlib import Path

from swarmauri_certs_crlverifyservice import CrlVerifyService


async def main() -> None:
    service = CrlVerifyService()

    cert_bytes = Path("leaf.pem").read_bytes()
    crl_bytes = Path("issuer.crl").read_bytes()

    verification = await service.verify_cert(
        cert=cert_bytes,
        crls=[crl_bytes],
        check_revocation=True,
    )

    if verification["valid"]:
        print("Certificate is valid.")
    elif verification.get("revoked"):
        print("Certificate was revoked:", verification["reason"])
    else:
        print("Certificate failed validation:", verification["reason"])


if __name__ == "__main__":
    asyncio.run(main())

Parsing Metadata

Use parse_cert to surface fields needed for logging, auditing, or dashboards:

import asyncio
from pathlib import Path

from swarmauri_certs_crlverifyservice import CrlVerifyService


async def describe() -> None:
    service = CrlVerifyService()
    cert_bytes = Path("leaf.pem").read_bytes()

    metadata = await service.parse_cert(cert_bytes)
    print("Subject:", metadata["subject"])
    print("Valid until:", metadata["not_after"])
    print("Key usage:", metadata.get("key_usage"))


if __name__ == "__main__":
    asyncio.run(describe())

Best Practices

  • Refresh CRLs frequently; RFC 5280 nextUpdate dictates how long a CRL should be considered valid.
  • Combine this service with Swarmauri signing services to perform a full lifecycle check (issue → deploy → monitor).
  • Cache CRLs in memory or a fast datastore to avoid repeatedly downloading them when calling verify_cert.
  • Log verification outputs (especially reason and revoked) to your observability pipeline to catch trust issues early.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

File details

Details for the file swarmauri_certs_crlverifyservice-0.1.0.dev23.tar.gz.

File metadata

  • Download URL: swarmauri_certs_crlverifyservice-0.1.0.dev23.tar.gz
  • Upload date:
  • Size: 8.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.9.27 {"installer":{"name":"uv","version":"0.9.27","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for swarmauri_certs_crlverifyservice-0.1.0.dev23.tar.gz
Algorithm Hash digest
SHA256 11bd50762f69524ff6ccb3dda2afedfe094ddc00ae96eafd45c076a6cb04a3ec
MD5 b6f0649077dbf3365a45ed9949d1f8f6
BLAKE2b-256 7dec254cecbf312c2f64e002c3c0b146050a81dcb622cb36b4d9380c034f3f5d

See more details on using hashes here.

File details

Details for the file swarmauri_certs_crlverifyservice-0.1.0.dev23-py3-none-any.whl.

File metadata

  • Download URL: swarmauri_certs_crlverifyservice-0.1.0.dev23-py3-none-any.whl
  • Upload date:
  • Size: 9.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: uv/0.9.27 {"installer":{"name":"uv","version":"0.9.27","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

File hashes

Hashes for swarmauri_certs_crlverifyservice-0.1.0.dev23-py3-none-any.whl
Algorithm Hash digest
SHA256 c2838be7a7b0f8cf7c886bd9b8c99de7b21c502116097e250fd1522eafb2d08e
MD5 adcb16c3ca06fcb4382ee25f36358e51
BLAKE2b-256 190e36d161edd05507b7d2c196ca429217269d3da73d4dcb4247453dc43c9f6a

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page