All Classes and Interfaces
Class
Description
Action performed on an attribute for access governance.
Context used for attribute ACL checks and audit correlation.
Decision outcome of an access control check.
Validated active profile resolution result used by end-entity issuance.
Append-only UTF-8 line store with best-effort POSIX permissions.
Generic asynchronous operation bus.
ServiceLoader provider for the PKI asynchronous operation bus.
Target endpoint that owns/executes operations and can be asked for their
status.
Event delivered to registered handlers whenever an operation status changes.
Callback handler for async operation events.
Immutable snapshot of an operation's identity and routing metadata.
Registration handle for a handler subscription.
Lifecycle state of an asynchronous operation.
Non-sensitive status snapshot of an asynchronous operation.
Policy decision point for attribute-level access control.
Governance hints controlling auditing and exportability of an attribute.
Registry/catalogue of attribute definitions.
Typed and governed attribute definition used across credential frameworks.
Named export targets used by governance and publication pipelines.
Policy enforcement point for attribute access with mandatory auditing.
Stable attribute identifier used by the attribute catalogue.
Structured, human-facing documentation metadata for an attribute definition.
Data sensitivity classification for an attribute.
Immutable set of typed attributes.
Lifecycle maturity of an attribute definition.
Typed attribute value.
Boolean value.
Byte string value.
Instant value.
Integer/long value.
String value.
Declares the logical value type of an attribute.
Auditable event emitted by the PKI core and governance layer.
Query constraints for searching audit events.
Records and queries audit events for PKI operations and attribute governance.
SPI for persisting audit events.
ServiceLoader provider for
AuditSink implementations.Opaque backup artifact produced by
BackupService.Requests creation of a PKI backup.
Backup/restore operations for PKI state.
Verification results for a backup artifact.
Bouncy Castle edge adapter for the provider-neutral X.509 binding authority.
Internal attribute identifiers used by the Bouncy Castle backed X.509 PKI
framework adapter.
Bouncy Castle backed parser for X.509 PKCS#10 certification requests.
Bouncy Castle backed X.509 implementation of
CredentialFramework.ServiceLoader provider for the Bouncy Castle backed X.509 credential
framework.
Bouncy Castle backed X.509 credential issuance backend.
Minimal framework attribute mapper for the internal Bouncy Castle backed
X.509 adapter.
Exact X.509 representation and postcondition helpers for validated leaf
profiles.
Bouncy Castle backed proof-of-possession verifier for X.509 PKCS#10
certification requests.
Bouncy Castle adapter for binding-owned SubjectPublicKeyInfo encodings.
Bouncy Castle edge inspection of a canonically validated signed X.509 object.
Exact role-specific identities extracted from validated original DER.
Bouncy Castle backed generator of X.509 status objects.
Stateless Bouncy Castle verification executor at the X.509 adapter edge.
Loader for the fixed built-in certificate-profile resource catalogue.
Immutable built-in certificate-profile provisioning template.
Command to build a distributable bundle for an existing credential.
Immutable issuer-controlled CA certificate policy.
Command to create a new root CA entity and issue its initial CA credential.
Command to import an existing root CA credential into PKI inventory.
Command to rotate a CA key reference and issue new corresponding CA
credentials.
Closed X.509 key-usage set available to CA certificate profiles.
Classifies CA entity type.
Exact versioned CA profile identity for a root or intermediate credential.
Query constraints for listing CA entities.
Represents one logical CA authority and its explicit issuer generations.
Command to roll over a CA credential while keeping the same key reference.
Manages Certificate Authority (CA) entities and their lifecycle.
Operational state of a CA entity.
Closed certificate-specific policy variant.
Defines issuance constraints and mapping hints for a class of credentials.
Immutable, versioned certificate-profile configuration.
Strict JSON parser and canonical writer for version 2 certificate-profile
documents.
Closed certificate category governed by a profile definition.
Exact immutable identity of one imported certificate-profile version.
Opaque certification request container.
Parses and normalizes framework-specific certification requests into the core
request model.
Processes certification requests (CSR-like objects) into a normalized
representation.
ServiceLoader provider for configurable implementations.
Atomic sequential sink for staged operation content.
Issued credential with mandatory core metadata and universal attributes.
Bundle of a primary credential and supporting objects.
Pluggable credential framework implementation.
Service provider for
CredentialFramework instances.Inventory and reporting service for issued credentials.
SPI contract for framework-specific credential issuance backends.
Closed immutable identity of the policy governing an issued credential.
Query constraints for searching credentials in inventory.
Status of a credential as tracked by PKI inventory.
Closed categories of currently reachable credential trust decisions.
Immutable structured input for one certificate-revocation-list entry.
Stable restartable source of CRL entries.
One-pass entry cursor.
Default enforcement implementation of
AttributeGovernanceService.Default store-backed implementation of
CaService.Default implementation of
CertificationRequestService.Default implementation of
IssuanceService.Store-backed implementation of the certificate-profile lifecycle.
Durable explicit post-commit publication lifecycle.
Store-backed authoritative revocation transition service.
Default implementation of
StatusObjectService.Immutable deployment-owned resource policy for streaming PKI operations.
Generic durable implementation of
AsyncBus.Typed immutable identity of a durable business owner of staged content.
Closed durable-owner categories reserved by the Phase A lifecycle.
Stable, payload-free reference to immutable staged content.
Durable ownership classification.
Runtime status used when deciding whether a credential may participate in a
security-sensitive operation.
Resolves authoritative runtime credential status for trust decisions.
One immutable-time effective-status evaluation.
Immutable container for an encoded artifact.
Specifies the encoding of a binary artifact payload.
Exact imported and activated profile identity for an end-entity credential.
Opaque export artifact containing exported objects.
Controls export representation.
Query constraints for exporting credentials and revocations.
Validated exact X.509 extended-key-usage object identifier.
Persistent
AuditSink provider storing audit events as daily gzip
files.AuditSinkProvider for the file-backed audit sink.Default async bus provider: in-memory state with append-only file
persistence.
Filesystem-based reference implementation of
PkiStore.PkiStoreProvider for the filesystem-backed PkiStore.Explicit filesystem publication-destination provider.
Filesystem-backed staged-content store with atomic completion and streaming
integrity verification.
Identifier of a credential framework/format handled by the PKI core.
Maps universal attributes to framework-specific constructs and optionally
back.
History configuration for mutable entities stored by
FilesystemPkiStore.Supported cleanup strategy.
Options for
FilesystemPkiStore.String codec for stable persistence of identifiers.
Package-owned immutable registry implementation used by session bootstrap.
Immutable persisted profile version and its canonical configuration bytes.
Import and export operations for migration and interoperability.
Policy flags controlling import behavior.
In-memory
AuditSink provider intended for deterministic tests and
local debugging.AuditSinkProvider for the in-memory audit sink.Command to issue a new CA credential for an existing intermediate CA entity.
Command to create a new intermediate CA entity and issue its initial CA
credential.
Normalized inputs for issuance policy evaluation.
Durable idempotency and frozen-selection authority for one issuance request.
Issues, renews, replaces, and reissues credentials, and builds distributable
bundles.
Command to issue an end-entity credential from a parsed certification
request.
Immutable explicitly ordered issuer chain from selected issuer certificate to
its trust-anchor certificate.
Immutable authority record for one concrete CA issuer generation.
Durable lifecycle state of one concrete CA issuer generation.
References the exact issuer generation that produced a credential.
Opaque reference to private key material.
Complete issuer-controlled leaf certificate extension and identity policy.
Closed X.509 key-usage bit set available to leaf certificate profiles.
Immutable immediate or resolved metadata-transaction result.
Stable non-sensitive metadata failure categories.
Closed commit-outcome model.
A closeable, snapshot-consistent streaming metadata cursor.
Immutable provider-neutral identity of one metadata record.
An immutable, store-issued view of one committed metadata revision.
Stable content-integrity metadata without payload or storage details.
An ordered range within one semantic namespace.
A repeatable record view owned by a snapshot.
Immutable adapter capability declaration.
Accepted repeatable-content length forms.
Optional facilities that do not weaken required store semantics.
Authoritative transaction-outcome retention model.
Adapter writer-concurrency model.
Checked metadata-store failure carrying a stable, non-sensitive category.
Stable provider-neutral metadata-store identity.
A single-use, store-issued metadata transaction.
Canonical durable transaction identity issued by one metadata store.
Transport-neutral strict OCSP response generation through confined signing.
One strictly parsed CertID.
Supported RFC CertID digest identities.
Exact already-authorized responder generation command.
Exact responder identifier representation.
Signed canonical response and stable revocation provenance.
Internal mapper from X.509 and PKCS#10 signature algorithm identifiers to
ZeroEcho canonical signature algorithm ids.
Utility for constructing canonical PKI operation identifiers for asynchronous
orchestration.
Durability policy for workflow continuation data managed by orchestrators.
Normalized representation of a certification request.
Minimal bootstrap entry point for the
pki module.Collection of PKI-specific codecs used by the durable asynchronous
orchestration layer.
Result codec for persisting
EncodedObject values as
<ENCODING>:<base64url-without-padding>.Codec for representing
PkiId values by their stable string form.Codec for representing
Principal values as type:name.Trivial identity codec for endpoint identifiers.
PKI-specific async bus type aliases.
Endpoint identifier type for PKI asynchronous operations.
Operation identifier type for PKI asynchronous operations.
Owner type for PKI asynchronous operations.
Result type for PKI asynchronous operations.
PKI bootstrap utilities for ServiceLoader-based components.
ContentSigner implementation that delegates the actual signature
operation to PkiSigningBus.PKI-specific codecs used to instantiate the generic async bus.
Base runtime exception for PKI domain failures.
Opaque identifier for PKI-managed entities.
Utility methods for generating and validating
PkiId values.Closed set of typed synchronous PKI operations available to transports.
Activates one already imported certificate-profile version.
Creates one root certificate authority using an existing managed key reference.
Generates one signed status object from a stable revocation view.
Strictly parses and durably imports one certification request.
Inspects one active X.509 algorithm binding by stable identifier.
Reads safe metadata for one committed certificate authority.
Reads safe metadata for one committed credential.
Reads one exact imported certificate-profile version.
Reads safe durable state for one publication operation.
Reads safe metadata for one stored certification request.
Reads the validated current revocation state for one credential.
Reads safe metadata for one committed status object.
Issues one end-entity credential from an already imported request.
Lists active X.509 algorithm bindings with optional finite filters.
Lists committed certificate authorities with a finite presentation limit.
Lists the finite imported versions of one logical profile.
Lists publication records using a bounded-memory cursor and finite result page.
Lists status objects for one issuer with a finite presentation limit.
Processes one explicitly selected pending publication operation.
Reads a bounded prefix from one closeable authoritative history cursor.
Reconciles one publication operation whose external outcome is unknown.
Imports one bounded validated certificate-profile document.
Registers post-commit publication of one authoritative source object.
Explicitly retries one eligible publication operation.
Permanently revokes one committed credential.
Reads a bounded page from one immutable current-revocation snapshot.
Applies one explicit lifecycle transition to an existing authority.
Validates the immutable active registry and optionally one exact binding.
Validates the already-open session configuration.
Validates one bounded certificate-profile JSON document without persisting it.
Verifies proof of possession for one stored request.
Synchronous transport-neutral executor for the closed PKI operation model.
Stable safe classifications for synchronous PKI operation failures.
Closed success-or-safe-failure outcome returned by the operation executor.
Safely classified operation failure without a throwable graph.
Successful operation outcome.
Finite structured result of one successful typed PKI operation.
Closed transport-neutral value model used by safe operation results and plan
arguments.
Boolean scalar.
Signed 64-bit integer scalar.
Immutable ordered list value.
Deterministically ordered object value.
Text scalar.
Read-only authoritative repository facade owned by one
PkiSession.Lifecycle-owned immutable repository content lease without store internals.
Closed semantic role of public repository content.
Read-only transport-neutral resolver for authorization scope cross-checks.
Lifecycle-owned synchronous PKI backend session.
Immutable, versioned configuration for one synchronous PKI backend session.
Explicit activation and namespace authorization for one installed binding
provider.
Explicit signing and X.509 service-graph configuration.
Immutable process-local capabilities for one PKI session composition.
PKI signing bus that orchestrates asynchronous signature operations.
Persisted continuation payload for a PKI sign operation.
Persistence boundary for PKI state.
ServiceLoader provider for PkiStore
implementations.Policy decision including optional modifications to be applied to an
operation.
Outcome status of a policy evaluation.
Policy evaluation and explainability.
Explainability trace for a policy decision.
Single evaluation step within a policy trace.
POSIX exclusive-writer implementation of the transactional metadata-store SPI.
Identifies an actor performing an operation or requesting access.
Internal typed classification for redacted profile lifecycle failures.
Closed profile lifecycle failure codes.
Query constraints for listing profiles.
Versioned certificate-profile import, activation, and lookup service.
Result of proof-of-possession (PoP) verification.
Outcome of proof-of-possession (PoP) verification.
Verifies proof-of-possession (PoP) for a parsed request in a
framework-specific manner.
Backend configuration for
ConfigurableProvider instances.Immutable non-secret identity and content commitment for one external attempt.
Closeable snapshot-consistent cursor over publication records.
Identifies how an exact attempt outcome was established.
Safe closed classifications for publication-operation failures.
Definitive outcomes a publisher may safely return for one exact attempt.
Query constraints for listing publication records.
Persisted current state of one publication operation.
Immutable request to register distribution of one already committed PKI object.
Result of a publish operation.
Publication and distribution operations.
Identifies the authoritative PKI object supplying publication content.
Durable publication-operation state.
Describes where and how to publish an artifact.
Classifies the publication destination type.
Functional contract for resolving public key information for a
KeyRef.Resolves exportable public-key information from the same managed-key authority
used by a signature workflow.
Publishes an encoded artifact to a configured publication target.
Service-provider contract for explicitly configured publication destinations.
Declares the purpose of an operation/access for governance and auditing.
Command to reissue based on a stored issuance record.
Command to renew an existing credential.
Command to replace an existing credential.
Query constraints for searching stored certification requests.
Controls whether and when parsed certification requests are persisted for
correlation and audit.
Explicit deployment-owned resource constraint.
Positive finite deployment-owned limit.
Stable non-sensitive failure for deployment resource rejection.
Explicit absence of a deployment-owned limit.
Result report for a restore operation.
Requests restore of PKI state from a backup artifact.
Optional persistence codec for results.
Closed, immutable commands accepted by the revocation state machine.
Places a credential on hold.
Permanently revokes a credential.
Removes an existing hold.
Closeable one-pass history of one credential in credential-local revision order.
Normalized inputs for revocation policy evaluation.
Query constraints for searching revocation records.
Revocation reason codes with PKIX-compatible semantics.
Immutable current revocation state for one credential.
Authoritative revocation transition, current-state, and history administration.
Stable, restartable ordered current-state view at one authoritative revision.
One-pass current-state cursor.
Effective state recorded by the authoritative global revocation log.
One committed transition in the authoritative global revocation log.
Stable direct-lookup view of one authoritative revocation log revision.
Asynchronous signature workflow boundary for PKI.
Immutable cooperative deadline and cancellation control for one provider
invocation.
Callback interface for receiving asynchronous status updates.
Terminal result of a signature workflow operation.
Status of a long-running or asynchronous signature workflow operation.
Handle representing a registered
SignatureWorkflow.NotificationSink.Signing request.
Lifecycle states of a signature workflow operation.
Verification request.
ServiceLoader provider for
SignatureWorkflow.Immutable runtime dependencies supplied when opening a signature workflow.
Immutable bounds for one transport-neutral signing reconciliation pass.
Aggregate safe outcome of one bounded signing reconciliation pass.
Versioned ZeroEcho signing-submission identifier.
Authoritative durable state machine for signing submissions.
Result of idempotent intent creation.
One bounded snapshot page ordered by canonical submission identifier.
Durable classification for one deferred reconciliation retry.
Complete durable signing state.
Signing orchestration states.
Minimal immutable
AttributeSet implementation used by PKI core
runtime services.Minimal immutable
AttributeSet implementation used by the Bouncy
Castle backed X.509 framework adapter.Mutable builder for
SimpleAttributeSet.Mutable builder for
SimpleAttributeSet.Immutable representation of one attribute entry.
Utility for selecting ServiceLoader providers by a stable identifier.
Provider id accessor used by the selector.
Reads component configuration from system properties using a prefix
convention.
Durable, runtime-owned staging boundary for signed-object content.
Immutable authoritative standard X.509 bootstrap bindings.
Generated status object used for revocation distribution.
Command to generate a new status object for an issuer CA.
Generates status objects for a credential framework (e.g., CRL/delta CRL/OCSP
for X.509).
Query constraints for listing status objects.
Status object generation and retrieval.
Identifies the kind of published status object.
Reference
AuditSink provider writing a deterministic summary line to
standard output.AuditSinkProvider for the standard-output audit sink.Store-backed authoritative resolver for runtime credential status.
Focused incremental canonical-DER structural validator.
Supported signed-object grammar.
Exact offsets into the validated original DER.
Focused canonical DER streaming primitives used by signed-object adapters.
Closed immutable canonical Subject Alternative Name representation.
Canonical DNS A-label name.
Canonical raw IPv4 or IPv6 address.
Canonical ASCII RFC 822 mailbox.
Canonical ASCII hierarchical absolute URI.
Deny-by-default Subject Alternative Name policy.
Occurrence and IP-family rule for one supported SAN type.
Closed set of requester-supplied Subject Alternative Name types.
Deny-by-default subject distinguished-name policy.
One ordered, single-valued, typed subject distinguished-name component.
Immutable occurrence and ownership rule for one supported subject RDN type.
Closed set of X.509 subject distinguished-name attributes supported by
end-entity certificate profiles.
Framework-agnostic subject identifier.
Runtime-owned file-backed uniqueness index for bounded individual values.
Provider-neutral authority for finite transactional control metadata.
Immutable gate-produced CA certificate request accepted by the issuer
backend.
Closed CA certificate operations authorized by this gate.
Immutable gate-produced end-entity certificate construction authority.
Validity interval for an issued credential.
Constraints for certification request verification.
Immutable internal authority for a request that passed the issuance PoP gate.
Proof-of-possession verifier for PKCS#10 certification requests that
delegates signature verification to a
SignatureWorkflow.Persisted continuation state for an orchestrated workflow.
Immutable safe descriptor of one role-specific X.509 algorithm binding.
Relying-party interoperability expectation.
Authority that owns the OID assignment.
Canonical AlgorithmIdentifier parameter representation.
Subject-public-key BIT STRING representation.
X.509 locations whose representations are independently authorized.
Signature BIT STRING representation.
Immutable explicit X.509 representation policy persisted with a certificate
profile.
Stable reference to one immutable binding contract.
Selection mode.
Installed-code provider of deployer-owned immutable X.509 bindings.
Immutable active X.509 algorithm-binding registry shared by one PKI session.
Provider-neutral canonical X.509
AlgorithmIdentifier representation.Exact parameter representation.
Provider-independent intersection of exact identity, binding, installed
execution capability, immutable security floor, configured policy, and key
compatibility.
Stable resolution failure categories.
Policy decision over exact identity data.
Resolution exception with a stable non-sensitive category.
Immutable effective selection.
Closed semantic role of an algorithm representation in X.509.
One immutable internally consistent runtime authority snapshot.
Immutable process-local executor contribution.
Deeply immutable snapshot of authoritative X.509 binding rules.
Immutable trusted-code rule between exact ZeroEcho identities and X.509
representations.
Subject-public-key bit-string representation.
Signature byte representation owned by a signature rule.
Trusted installed-code contribution of additive X.509 binding rules.
Immutable code-owned PKI defaults.
Immutable additive catalog of X.509 component identities used inside
parameterized binding rules.
Immutable component binding.
Closed component role.
Immutable process-local authorization to execute one resolved X.509
operation.
Non-overridable PKI algorithm security floor.
Non-forgeable live completion of one X.509 signed status-object operation.
Contextual compatibility validation for current classic X.509 suites.
ZeroEcho-lib backed implementation of
SignatureWorkflow.Production provider bridging PKI signature workflow to ZeroEcho lib based on
KeyringStore.Loads and locks the version-one ZeroEcho-owned private X.509 assignments.