Index

A B C D E F G H I K L M N O P R S T U V W X Z 
All Classes and Interfaces|All Packages|Constant Field Values|Serialized Form

A

AA_COMPROMISE - Enum constant in enum class zeroecho.pki.api.revocation.RevocationReason
Attribute authority is compromised.
ABANDONED_BY_RECOVERY - Enum constant in enum class zeroecho.pki.spi.store.MetadataCommitResult.FailureCategory
The transaction was durably issued but had no authoritative terminal outcome when recovery closed its preceding recovery epoch.
abort() - Method in interface zeroecho.pki.spi.store.ContentSink
Aborts and removes partial content.
abort() - Method in interface zeroecho.pki.spi.store.MetadataTransaction
Aborts the transaction and releases detached staging resources.
absent(String) - Static method in class zeroecho.pki.impl.framework.x509.X509AlgorithmIdentifier
Creates an identifier with absent parameters.
ABSENT - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.ParameterRule
Parameters must be absent.
ABSENT - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509AlgorithmIdentifier.ParameterForm
Parameters are omitted.
acceptedSourceBytes() - Method in record class zeroecho.pki.api.content.DeploymentResourcePolicy
Returns the value of the acceptedSourceBytes record component.
AccessAction - Enum Class in zeroecho.pki.api.audit
Action performed on an attribute for access governance.
accessContext() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.SignRequest
Returns the value of the accessContext record component.
accessContext() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.VerifyRequest
Returns the value of the accessContext record component.
AccessContext - Record Class in zeroecho.pki.api.audit
Context used for attribute ACL checks and audit correlation.
AccessContext(Principal, Purpose, Optional<PkiId>, Optional<FormatId>) - Constructor for record class zeroecho.pki.api.audit.AccessContext
Creates an access context.
AccessDecision - Enum Class in zeroecho.pki.api.audit
Decision outcome of an access control check.
accessPolicy() - Method in record class zeroecho.pki.api.attr.AttributeDefinition
Returns the value of the accessPolicy record component.
acknowledge(MetadataTransactionId) - Method in class zeroecho.pki.impl.fs.PosixTransactionalMetadataStore
Acknowledges a terminal retained outcome when supported.
acknowledge(MetadataTransactionId) - Method in interface zeroecho.pki.spi.store.TransactionalMetadataStore
Acknowledges a terminal retained outcome when supported.
action() - Method in record class zeroecho.pki.api.audit.AuditEvent
Returns the value of the action record component.
action() - Method in record class zeroecho.pki.api.audit.AuditQuery
Returns the value of the action record component.
activateProfile(String, long) - Method in interface zeroecho.pki.api.ProfileService
Explicitly activates one already imported version.
activateProfile(String, long) - Method in class zeroecho.pki.impl.core.DefaultProfileService
 
activateProfile(String, long) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
activateProfile(String, long) - Method in interface zeroecho.pki.spi.store.PkiStore
Atomically activates one imported version.
ActivateProfile(String, long) - Constructor for record class zeroecho.pki.application.PkiOperation.ActivateProfile
Validates the exact profile identity.
ACTIVE - Enum constant in enum class zeroecho.pki.api.ca.CaState
CA is active and may issue new credentials according to policy.
ACTIVE - Enum constant in enum class zeroecho.pki.api.ca.IssuerGenerationState
Available for explicitly selected issuance.
ActiveCertificateProfile - Record Class in zeroecho.pki.api.profile
Validated active profile resolution result used by end-entity issuance.
ActiveCertificateProfile(CertificateProfileRef, CertificateProfileDefinition) - Constructor for record class zeroecho.pki.api.profile.ActiveCertificateProfile
Creates an active profile result.
activeOnly() - Method in record class zeroecho.pki.api.profile.ProfileQuery
Returns the value of the activeOnly record component.
add(byte[]) - Method in interface zeroecho.pki.spi.store.TemporaryUniqueIndex
Adds one immutable bounded value.
AFFILIATION_CHANGED - Enum constant in enum class zeroecho.pki.api.revocation.RevocationReason
Subject affiliation has changed.
after() - Method in record class zeroecho.pki.api.audit.AuditQuery
Returns the value of the after record component.
after() - Method in record class zeroecho.pki.api.publication.PublicationQuery
Returns the value of the after record component.
algorithm() - Method in record class zeroecho.pki.spi.store.MetadataSnapshot.Integrity
Returns the value of the algorithm record component.
algorithmBindingPolicy() - Method in record class zeroecho.pki.api.profile.CertificateProfile
Returns the value of the algorithmBindingPolicy record component.
algorithmBindingPolicy() - Method in record class zeroecho.pki.api.profile.CertificateProfileDefinition
Returns the value of the algorithmBindingPolicy record component.
algorithmBindingPolicy() - Method in class zeroecho.pki.impl.core.ValidatedCaCertificateRequest
 
algorithmBindingPolicy() - Method in class zeroecho.pki.impl.core.ValidatedCertificateRequest
 
algorithmBindings() - Method in interface zeroecho.pki.application.PkiSession
Returns the immutable active X.509 algorithm-binding registry.
Algorithm handling - Search tag in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
Section
algorithmId() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.SignRequest
Returns the value of the algorithmId record component.
algorithmId() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.VerifyRequest
Returns the value of the algorithmId record component.
algorithmIdentity() - Method in record class zeroecho.pki.api.algorithm.X509AlgorithmBinding
Returns the value of the algorithmIdentity record component.
aliases() - Method in interface zeroecho.pki.impl.framework.x509.X509BindingRuleProvider
Returns finite compatibility aliases.
all(String) - Static method in record class zeroecho.pki.spi.store.MetadataSnapshot.KeyRange
Returns a range containing the complete namespace.
allocate(ProviderConfig) - Method in class zeroecho.pki.impl.async.FileBackedAsyncBusProvider
 
allocate(ProviderConfig) - Method in class zeroecho.pki.impl.audit.FileAuditSinkProvider
 
allocate(ProviderConfig) - Method in class zeroecho.pki.impl.audit.InMemoryAuditSinkProvider
 
allocate(ProviderConfig) - Method in class zeroecho.pki.impl.audit.StdoutAuditSinkProvider
 
allocate(ProviderConfig) - Method in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflowProvider
 
allocate(ProviderConfig) - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFrameworkProvider
Allocates a new Bouncy Castle backed X.509 credential framework instance.
allocate(ProviderConfig) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStoreProvider
 
allocate(ProviderConfig) - Method in class zeroecho.pki.impl.publish.FilesystemPublisherProvider
 
allocate(ProviderConfig) - Method in interface zeroecho.pki.spi.audit.AuditSinkProvider
Opens a new AuditSink instance using the provided configuration.
allocate(ProviderConfig) - Method in interface zeroecho.pki.spi.ConfigurableProvider
Allocates a new instance using the provided configuration.
allocate(ProviderConfig) - Method in interface zeroecho.pki.spi.framework.CredentialFrameworkProvider
Allocates a credential framework instance using the provided configuration.
allocate(ProviderConfig) - Method in interface zeroecho.pki.spi.store.PkiStoreProvider
Opens a new PkiStore instance using the provided configuration.
allocate(ProviderConfig, SignatureWorkflowRuntimeDependencies) - Method in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflowProvider
Allocates a workflow using explicit runtime dependencies.
allocate(ProviderConfig, SignatureWorkflowRuntimeDependencies) - Method in interface zeroecho.pki.spi.crypto.SignatureWorkflowProvider
Allocates a workflow using explicit process-local runtime dependencies.
ALLOW - Enum constant in enum class zeroecho.pki.api.audit.AccessDecision
Access is allowed.
ALLOW - Enum constant in enum class zeroecho.pki.api.policy.PolicyDecisionStatus
Operation is allowed under current policy.
ALLOW_WITH_MODIFICATIONS - Enum constant in enum class zeroecho.pki.api.policy.PolicyDecisionStatus
Operation is allowed, but policy requires modifications (e.g., validity truncation).
allowDnsWildcard() - Method in record class zeroecho.pki.api.profile.SubjectAlternativeNamePolicy
Returns the value of the allowDnsWildcard record component.
allowedSubjectKeyAlgorithmIds() - Method in record class zeroecho.pki.api.profile.CaCertificatePolicy
Returns the value of the allowedSubjectKeyAlgorithmIds record component.
allowedSubjectKeyAlgorithmIds() - Method in record class zeroecho.pki.api.profile.LeafCertificatePolicy
Returns the value of the allowedSubjectKeyAlgorithmIds record component.
allowedUriSchemes() - Method in record class zeroecho.pki.api.profile.SubjectAlternativeNamePolicy
Returns the value of the allowedUriSchemes record component.
allowEmpty() - Method in record class zeroecho.pki.api.profile.SubjectPolicy
Returns the value of the allowEmpty record component.
allowIpv4() - Method in record class zeroecho.pki.api.profile.SubjectAlternativeNameRule
Returns the value of the allowIpv4 record component.
allowIpv6() - Method in record class zeroecho.pki.api.profile.SubjectAlternativeNameRule
Returns the value of the allowIpv6 record component.
allowOverwrite() - Method in record class zeroecho.pki.api.transfer.ImportPolicy
Returns the value of the allowOverwrite record component.
AMBIGUOUS_IMPLEMENTATION - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Failure
More than one implementation remains without explicit selection.
API - Enum constant in enum class zeroecho.pki.api.attr.AttributeExportTarget
Export via a programmatic API.
API stability and integration - Search tag in package zeroecho.pki.api.orch
Section
appendLine(String) - Method in class zeroecho.pki.util.async.impl.AppendOnlyLineStore
Appends a single line (with trailing '\n') to the store.
AppendOnlyLineStore - Class in zeroecho.pki.util.async.impl
Append-only UTF-8 line store with best-effort POSIX permissions.
AppendOnlyLineStore(Path) - Constructor for class zeroecho.pki.util.async.impl.AppendOnlyLineStore
Creates a store backed by the provided file path.
appliedOverrides() - Method in record class zeroecho.pki.api.policy.PolicyDecision
Returns the value of the appliedOverrides record component.
Architectural boundaries - Search tag in package zeroecho.pki.impl.core
Section
Architectural boundaries - Search tag in package zeroecho.pki.impl.framework.x509.bc
Section
Architectural note - Search tag in class zeroecho.pki.impl.framework.x509.bc.OidAlgorithmMapper
Section
Architectural role - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509FrameworkAttributeMapper
Section
Architectural role - Search tag in interface zeroecho.pki.spi.framework.CredentialIssuerBackend
Section
Architectural role - Search tag in package zeroecho.pki.impl.core.async
Section
Architectural role - Search tag in package zeroecho.pki.impl.crypto.zeroecholib
Section
artifact() - Method in record class zeroecho.pki.api.backup.RestoreRequest
Returns the value of the artifact record component.
Artifacts - Search tag in package zeroecho.pki.api.publication
Section
AsyncBus<OpId,Owner,EndpointId,Result> - Interface in zeroecho.pki.util.async
Generic asynchronous operation bus.
AsyncBusProvider - Interface in zeroecho.pki.spi.async
ServiceLoader provider for the PKI asynchronous operation bus.
Async bus sweep - Search tag in class zeroecho.pki.PkiApplication
Section
AsyncEndpoint<OpId,Res> - Interface in zeroecho.pki.util.async
Target endpoint that owns/executes operations and can be asked for their status.
AsyncEvent<OpId,Owner,Eid,Result> - Record Class in zeroecho.pki.util.async
Event delivered to registered handlers whenever an operation status changes.
AsyncEvent(AsyncOperationSnapshot<OpId, Owner, Eid>, AsyncStatus, Optional<Result>) - Constructor for record class zeroecho.pki.util.async.AsyncEvent
Creates an event.
AsyncHandler<OpId,Owner,Eid,Result> - Interface in zeroecho.pki.util.async
Callback handler for async operation events.
AsyncOperationSnapshot<OpId,Owner,EndpointId> - Record Class in zeroecho.pki.util.async
Immutable snapshot of an operation's identity and routing metadata.
AsyncOperationSnapshot(OpId, String, Owner, EndpointId, Instant, Instant) - Constructor for record class zeroecho.pki.util.async.AsyncOperationSnapshot
Creates a snapshot and validates invariants.
AsyncRegistration - Interface in zeroecho.pki.util.async
Registration handle for a handler subscription.
AsyncState - Enum Class in zeroecho.pki.util.async
Lifecycle state of an asynchronous operation.
AsyncStatus - Record Class in zeroecho.pki.util.async
Non-sensitive status snapshot of an asynchronous operation.
AsyncStatus(AsyncState, Instant, Optional<String>, Map<String, String>) - Constructor for record class zeroecho.pki.util.async.AsyncStatus
Creates a status record and validates invariants.
ATTACHED - Enum constant in enum class zeroecho.pki.spi.store.SignWorkflowStore.CreateResult
 
attemptNumber() - Method in record class zeroecho.pki.api.publication.PublicationRecord
Returns the value of the attemptNumber record component.
attemptNumber() - Method in record class zeroecho.pki.api.publication.PublicationResult
Returns the value of the attemptNumber record component.
attemptNumber() - Method in record class zeroecho.pki.spi.publish.PublicationAttempt
Returns the value of the attemptNumber record component.
attemptToken() - Method in record class zeroecho.pki.api.publication.PublicationRecord
Returns the value of the attemptToken record component.
attemptToken() - Method in record class zeroecho.pki.spi.publish.PublicationAttempt
Returns the value of the attemptToken record component.
AttributeAccessController - Interface in zeroecho.pki.api.audit
Policy decision point for attribute-level access control.
AttributeAccessPolicy - Record Class in zeroecho.pki.api.attr
Governance hints controlling auditing and exportability of an attribute.
AttributeAccessPolicy(boolean, boolean, Set<AttributeExportTarget>) - Constructor for record class zeroecho.pki.api.attr.AttributeAccessPolicy
Creates an access policy.
AttributeCatalogue - Interface in zeroecho.pki.api.attr
Registry/catalogue of attribute definitions.
AttributeDefinition - Record Class in zeroecho.pki.api.attr
Typed and governed attribute definition used across credential frameworks.
AttributeDefinition(AttributeId, String, AttributeValueType, boolean, AttributeSensitivity, AttributeStability, AttributeAccessPolicy, AttributeMeta) - Constructor for record class zeroecho.pki.api.attr.AttributeDefinition
Creates an attribute definition.
AttributeExportTarget - Enum Class in zeroecho.pki.api.attr
Named export targets used by governance and publication pipelines.
AttributeGovernanceService - Interface in zeroecho.pki.api.audit
Policy enforcement point for attribute access with mandatory auditing.
AttributeId - Record Class in zeroecho.pki.api.attr
Stable attribute identifier used by the attribute catalogue.
AttributeId(String) - Constructor for record class zeroecho.pki.api.attr.AttributeId
Creates an attribute identifier.
attributeMapper() - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFramework
Returns the framework-specific attribute mapper used by this framework instance.
attributeMapper() - Method in interface zeroecho.pki.spi.framework.CredentialFramework
Returns the framework attribute mapper.
AttributeMeta - Record Class in zeroecho.pki.api.attr
Structured, human-facing documentation metadata for an attribute definition.
AttributeMeta(String, List<String>, List<String>, List<String>, Map<String, String>) - Constructor for record class zeroecho.pki.api.attr.AttributeMeta
Creates attribute metadata.
attributes() - Method in record class zeroecho.pki.api.backup.BackupRequest
Returns the value of the attributes record component.
attributes() - Method in record class zeroecho.pki.api.backup.RestoreRequest
Returns the value of the attributes record component.
attributes() - Method in record class zeroecho.pki.api.ca.CaCreateCommand
Returns the value of the attributes record component.
attributes() - Method in record class zeroecho.pki.api.ca.CaImportCommand
Returns the value of the attributes record component.
attributes() - Method in record class zeroecho.pki.api.ca.CaKeyRotationCommand
Returns the value of the attributes record component.
attributes() - Method in record class zeroecho.pki.api.ca.CaRolloverCommand
Returns the value of the attributes record component.
attributes() - Method in record class zeroecho.pki.api.ca.IntermediateCertIssueCommand
Returns the value of the attributes record component.
attributes() - Method in record class zeroecho.pki.api.ca.IntermediateCreateCommand
Returns the value of the attributes record component.
attributes() - Method in record class zeroecho.pki.api.credential.Credential
Returns the value of the attributes record component.
attributes() - Method in record class zeroecho.pki.api.request.ParsedCertificationRequest
Returns the value of the attributes record component.
attributes() - Method in interface zeroecho.pki.api.revocation.RevocationCommand
Returns an immutable snapshot of safe administrative metadata.
attributes() - Method in record class zeroecho.pki.api.revocation.RevocationCommand.Hold
Returns the value of the attributes record component.
attributes() - Method in record class zeroecho.pki.api.revocation.RevocationCommand.RevokePermanently
Returns the value of the attributes record component.
attributes() - Method in record class zeroecho.pki.api.revocation.RevocationCommand.Unhold
Returns the value of the attributes record component.
attributes() - Method in record class zeroecho.pki.api.revocation.RevocationInputs
Returns the value of the attributes record component.
attributes() - Method in record class zeroecho.pki.api.revocation.RevocationTransition
Returns the value of the attributes record component.
attributes() - Method in record class zeroecho.pki.api.status.StatusObject
Returns the value of the attributes record component.
attributes() - Method in record class zeroecho.pki.api.status.StatusObjectGenerateCommand
Returns the value of the attributes record component.
attributes() - Method in record class zeroecho.pki.api.transfer.ImportPolicy
Returns the value of the attributes record component.
AttributeSensitivity - Enum Class in zeroecho.pki.api.attr
Data sensitivity classification for an attribute.
AttributeSet - Interface in zeroecho.pki.api.attr
Immutable set of typed attributes.
AttributeStability - Enum Class in zeroecho.pki.api.attr
Lifecycle maturity of an attribute definition.
AttributeValue - Interface in zeroecho.pki.api.attr
Typed attribute value.
AttributeValue.BooleanValue - Record Class in zeroecho.pki.api.attr
Boolean value.
AttributeValue.BytesValue - Record Class in zeroecho.pki.api.attr
Byte string value.
AttributeValue.InstantValue - Record Class in zeroecho.pki.api.attr
Instant value.
AttributeValue.IntegerValue - Record Class in zeroecho.pki.api.attr
Integer/long value.
AttributeValue.StringValue - Record Class in zeroecho.pki.api.attr
String value.
AttributeValueType - Enum Class in zeroecho.pki.api.attr
Declares the logical value type of an attribute.
audit() - Method in record class zeroecho.pki.application.PkiSessionConfiguration
Returns the value of the audit record component.
AuditEvent - Record Class in zeroecho.pki.api.audit
Auditable event emitted by the PKI core and governance layer.
AuditEvent(Instant, String, String, Principal, Purpose, Optional<PkiId>, Optional<FormatId>, Map<String, String>) - Constructor for record class zeroecho.pki.api.audit.AuditEvent
Creates an audit event and validates record invariants.
auditOnAllow() - Method in record class zeroecho.pki.api.attr.AttributeAccessPolicy
Returns the value of the auditOnAllow record component.
auditOnDeny() - Method in record class zeroecho.pki.api.attr.AttributeAccessPolicy
Returns the value of the auditOnDeny record component.
auditOrder() - Static method in record class zeroecho.pki.api.audit.AuditEvent
Returns a deterministic comparator for audit events.
AuditQuery - Record Class in zeroecho.pki.api.audit
Query constraints for searching audit events.
AuditQuery(Optional<String>, Optional<String>, Optional<Instant>, Optional<Instant>, Optional<PkiId>, Optional<String>) - Constructor for record class zeroecho.pki.api.audit.AuditQuery
Creates an audit query.
AuditService - Interface in zeroecho.pki.api.audit
Records and queries audit events for PKI operations and attribute governance.
auditSink() - Method in record class zeroecho.pki.application.PkiSessionRuntimeDependencies
Returns the value of the auditSink record component.
AuditSink - Interface in zeroecho.pki.spi.audit
SPI for persisting audit events.
AuditSinkProvider - Interface in zeroecho.pki.spi.audit
ServiceLoader provider for AuditSink implementations.
authorities() - Method in interface zeroecho.pki.application.PkiSession
 
authorities(Optional<PkiId>, int) - Method in interface zeroecho.pki.application.PkiRepository
Returns a finite canonical authority page after an optional exclusive key.
authority() - Method in class zeroecho.pki.impl.core.async.PkiSigningBus
Returns the immutable authority used by this workflow graph.
authority() - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFramework
Returns the immutable algorithm authority owned by this framework graph.
authority(PkiId) - Method in interface zeroecho.pki.application.PkiRepository
Returns an exact logical authority.
authorityFingerprint() - Method in record class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Selection
Returns the value of the authorityFingerprint record component.
authorityId() - Method in record class zeroecho.pki.api.ca.IssuerChainPath
Returns the value of the authorityId record component.
authorityId() - Method in record class zeroecho.pki.api.ca.IssuerGeneration
Returns the value of the authorityId record component.
authorityId() - Method in record class zeroecho.pki.application.OcspResponseService.Command
Returns the value of the authorityId record component.
authorityId() - Method in class zeroecho.pki.application.PkiRepositoryContent
 
authorize(X509ExecutionPlan<?>, Object, AlgorithmExecutionCapability.Direction) - Method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Validates an execution plan immediately before invoking its executor.
authorizedOidRoots() - Method in record class zeroecho.pki.application.PkiSessionConfiguration.BindingProviderConfiguration
Returns the value of the authorizedOidRoots record component.

B

backendId() - Method in record class zeroecho.pki.spi.ProviderConfig
Returns the value of the backendId record component.
BACKUP - Enum constant in enum class zeroecho.pki.api.attr.AttributeExportTarget
Export to backups.
BackupArtifact - Record Class in zeroecho.pki.api.backup
Opaque backup artifact produced by BackupService.
BackupArtifact(PkiId, EncodedObject) - Constructor for record class zeroecho.pki.api.backup.BackupArtifact
Creates a backup artifact.
backupId() - Method in record class zeroecho.pki.api.backup.BackupArtifact
Returns the value of the backupId record component.
BackupRequest - Record Class in zeroecho.pki.api.backup
Requests creation of a PKI backup.
BackupRequest(String, AttributeSet) - Constructor for record class zeroecho.pki.api.backup.BackupRequest
Creates a backup request.
BackupService - Interface in zeroecho.pki.api
Backup/restore operations for PKI state.
BackupVerificationReport - Record Class in zeroecho.pki.api.backup
Verification results for a backup artifact.
BackupVerificationReport(boolean, List<String>) - Constructor for record class zeroecho.pki.api.backup.BackupVerificationReport
Creates a backup verification report.
basicConstraintsCritical() - Method in record class zeroecho.pki.api.profile.CaCertificatePolicy
Returns the value of the basicConstraintsCritical record component.
basicConstraintsCritical() - Method in record class zeroecho.pki.api.profile.LeafCertificatePolicy
Returns the value of the basicConstraintsCritical record component.
basicConstraintsCritical() - Method in class zeroecho.pki.impl.core.ValidatedCertificateRequest
 
BcX509AlgorithmAdapter - Class in zeroecho.pki.impl.framework.x509.bc
Bouncy Castle edge adapter for the provider-neutral X.509 binding authority.
BcX509AlgorithmAdapter(X509BindingCatalog) - Constructor for class zeroecho.pki.impl.framework.x509.bc.BcX509AlgorithmAdapter
Creates an adapter for one immutable catalog snapshot.
BcX509Attributes - Class in zeroecho.pki.impl.framework.x509.bc
Internal attribute identifiers used by the Bouncy Castle backed X.509 PKI framework adapter.
BcX509CertificationRequestParser - Class in zeroecho.pki.impl.framework.x509.bc
Bouncy Castle backed parser for X.509 PKCS#10 certification requests.
BcX509CertificationRequestParser() - Constructor for class zeroecho.pki.impl.framework.x509.bc.BcX509CertificationRequestParser
 
BcX509CredentialFramework - Class in zeroecho.pki.impl.framework.x509.bc
Bouncy Castle backed X.509 implementation of CredentialFramework.
BcX509CredentialFramework(X509AuthoritySnapshot, BcX509VerificationExecutor) - Constructor for class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFramework
Creates a partially wired X.509 framework instance with default components.
BcX509CredentialFrameworkProvider - Class in zeroecho.pki.impl.framework.x509.bc
ServiceLoader provider for the Bouncy Castle backed X.509 credential framework.
BcX509CredentialFrameworkProvider() - Constructor for class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFrameworkProvider
 
BcX509CredentialIssuerBackend - Class in zeroecho.pki.impl.framework.x509.bc
Bouncy Castle backed X.509 credential issuance backend.
BcX509CredentialIssuerBackend(PkiSigningBus, String, Duration) - Constructor for class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialIssuerBackend
Creates the X.509 issuance backend.
BcX509CredentialIssuerBackend(PkiSigningBus, AlgorithmIdentity, Duration) - Constructor for class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialIssuerBackend
Creates the X.509 issuance backend with an exact signature identity.
BcX509CredentialIssuerBackend(PkiSigningBus, AlgorithmIdentity, Optional<String>, Duration) - Constructor for class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialIssuerBackend
Creates an issuance backend with an optional explicit certificate binding.
BcX509FrameworkAttributeMapper - Class in zeroecho.pki.impl.framework.x509.bc
Minimal framework attribute mapper for the internal Bouncy Castle backed X.509 adapter.
BcX509FrameworkAttributeMapper() - Constructor for class zeroecho.pki.impl.framework.x509.bc.BcX509FrameworkAttributeMapper
 
BcX509ProfileSupport - Class in zeroecho.pki.impl.framework.x509.bc
Exact X.509 representation and postcondition helpers for validated leaf profiles.
BcX509ProofOfPossessionVerifier - Class in zeroecho.pki.impl.framework.x509.bc
Bouncy Castle backed proof-of-possession verifier for X.509 PKCS#10 certification requests.
BcX509ProofOfPossessionVerifier(X509AuthoritySnapshot, BcX509VerificationExecutor) - Constructor for class zeroecho.pki.impl.framework.x509.bc.BcX509ProofOfPossessionVerifier
Creates a verifier backed by one runtime authority and its exact executor.
BcX509PublicKeyAdapter - Class in zeroecho.pki.impl.framework.x509.bc
Bouncy Castle adapter for binding-owned SubjectPublicKeyInfo encodings.
BcX509PublicKeyAdapter(X509BindingCatalog) - Constructor for class zeroecho.pki.impl.framework.x509.bc.BcX509PublicKeyAdapter
Creates an adapter for one immutable binding catalog.
BcX509SignedObjectValidator - Class in zeroecho.pki.impl.framework.x509.bc
Bouncy Castle edge inspection of a canonically validated signed X.509 object.
BcX509SignedObjectValidator(X509AuthoritySnapshot) - Constructor for class zeroecho.pki.impl.framework.x509.bc.BcX509SignedObjectValidator
Creates a validator owned by one immutable authority snapshot.
BcX509SignedObjectValidator.CertificateBindings - Record Class in zeroecho.pki.impl.framework.x509.bc
Exact role-specific identities extracted from validated original DER.
BcX509StatusObjectGenerator - Class in zeroecho.pki.impl.framework.x509.bc
Bouncy Castle backed generator of X.509 status objects.
BcX509StatusObjectGenerator(PkiSigningBus, String, Duration) - Constructor for class zeroecho.pki.impl.framework.x509.bc.BcX509StatusObjectGenerator
Creates the X.509 status object generator.
BcX509StatusObjectGenerator(PkiSigningBus, AlgorithmIdentity, Duration) - Constructor for class zeroecho.pki.impl.framework.x509.bc.BcX509StatusObjectGenerator
Creates the generator with an exact signature identity.
BcX509StatusObjectGenerator(PkiSigningBus, AlgorithmIdentity, Optional<String>, Duration) - Constructor for class zeroecho.pki.impl.framework.x509.bc.BcX509StatusObjectGenerator
Creates a generator with an optional explicit CRL-signature binding.
BcX509VerificationExecutor - Class in zeroecho.pki.impl.framework.x509.bc
Stateless Bouncy Castle verification executor at the X.509 adapter edge.
BcX509VerificationExecutor() - Constructor for class zeroecho.pki.impl.framework.x509.bc.BcX509VerificationExecutor
 
before() - Method in record class zeroecho.pki.api.audit.AuditQuery
Returns the value of the before record component.
before() - Method in record class zeroecho.pki.api.publication.PublicationQuery
Returns the value of the before record component.
beginContent(Encoding, DurableContentReference.Lifecycle) - Method in class zeroecho.pki.impl.core.async.PkiSigningBus
Begins atomic runtime-owned content staging.
beginContent(Encoding, DurableContentReference.Lifecycle) - Method in class zeroecho.pki.impl.fs.FilesystemStagedContentStore
 
beginContent(Encoding, DurableContentReference.Lifecycle) - Method in interface zeroecho.pki.spi.store.StagedContentStore
Begins an atomic staged write.
beginEvaluation() - Method in interface zeroecho.pki.api.credential.EffectiveCredentialStatusResolver
Starts one status evaluation using one captured authoritative time.
beginEvaluation() - Method in class zeroecho.pki.impl.core.StoreBackedEffectiveCredentialStatusResolver
 
beginSigningContent(Encoding) - Method in class zeroecho.pki.impl.core.async.PkiSigningBus
Begins runtime-owned durable staging for one signing input.
beginTransaction() - Method in class zeroecho.pki.impl.fs.PosixTransactionalMetadataStore
Begins a single-use store-issued transaction.
beginTransaction() - Method in interface zeroecho.pki.spi.store.TransactionalMetadataStore
Begins a single-use store-issued transaction.
beginUniqueIndex() - Method in class zeroecho.pki.impl.core.async.PkiSigningBus
Begins a runtime-owned file-backed uniqueness index.
beginUniqueIndex() - Method in class zeroecho.pki.impl.fs.FilesystemStagedContentStore
 
beginUniqueIndex() - Method in interface zeroecho.pki.spi.store.StagedContentStore
Begins one file-backed uniqueness index for bounded individual values.
BINARY - Enum constant in enum class zeroecho.pki.api.Encoding
Raw binary blob without implying ASN.1 DER or PEM semantics.
BINARY_ARCHIVE - Enum constant in enum class zeroecho.pki.api.transfer.ExportFormat
Export as a binary archive (tar/zip-like).
bindExecutor(String, AlgorithmExecutionCapability.Direction, Object) - Static method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Creates one exact process-local executor binding.
binding() - Method in record class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Selection
Returns the value of the binding record component.
bindingId() - Method in record class zeroecho.pki.api.algorithm.X509AlgorithmBinding
Returns the value of the bindingId record component.
bindingId() - Method in record class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy.BindingReference
Returns the value of the bindingId record component.
bindingId() - Method in record class zeroecho.pki.application.PkiOperation.InspectAlgorithmBinding
Returns the value of the bindingId record component.
bindingId() - Method in record class zeroecho.pki.application.PkiOperation.ValidateAlgorithmBindings
Returns the value of the bindingId record component.
bindingId(X509AlgorithmIdentifier, X509AlgorithmRole) - Method in class zeroecho.pki.impl.framework.x509.X509BindingCatalog
Returns the stable binding identifier owning an exact representation.
BindingProviderConfiguration(String, List<String>, Optional<String>) - Constructor for record class zeroecho.pki.application.PkiSessionConfiguration.BindingProviderConfiguration
Validates and snapshots the activation.
bindingProviders() - Method in record class zeroecho.pki.application.PkiSessionConfiguration
Returns the value of the bindingProviders record component.
BindingReference(String, String) - Constructor for record class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy.BindingReference
Validates one binding reference.
bindings() - Method in interface zeroecho.pki.api.algorithm.X509AlgorithmBindingRegistry
 
bindings() - Method in class zeroecho.pki.impl.framework.x509.ImmutableX509AlgorithmBindingRegistry
 
bindings() - Method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Returns the binding catalog snapshot.
bindings() - Method in interface zeroecho.pki.impl.framework.x509.X509BindingRule
Returns the finite safe descriptors owned by this encoding rule.
bindings() - Method in interface zeroecho.pki.spi.algorithm.X509AlgorithmBindingProvider
 
bindingSetVersion() - Method in interface zeroecho.pki.spi.algorithm.X509AlgorithmBindingProvider
 
BIT_STRING_TAG - Static variable in class zeroecho.pki.impl.framework.x509.StreamingDerWriter
DER universal BIT STRING tag.
BOOLEAN - Enum constant in enum class zeroecho.pki.api.attr.AttributeValueType
Boolean value.
BooleanValue(boolean) - Constructor for record class zeroecho.pki.api.attr.AttributeValue.BooleanValue
Creates an instance of a BooleanValue record class.
BooleanValue(boolean) - Constructor for record class zeroecho.pki.application.PkiOperationValue.BooleanValue
Creates an instance of a BooleanValue record class.
boundary() - Method in interface zeroecho.pki.spi.store.RevocationSnapshot
 
build() - Method in class zeroecho.pki.impl.core.attr.SimpleAttributeSet.Builder
Builds a new immutable attribute set from the builder contents.
build() - Method in class zeroecho.pki.impl.framework.x509.bc.SimpleAttributeSet.Builder
Builds a new immutable SimpleAttributeSet from the current builder contents.
buildBundle(BundleCommand) - Method in interface zeroecho.pki.api.IssuanceService
Builds a distributable bundle for an existing credential using chain selection rules.
buildBundle(BundleCommand) - Method in class zeroecho.pki.impl.core.DefaultIssuanceService
Builds a runtime credential bundle for a previously persisted leaf credential.
builder() - Static method in record class zeroecho.pki.impl.core.attr.SimpleAttributeSet
Creates a new mutable builder for assembling a SimpleAttributeSet.
builder() - Static method in class zeroecho.pki.impl.framework.x509.bc.SimpleAttributeSet
Creates a mutable builder for assembling a SimpleAttributeSet.
BUILT_IN_PROFILE_INVALID - Enum constant in enum class zeroecho.pki.impl.ProfileLifecycleFailure.Code
 
builtIn() - Static method in class zeroecho.pki.impl.framework.x509.X509ComponentCatalog
Returns immutable built-in components.
builtIn() - Method in record class zeroecho.pki.impl.framework.x509.X509ComponentCatalog.Component
Returns the value of the builtIn record component.
builtIn(List<X509BindingRule>) - Static method in class zeroecho.pki.impl.framework.x509.X509BindingCatalog
Creates the immutable built-in catalog.
BUILTIN_PREFIX - Static variable in class zeroecho.pki.impl.framework.x509.X509BindingCatalog
Prefix reserved for built-in binding identifiers.
BuiltInCertificateProfileCatalog - Class in zeroecho.pki.api.profile
Loader for the fixed built-in certificate-profile resource catalogue.
BuiltInCertificateProfileTemplate - Class in zeroecho.pki.api.profile
Immutable built-in certificate-profile provisioning template.
BUNDLE_DELIVERY - Enum constant in enum class zeroecho.pki.api.credential.CredentialUse
Leaf credential delivered in a trusted credential bundle.
BundleCommand - Record Class in zeroecho.pki.api.issuance
Command to build a distributable bundle for an existing credential.
BundleCommand(PkiId, Optional<PkiId>, Optional<String>) - Constructor for record class zeroecho.pki.api.issuance.BundleCommand
Creates a bundle command.
busPath() - Method in record class zeroecho.pki.application.PkiSessionConfiguration.SigningConfiguration
Returns the value of the busPath record component.
BY_KEY - Enum constant in enum class zeroecho.pki.application.OcspResponseService.ResponderId
 
BY_NAME - Enum constant in enum class zeroecho.pki.application.OcspResponseService.ResponderId
 
bytes() - Method in record class zeroecho.pki.api.EncodedObject
Returns a defensive copy of the encoded payload.
bytes() - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.IpAddress
Returns the value of the bytes record component.
BYTES - Enum constant in enum class zeroecho.pki.api.attr.AttributeValueType
Raw byte string.
BytesValue(byte[]) - Constructor for record class zeroecho.pki.api.attr.AttributeValue.BytesValue
Creates a byte string value.

C

CA_COMPROMISE - Enum constant in enum class zeroecho.pki.api.revocation.RevocationReason
CA private key is compromised.
CaCertificatePolicy - Record Class in zeroecho.pki.api.profile
Immutable issuer-controlled CA certificate policy.
CaCertificatePolicy(boolean, int, boolean, Set<CaKeyUsage>, Set<String>) - Constructor for record class zeroecho.pki.api.profile.CaCertificatePolicy
Validates and constructs the CA policy.
CaCreateCommand - Record Class in zeroecho.pki.api.ca
Command to create a new root CA entity and issue its initial CA credential.
CaCreateCommand(FormatId, SubjectRef, String, Optional<KeyRef>, AttributeSet) - Constructor for record class zeroecho.pki.api.ca.CaCreateCommand
Creates a CA create command.
caHistoryPolicy() - Method in record class zeroecho.pki.impl.fs.FsPkiStoreOptions
Returns the value of the caHistoryPolicy record component.
caId() - Method in record class zeroecho.pki.api.ca.CaKeyRotationCommand
Returns the value of the caId record component.
caId() - Method in record class zeroecho.pki.api.ca.CaRecord
Returns the value of the caId record component.
caId() - Method in record class zeroecho.pki.api.ca.CaRolloverCommand
Returns the value of the caId record component.
caId() - Method in record class zeroecho.pki.api.IssuerRef
Returns the value of the caId record component.
caId() - Method in record class zeroecho.pki.application.PkiOperation.InspectAuthority
Returns the value of the caId record component.
caId() - Method in record class zeroecho.pki.application.PkiOperation.TransitionAuthority
Returns the value of the caId record component.
CaImportCommand - Record Class in zeroecho.pki.api.ca
Command to import an existing root CA credential into PKI inventory.
CaImportCommand(FormatId, SubjectRef, String, KeyRef, DurableContentReference, AttributeSet) - Constructor for record class zeroecho.pki.api.ca.CaImportCommand
Creates a CA import command.
CaKeyRotationCommand - Record Class in zeroecho.pki.api.ca
Command to rotate a CA key reference and issue new corresponding CA credentials.
CaKeyRotationCommand(PkiId, Optional<KeyRef>, Optional<PkiId>, AttributeSet) - Constructor for record class zeroecho.pki.api.ca.CaKeyRotationCommand
Creates a CA key rotation command.
CaKeyUsage - Enum Class in zeroecho.pki.api.profile
Closed X.509 key-usage set available to CA certificate profiles.
CaKind - Enum Class in zeroecho.pki.api.ca
Classifies CA entity type.
CallControl(Instant, CancellationSignal) - Constructor for record class zeroecho.pki.spi.crypto.SignatureWorkflow.CallControl
Validates one call control.
cancel(PkiId, long, String, SignatureWorkflow.CallControl) - Method in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
Attempts to cancel a non-terminal operation.
cancel(PkiId, long, String, SignatureWorkflow.CallControl) - Method in interface zeroecho.pki.spi.crypto.SignatureWorkflow
Best-effort cancellation.
cancellation() - Method in record class zeroecho.pki.application.SigningReconciliationRequest
Returns the value of the cancellation record component.
cancellation() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.CallControl
Returns the value of the cancellation record component.
cancellation() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.SignRequest
Returns the value of the cancellation record component.
cancellation() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.VerifyRequest
Returns the value of the cancellation record component.
CANCELLATION_UNCERTAIN - Enum constant in enum class zeroecho.pki.spi.store.SignWorkflowStore.ReconciliationFailureClass
Provider cancellation outcome is uncertain.
CANCELLED - Enum constant in enum class zeroecho.pki.application.PkiOperationFailure
Cooperative cancellation was observed.
CANCELLED - Enum constant in enum class zeroecho.pki.spi.crypto.SignatureWorkflow.State
 
CANCELLED - Enum constant in enum class zeroecho.pki.spi.store.MetadataCommitResult.FailureCategory
Cooperative cancellation was requested.
CANCELLED - Enum constant in enum class zeroecho.pki.spi.store.SignWorkflowStore.State
 
CANCELLED - Enum constant in enum class zeroecho.pki.util.async.AsyncState
The operation was cancelled by a caller or operator.
CANCELLING - Enum constant in enum class zeroecho.pki.spi.store.SignWorkflowStore.State
 
canonical() - Method in record class zeroecho.pki.spi.store.MetadataKey
Returns the complete versioned length-framed canonical representation.
canonicalForm() - Method in record class zeroecho.pki.api.content.DurableContentOwner
Returns a deterministic persistence token containing no path or payload.
canonicalForm() - Method in class zeroecho.pki.impl.framework.x509.X509AlgorithmIdentifier
Returns the deterministic reverse-lookup representation.
canonicalizeOperationId(PkiId, Principal) - Method in class zeroecho.pki.impl.core.async.PkiSigningBus
Builds a canonical, globally unique operation identifier derived from tuple (owner, clientOpId).
canonicalJson() - Method in class zeroecho.pki.api.profile.BuiltInCertificateProfileTemplate
Returns a copy of the canonical ZeroEcho profile JSON.
canonicalJson() - Method in class zeroecho.pki.api.profile.ImportedCertificateProfileVersion
 
canonicalSha256() - Method in class zeroecho.pki.api.profile.BuiltInCertificateProfileTemplate
Returns a copy of the SHA-256 hash of the canonical JSON.
canonicalSha256() - Method in class zeroecho.pki.api.profile.CertificateProfileRef
 
canonicalValue(SubjectRdnType, String) - Static method in record class zeroecho.pki.api.profile.SubjectRdnRule
Applies the type-specific canonical form and validation.
capabilities() - Method in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflowProvider
Declares the exact classic signature domain implemented by the workflow.
capabilities() - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509VerificationExecutor
 
capabilities() - Method in class zeroecho.pki.impl.fs.PosixTransactionalMetadataStore
Returns immutable adapter capabilities.
capabilities() - Method in interface zeroecho.pki.spi.store.TransactionalMetadataStore
Returns immutable adapter capabilities.
caPolicy() - Method in record class zeroecho.pki.api.profile.CertificateProfileDefinition
Returns the CA policy.
CaProfileBinding - Record Class in zeroecho.pki.api.credential
Exact versioned CA profile identity for a root or intermediate credential.
CaProfileBinding(CertificateProfileRef) - Constructor for record class zeroecho.pki.api.credential.CaProfileBinding
Creates a CA profile binding.
CaQuery - Record Class in zeroecho.pki.api.ca
Query constraints for listing CA entities.
CaQuery(Optional<CaKind>, Optional<CaState>, Optional<FormatId>, Optional<SubjectRef>) - Constructor for record class zeroecho.pki.api.ca.CaQuery
Creates a CA query.
CaRecord - Record Class in zeroecho.pki.api.ca
Represents one logical CA authority and its explicit issuer generations.
CaRecord(PkiId, CaKind, CaState, KeyRef, SubjectRef, List<PkiId>, PkiId, PkiId) - Constructor for record class zeroecho.pki.api.ca.CaRecord
Creates a CA record.
CaRolloverCommand - Record Class in zeroecho.pki.api.ca
Command to roll over a CA credential while keeping the same key reference.
CaRolloverCommand(PkiId, Optional<PkiId>, Optional<Validity>, AttributeSet) - Constructor for record class zeroecho.pki.api.ca.CaRolloverCommand
Creates a CA rollover command.
CaService - Interface in zeroecho.pki.api
Manages Certificate Authority (CA) entities and their lifecycle.
CaState - Enum Class in zeroecho.pki.api.ca
Operational state of a CA entity.
catalog() - Static method in class zeroecho.pki.impl.framework.x509.StandardX509Bindings
Returns the immutable built-in standard catalog.
catalog() - Static method in class zeroecho.pki.impl.framework.x509.ZeroEchoPrivateX509Bindings
 
catalog(X509ComponentCatalog) - Static method in class zeroecho.pki.impl.framework.x509.StandardX509Bindings
Creates the built-in rules against an immutable component authority.
category() - Method in record class zeroecho.pki.api.audit.AuditEvent
Returns the value of the category record component.
category() - Method in record class zeroecho.pki.api.audit.AuditQuery
Returns the value of the category record component.
category() - Method in record class zeroecho.pki.api.content.DurableContentOwner
Returns the value of the category record component.
category() - Method in exception class zeroecho.pki.spi.store.MetadataStoreException
Returns the stable safe category.
CertId(OcspResponseService.CertIdHash, byte[], byte[], BigInteger) - Constructor for record class zeroecho.pki.application.OcspResponseService.CertId
Defensively owns all request values.
CERTIFICATE - Enum constant in enum class zeroecho.pki.application.PkiRepositoryContent.Role
X.509 certificate DER.
CERTIFICATE - Enum constant in enum class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectKind
X.509 Certificate.
CERTIFICATE_HOLD - Enum constant in enum class zeroecho.pki.api.revocation.RevocationReason
Credential is temporarily on hold.
CERTIFICATE_SIGNATURE - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.Role
Certificate signature.
CertificateBindings(AlgorithmIdentity, AlgorithmIdentity, StreamingDerReader.SignedObjectLayout) - Constructor for record class zeroecho.pki.impl.framework.x509.bc.BcX509SignedObjectValidator.CertificateBindings
Creates immutable binding results.
certificatePolicy() - Method in record class zeroecho.pki.api.profile.CertificateProfileDefinition
Returns the value of the certificatePolicy record component.
CertificatePolicy - Interface in zeroecho.pki.api.profile
Closed certificate-specific policy variant.
CertificateProfile - Record Class in zeroecho.pki.api.profile
Defines issuance constraints and mapping hints for a class of credentials.
CertificateProfile(String, FormatId, String, Duration, SubjectPolicy, LeafCertificatePolicy) - Constructor for record class zeroecho.pki.api.profile.CertificateProfile
Creates a standard-only runtime profile.
CertificateProfile(String, FormatId, String, Duration, SubjectPolicy, LeafCertificatePolicy, X509AlgorithmBindingPolicy) - Constructor for record class zeroecho.pki.api.profile.CertificateProfile
Creates a certificate profile.
CertificateProfileDefinition - Record Class in zeroecho.pki.api.profile
Immutable, versioned certificate-profile configuration.
CertificateProfileDefinition(CertificateProfileKind, String, long, FormatId, String, Duration, SubjectPolicy, CertificatePolicy) - Constructor for record class zeroecho.pki.api.profile.CertificateProfileDefinition
Creates a standard-only profile definition.
CertificateProfileDefinition(CertificateProfileKind, String, long, FormatId, String, Duration, SubjectPolicy, CertificatePolicy, X509AlgorithmBindingPolicy) - Constructor for record class zeroecho.pki.api.profile.CertificateProfileDefinition
Creates a certificate-profile definition.
CertificateProfileDocumentCodec - Class in zeroecho.pki.api.profile
Strict JSON parser and canonical writer for version 2 certificate-profile documents.
CertificateProfileKind - Enum Class in zeroecho.pki.api.profile
Closed certificate category governed by a profile definition.
CertificateProfileRef - Class in zeroecho.pki.api.profile
Exact immutable identity of one imported certificate-profile version.
CertificateProfileRef(String, long, byte[]) - Constructor for class zeroecho.pki.api.profile.CertificateProfileRef
Creates an exact profile reference.
certificateSignature() - Method in record class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy
Returns the value of the certificateSignature record component.
certificateSignatureBinding() - Method in record class zeroecho.pki.application.PkiSessionConfiguration.SigningConfiguration
Returns the value of the certificateSignatureBinding record component.
certificateType() - Method in record class zeroecho.pki.api.profile.CertificateProfileDefinition
Returns the value of the certificateType record component.
certificateType() - Method in class zeroecho.pki.impl.core.ValidatedCaCertificateRequest
Returns the required certificate kind.
CertificationRequest - Record Class in zeroecho.pki.api.request
Opaque certification request container.
CertificationRequest(FormatId, EncodedObject) - Constructor for record class zeroecho.pki.api.request.CertificationRequest
Creates a certification request.
CertificationRequestParser - Interface in zeroecho.pki.spi.framework
Parses and normalizes framework-specific certification requests into the core request model.
CertificationRequestService - Interface in zeroecho.pki.api
Processes certification requests (CSR-like objects) into a normalized representation.
CESSATION_OF_OPERATION - Enum constant in enum class zeroecho.pki.api.revocation.RevocationReason
Subject has ceased operation.
chainPath(PkiId) - Method in interface zeroecho.pki.application.PkiRepository
Returns an exact immutable issuer chain path.
chainPathId() - Method in record class zeroecho.pki.api.IssuerRef
Returns the value of the chainPathId record component.
CHECKPOINT - Enum constant in enum class zeroecho.pki.spi.store.MetadataStoreCapabilities.OptionalFeature
Adapter supports explicit checkpoints.
classification() - Method in record class zeroecho.pki.application.PkiOperationOutcome.Failure
Returns the value of the classification record component.
cleanupStrategy() - Method in class zeroecho.pki.impl.fs.FsHistoryPolicy
Cleanup strategy.
CLEAR - Enum constant in enum class zeroecho.pki.api.revocation.RevocationState
Credential has no effective revocation restriction.
clearSignReconciliation(PkiId, long, long) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
clearSignReconciliation(PkiId, long, long) - Method in interface zeroecho.pki.spi.store.SignWorkflowStore
Clears durable retry metadata against the current revision and fence.
close() - Method in interface zeroecho.pki.api.publication.PublicationCursor
Closes the underlying stable metadata view idempotently.
close() - Method in interface zeroecho.pki.api.PublicationService
Rejects new operations while allowing an in-flight synchronous call to classify its result.
close() - Method in class zeroecho.pki.application.PkiRepositoryContent
Releases provider-owned lease resources.
close() - Method in interface zeroecho.pki.application.PkiSession
Closes services and backend resources in reverse construction order.
close() - Method in class zeroecho.pki.impl.core.async.PkiSigningBus
 
close() - Method in class zeroecho.pki.impl.core.DefaultPublicationService
 
close() - Method in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
Clears memory-resident state and releases the operation-root ownership lock.
close() - Method in class zeroecho.pki.impl.framework.x509.bc.PkiBusContentSigner
Aborts incomplete staged content owned by this signer.
close() - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
close() - Method in class zeroecho.pki.impl.fs.PosixTransactionalMetadataStore
Closes the store idempotently.
close() - Method in interface zeroecho.pki.spi.audit.AuditSink
Releases lifecycle-owned sink resources.
close() - Method in interface zeroecho.pki.spi.crypto.SignatureWorkflow
 
close() - Method in interface zeroecho.pki.spi.crypto.SignatureWorkflow.Registration
Unregisters the associated SignatureWorkflow.NotificationSink.
close() - Method in interface zeroecho.pki.spi.framework.CrlEntrySource
Releases the stable snapshot.
close() - Method in interface zeroecho.pki.spi.framework.CrlEntrySource.Cursor
 
close() - Method in interface zeroecho.pki.spi.store.ContentSink
Aborts an incomplete sink.
close() - Method in interface zeroecho.pki.spi.store.MetadataCursor
Closes this cursor idempotently.
close() - Method in interface zeroecho.pki.spi.store.MetadataSnapshot
Closes this snapshot idempotently and invalidates its cursors.
close() - Method in interface zeroecho.pki.spi.store.MetadataTransaction
Closes the transaction idempotently, aborting an uncommitted transaction.
close() - Method in interface zeroecho.pki.spi.store.PkiStore
Closes this store and releases all lifecycle-owned resources.
close() - Method in interface zeroecho.pki.spi.store.RevocationHistory
Closes the underlying authoritative-log channel.
close() - Method in interface zeroecho.pki.spi.store.RevocationSnapshot
Releases snapshot resources.
close() - Method in interface zeroecho.pki.spi.store.RevocationSnapshot.Cursor
Closes the cursor.
close() - Method in interface zeroecho.pki.spi.store.RevocationView
Releases the stable view.
close() - Method in interface zeroecho.pki.spi.store.TemporaryUniqueIndex
Removes all index storage.
close() - Method in interface zeroecho.pki.spi.store.TransactionalMetadataStore
Closes the store idempotently.
close() - Method in interface zeroecho.pki.util.async.AsyncRegistration
Unregisters the handler.
code() - Method in enum class zeroecho.pki.application.OcspResponseService.CertIdHash
Stable persistence code.
code() - Method in enum class zeroecho.pki.application.OcspResponseService.ResponderId
Stable persistence code.
code() - Method in record class zeroecho.pki.application.PkiOperationOutcome.Failure
Returns the value of the code record component.
code() - Method in exception class zeroecho.pki.impl.ProfileLifecycleFailure
 
codecs() - Method in interface zeroecho.pki.impl.framework.x509.X509BindingRuleProvider
Returns trusted parameter codecs required by contributed identities.
Command(PkiId, PkiId, PkiId, PkiId, KeyRef, List<PkiId>, String, Optional<String>, OcspResponseService.ResponderId, Instant, Instant, Instant, Optional<byte[]>, List<OcspResponseService.CertId>) - Constructor for record class zeroecho.pki.application.OcspResponseService.Command
Validates finite exact responder inputs.
commandCommitment() - Method in record class zeroecho.pki.api.issuance.IssuanceIntent
Returns the value of the commandCommitment record component.
Command-driven operations - Search tag in package zeroecho.pki.api.issuance
Section
commit() - Method in interface zeroecho.pki.spi.store.MetadataTransaction
Attempts one atomic durable commit.
commitment() - Method in interface zeroecho.pki.api.algorithm.X509AlgorithmBindingRegistry
 
commitment() - Method in class zeroecho.pki.impl.framework.x509.ImmutableX509AlgorithmBindingRegistry
 
commitment() - Method in interface zeroecho.pki.spi.store.RevocationSnapshot
 
commitment() - Method in interface zeroecho.pki.spi.store.RevocationView
 
COMMITMENT_ATTRIBUTE - Static variable in record class zeroecho.pki.api.issuance.IssuanceIntent
Stable internal metadata attribute carrying the canonical command commitment.
commitmentFor(PkiId, PkiId, List<PkiId>) - Static method in record class zeroecho.pki.api.ca.IssuerChainPath
Returns the canonical commitment to authority, generation, and order.
commitRevision() - Method in interface zeroecho.pki.spi.store.MetadataSnapshot.Record
Returns the committed store revision containing this record revision.
COMMITTED - Enum constant in enum class zeroecho.pki.spi.store.MetadataCommitResult.Outcome
Every mutation was durably committed and atomically visible.
committedRevision() - Method in record class zeroecho.pki.spi.store.MetadataCommitResult
Returns the value of the committedRevision record component.
COMMON_NAME - Enum constant in enum class zeroecho.pki.api.profile.SubjectRdnType
X.520 common name.
COMPACTION - Enum constant in enum class zeroecho.pki.spi.store.MetadataStoreCapabilities.OptionalFeature
Adapter supports history compaction.
compareTo(MetadataKey) - Method in record class zeroecho.pki.spi.store.MetadataKey
compatibilityProfileId() - Method in record class zeroecho.pki.api.issuance.BundleCommand
Returns the value of the compatibilityProfileId record component.
compatibilityProfileId() - Method in record class zeroecho.pki.api.issuance.VerificationPolicy
Returns the value of the compatibilityProfileId record component.
complete() - Method in interface zeroecho.pki.spi.store.ContentSink
Atomically completes the content.
completeStatusObject(StatusObject, X509ExecutionPlan<SignatureWorkflow>) - Method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Mints the live completion of an X.509 status-object SIGN operation.
Complexity - Search tag in class zeroecho.pki.impl.framework.x509.bc.PkiBusContentSigner
Section
Component(String, X509ComponentCatalog.Kind, AlgorithmIdentity, String, boolean) - Constructor for record class zeroecho.pki.impl.framework.x509.X509ComponentCatalog.Component
Creates a component.
components() - Method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Returns the component catalog snapshot.
components() - Method in interface zeroecho.pki.impl.framework.x509.X509BindingRuleProvider
Returns component bindings used by parameterized rules.
compose(List<X509BindingRuleProvider>, List<AlgorithmExecutionCapabilityProvider>, List<X509AuthoritySnapshot.ExecutorBinding>, X509AlgorithmResolver.Policy) - Static method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Composes one runtime graph with exact process-local executor bindings.
compose(List<X509BindingRuleProvider>, List<AlgorithmExecutionCapabilityProvider>, X509AlgorithmResolver.Policy) - Static method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Composes one runtime graph from explicitly selected trusted providers.
COMPROMISED - Enum constant in enum class zeroecho.pki.api.ca.CaState
CA is compromised and must not be used for issuance.
COMPROMISED - Enum constant in enum class zeroecho.pki.api.ca.IssuerGenerationState
Known or suspected compromised generation.
computeStatus(PkiId, Instant) - Method in interface zeroecho.pki.api.CredentialInventoryService
Computes credential status at a given time.
ConfigurableProvider<T> - Interface in zeroecho.pki.spi
ServiceLoader provider for configurable implementations.
Configuration - Search tag in class zeroecho.pki.impl.audit.InMemoryAuditSink
Section
Configuration - Search tag in interface zeroecho.pki.spi.ConfigurableProvider
Section
Configuration keys - Search tag in class zeroecho.pki.impl.async.FileBackedAsyncBusProvider
Section
Configuration model - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFrameworkProvider
Section
CONFLICT - Enum constant in enum class zeroecho.pki.application.PkiOperationFailure
The requested state conflicts with committed state.
CONFLICT - Enum constant in enum class zeroecho.pki.spi.store.MetadataCommitResult.FailureCategory
Create or expected-revision precondition failed.
CONFLICT - Enum constant in enum class zeroecho.pki.spi.store.SignWorkflowStore.CreateResult
 
Consistency and Atomicity Guarantees - Search tag in class zeroecho.pki.impl.fs.FilesystemPkiStore
Section
consumeResult(OpId) - Method in interface zeroecho.pki.util.async.AsyncBus
Consumes the stored result if present and removes it from the bus.
consumeResult(OpId) - Method in class zeroecho.pki.util.async.impl.DurableAsyncBus
Returns and removes a previously stored successful result.
consumeResult(PkiId) - Method in class zeroecho.pki.impl.core.async.PkiSigningBus
Consumes result if present.
Contained responsibilities - Search tag in package zeroecho.pki.impl.core
Section
Contained responsibilities - Search tag in package zeroecho.pki.impl.framework.x509.bc
Section
contains(byte[]) - Method in interface zeroecho.pki.spi.store.TemporaryUniqueIndex
Tests whether an exact bounded value is present.
contains(MetadataKey) - Method in record class zeroecho.pki.spi.store.MetadataSnapshot.KeyRange
Tests whether a key belongs to this range.
content() - Method in record class zeroecho.pki.api.credential.Credential
Returns the value of the content record component.
content() - Method in record class zeroecho.pki.api.publication.PublicationRecord
Returns the value of the content record component.
content() - Method in record class zeroecho.pki.api.status.StatusObject
Returns the value of the content record component.
content() - Method in class zeroecho.pki.impl.core.async.PkiSigningBus.SignContinuation
Returns the payload-free durable reference used for recovery.
content() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.SignRequest
Returns the value of the content record component.
content() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.VerifyRequest
Returns the value of the content record component.
CONTENT_COMMITMENT - Enum constant in enum class zeroecho.pki.api.profile.LeafKeyUsage
nonRepudiation/contentCommitment.
CONTENT_INVALID - Enum constant in enum class zeroecho.pki.api.publication.PublicationFailure
The exact immutable source content could not be validated.
contentId() - Method in interface zeroecho.pki.api.content.DurableContentReference
Returns the opaque canonical content identity issued by the store.
contentLengthModel() - Method in record class zeroecho.pki.spi.store.MetadataStoreCapabilities
Returns the value of the contentLengthModel record component.
contentOwners(DurableContentReference) - Method in class zeroecho.pki.impl.fs.FilesystemStagedContentStore
 
contentOwners(DurableContentReference) - Method in interface zeroecho.pki.spi.store.StagedContentStore
Returns the immutable exact owner set for sealed content.
ContentSink - Interface in zeroecho.pki.spi.store
Atomic sequential sink for staged operation content.
contentStoreId() - Method in class zeroecho.pki.impl.fs.FilesystemStagedContentStore
 
contentStoreId() - Method in interface zeroecho.pki.spi.store.StagedContentStore
Returns the stable logical store identifier.
copy(InputStream, OutputStream, CancellationSignal) - Static method in class zeroecho.pki.impl.framework.x509.StreamingDerWriter
Copies content incrementally and returns the exact byte count.
count() - Method in interface zeroecho.pki.spi.framework.CrlEntrySource
Returns the entry count when cheaply known.
count() - Method in interface zeroecho.pki.spi.store.RevocationSnapshot
Returns the current-state count when the store can provide it without materialization.
COUNTRY_NAME - Enum constant in enum class zeroecho.pki.api.profile.SubjectRdnType
X.520 country name.
create(String, Instant, SecureRandom) - Static method in record class zeroecho.pki.api.orch.SigningSubmissionId
Creates a new identifier using a cryptographically strong random source.
create(Path, MetadataStoreId) - Static method in class zeroecho.pki.impl.fs.PosixTransactionalMetadataStore
Creates a new append-only store without an adapter-specific record limit.
create(Path, MetadataStoreId, OptionalLong) - Static method in class zeroecho.pki.impl.fs.PosixTransactionalMetadataStore
Creates a new append-only store.
create(List<X509AlgorithmBinding>) - Static method in class zeroecho.pki.impl.framework.x509.ImmutableX509AlgorithmBindingRegistry
Constructs and validates one deterministic registry snapshot.
create(PkiId, String, long, AccessContext, KeyRef, String, RepeatableContent, Optional<Encoding>, Optional<Instant>) - Static method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.SignRequest
Creates a request with its canonical versioned fingerprint.
create(PkiId, PkiId, List<PkiId>) - Static method in record class zeroecho.pki.api.ca.IssuerChainPath
Creates a canonical path from its exact ordered credential identities.
create(MetadataKey, RepeatableContent, CancellationSignal) - Method in interface zeroecho.pki.spi.store.MetadataTransaction
Adds a create-if-absent mutation.
CREATE_INTERMEDIATE - Enum constant in enum class zeroecho.pki.impl.core.ValidatedCaCertificateRequest.Operation
Creates an intermediate CA's initial credential.
CREATE_ROOT - Enum constant in enum class zeroecho.pki.impl.core.ValidatedCaCertificateRequest.Operation
Creates a self-signed root credential.
CreateAuthority(FormatId, SubjectRef, String, KeyRef) - Constructor for record class zeroecho.pki.application.PkiOperation.CreateAuthority
Validates the closed authority-creation input.
createBackup(BackupRequest) - Method in interface zeroecho.pki.api.BackupService
Creates a backup of PKI state.
CREATED - Enum constant in enum class zeroecho.pki.spi.store.SignWorkflowStore.CreateResult
 
createdAfter() - Method in record class zeroecho.pki.api.request.RequestQuery
Returns the value of the createdAfter record component.
createdAfter() - Method in record class zeroecho.pki.api.status.StatusObjectQuery
Returns the value of the createdAfter record component.
createdAt() - Method in record class zeroecho.pki.api.orch.SigningSubmissionId
Returns the value of the createdAt record component.
createdAt() - Method in record class zeroecho.pki.api.orch.WorkflowStateRecord
Returns the value of the createdAt record component.
createdAt() - Method in record class zeroecho.pki.api.publication.PublicationRecord
Returns the value of the createdAt record component.
createdAt() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Returns the value of the createdAt record component.
createdAt() - Method in record class zeroecho.pki.util.async.AsyncOperationSnapshot
Returns the value of the createdAt record component.
createdBefore() - Method in record class zeroecho.pki.api.request.RequestQuery
Returns the value of the createdBefore record component.
createdBefore() - Method in record class zeroecho.pki.api.status.StatusObjectQuery
Returns the value of the createdBefore record component.
createIntermediate(IntermediateCreateCommand) - Method in interface zeroecho.pki.api.CaService
Creates a new intermediate CA entity and issues its initial intermediate CA credential.
createIntermediate(IntermediateCreateCommand) - Method in class zeroecho.pki.impl.core.DefaultCaService
Creates a new intermediate CA record and requests issuance of its initial CA certificate.
createPublicationRecord(PublicationRecord) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
createPublicationRecord(PublicationRecord) - Method in interface zeroecho.pki.spi.store.PkiStore
Creates one publication operation if absent.
createRoot(CaCreateCommand) - Method in interface zeroecho.pki.api.CaService
Creates a new root CA entity and issues its initial CA credential.
createRoot(CaCreateCommand) - Method in class zeroecho.pki.impl.core.DefaultCaService
Creates and persists a new root CA together with its initial self-signed credential.
createSignIntent(SignWorkflowStore.Record) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
createSignIntent(SignWorkflowStore.Record) - Method in interface zeroecho.pki.spi.store.SignWorkflowStore
Creates an INTENT or attaches to an identical existing record.
credential() - Method in record class zeroecho.pki.api.credential.CredentialBundle
Returns the value of the credential record component.
credential(PkiId) - Method in interface zeroecho.pki.application.PkiRepository
Returns an exact credential metadata record.
credential(PkiId, BigInteger) - Method in interface zeroecho.pki.application.PkiRepository
Returns an exact credential through the issuer-generation/serial index.
Credential - Record Class in zeroecho.pki.api.credential
Issued credential with mandatory core metadata and universal attributes.
Credential(PkiId, FormatId, IssuerRef, SubjectRef, Validity, String, PkiId, CredentialProfileBinding, CredentialStatus, DurableContentReference, AttributeSet) - Constructor for record class zeroecho.pki.api.credential.Credential
Creates a credential record.
CREDENTIAL - Enum constant in enum class zeroecho.pki.api.publication.PublicationSourceType
An immutable committed credential.
CREDENTIAL_RECORD - Enum constant in enum class zeroecho.pki.api.content.DurableContentOwner.Category
Persisted credential record; integration is deferred.
credentialAuthority(PkiId) - Method in interface zeroecho.pki.application.PkiResourceScopeResolver
Returns the exact logical issuer authority of one committed credential.
CredentialBundle - Record Class in zeroecho.pki.api.credential
Bundle of a primary credential and supporting objects.
CredentialBundle(Credential, List<DurableContentReference>) - Constructor for record class zeroecho.pki.api.credential.CredentialBundle
Creates a bundle.
CredentialFramework - Interface in zeroecho.pki.spi.framework
Pluggable credential framework implementation.
CredentialFrameworkProvider - Interface in zeroecho.pki.spi.framework
Service provider for CredentialFramework instances.
credentialId() - Method in record class zeroecho.pki.api.ca.IssuerGeneration
Returns the value of the credentialId record component.
credentialId() - Method in record class zeroecho.pki.api.credential.Credential
Returns the value of the credentialId record component.
credentialId() - Method in record class zeroecho.pki.api.issuance.BundleCommand
Returns the value of the credentialId record component.
credentialId() - Method in interface zeroecho.pki.api.revocation.RevocationCommand
Returns the target credential.
credentialId() - Method in record class zeroecho.pki.api.revocation.RevocationCommand.Hold
Returns the value of the credentialId record component.
credentialId() - Method in record class zeroecho.pki.api.revocation.RevocationCommand.RevokePermanently
Returns the value of the credentialId record component.
credentialId() - Method in record class zeroecho.pki.api.revocation.RevocationCommand.Unhold
Returns the value of the credentialId record component.
credentialId() - Method in record class zeroecho.pki.api.revocation.RevocationInputs
Returns the value of the credentialId record component.
credentialId() - Method in record class zeroecho.pki.api.revocation.RevocationRecord
Returns the value of the credentialId record component.
credentialId() - Method in record class zeroecho.pki.application.PkiOperation.InspectCredential
Returns the value of the credentialId record component.
credentialId() - Method in record class zeroecho.pki.application.PkiOperation.InspectRevocation
Returns the value of the credentialId record component.
credentialId() - Method in record class zeroecho.pki.application.PkiOperation.ReadRevocationHistory
Returns the value of the credentialId record component.
credentialId() - Method in record class zeroecho.pki.application.PkiOperation.RevokeCredential
Returns the value of the credentialId record component.
credentialId() - Method in interface zeroecho.pki.spi.store.RevocationHistory
 
CredentialInventoryService - Interface in zeroecho.pki.api
Inventory and reporting service for issued credentials.
CredentialIssuerBackend - Interface in zeroecho.pki.spi.framework
SPI contract for framework-specific credential issuance backends.
CredentialProfileBinding - Interface in zeroecho.pki.api.credential
Closed immutable identity of the policy governing an issued credential.
CredentialQuery - Record Class in zeroecho.pki.api.credential
Query constraints for searching credentials in inventory.
CredentialQuery(Optional<FormatId>, Optional<PkiId>, Optional<SubjectRef>, Optional<String>, Optional<CredentialStatus>, Optional<PkiId>, Optional<Instant>) - Constructor for record class zeroecho.pki.api.credential.CredentialQuery
Creates a credential query.
credentialRecord(PkiId) - Static method in record class zeroecho.pki.api.content.DurableContentOwner
Creates the canonical owner for one persisted credential record.
CredentialStatus - Enum Class in zeroecho.pki.api.credential
Status of a credential as tracked by PKI inventory.
CredentialUse - Enum Class in zeroecho.pki.api.credential
Closed categories of currently reachable credential trust decisions.
criticalWithNonemptySubject() - Method in record class zeroecho.pki.api.profile.SubjectAlternativeNamePolicy
Returns the value of the criticalWithNonemptySubject record component.
CRL - Enum constant in enum class zeroecho.pki.api.status.StatusObjectType
Certificate Revocation List.
CRL - Enum constant in enum class zeroecho.pki.application.PkiRepositoryContent.Role
X.509 certificate-revocation-list DER.
CRL - Enum constant in enum class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectKind
X.509 CertificateList (CRL).
CRL_SIGN - Enum constant in enum class zeroecho.pki.api.profile.CaKeyUsage
cRLSign.
CRL_SIGNATURE - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.Role
Certificate-revocation-list signature.
CrlEntry - Record Class in zeroecho.pki.spi.framework
Immutable structured input for one certificate-revocation-list entry.
CrlEntry(BigInteger, Instant, RevocationReason) - Constructor for record class zeroecho.pki.spi.framework.CrlEntry
Validates one structured CRL entry.
CrlEntrySource - Interface in zeroecho.pki.spi.framework
Stable restartable source of CRL entries.
CrlEntrySource.Cursor - Interface in zeroecho.pki.spi.framework
One-pass entry cursor.
crlSignature() - Method in record class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy
Returns the value of the crlSignature record component.
crlSignatureBinding() - Method in record class zeroecho.pki.application.PkiSessionConfiguration.SigningConfiguration
Returns the value of the crlSignatureBinding record component.
CROSS_PROCESS_COORDINATION - Enum constant in enum class zeroecho.pki.spi.store.MetadataStoreCapabilities.OptionalFeature
Store authority coordinates cooperating processes.
CSR_DER - Static variable in class zeroecho.pki.impl.framework.x509.bc.BcX509Attributes
Attribute identifier for a DER-encoded PKCS#10 certification request.
CSR_SIGNATURE - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.Role
PKCS#10 certification-request signature.
csrSignature() - Method in record class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy
Returns the value of the csrSignature record component.
current() - Method in interface zeroecho.pki.spi.framework.CrlEntrySource.Cursor
Returns the current entry.
current() - Method in interface zeroecho.pki.spi.store.RevocationHistory
Returns the current transition.
current() - Method in interface zeroecho.pki.spi.store.RevocationSnapshot.Cursor
Returns the current state.
CURRENT_VERSION - Static variable in record class zeroecho.pki.application.PkiSessionConfiguration
Current configuration schema version.
currentIssuanceIssuerId() - Method in record class zeroecho.pki.api.ca.CaRecord
Returns the value of the currentIssuanceIssuerId record component.
cursor() - Method in record class zeroecho.pki.application.SigningReconciliationRequest
Returns the value of the cursor record component.
CUSTOM - Enum constant in enum class zeroecho.pki.api.publication.PublicationTargetType
Custom target type implemented by a publisher plugin.

D

DATA_ENCIPHERMENT - Enum constant in enum class zeroecho.pki.api.profile.LeafKeyUsage
dataEncipherment.
DC_ALGORITHM_MISMATCH - Static variable in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
 
DC_CANCELLED - Static variable in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
 
DC_CRYPTO_FAILURE - Static variable in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
 
DC_INVALID_ALGORITHM_ID - Static variable in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
 
DC_INVALID_KEYREF_PREFIX - Static variable in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
 
DC_INVALID_KEYREF_SUFFIX - Static variable in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
 
DC_KEY_NOT_FOUND - Static variable in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
 
DC_KEYRING_IO_ERROR - Static variable in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
 
DC_KEYRING_OPEN_FAILED - Static variable in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflowProvider
Stable failure code for an I/O failure while opening the keyring.
DC_KEYRING_UNLOCK_PROVIDER_FAILED - Static variable in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflowProvider
Stable failure code for an unlock-provider acquisition failure.
DC_KEYRING_UNLOCK_PROVIDER_REQUIRED - Static variable in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflowProvider
Stable failure code for a missing explicit keyring unlock provider.
DC_REJECTED - Static variable in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
 
DC_SIGNED - Static variable in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
 
DC_SUBMITTED - Static variable in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
 
DC_UNKNOWN_OPERATION - Static variable in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
 
DC_UNSUPPORTED_PUBLICKEY_FORM - Static variable in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
 
DC_UNSUPPORTED_SIGNATURE_ENCODING - Static variable in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
 
DC_VERIFIED - Static variable in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
 
deadline() - Method in record class zeroecho.pki.application.SigningReconciliationRequest
Returns the value of the deadline record component.
deadline() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.CallControl
Returns the value of the deadline record component.
deadline() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.SignRequest
Returns the value of the deadline record component.
deadline() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.VerifyRequest
Returns the value of the deadline record component.
deadline() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Returns the value of the deadline record component.
decide(AttributeDefinition, AccessAction, AccessContext) - Method in interface zeroecho.pki.api.audit.AttributeAccessController
Evaluates an access request.
DECIPHER_ONLY - Enum constant in enum class zeroecho.pki.api.profile.LeafKeyUsage
decipherOnly.
decisionId() - Method in record class zeroecho.pki.api.policy.PolicyDecision
Returns the value of the decisionId record component.
decisionId() - Method in record class zeroecho.pki.api.policy.PolicyTrace
Returns the value of the decisionId record component.
decode(String) - Method in class zeroecho.pki.impl.core.async.PkiAsyncCodecs.EncodedObjectResultCodec
Decodes a previously persisted EncodedObject token.
decode(String) - Method in class zeroecho.pki.impl.core.async.PkiAsyncCodecs.PkiIdCodec
Decodes a persisted identifier token back into a PkiId.
decode(String) - Method in class zeroecho.pki.impl.core.async.PkiAsyncCodecs.PrincipalCodec
Decodes a principal token in type:name form.
decode(String) - Method in class zeroecho.pki.impl.core.async.PkiAsyncCodecs.StringIdCodec
Returns the persisted endpoint token unchanged.
decode(String) - Method in interface zeroecho.pki.util.async.codec.IdCodec
Decodes a previously encoded token.
decode(String) - Method in interface zeroecho.pki.util.async.codec.ResultCodec
Decodes a previously encoded result token.
decode(AlgorithmIdentifier, X509AlgorithmRole) - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509AlgorithmAdapter
Converts and reverse-resolves a BC algorithm identifier.
decode(EncodedObject, StagedContentStore) - Static method in class zeroecho.pki.impl.core.async.PkiSigningBus.SignContinuation
Decodes a binary continuation payload previously produced by PkiSigningBus.SignContinuation.encode().
decode(X509AlgorithmIdentifier) - Method in interface zeroecho.pki.impl.framework.x509.X509BindingRule
Reverse-resolves an exact X.509 representation.
decodeOptional(String) - Method in interface zeroecho.pki.util.async.codec.ResultCodec
Convenience: optional decode wrapper.
DEFAULT_DISPLAY_SUFFIX_MAX_LEN - Static variable in class zeroecho.pki.impl.core.async.PkiSigningBus
Default maximum length of the display suffix.
DefaultAttributeGovernanceService - Class in zeroecho.pki.impl.audit
Default enforcement implementation of AttributeGovernanceService.
DefaultAttributeGovernanceService(AttributeAccessController, AuditService, Clock) - Constructor for class zeroecho.pki.impl.audit.DefaultAttributeGovernanceService
Creates a governance service.
DefaultCaService - Class in zeroecho.pki.impl.core
Default store-backed implementation of CaService.
DefaultCaService(PkiStore, CredentialFramework, CredentialIssuerBackend, PublicKeyInfoResolver, PkiSigningBus, AuditSink, EffectiveCredentialStatusResolver, ProfileService, Clock, String, Duration) - Constructor for class zeroecho.pki.impl.core.DefaultCaService
Creates a CA service bound to a specific store, credential framework, and signing runtime.
DefaultCaService(PkiStore, CredentialFramework, CredentialIssuerBackend, PublicKeyInfoResolver, PkiSigningBus, AuditSink, EffectiveCredentialStatusResolver, ProfileService, Clock, String, Optional<String>, Duration) - Constructor for class zeroecho.pki.impl.core.DefaultCaService
Creates a CA service with an optional explicit X.509 signature binding.
DefaultCertificationRequestService - Class in zeroecho.pki.impl.core
Default implementation of CertificationRequestService.
DefaultCertificationRequestService(PkiStore, CredentialFramework) - Constructor for class zeroecho.pki.impl.core.DefaultCertificationRequestService
Creates a certification request service bound to the supplied persistence and framework collaborators.
DefaultIssuanceService - Class in zeroecho.pki.impl.core
Default implementation of IssuanceService.
DefaultIssuanceService(PkiStore, CredentialFramework, CredentialIssuerBackend, AuditSink, EffectiveCredentialStatusResolver, ProfileService, Clock) - Constructor for class zeroecho.pki.impl.core.DefaultIssuanceService
Creates the issuance service bound to the supplied persistence and framework collaborators.
DefaultProfileService - Class in zeroecho.pki.impl.core
Store-backed implementation of the certificate-profile lifecycle.
DefaultProfileService(PkiStore, Clock, AuditSink) - Constructor for class zeroecho.pki.impl.core.DefaultProfileService
Creates a profile service using one authoritative clock.
DefaultProfileService(PkiStore, Clock, AuditSink, X509AlgorithmBindingRegistry) - Constructor for class zeroecho.pki.impl.core.DefaultProfileService
Creates a profile service bound to one immutable algorithm registry.
DefaultProfileService(PkiStore, Clock, AuditSink, X509AlgorithmBindingRegistry, boolean, Optional<String>, Optional<String>, Optional<String>) - Constructor for class zeroecho.pki.impl.core.DefaultProfileService
Creates a profile service with the session's explicit signing bindings.
DefaultPublicationService - Class in zeroecho.pki.impl.core
Durable explicit post-commit publication lifecycle.
DefaultPublicationService(PkiStore, Clock, Collection<? extends Publisher>) - Constructor for class zeroecho.pki.impl.core.DefaultPublicationService
Opens a publication lifecycle over one store and immutable publisher registry.
DefaultRevocationService - Class in zeroecho.pki.impl.core
Store-backed authoritative revocation transition service.
DefaultRevocationService(PkiStore, Clock, AuditSink) - Constructor for class zeroecho.pki.impl.core.DefaultRevocationService
Creates the service with one authoritative clock.
defaults() - Method in interface zeroecho.pki.impl.framework.x509.X509BindingRuleProvider
Returns additive explicitly versioned defaults.
defaults() - Static method in record class zeroecho.pki.impl.fs.FsPkiStoreOptions
Returns default options (history enabled with 90 days retention).
DefaultStatusObjectService - Class in zeroecho.pki.impl.core
Default implementation of StatusObjectService.
DefaultStatusObjectService(PkiStore, CredentialFramework, AuditSink, EffectiveCredentialStatusResolver, X509AuthoritySnapshot) - Constructor for class zeroecho.pki.impl.core.DefaultStatusObjectService
Creates a status object service bound to the supplied persistence and framework collaborators.
deferSignReconciliation(PkiId, long, long, SignWorkflowStore.ReconciliationFailureClass) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
deferSignReconciliation(PkiId, long, long, SignWorkflowStore.ReconciliationFailureClass) - Method in interface zeroecho.pki.spi.store.SignWorkflowStore
Defers reconciliation with store-authoritative exponential backoff.
definition() - Method in record class zeroecho.pki.api.profile.ActiveCertificateProfile
Returns the value of the definition record component.
definition() - Method in class zeroecho.pki.api.profile.BuiltInCertificateProfileTemplate
Returns the validated immutable profile definition.
definition() - Method in class zeroecho.pki.api.profile.ImportedCertificateProfileVersion
 
delete(MetadataKey, long) - Method in interface zeroecho.pki.spi.store.MetadataTransaction
Adds a compare-and-delete mutation.
deleteWorkflowState(PkiId) - Method in class zeroecho.pki.impl.core.async.PkiSigningBus
Deletes workflow continuation state once finished.
deleteWorkflowState(PkiId) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
deleteWorkflowState(PkiId) - Method in interface zeroecho.pki.spi.store.PkiStore
Deletes workflow continuation state for a given operation.
DELTA_CRL - Enum constant in enum class zeroecho.pki.api.status.StatusObjectType
Delta CRL (incremental updates).
DENY - Enum constant in enum class zeroecho.pki.api.audit.AccessDecision
Access is denied.
DENY - Enum constant in enum class zeroecho.pki.api.policy.PolicyDecisionStatus
Operation is denied under current policy.
Dependency boundary - Search tag in interface zeroecho.pki.spi.framework.CredentialFrameworkProvider
Section
DEPLOYER_ECOSYSTEM - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.Interoperability
One explicitly configured deployment ecosystem.
DEPLOYER_PRIVATE - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.Origin
Explicitly enabled deployment-owned assignment.
DeploymentResourcePolicy - Record Class in zeroecho.pki.api.content
Immutable deployment-owned resource policy for streaming PKI operations.
DeploymentResourcePolicy(ResourceLimit, ResourceLimit, ResourceLimit, ResourceLimit, ResourceLimit, ResourceLimit, ResourceLimit) - Constructor for record class zeroecho.pki.api.content.DeploymentResourcePolicy
Creates a deployment resource policy.
DEPRECATED - Enum constant in enum class zeroecho.pki.api.attr.AttributeStability
Attribute is deprecated and should not be used for new profiles.
der() - Method in record class zeroecho.pki.application.OcspResponseService.Response
Returns the value of the der record component.
DER - Enum constant in enum class zeroecho.pki.api.Encoding
ASN.1 Distinguished Encoding Rules (DER).
DER - Enum constant in enum class zeroecho.pki.api.transfer.ExportFormat
Export as DER artifacts where applicable.
DER_NULL - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.ParameterRule
Parameters must be canonical DER NULL.
DER_NULL - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509AlgorithmIdentifier.ParameterForm
Parameters are canonical DER NULL.
derive(AttributeCatalogue, AttributeSet, AttributeId, AccessContext) - Method in interface zeroecho.pki.api.audit.AttributeGovernanceService
Derives an attribute value from other inputs after applying access control.
derive(AttributeCatalogue, AttributeSet, AttributeId, AccessContext) - Method in class zeroecho.pki.impl.audit.DefaultAttributeGovernanceService
 
DERIVE - Enum constant in enum class zeroecho.pki.api.audit.AccessAction
Derive/computed attribute value from other sources.
derNull(String) - Static method in class zeroecho.pki.impl.framework.x509.X509AlgorithmIdentifier
Creates an identifier with canonical DER NULL parameters.
description() - Method in record class zeroecho.pki.api.attr.AttributeMeta
Returns the value of the description record component.
descriptors() - Static method in class zeroecho.pki.impl.framework.x509.StandardX509Bindings
Returns deterministic safe descriptors for every sealed standard binding.
descriptors() - Static method in class zeroecho.pki.impl.framework.x509.ZeroEchoPrivateX509Bindings
 
Design goals - Search tag in package zeroecho.pki.impl.core.attr
Section
Design principles - Search tag in package zeroecho.pki.api
Section
Design principles - Search tag in package zeroecho.pki.impl.fs
Section
Design principles - Search tag in package zeroecho.pki.util
Section
detailCode() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.OperationStatus
Returns the value of the detailCode record component.
detailCode() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Returns the value of the detailCode record component.
detailCode() - Method in record class zeroecho.pki.util.async.AsyncStatus
Returns the value of the detailCode record component.
details() - Method in record class zeroecho.pki.api.audit.AuditEvent
Returns the value of the details record component.
details() - Method in record class zeroecho.pki.api.request.ProofOfPossessionResult
Returns the value of the details record component.
details() - Method in record class zeroecho.pki.util.async.AsyncStatus
Returns the value of the details record component.
Determinism - Search tag in class zeroecho.pki.impl.audit.StdoutAuditSink
Section
Determinism - Search tag in package zeroecho.pki.impl.audit
Section
Determinism and ordering - Search tag in record class zeroecho.pki.api.audit.AuditEvent
Section
DIAGNOSTICS - Enum constant in enum class zeroecho.pki.api.attr.AttributeExportTarget
Export to diagnostics/debugging channels (typically heavily redacted).
DIGEST - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509ComponentCatalog.Kind
Digest AlgorithmIdentifier component.
DIGITAL_SIGNATURE - Enum constant in enum class zeroecho.pki.api.profile.LeafKeyUsage
digitalSignature.
DIRECT_RESPONSE - Enum constant in enum class zeroecho.pki.api.publication.PublicationEvidence
The publisher returned a definitive result from direct dispatch.
direction() - Method in record class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Selection
Returns the value of the direction record component.
disabled() - Static method in class zeroecho.pki.impl.fs.FsHistoryPolicy
Disables history tracking.
DISABLED - Enum constant in enum class zeroecho.pki.api.ca.CaState
CA is administratively disabled.
DISABLED - Enum constant in enum class zeroecho.pki.api.ca.IssuerGenerationState
Administratively disabled generation.
DISPATCH_PREPARED - Enum constant in enum class zeroecho.pki.api.publication.PublicationStatus
One exact attempt is durably prepared but has no classified outcome.
DISPATCHED - Enum constant in enum class zeroecho.pki.spi.store.SignWorkflowStore.State
 
displayName() - Method in record class zeroecho.pki.api.attr.AttributeDefinition
Returns the value of the displayName record component.
displayName() - Method in record class zeroecho.pki.api.profile.CertificateProfile
Returns the value of the displayName record component.
displayName() - Method in record class zeroecho.pki.api.profile.CertificateProfileDefinition
Returns the value of the displayName record component.
DN - Enum constant in enum class zeroecho.pki.api.attr.AttributeValueType
Distinguished Name representation (string form with normalization rules defined by profile/policy).
DNS_NAME - Enum constant in enum class zeroecho.pki.api.profile.SubjectAlternativeNameType
DNS service name.
DnsName(String) - Constructor for record class zeroecho.pki.api.request.SubjectAlternativeName.DnsName
Canonicalizes and validates the DNS name.
DO_NOT_STORE - Enum constant in enum class zeroecho.pki.api.request.RequestStorePolicy
Do not persist parsed requests.
document() - Method in record class zeroecho.pki.application.PkiOperation.RegisterProfile
Returns the value of the document record component.
document() - Method in record class zeroecho.pki.application.PkiOperation.ValidateProfile
Returns the value of the document record component.
Durability model - Search tag in package zeroecho.pki.util.async
Section
durabilityPolicy() - Method in record class zeroecho.pki.api.orch.WorkflowStateRecord
Returns the value of the durabilityPolicy record component.
Durability semantics - Search tag in class zeroecho.pki.util.async.impl.DurableAsyncBus
Section
DURABLE_ENCRYPTED_STATE - Enum constant in enum class zeroecho.pki.api.orch.OrchestrationDurabilityPolicy
Durable operation with encrypted continuation state.
DURABLE_MIN_STATE - Enum constant in enum class zeroecho.pki.api.orch.OrchestrationDurabilityPolicy
Durable operation using minimal non-sensitive state.
DurableAsyncBus<OpId,Owner,EndpointId,Result> - Class in zeroecho.pki.util.async.impl
Generic durable implementation of AsyncBus.
DurableAsyncBus(IdCodec<OpId>, IdCodec<Owner>, IdCodec<EndpointId>, ResultCodec<Result>, AppendOnlyLineStore) - Constructor for class zeroecho.pki.util.async.impl.DurableAsyncBus
Creates the durable async bus and immediately replays persisted state from the append-only store.
DurableContentOwner - Record Class in zeroecho.pki.api.content
Typed immutable identity of a durable business owner of staged content.
DurableContentOwner(DurableContentOwner.Category, String) - Constructor for record class zeroecho.pki.api.content.DurableContentOwner
Creates and validates one typed owner identity.
DurableContentOwner.Category - Enum Class in zeroecho.pki.api.content
Closed durable-owner categories reserved by the Phase A lifecycle.
DurableContentReference - Interface in zeroecho.pki.api.content
Stable, payload-free reference to immutable staged content.
DurableContentReference.Lifecycle - Enum Class in zeroecho.pki.api.content
Durable ownership classification.

E

EC_POINT - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.PublicKeyEncoding
SEC1 elliptic-curve point.
EC_POINT - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509BindingRule.PublicKeyEncoding
SEC1 encoded elliptic-curve point.
ECDSA_DER - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.SignatureEncoding
Canonical DER sequence of positive ECDSA integers.
ECDSA_DER - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509BindingRule.SignatureEncoding
ASN.1 DER SEQUENCE { r, s }.
EffectiveCredentialStatus - Enum Class in zeroecho.pki.api.credential
Runtime status used when deciding whether a credential may participate in a security-sensitive operation.
EffectiveCredentialStatusResolver - Interface in zeroecho.pki.api.credential
Resolves authoritative runtime credential status for trust decisions.
EffectiveCredentialStatusResolver.Evaluation - Interface in zeroecho.pki.api.credential
One immutable-time effective-status evaluation.
EGOTHOR_PEN - Static variable in class zeroecho.pki.impl.framework.x509.ImmutableX509AlgorithmBindingRegistry
Egothor Private Enterprise Number root.
EMAIL_ADDRESS - Enum constant in enum class zeroecho.pki.api.profile.SubjectRdnType
PKCS #9 email address.
EMPTY - Static variable in interface zeroecho.pki.api.content.ResourceLimit
Smallest valid observed aggregate value.
enabled() - Method in class zeroecho.pki.impl.fs.FsHistoryPolicy
Whether history is enabled.
ENCIPHER_ONLY - Enum constant in enum class zeroecho.pki.api.profile.LeafKeyUsage
encipherOnly.
encode() - Method in class zeroecho.pki.impl.core.async.PkiSigningBus.SignContinuation
Encodes this continuation into a versioned binary payload suitable for persistence inside a WorkflowStateRecord.
encode(String) - Method in class zeroecho.pki.impl.core.async.PkiAsyncCodecs.StringIdCodec
Returns the endpoint identifier unchanged.
encode(R) - Method in interface zeroecho.pki.util.async.codec.ResultCodec
Encodes a result to a single-line string.
encode(T) - Method in interface zeroecho.pki.util.async.codec.IdCodec
Encodes a value as a stable, filesystem-safe string token.
encode(AlgorithmIdentity) - Method in interface zeroecho.pki.impl.framework.x509.X509BindingRule
Resolves an exact identity to its canonical X.509 representation.
encode(AlgorithmIdentity, X509AlgorithmRole) - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509AlgorithmAdapter
Resolves an exact identity and converts it to Bouncy Castle representation.
encode(Principal) - Method in class zeroecho.pki.impl.core.async.PkiAsyncCodecs.PrincipalCodec
Encodes the principal as type:name.
encode(EncodedObject) - Method in class zeroecho.pki.impl.core.async.PkiAsyncCodecs.EncodedObjectResultCodec
Encodes an EncodedObject into a text-safe durable form.
encode(PkiId) - Method in class zeroecho.pki.impl.core.async.PkiAsyncCodecs.PkiIdCodec
Encodes the identifier as its stable string value.
encoded() - Method in record class zeroecho.pki.api.request.CertificationRequest
Returns the value of the encoded record component.
encoded() - Method in record class zeroecho.pki.application.PkiOperation.ImportRequest
Returns the value of the encoded record component.
encodedLength(long) - Static method in class zeroecho.pki.impl.framework.x509.StreamingDerWriter
Returns the encoded size of one tag-length-value object.
EncodedObject - Record Class in zeroecho.pki.api
Immutable container for an encoded artifact.
EncodedObject(Encoding, byte[]) - Constructor for record class zeroecho.pki.api.EncodedObject
Creates an encoded object.
EncodedObjectResultCodec(boolean) - Constructor for class zeroecho.pki.impl.core.async.PkiAsyncCodecs.EncodedObjectResultCodec
Creates the result codec.
encoding() - Method in interface zeroecho.pki.api.content.DurableContentReference
Returns the semantic transport encoding.
encoding() - Method in record class zeroecho.pki.api.EncodedObject
Returns the value of the encoding record component.
encoding() - Method in record class zeroecho.pki.spi.publish.PublicationAttempt
Returns the value of the encoding record component.
Encoding - Search tag in class zeroecho.pki.impl.audit.FileAuditSink
Section
Encoding - Enum Class in zeroecho.pki.api
Specifies the encoding of a binary artifact payload.
Encoding model - Search tag in class zeroecho.pki.impl.core.async.PkiSigningBus.SignContinuation
Section
encodingVersion() - Method in record class zeroecho.pki.api.algorithm.X509AlgorithmBinding
Returns the value of the encodingVersion record component.
END_ENTITY - Enum constant in enum class zeroecho.pki.api.profile.CertificateProfileKind
End-entity certificate.
END_ENTITY_ISSUER - Enum constant in enum class zeroecho.pki.api.credential.CredentialUse
Issuer credential used for end-entity issuance.
EndEntityProfileBinding - Record Class in zeroecho.pki.api.credential
Exact imported and activated profile identity for an end-entity credential.
EndEntityProfileBinding(CertificateProfileRef) - Constructor for record class zeroecho.pki.api.credential.EndEntityProfileBinding
Creates an end-entity binding.
endpointId() - Method in record class zeroecho.pki.util.async.AsyncOperationSnapshot
Returns the value of the endpointId record component.
endReached() - Method in record class zeroecho.pki.application.SigningReconciliationResult
Returns the value of the endReached record component.
endReached() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Page
Returns the value of the endReached record component.
entries() - Method in record class zeroecho.pki.impl.core.attr.SimpleAttributeSet
Returns the value of the entries record component.
Entry(AttributeId, List<AttributeValue>) - Constructor for record class zeroecho.pki.impl.core.attr.SimpleAttributeSet.Entry
Creates an immutable attribute entry.
entryCount() - Method in record class zeroecho.pki.api.content.DeploymentResourcePolicy
Returns the value of the entryCount record component.
equals(Object) - Method in record class zeroecho.pki.api.algorithm.X509AlgorithmBinding
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.attr.AttributeAccessPolicy
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.attr.AttributeDefinition
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.attr.AttributeId
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.attr.AttributeMeta
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.attr.AttributeValue.BooleanValue
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.attr.AttributeValue.BytesValue
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.attr.AttributeValue.InstantValue
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.attr.AttributeValue.IntegerValue
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.attr.AttributeValue.StringValue
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.audit.AccessContext
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.audit.AuditEvent
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.audit.AuditQuery
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.audit.Principal
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.audit.Purpose
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.backup.BackupArtifact
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.backup.BackupRequest
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.backup.BackupVerificationReport
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.backup.RestoreReport
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.backup.RestoreRequest
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.ca.CaCreateCommand
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.ca.CaImportCommand
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.ca.CaKeyRotationCommand
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.ca.CaQuery
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.ca.CaRecord
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.ca.CaRolloverCommand
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.ca.IntermediateCertIssueCommand
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.ca.IntermediateCreateCommand
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.ca.IssuerChainPath
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.ca.IssuerGeneration
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.content.DeploymentResourcePolicy
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.content.DurableContentOwner
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.content.ResourceLimit.LimitedTo
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.content.ResourceLimit.UnrestrictedByDeployment
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.credential.CaProfileBinding
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.credential.Credential
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.credential.CredentialBundle
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.credential.CredentialQuery
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.credential.EndEntityProfileBinding
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.EncodedObject
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.FormatId
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.issuance.BundleCommand
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.issuance.IssuanceInputs
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.issuance.IssuanceIntent
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.issuance.IssueEndEntityCommand
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.issuance.ReissueCommand
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.issuance.RenewCommand
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.issuance.ReplaceCommand
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.issuance.VerificationPolicy
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.IssuerRef
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.KeyRef
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.orch.SigningSubmissionId
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.orch.WorkflowStateRecord
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.PkiId
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.policy.PolicyDecision
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.policy.PolicyTrace
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.policy.PolicyTraceStep
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.profile.ActiveCertificateProfile
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in class zeroecho.pki.api.profile.BuiltInCertificateProfileTemplate
 
equals(Object) - Method in record class zeroecho.pki.api.profile.CaCertificatePolicy
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.profile.CertificateProfile
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.profile.CertificateProfileDefinition
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in class zeroecho.pki.api.profile.CertificateProfileRef
 
equals(Object) - Method in record class zeroecho.pki.api.profile.ExtendedKeyUsageId
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in class zeroecho.pki.api.profile.ImportedCertificateProfileVersion
 
equals(Object) - Method in record class zeroecho.pki.api.profile.LeafCertificatePolicy
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.profile.ProfileQuery
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.profile.SubjectAlternativeNamePolicy
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.profile.SubjectAlternativeNameRule
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.profile.SubjectPolicy
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.profile.SubjectRdnRule
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy.BindingReference
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.publication.PublicationQuery
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.publication.PublicationRecord
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.publication.PublicationRequest
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.publication.PublicationResult
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.publication.PublicationTarget
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.request.CertificationRequest
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.request.ParsedCertificationRequest
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.request.ProofOfPossessionResult
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.request.RequestQuery
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.DnsName
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.IpAddress
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.Rfc822Name
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.UriName
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.request.SubjectRdn
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.revocation.RevocationCommand.Hold
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.revocation.RevocationCommand.RevokePermanently
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.revocation.RevocationCommand.Unhold
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.revocation.RevocationInputs
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.revocation.RevocationQuery
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.revocation.RevocationRecord
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.revocation.RevocationTransition
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.status.StatusObject
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.status.StatusObjectGenerateCommand
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.status.StatusObjectQuery
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.SubjectRef
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.transfer.ExportArtifact
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.transfer.ExportQuery
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.transfer.ImportPolicy
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.api.Validity
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.OcspResponseService.CertId
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.OcspResponseService.Command
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.OcspResponseService.Response
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.ActivateProfile
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.CreateAuthority
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.GenerateStatus
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.ImportRequest
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.InspectAlgorithmBinding
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.InspectAuthority
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.InspectCredential
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.InspectProfile
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.InspectPublication
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.InspectRequest
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.InspectRevocation
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.InspectStatus
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.IssueCredential
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.ListAlgorithmBindings
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.ListAuthorities
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.ListProfileVersions
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.ListPublications
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.ListStatus
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.ProcessPublication
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.ReadRevocationHistory
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.ReconcilePublication
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.RegisterProfile
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.RegisterPublication
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.RetryPublication
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.RevokeCredential
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.SnapshotRevocations
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.TransitionAuthority
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.ValidateAlgorithmBindings
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.ValidateConfiguration
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.ValidateProfile
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperation.VerifyRequest
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperationOutcome.Failure
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperationOutcome.Success
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperationResult
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperationValue.BooleanValue
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperationValue.IntegerValue
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperationValue.ListValue
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperationValue.ObjectValue
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiOperationValue.Text
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiSessionConfiguration.BindingProviderConfiguration
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiSessionConfiguration
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiSessionConfiguration.SigningConfiguration
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.PkiSessionRuntimeDependencies
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.SigningReconciliationRequest
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.application.SigningReconciliationResult
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.impl.core.attr.SimpleAttributeSet.Entry
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.impl.core.attr.SimpleAttributeSet
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.impl.framework.x509.bc.BcX509SignedObjectValidator.CertificateBindings
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectLayout
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in class zeroecho.pki.impl.framework.x509.X509AlgorithmIdentifier
 
equals(Object) - Method in record class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Selection
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.impl.framework.x509.X509ComponentCatalog.Component
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.impl.fs.FsPkiStoreOptions
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.CallControl
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.OperationResult
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.OperationStatus
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.SignRequest
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.VerifyRequest
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.spi.framework.CrlEntry
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.spi.ProviderConfig
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.spi.publish.PublicationAttempt
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.spi.store.MetadataCommitResult
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.spi.store.MetadataKey
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.spi.store.MetadataSnapshot.Integrity
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.spi.store.MetadataSnapshot.KeyRange
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.spi.store.MetadataStoreCapabilities
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.spi.store.MetadataStoreId
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.spi.store.MetadataTransactionId
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Page
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.util.async.AsyncEvent
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.util.async.AsyncOperationSnapshot
Indicates whether some other object is "equal to" this one.
equals(Object) - Method in record class zeroecho.pki.util.async.AsyncStatus
Indicates whether some other object is "equal to" this one.
Error handling - Search tag in interface zeroecho.pki.spi.store.PkiStore
Section
errors() - Method in record class zeroecho.pki.api.backup.RestoreReport
Returns the value of the errors record component.
evaluateIssuance(IssuanceInputs) - Method in interface zeroecho.pki.api.PolicyService
Evaluates an issuance request against policy and profile constraints.
evaluateRevocation(RevocationInputs) - Method in interface zeroecho.pki.api.PolicyService
Evaluates a revocation request against policy constraints.
evaluationTime() - Method in interface zeroecho.pki.api.credential.EffectiveCredentialStatusResolver.Evaluation
Returns the authoritative instant captured for this evaluation.
evidence() - Method in record class zeroecho.pki.api.publication.PublicationRecord
Returns the value of the evidence record component.
exact(String, byte[]) - Static method in class zeroecho.pki.impl.framework.x509.X509AlgorithmIdentifier
Creates an identifier with exact canonical structured parameters.
EXACT_DER - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509AlgorithmIdentifier.ParameterForm
Parameters are exact canonical structured DER.
exactPublicKey() - Method in class zeroecho.pki.impl.core.ValidatedCaCertificateRequest
Returns a defensive copy of the proof-bound public key.
exactPublicKey() - Method in class zeroecho.pki.impl.core.ValidatedCertificateRequest
 
exactPublicKey() - Method in class zeroecho.pki.impl.core.VerifiedIssuanceCandidate
Returns a defensive copy of the exact verified subject public key.
examined() - Method in record class zeroecho.pki.application.SigningReconciliationResult
Returns the value of the examined record component.
examined() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Page
Returns the value of the examined record component.
examples() - Method in record class zeroecho.pki.api.attr.AttributeMeta
Returns the value of the examples record component.
Examples - Search tag in enum class zeroecho.pki.api.orch.OrchestrationDurabilityPolicy
Section
EXCLUSIVE_WRITER - Enum constant in enum class zeroecho.pki.spi.store.MetadataStoreCapabilities.WriterModel
At most one writer transaction may be active.
execute(PkiOperation, CancellationSignal) - Method in interface zeroecho.pki.application.PkiOperationExecutor
Executes one typed operation synchronously.
Execution - Search tag in class zeroecho.pki.impl.core.async.PkiSigningBus
Section
Execution model - Search tag in class zeroecho.pki.impl.framework.x509.bc.PkiBusContentSigner
Section
Execution model - Search tag in class zeroecho.pki.impl.framework.x509.bc.WorkflowProofOfPossessionVerifier
Section
Execution model - Search tag in package zeroecho.pki.impl.crypto.zeroecholib
Section
executor() - Method in class zeroecho.pki.impl.framework.x509.X509ExecutionPlan
Returns the exact runtime executor bound by the authority.
existingCaCredential() - Method in record class zeroecho.pki.api.ca.CaImportCommand
Returns the value of the existingCaCredential record component.
existingCredentialId() - Method in record class zeroecho.pki.api.issuance.RenewCommand
Returns the value of the existingCredentialId record component.
existingCredentialId() - Method in record class zeroecho.pki.api.issuance.ReplaceCommand
Returns the value of the existingCredentialId record component.
expectedBindingSetVersion() - Method in record class zeroecho.pki.application.PkiSessionConfiguration.BindingProviderConfiguration
Returns the value of the expectedBindingSetVersion record component.
expectedChainPathCommitment() - Method in record class zeroecho.pki.api.issuance.IssuanceIntent
Returns the value of the expectedChainPathCommitment record component.
expectedChainPathId() - Method in record class zeroecho.pki.api.issuance.IssuanceIntent
Returns the value of the expectedChainPathId record component.
expectedCommitment() - Method in record class zeroecho.pki.application.PkiOperation.ValidateAlgorithmBindings
Returns the value of the expectedCommitment record component.
expectedIssuerId() - Method in record class zeroecho.pki.api.issuance.IssuanceIntent
Returns the value of the expectedIssuerId record component.
expectedProfile() - Method in record class zeroecho.pki.api.issuance.IssuanceIntent
Returns the value of the expectedProfile record component.
EXPERIMENTAL - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.Interoperability
Experimental representation without general interoperability.
EXPERIMENTAL - Enum constant in enum class zeroecho.pki.api.attr.AttributeStability
Attribute is experimental and may change under a controlled evolution process.
EXPIRED - Enum constant in enum class zeroecho.pki.api.credential.CredentialStatus
Credential validity interval has ended.
EXPIRED - Enum constant in enum class zeroecho.pki.api.credential.EffectiveCredentialStatus
The credential is expired by metadata or evaluation time.
EXPIRED - Enum constant in enum class zeroecho.pki.spi.crypto.SignatureWorkflow.State
 
EXPIRED - Enum constant in enum class zeroecho.pki.spi.store.SignWorkflowStore.State
 
EXPIRED - Enum constant in enum class zeroecho.pki.util.async.AsyncState
The operation exceeded its declared deadline and was expired by the bus.
expiresAt() - Method in record class zeroecho.pki.api.orch.WorkflowStateRecord
Returns the value of the expiresAt record component.
expiresAt() - Method in record class zeroecho.pki.util.async.AsyncOperationSnapshot
Returns the value of the expiresAt record component.
explain(PkiId) - Method in interface zeroecho.pki.api.PolicyService
Retrieves a trace explaining a previous decision.
Explainability - Search tag in package zeroecho.pki.api.policy
Section
EXPLICIT - Enum constant in enum class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy.Mode
Every custom representation is selected by stable binding identity.
export(AttributeCatalogue, AttributeSet, AttributeId, AccessContext) - Method in interface zeroecho.pki.api.audit.AttributeGovernanceService
Exports an attribute value after applying access control.
export(AttributeCatalogue, AttributeSet, AttributeId, AccessContext) - Method in class zeroecho.pki.impl.audit.DefaultAttributeGovernanceService
 
EXPORT - Enum constant in enum class zeroecho.pki.api.audit.AccessAction
Export attribute value to an external channel (e.g., UI, LDAP, backups).
ExportArtifact - Record Class in zeroecho.pki.api.transfer
Opaque export artifact containing exported objects.
ExportArtifact(PkiId, EncodedObject) - Constructor for record class zeroecho.pki.api.transfer.ExportArtifact
Creates an export artifact.
exportCa(PkiId, ExportFormat) - Method in interface zeroecho.pki.api.ImportExportService
Exports CA materials for a given CA entity in the requested export format.
exportCredentials(ExportQuery, ExportFormat) - Method in interface zeroecho.pki.api.ImportExportService
Exports credentials matching the query constraints in the requested export format.
ExportFormat - Enum Class in zeroecho.pki.api.transfer
Controls export representation.
exportId() - Method in record class zeroecho.pki.api.transfer.ExportArtifact
Returns the value of the exportId record component.
ExportQuery - Record Class in zeroecho.pki.api.transfer
Query constraints for exporting credentials and revocations.
ExportQuery(Optional<PkiId>, Optional<SubjectRef>, Optional<Instant>, Optional<Instant>, Optional<CredentialStatus>) - Constructor for record class zeroecho.pki.api.transfer.ExportQuery
Creates an export query.
exportRevocations(ExportQuery, ExportFormat) - Method in interface zeroecho.pki.api.ImportExportService
Exports revocation records matching the query constraints in the requested export format.
exportSnapshot(Path, Instant) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
Exports a snapshot of this store as of time at into targetRoot.
exportTargets() - Method in record class zeroecho.pki.api.attr.AttributeAccessPolicy
Returns the value of the exportTargets record component.
extendedKeyUsageCritical() - Method in record class zeroecho.pki.api.profile.LeafCertificatePolicy
Returns the value of the extendedKeyUsageCritical record component.
extendedKeyUsageCritical() - Method in class zeroecho.pki.impl.core.ValidatedCertificateRequest
 
ExtendedKeyUsageId - Record Class in zeroecho.pki.api.profile
Validated exact X.509 extended-key-usage object identifier.
ExtendedKeyUsageId(String) - Constructor for record class zeroecho.pki.api.profile.ExtendedKeyUsageId
Validates and constructs the identifier.
extendedKeyUsages() - Method in record class zeroecho.pki.api.profile.LeafCertificatePolicy
Returns the value of the extendedKeyUsages record component.
extendedKeyUsages() - Method in class zeroecho.pki.impl.core.ValidatedCertificateRequest
 
extension(List<X509BindingRule>) - Static method in class zeroecho.pki.impl.framework.x509.X509BindingCatalog
Creates a trusted additive extension catalog.
extension(List<X509ComponentCatalog.Component>) - Static method in class zeroecho.pki.impl.framework.x509.X509ComponentCatalog
Creates a trusted additive extension catalog.
EXTERNAL_OUTCOME_UNKNOWN - Enum constant in enum class zeroecho.pki.api.publication.PublicationFailure
The publisher call did not establish whether an external effect occurred.
EXTERNAL_OUTCOME_UNKNOWN - Enum constant in enum class zeroecho.pki.application.PkiOperationFailure
An external operation may have completed and must be reconciled.
EXTERNAL_RETRYABLE - Enum constant in enum class zeroecho.pki.api.publication.PublicationFailure
The publisher authoritatively classified the attempt as retryable.
EXTERNAL_TERMINAL - Enum constant in enum class zeroecho.pki.api.publication.PublicationFailure
The publisher authoritatively classified the attempt as terminal.
extra() - Method in record class zeroecho.pki.api.attr.AttributeMeta
Returns the value of the extra record component.

F

FAILED - Enum constant in enum class zeroecho.pki.api.request.ProofOfPossessionStatus
Proof-of-possession evidence is present but invalid.
FAILED - Enum constant in enum class zeroecho.pki.spi.crypto.SignatureWorkflow.State
 
FAILED - Enum constant in enum class zeroecho.pki.spi.store.SignWorkflowStore.State
 
FAILED - Enum constant in enum class zeroecho.pki.util.async.AsyncState
The operation completed unsuccessfully (terminal failure).
failure() - Method in record class zeroecho.pki.api.publication.PublicationRecord
Returns the value of the failure record component.
failure() - Method in exception class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.ResolutionException
Returns the stable failure category.
Failure(String, PkiOperationFailure, String) - Constructor for record class zeroecho.pki.application.PkiOperationOutcome.Failure
Validates stable, non-sensitive failure data.
Failure and audit model - Search tag in record class zeroecho.pki.spi.crypto.SignatureWorkflow.OperationStatus
Section
failureCategory() - Method in record class zeroecho.pki.spi.store.MetadataCommitResult
Returns the value of the failureCategory record component.
failureCount() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Returns the value of the failureCount record component.
Failure model - Search tag in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
Section
Failure model - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509ProofOfPossessionVerifier
Section
Failure model - Search tag in class zeroecho.pki.impl.framework.x509.bc.WorkflowProofOfPossessionVerifier
Section
Failure model (normative) - Search tag in zeroecho.pki.spi.crypto.SignatureWorkflow.submitSign(SignatureWorkflow.SignRequest, SignatureWorkflow.CallControl)
Section
Failure model (normative) - Search tag in zeroecho.pki.spi.crypto.SignatureWorkflow.submitVerify(SignatureWorkflow.VerifyRequest, SignatureWorkflow.CallControl)
Section
Failure model (normative - Variant 1) - Search tag in interface zeroecho.pki.spi.crypto.SignatureWorkflow
Section
failures() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Page
Returns the value of the failures record component.
fence() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Returns the value of the fence record component.
fencingToken() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.SignRequest
Returns the value of the fencingToken record component.
field(String) - Method in record class zeroecho.pki.application.PkiOperationResult
Returns one declared safe field.
fields() - Method in record class zeroecho.pki.application.PkiOperationResult
Returns the value of the fields record component.
fields() - Method in record class zeroecho.pki.application.PkiOperationValue.ObjectValue
Returns the value of the fields record component.
FileAuditSink - Class in zeroecho.pki.impl.audit
Persistent AuditSink provider storing audit events as daily gzip files.
FileAuditSink(Path) - Constructor for class zeroecho.pki.impl.audit.FileAuditSink
Creates the sink with an explicit base directory.
FileAuditSinkProvider - Class in zeroecho.pki.impl.audit
AuditSinkProvider for the file-backed audit sink.
FileAuditSinkProvider() - Constructor for class zeroecho.pki.impl.audit.FileAuditSinkProvider
 
FileBackedAsyncBusProvider - Class in zeroecho.pki.impl.async
Default async bus provider: in-memory state with append-only file persistence.
FileBackedAsyncBusProvider() - Constructor for class zeroecho.pki.impl.async.FileBackedAsyncBusProvider
 
FILESYSTEM - Enum constant in enum class zeroecho.pki.api.publication.PublicationTargetType
Publish to a filesystem location.
FilesystemPkiStore - Class in zeroecho.pki.impl.fs
Filesystem-based reference implementation of PkiStore.
FilesystemPkiStore(Path, FsPkiStoreOptions) - Constructor for class zeroecho.pki.impl.fs.FilesystemPkiStore
Opens or creates a filesystem PKI store rooted at root.
FilesystemPkiStore(Path, FsPkiStoreOptions, Clock) - Constructor for class zeroecho.pki.impl.fs.FilesystemPkiStore
Opens or creates a filesystem store with an explicit authoritative clock.
FilesystemPkiStoreProvider - Class in zeroecho.pki.impl.fs
PkiStoreProvider for the filesystem-backed PkiStore.
FilesystemPkiStoreProvider() - Constructor for class zeroecho.pki.impl.fs.FilesystemPkiStoreProvider
Public no-arg constructor required by ServiceLoader.
FilesystemPublisherProvider - Class in zeroecho.pki.impl.publish
Explicit filesystem publication-destination provider.
FilesystemPublisherProvider() - Constructor for class zeroecho.pki.impl.publish.FilesystemPublisherProvider
 
FilesystemStagedContentStore - Class in zeroecho.pki.impl.fs
Filesystem-backed staged-content store with atomic completion and streaming integrity verification.
FilesystemStagedContentStore(Path, String) - Constructor for class zeroecho.pki.impl.fs.FilesystemStagedContentStore
Creates a staged-content store.
find(String) - Method in interface zeroecho.pki.api.algorithm.X509AlgorithmBindingRegistry
Resolves a stable binding identifier.
find(String) - Method in class zeroecho.pki.impl.framework.x509.ImmutableX509AlgorithmBindingRegistry
 
find(AttributeId) - Method in interface zeroecho.pki.api.attr.AttributeCatalogue
Finds a definition by id.
find(PkiId) - Method in interface zeroecho.pki.api.PublicationService
Reads one durable publication operation.
find(PkiId) - Method in class zeroecho.pki.impl.core.DefaultPublicationService
 
find(X509ComponentCatalog.Kind, String) - Method in class zeroecho.pki.impl.framework.x509.X509ComponentCatalog
Resolves a component when present.
findByIssuerSerial(PkiId, String) - Method in interface zeroecho.pki.api.CredentialInventoryService
Finds a credential by issuer CA and serial/unique identifier.
fingerprint() - Method in class zeroecho.pki.impl.core.VerifiedIssuanceCandidate
Returns the identity bound to the verified request.
fingerprint() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Returns the value of the fingerprint record component.
fingerprint(String, AccessContext, KeyRef, String, RepeatableContent, Optional<Encoding>, Optional<Instant>) - Static method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.SignRequest
Computes the canonical signfp:v1 semantic fingerprint in O(payload) time and O(payload) temporary memory from the defensive payload copy, with constant-size digest state.
fingerprint(CertificationRequest) - Method in interface zeroecho.pki.api.CertificationRequestService
Computes a stable identifier (fingerprint) for the given request payload.
fingerprint(CertificationRequest) - Method in class zeroecho.pki.impl.core.DefaultCertificationRequestService
Computes a deterministic identifier for the supplied certification request.
fixedValue() - Method in record class zeroecho.pki.api.profile.SubjectRdnRule
Returns the value of the fixedValue record component.
FOREIGN_TRANSACTION - Enum constant in enum class zeroecho.pki.spi.store.MetadataCommitResult.FailureCategory
Transaction identity belongs to another store.
FORMAT_ID - Static variable in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFramework
X.509 format identifier used by this framework.
formatId() - Method in record class zeroecho.pki.api.audit.AccessContext
Returns the value of the formatId record component.
formatId() - Method in record class zeroecho.pki.api.audit.AuditEvent
Returns the value of the formatId record component.
formatId() - Method in record class zeroecho.pki.api.ca.CaCreateCommand
Returns the value of the formatId record component.
formatId() - Method in record class zeroecho.pki.api.ca.CaImportCommand
Returns the value of the formatId record component.
formatId() - Method in record class zeroecho.pki.api.ca.CaQuery
Returns the value of the formatId record component.
formatId() - Method in record class zeroecho.pki.api.ca.IntermediateCertIssueCommand
Returns the value of the formatId record component.
formatId() - Method in record class zeroecho.pki.api.ca.IntermediateCreateCommand
Returns the value of the formatId record component.
formatId() - Method in record class zeroecho.pki.api.credential.Credential
Returns the value of the formatId record component.
formatId() - Method in record class zeroecho.pki.api.credential.CredentialQuery
Returns the value of the formatId record component.
formatId() - Method in record class zeroecho.pki.api.profile.CertificateProfile
Returns the value of the formatId record component.
formatId() - Method in record class zeroecho.pki.api.profile.CertificateProfileDefinition
Returns the value of the formatId record component.
formatId() - Method in record class zeroecho.pki.api.profile.ProfileQuery
Returns the value of the formatId record component.
formatId() - Method in record class zeroecho.pki.api.request.CertificationRequest
Returns the value of the formatId record component.
formatId() - Method in record class zeroecho.pki.api.request.ParsedCertificationRequest
Returns the value of the formatId record component.
formatId() - Method in record class zeroecho.pki.api.request.RequestQuery
Returns the value of the formatId record component.
formatId() - Method in record class zeroecho.pki.api.status.StatusObject
Returns the value of the formatId record component.
formatId() - Method in record class zeroecho.pki.api.status.StatusObjectGenerateCommand
Returns the value of the formatId record component.
formatId() - Method in record class zeroecho.pki.application.PkiOperation.CreateAuthority
Returns the value of the formatId record component.
formatId() - Method in record class zeroecho.pki.application.PkiOperation.GenerateStatus
Returns the value of the formatId record component.
formatId() - Method in record class zeroecho.pki.application.PkiOperation.ImportRequest
Returns the value of the formatId record component.
formatId() - Method in class zeroecho.pki.impl.core.ValidatedCaCertificateRequest
Returns the credential format.
formatId() - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFramework
Returns the framework format identifier.
formatId() - Method in interface zeroecho.pki.spi.framework.CredentialFramework
Returns the format id supported by this framework.
FormatId - Record Class in zeroecho.pki.api
Identifier of a credential framework/format handled by the PKI core.
FormatId(String) - Constructor for record class zeroecho.pki.api.FormatId
Creates a format identifier.
framework() - Method in record class zeroecho.pki.application.PkiSessionConfiguration.SigningConfiguration
Returns the value of the framework record component.
FrameworkAttributeMapper - Interface in zeroecho.pki.spi.framework
Maps universal attributes to framework-specific constructs and optionally back.
fromBc(AlgorithmIdentifier) - Static method in class zeroecho.pki.impl.framework.x509.bc.BcX509AlgorithmAdapter
Converts a BC identifier to an exact provider-neutral representation.
fromCode(int) - Static method in enum class zeroecho.pki.application.OcspResponseService.CertIdHash
Resolves an exact stable persistence code.
fromCode(int) - Static method in enum class zeroecho.pki.application.OcspResponseService.ResponderId
Resolves an exact stable persistence code.
fromDefinition(CertificateProfileDefinition) - Static method in record class zeroecho.pki.api.profile.CertificateProfile
Creates the deterministic runtime projection of a validated definition.
fromOid(String) - Static method in enum class zeroecho.pki.api.profile.SubjectRdnType
Resolves a supported RDN type.
fromPersistentCode(int) - Static method in enum class zeroecho.pki.spi.store.SignWorkflowStore.State
Resolves a current stable persistence code.
FsHistoryPolicy - Class in zeroecho.pki.impl.fs
History configuration for mutable entities stored by FilesystemPkiStore.
FsHistoryPolicy.CleanupStrategy - Enum Class in zeroecho.pki.impl.fs
Supported cleanup strategy.
FsPkiStoreOptions - Record Class in zeroecho.pki.impl.fs
Options for FilesystemPkiStore.
FsPkiStoreOptions(FsHistoryPolicy, FsHistoryPolicy, FsHistoryPolicy, FsHistoryPolicy, boolean, Duration, Duration) - Constructor for record class zeroecho.pki.impl.fs.FsPkiStoreOptions
Canonical constructor with validation.

G

GENERAL_NAME - Enum constant in enum class zeroecho.pki.api.attr.AttributeValueType
GeneralName-like identity (DNS/IP/URI/email/etc.) represented in a canonical structured form.
generate(StatusObjectGenerateCommand) - Method in interface zeroecho.pki.api.StatusObjectService
Generates a new status object for an issuer CA.
generate(StatusObjectGenerateCommand) - Method in class zeroecho.pki.impl.core.DefaultStatusObjectService
Generates a new status object for the specified issuer CA and persists the result.
generate(StatusObjectGenerateCommand, CrlEntrySource) - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509StatusObjectGenerator
Generates an X.509 CRL status object.
generate(StatusObjectGenerateCommand, CrlEntrySource) - Method in interface zeroecho.pki.spi.framework.StatusObjectGenerator
Generates a status object.
generatedObjectBytes() - Method in record class zeroecho.pki.api.content.DeploymentResourcePolicy
Returns the value of the generatedObjectBytes record component.
GenerateStatus(PkiId, StatusObjectType, FormatId) - Constructor for record class zeroecho.pki.application.PkiOperation.GenerateStatus
Validates the generation input.
get(String) - Method in record class zeroecho.pki.spi.ProviderConfig
Returns an optional value for the given key.
get(AttributeId) - Method in interface zeroecho.pki.api.attr.AttributeSet
Reads a single-valued attribute.
get(AttributeId) - Method in record class zeroecho.pki.impl.core.attr.SimpleAttributeSet
Returns the first value associated with the supplied attribute identifier.
get(AttributeId) - Method in class zeroecho.pki.impl.framework.x509.bc.SimpleAttributeSet
Returns the first value associated with the supplied attribute identifier.
get(PkiId) - Method in interface zeroecho.pki.api.audit.AuditService
Retrieves an audit event by id if the implementation assigns stable ids.
get(PkiId) - Method in interface zeroecho.pki.api.CertificationRequestService
Retrieves a stored request.
get(PkiId) - Method in interface zeroecho.pki.api.CredentialInventoryService
Retrieves a credential by id.
get(PkiId) - Method in interface zeroecho.pki.api.RevocationService
Retrieves the validated current state for one credential.
get(PkiId) - Method in class zeroecho.pki.impl.core.DefaultCertificationRequestService
Resolves a previously stored parsed certification request by its identifier.
get(PkiId) - Method in class zeroecho.pki.impl.core.DefaultRevocationService
 
get(PkiId) - Method in interface zeroecho.pki.spi.store.RevocationView
Returns one current state without scanning the revocation population.
get(MetadataKey) - Method in interface zeroecho.pki.spi.store.MetadataSnapshot
Reads one record from this stable view.
getActiveProfileRef(String) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
getActiveProfileRef(String) - Method in interface zeroecho.pki.spi.store.PkiStore
Retrieves the current active reference.
getActiveReference(String) - Method in interface zeroecho.pki.api.ProfileService
Retrieves the current active reference without activating anything.
getActiveReference(String) - Method in class zeroecho.pki.impl.core.DefaultProfileService
 
getAlgorithmIdentifier() - Method in class zeroecho.pki.impl.framework.x509.bc.PkiBusContentSigner
Returns the ASN.1 algorithm identifier corresponding to the configured signature algorithm name.
getAll(AttributeId) - Method in interface zeroecho.pki.api.attr.AttributeSet
Reads a potentially multi-valued attribute.
getAll(AttributeId) - Method in record class zeroecho.pki.impl.core.attr.SimpleAttributeSet
Returns all values associated with the supplied attribute identifier.
getAll(AttributeId) - Method in class zeroecho.pki.impl.framework.x509.bc.SimpleAttributeSet
Returns all values associated with the supplied attribute identifier.
getById(PkiId) - Method in class zeroecho.pki.impl.audit.FileAuditSink
 
getById(PkiId) - Method in class zeroecho.pki.impl.audit.InMemoryAuditSink
 
getCa(PkiId) - Method in interface zeroecho.pki.api.CaService
Retrieves a CA record.
getCa(PkiId) - Method in class zeroecho.pki.impl.core.DefaultCaService
Resolves a CA record by its identifier.
getCa(PkiId) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
getCa(PkiId) - Method in interface zeroecho.pki.spi.store.PkiStore
Retrieves a CA record.
getCredential(PkiId) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
getCredential(PkiId) - Method in interface zeroecho.pki.spi.store.PkiStore
Retrieves a credential record.
getCredentialByIssuanceIntent(IssuanceIntent) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
getCredentialByIssuanceIntent(IssuanceIntent) - Method in interface zeroecho.pki.spi.store.PkiStore
Resolves the exact credential atomically persisted with one issuance intent.
getCredentialByIssuerAndSerial(PkiId, BigInteger) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
getCredentialByIssuerAndSerial(PkiId, BigInteger) - Method in interface zeroecho.pki.spi.store.PkiStore
Resolves one exact X.509 credential through the derived issuer-generation and canonical positive serial index.
getImportedVersion(String, long) - Method in interface zeroecho.pki.api.ProfileService
Retrieves one immutable imported version for administration.
getImportedVersion(String, long) - Method in class zeroecho.pki.impl.core.DefaultProfileService
 
getIssuerChainPath(PkiId) - Method in interface zeroecho.pki.api.CaService
Returns one exact immutable issuer chain path.
getIssuerChainPath(PkiId) - Method in class zeroecho.pki.impl.core.DefaultCaService
 
getIssuerChainPath(PkiId) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
getIssuerChainPath(PkiId) - Method in interface zeroecho.pki.spi.store.PkiStore
Retrieves one immutable issuer chain path.
getIssuerGeneration(PkiId) - Method in interface zeroecho.pki.api.CaService
Returns one exact issuer generation owned by this PKI authority.
getIssuerGeneration(PkiId) - Method in class zeroecho.pki.impl.core.DefaultCaService
 
getIssuerGeneration(PkiId) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
getIssuerGeneration(PkiId) - Method in interface zeroecho.pki.spi.store.PkiStore
Retrieves one canonical issuer-generation record.
getLatest(PkiId, StatusObjectType) - Method in interface zeroecho.pki.api.StatusObjectService
Retrieves the latest status object of a given type for an issuer CA.
getLatest(PkiId, StatusObjectType) - Method in class zeroecho.pki.impl.core.DefaultStatusObjectService
Resolves the most recent status object of the requested type for a given issuer CA.
getOutputStream() - Method in class zeroecho.pki.impl.framework.x509.bc.PkiBusContentSigner
Returns the output stream used to collect the to-be-signed bytes.
getPolicyTrace(PkiId) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
getPolicyTrace(PkiId) - Method in interface zeroecho.pki.spi.store.PkiStore
Retrieves a policy trace.
getProfileVersion(String, long) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
getProfileVersion(String, long) - Method in interface zeroecho.pki.spi.store.PkiStore
Retrieves one imported version.
getPublicationRecord(PkiId) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
getPublicationRecord(PkiId) - Method in interface zeroecho.pki.spi.store.PkiStore
Reads one publication operation by exact semantic identity.
getRequest(PkiId) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
getRequest(PkiId) - Method in interface zeroecho.pki.spi.store.PkiStore
Retrieves a parsed certification request.
getRevocation(PkiId) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
getRevocation(PkiId) - Method in interface zeroecho.pki.spi.store.PkiStore
Retrieves the validated current revocation state for a credential.
getSignature() - Method in class zeroecho.pki.impl.framework.x509.bc.PkiBusContentSigner
Submits the buffered to-be-signed payload to the PKI signing bus and waits for the resulting signature bytes.
getSignRecord(PkiId) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
getSignRecord(PkiId) - Method in interface zeroecho.pki.spi.store.SignWorkflowStore
Returns authoritative state for an identifier.
getStatusObject(PkiId) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
getStatusObject(PkiId) - Method in interface zeroecho.pki.spi.store.PkiStore
Retrieves a status object.
getWorkflowState(PkiId) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
getWorkflowState(PkiId) - Method in interface zeroecho.pki.spi.store.PkiStore
Retrieves workflow continuation state for a given operation.
goodCount() - Method in record class zeroecho.pki.application.OcspResponseService.Response
Returns the value of the goodCount record component.

H

HARD_MAXIMUM_COUNT - Static variable in record class zeroecho.pki.api.profile.SubjectAlternativeNamePolicy
Maximum number of SAN entries.
HARD_MAXIMUM_RDN_COUNT - Static variable in record class zeroecho.pki.api.profile.SubjectPolicy
Maximum number of subject RDNs.
HARD_MAXIMUM_UTF8_BYTES - Static variable in record class zeroecho.pki.api.profile.SubjectRdnRule
Maximum hard value size.
hash() - Method in record class zeroecho.pki.application.OcspResponseService.CertId
Returns the value of the hash record component.
HASH_BYTES - Static variable in class zeroecho.pki.api.profile.CertificateProfileRef
SHA-256 digest length in bytes.
hashCode() - Method in record class zeroecho.pki.api.algorithm.X509AlgorithmBinding
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.attr.AttributeAccessPolicy
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.attr.AttributeDefinition
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.attr.AttributeId
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.attr.AttributeMeta
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.attr.AttributeValue.BooleanValue
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.attr.AttributeValue.BytesValue
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.attr.AttributeValue.InstantValue
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.attr.AttributeValue.IntegerValue
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.attr.AttributeValue.StringValue
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.audit.AccessContext
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.audit.AuditEvent
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.audit.AuditQuery
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.audit.Principal
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.audit.Purpose
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.backup.BackupArtifact
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.backup.BackupRequest
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.backup.BackupVerificationReport
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.backup.RestoreReport
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.backup.RestoreRequest
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.ca.CaCreateCommand
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.ca.CaImportCommand
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.ca.CaKeyRotationCommand
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.ca.CaQuery
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.ca.CaRecord
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.ca.CaRolloverCommand
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.ca.IntermediateCertIssueCommand
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.ca.IntermediateCreateCommand
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.ca.IssuerChainPath
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.ca.IssuerGeneration
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.content.DeploymentResourcePolicy
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.content.DurableContentOwner
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.content.ResourceLimit.LimitedTo
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.content.ResourceLimit.UnrestrictedByDeployment
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.credential.CaProfileBinding
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.credential.Credential
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.credential.CredentialBundle
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.credential.CredentialQuery
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.credential.EndEntityProfileBinding
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.EncodedObject
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.FormatId
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.issuance.BundleCommand
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.issuance.IssuanceInputs
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.issuance.IssuanceIntent
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.issuance.IssueEndEntityCommand
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.issuance.ReissueCommand
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.issuance.RenewCommand
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.issuance.ReplaceCommand
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.issuance.VerificationPolicy
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.IssuerRef
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.KeyRef
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.orch.SigningSubmissionId
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.orch.WorkflowStateRecord
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.PkiId
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.policy.PolicyDecision
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.policy.PolicyTrace
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.policy.PolicyTraceStep
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.profile.ActiveCertificateProfile
Returns a hash code value for this object.
hashCode() - Method in class zeroecho.pki.api.profile.BuiltInCertificateProfileTemplate
 
hashCode() - Method in record class zeroecho.pki.api.profile.CaCertificatePolicy
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.profile.CertificateProfile
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.profile.CertificateProfileDefinition
Returns a hash code value for this object.
hashCode() - Method in class zeroecho.pki.api.profile.CertificateProfileRef
 
hashCode() - Method in record class zeroecho.pki.api.profile.ExtendedKeyUsageId
Returns a hash code value for this object.
hashCode() - Method in class zeroecho.pki.api.profile.ImportedCertificateProfileVersion
 
hashCode() - Method in record class zeroecho.pki.api.profile.LeafCertificatePolicy
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.profile.ProfileQuery
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.profile.SubjectAlternativeNamePolicy
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.profile.SubjectAlternativeNameRule
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.profile.SubjectPolicy
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.profile.SubjectRdnRule
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy.BindingReference
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.publication.PublicationQuery
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.publication.PublicationRecord
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.publication.PublicationRequest
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.publication.PublicationResult
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.publication.PublicationTarget
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.request.CertificationRequest
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.request.ParsedCertificationRequest
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.request.ProofOfPossessionResult
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.request.RequestQuery
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.DnsName
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.IpAddress
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.Rfc822Name
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.UriName
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.request.SubjectRdn
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.revocation.RevocationCommand.Hold
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.revocation.RevocationCommand.RevokePermanently
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.revocation.RevocationCommand.Unhold
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.revocation.RevocationInputs
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.revocation.RevocationQuery
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.revocation.RevocationRecord
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.revocation.RevocationTransition
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.status.StatusObject
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.status.StatusObjectGenerateCommand
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.status.StatusObjectQuery
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.SubjectRef
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.transfer.ExportArtifact
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.transfer.ExportQuery
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.transfer.ImportPolicy
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.api.Validity
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.OcspResponseService.CertId
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.OcspResponseService.Command
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.OcspResponseService.Response
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.ActivateProfile
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.CreateAuthority
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.GenerateStatus
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.ImportRequest
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.InspectAlgorithmBinding
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.InspectAuthority
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.InspectCredential
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.InspectProfile
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.InspectPublication
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.InspectRequest
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.InspectRevocation
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.InspectStatus
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.IssueCredential
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.ListAlgorithmBindings
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.ListAuthorities
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.ListProfileVersions
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.ListPublications
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.ListStatus
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.ProcessPublication
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.ReadRevocationHistory
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.ReconcilePublication
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.RegisterProfile
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.RegisterPublication
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.RetryPublication
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.RevokeCredential
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.SnapshotRevocations
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.TransitionAuthority
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.ValidateAlgorithmBindings
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.ValidateConfiguration
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.ValidateProfile
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperation.VerifyRequest
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperationOutcome.Failure
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperationOutcome.Success
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperationResult
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperationValue.BooleanValue
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperationValue.IntegerValue
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperationValue.ListValue
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperationValue.ObjectValue
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiOperationValue.Text
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiSessionConfiguration.BindingProviderConfiguration
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiSessionConfiguration
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiSessionConfiguration.SigningConfiguration
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.PkiSessionRuntimeDependencies
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.SigningReconciliationRequest
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.application.SigningReconciliationResult
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.impl.core.attr.SimpleAttributeSet.Entry
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.impl.core.attr.SimpleAttributeSet
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.impl.framework.x509.bc.BcX509SignedObjectValidator.CertificateBindings
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectLayout
Returns a hash code value for this object.
hashCode() - Method in class zeroecho.pki.impl.framework.x509.X509AlgorithmIdentifier
 
hashCode() - Method in record class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Selection
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.impl.framework.x509.X509ComponentCatalog.Component
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.impl.fs.FsPkiStoreOptions
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.CallControl
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.OperationResult
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.OperationStatus
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.SignRequest
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.VerifyRequest
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.spi.framework.CrlEntry
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.spi.ProviderConfig
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.spi.publish.PublicationAttempt
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.spi.store.MetadataCommitResult
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.spi.store.MetadataKey
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.spi.store.MetadataSnapshot.Integrity
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.spi.store.MetadataSnapshot.KeyRange
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.spi.store.MetadataStoreCapabilities
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.spi.store.MetadataStoreId
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.spi.store.MetadataTransactionId
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Page
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.util.async.AsyncEvent
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.util.async.AsyncOperationSnapshot
Returns a hash code value for this object.
hashCode() - Method in record class zeroecho.pki.util.async.AsyncStatus
Returns a hash code value for this object.
hasLiveContent() - Method in class zeroecho.pki.impl.core.async.PkiSigningBus.SignContinuation
Returns whether this continuation still requires live staged content.
hasSameOperation(PublicationRecord) - Method in record class zeroecho.pki.api.publication.PublicationRecord
Tests whether another record describes the same immutable operation.
HELD - Enum constant in enum class zeroecho.pki.api.credential.EffectiveCredentialStatus
The credential is temporarily held.
HELD - Enum constant in enum class zeroecho.pki.api.revocation.RevocationState
Credential is temporarily held.
history(PkiId) - Method in interface zeroecho.pki.api.RevocationService
Opens the authoritative transition history for one credential.
history(PkiId) - Method in class zeroecho.pki.impl.core.DefaultRevocationService
 
History tracking - Search tag in record class zeroecho.pki.impl.fs.FsPkiStoreOptions
Section
hold(RevocationCommand.Hold) - Method in interface zeroecho.pki.api.RevocationService
Places a credential on hold.
hold(RevocationCommand.Hold) - Method in class zeroecho.pki.impl.core.DefaultRevocationService
 
Hold(PkiId, AttributeSet) - Constructor for record class zeroecho.pki.api.revocation.RevocationCommand.Hold
Validates and snapshots the command.
HTTP - Enum constant in enum class zeroecho.pki.api.publication.PublicationTargetType
Publish via an HTTP(S) endpoint.

I

id() - Method in record class zeroecho.pki.api.attr.AttributeDefinition
Returns the value of the id record component.
id() - Method in record class zeroecho.pki.api.orch.SigningSubmissionId
Returns the value of the id record component.
id() - Method in class zeroecho.pki.impl.async.FileBackedAsyncBusProvider
 
id() - Method in class zeroecho.pki.impl.audit.FileAuditSinkProvider
 
id() - Method in class zeroecho.pki.impl.audit.InMemoryAuditSinkProvider
 
id() - Method in class zeroecho.pki.impl.audit.StdoutAuditSinkProvider
 
id() - Method in record class zeroecho.pki.impl.core.attr.SimpleAttributeSet.Entry
Returns the value of the id record component.
id() - Method in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
 
id() - Method in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflowProvider
 
id() - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFrameworkProvider
Returns the stable provider identifier used to select this X.509 framework backend.
id() - Method in interface zeroecho.pki.impl.framework.x509.X509BindingRule
Returns the stable namespaced rule identifier.
id() - Method in record class zeroecho.pki.impl.framework.x509.X509ComponentCatalog.Component
Returns the value of the id record component.
id() - Method in class zeroecho.pki.impl.fs.FilesystemPkiStoreProvider
 
id() - Method in class zeroecho.pki.impl.fs.PosixTransactionalMetadataStore
Returns this durable store authority identity.
id() - Method in class zeroecho.pki.impl.publish.FilesystemPublisherProvider
 
id() - Method in interface zeroecho.pki.spi.ConfigurableProvider
Returns a stable backend identifier (e.g.
id() - Method in interface zeroecho.pki.spi.crypto.SignatureWorkflow
Provider identifier for diagnostics and audit correlation.
id() - Method in interface zeroecho.pki.spi.store.MetadataTransaction
Returns the store-issued transaction identity.
id() - Method in interface zeroecho.pki.spi.store.TransactionalMetadataStore
Returns this durable store authority identity.
id(T) - Method in interface zeroecho.pki.spi.bootstrap.SpiSelector.ProviderId
Returns the stable id for a provider instance.
ID_ATTRIBUTE - Static variable in record class zeroecho.pki.api.issuance.IssuanceIntent
Stable internal metadata attribute carrying the non-secret issuance identity.
IdCodec<T> - Interface in zeroecho.pki.util.async.codec
String codec for stable persistence of identifiers.
identifier() - Method in record class zeroecho.pki.api.content.DurableContentOwner
Returns the value of the identifier record component.
Identifier form - Search tag in class zeroecho.pki.impl.core.async.OperationIdCodec
Section
identities() - Method in interface zeroecho.pki.impl.framework.x509.X509BindingRuleProvider
Returns exact identities introduced by this installed extension.
identity() - Method in record class zeroecho.pki.impl.framework.x509.X509ComponentCatalog.Component
Returns the value of the identity record component.
identity(X509ComponentCatalog.Kind, String) - Method in class zeroecho.pki.impl.framework.x509.X509ComponentCatalog
Reverse-resolves an exact component OID.
idFor(String) - Static method in record class zeroecho.pki.api.ca.IssuerChainPath
Returns the canonical path identity for a path commitment.
idFor(PkiId, PkiId) - Static method in record class zeroecho.pki.api.ca.IssuerGeneration
Returns the canonical identity for an authority credential generation.
ids() - Method in interface zeroecho.pki.api.attr.AttributeSet
Returns all attribute identifiers present in this set.
ids() - Method in record class zeroecho.pki.impl.core.attr.SimpleAttributeSet
Returns the distinct set of attribute identifiers present in this set.
ids() - Method in class zeroecho.pki.impl.framework.x509.bc.SimpleAttributeSet
Returns the identifiers present in this attribute set.
Immutability - Search tag in class zeroecho.pki.impl.framework.x509.bc.SimpleAttributeSet
Section
Immutability and history - Search tag in package zeroecho.pki.api.orch
Section
Immutability and lifecycle - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFramework
Section
ImmutableX509AlgorithmBindingRegistry - Class in zeroecho.pki.impl.framework.x509
Package-owned immutable registry implementation used by session bootstrap.
implementation() - Method in record class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Selection
Returns the value of the implementation record component.
IMPLEMENTATION_ID - Static variable in class zeroecho.pki.impl.framework.x509.bc.BcX509VerificationExecutor
Stable semantic implementation identifier.
Implementation expectations - Search tag in interface zeroecho.pki.spi.framework.CredentialIssuerBackend
Section
Implementation notes - Search tag in package zeroecho.pki.impl.core.async
Section
Implementation style - Search tag in package zeroecho.pki.impl.core
Section
Implementation style - Search tag in package zeroecho.pki.impl.framework.x509.bc
Section
IMPORT_ROOT - Enum constant in enum class zeroecho.pki.impl.core.ValidatedCaCertificateRequest.Operation
Imports an existing root credential after full profile validation.
Important limitation - Search tag in class zeroecho.pki.impl.core.async.PkiSigningBus.SignContinuation
Section
importBuiltIn(BuiltInCertificateProfileTemplate) - Method in interface zeroecho.pki.api.ProfileService
Imports a built-in provisioning template through the same document path.
importBuiltIn(BuiltInCertificateProfileTemplate) - Method in class zeroecho.pki.impl.core.DefaultProfileService
 
importCaCertificate(PkiId, EncodedObject, ImportPolicy) - Method in interface zeroecho.pki.api.ImportExportService
Imports a CA certificate payload into an existing CA entity's credential set.
importCredential(FormatId, EncodedObject, ImportPolicy) - Method in interface zeroecho.pki.api.ImportExportService
Imports an issued credential payload into inventory.
importedAt() - Method in class zeroecho.pki.api.profile.ImportedCertificateProfileVersion
 
ImportedCertificateProfileVersion - Class in zeroecho.pki.api.profile
Immutable persisted profile version and its canonical configuration bytes.
ImportedCertificateProfileVersion(CertificateProfileRef, int, CertificateProfileDefinition, byte[], Instant) - Constructor for class zeroecho.pki.api.profile.ImportedCertificateProfileVersion
Creates an immutable imported version.
ImportExportService - Interface in zeroecho.pki.api
Import and export operations for migration and interoperability.
ImportPolicy - Record Class in zeroecho.pki.api.transfer
Policy flags controlling import behavior.
ImportPolicy(boolean, boolean, AttributeSet) - Constructor for record class zeroecho.pki.api.transfer.ImportPolicy
Creates an import policy.
importProfile(byte[]) - Method in interface zeroecho.pki.api.ProfileService
Imports a bounded strict JSON profile document.
importProfile(byte[]) - Method in class zeroecho.pki.impl.core.DefaultProfileService
 
importProfile(InputStream) - Method in interface zeroecho.pki.api.ProfileService
Imports a strict JSON profile document without taking ownership of the supplied stream.
importProfile(InputStream) - Method in class zeroecho.pki.impl.core.DefaultProfileService
 
importProfileVersion(ImportedCertificateProfileVersion) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
importProfileVersion(ImportedCertificateProfileVersion) - Method in interface zeroecho.pki.spi.store.PkiStore
Atomically imports one immutable validated profile version.
ImportRequest(FormatId, EncodedObject) - Constructor for record class zeroecho.pki.application.PkiOperation.ImportRequest
Validates the finite request input.
importRoot(CaImportCommand) - Method in interface zeroecho.pki.api.CaService
Imports an existing root CA into the PKI inventory.
importRoot(CaImportCommand) - Method in class zeroecho.pki.impl.core.DefaultCaService
Imports an existing root CA credential and persists the corresponding CA record.
INCOMPATIBLE_KEY - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Failure
Signature and key identities are incompatible.
INDEFINITE - Enum constant in enum class zeroecho.pki.spi.store.MetadataStoreCapabilities.OutcomeRetention
Known terminal outcomes remain resolvable indefinitely.
InMemoryAuditSink - Class in zeroecho.pki.impl.audit
In-memory AuditSink provider intended for deterministic tests and local debugging.
InMemoryAuditSink() - Constructor for class zeroecho.pki.impl.audit.InMemoryAuditSink
Public no-arg constructor required for ServiceLoader.
InMemoryAuditSink(int) - Constructor for class zeroecho.pki.impl.audit.InMemoryAuditSink
Creates a sink with an explicit maximum number of events.
InMemoryAuditSinkProvider - Class in zeroecho.pki.impl.audit
AuditSinkProvider for the in-memory audit sink.
InMemoryAuditSinkProvider() - Constructor for class zeroecho.pki.impl.audit.InMemoryAuditSinkProvider
 
InspectAlgorithmBinding(String) - Constructor for record class zeroecho.pki.application.PkiOperation.InspectAlgorithmBinding
Validates the stable identifier.
InspectAuthority(PkiId) - Constructor for record class zeroecho.pki.application.PkiOperation.InspectAuthority
Validates the authority identity.
InspectCredential(PkiId) - Constructor for record class zeroecho.pki.application.PkiOperation.InspectCredential
Validates the identifier.
InspectProfile(String, long) - Constructor for record class zeroecho.pki.application.PkiOperation.InspectProfile
Validates the exact profile identity.
InspectPublication(PkiId) - Constructor for record class zeroecho.pki.application.PkiOperation.InspectPublication
Validates the identifier.
InspectRequest(PkiId) - Constructor for record class zeroecho.pki.application.PkiOperation.InspectRequest
Validates the request identity.
InspectRevocation(PkiId) - Constructor for record class zeroecho.pki.application.PkiOperation.InspectRevocation
Validates the credential identity.
inspectSignedObject(RepeatableContent, StreamingDerReader.SignedObjectKind, CancellationSignal) - Method in class zeroecho.pki.impl.framework.x509.StreamingDerReader
Validates and locates the signed portions of one certificate or CRL.
InspectStatus(PkiId) - Constructor for record class zeroecho.pki.application.PkiOperation.InspectStatus
Validates the status-object identity.
installed(X509AlgorithmResolver.Policy) - Static method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Creates the installed runtime snapshot with an explicit policy.
INSTANT - Enum constant in enum class zeroecho.pki.api.attr.AttributeValueType
Timestamp value.
Instantiation model - Search tag in package zeroecho.pki.spi.audit
Section
InstantValue(Instant) - Constructor for record class zeroecho.pki.api.attr.AttributeValue.InstantValue
Creates an instant value.
INTEGER - Enum constant in enum class zeroecho.pki.api.attr.AttributeValueType
Integer/long value.
IntegerValue(long) - Constructor for record class zeroecho.pki.api.attr.AttributeValue.IntegerValue
Creates an instance of a IntegerValue record class.
IntegerValue(long) - Constructor for record class zeroecho.pki.application.PkiOperationValue.IntegerValue
Creates an instance of a IntegerValue record class.
integrity() - Method in interface zeroecho.pki.spi.store.MetadataSnapshot.Record
Returns stable adapter-supplied integrity metadata when available.
Integrity(String, String) - Constructor for record class zeroecho.pki.spi.store.MetadataSnapshot.Integrity
Creates integrity metadata.
INTEGRITY_FAILURE - Enum constant in enum class zeroecho.pki.spi.store.MetadataCommitResult.FailureCategory
Stored metadata failed integrity validation.
Intended usage - Search tag in package zeroecho.pki.spi.audit
Section
INTENT - Enum constant in enum class zeroecho.pki.spi.store.SignWorkflowStore.State
 
INTERMEDIATE - Enum constant in enum class zeroecho.pki.api.ca.CaKind
Intermediate CA (issued by another CA).
INTERMEDIATE_CA - Enum constant in enum class zeroecho.pki.api.profile.CertificateProfileKind
Issuer-signed intermediate certification-authority certificate.
INTERMEDIATE_ISSUER - Enum constant in enum class zeroecho.pki.api.credential.CredentialUse
Issuer credential used for intermediate CA issuance.
IntermediateCertIssueCommand - Record Class in zeroecho.pki.api.ca
Command to issue a new CA credential for an existing intermediate CA entity.
IntermediateCertIssueCommand(FormatId, PkiId, PkiId, String, Optional<Validity>, AttributeSet) - Constructor for record class zeroecho.pki.api.ca.IntermediateCertIssueCommand
Creates an intermediate CA credential issuance command.
IntermediateCreateCommand - Record Class in zeroecho.pki.api.ca
Command to create a new intermediate CA entity and issue its initial CA credential.
IntermediateCreateCommand(FormatId, PkiId, SubjectRef, String, Optional<KeyRef>, AttributeSet) - Constructor for record class zeroecho.pki.api.ca.IntermediateCreateCommand
Creates an intermediate create command.
INTERNAL - Enum constant in enum class zeroecho.pki.api.attr.AttributeSensitivity
Internal operational value; restricted to internal components and operators.
INTERNAL_FAILURE - Enum constant in enum class zeroecho.pki.application.PkiOperationFailure
An unexpected implementation defect prevented a safe result.
interoperability() - Method in record class zeroecho.pki.api.algorithm.X509AlgorithmBinding
Returns the value of the interoperability record component.
IP_ADDRESS - Enum constant in enum class zeroecho.pki.api.profile.SubjectAlternativeNameType
Raw IPv4 or IPv6 address.
IpAddress(byte[]) - Constructor for record class zeroecho.pki.api.request.SubjectAlternativeName.IpAddress
Defensively snapshots and validates the address.
IPV4_OCTET_COUNT - Static variable in interface zeroecho.pki.api.request.SubjectAlternativeName
IPv4 octet count.
isBoundTo(PkiId, Principal) - Method in class zeroecho.pki.impl.core.async.PkiSigningBus.SignContinuation
Tests whether this continuation is bound to the durable operation identity.
isExpiredAt(Instant) - Method in record class zeroecho.pki.api.orch.WorkflowStateRecord
Returns whether the record is expired at the provided time.
issuance() - Method in interface zeroecho.pki.application.PkiSession
 
issuanceChainPathId() - Method in record class zeroecho.pki.api.ca.CaRecord
Returns the value of the issuanceChainPathId record component.
issuanceId() - Method in record class zeroecho.pki.api.issuance.IssuanceIntent
Returns the value of the issuanceId record component.
IssuanceInputs - Record Class in zeroecho.pki.api.issuance
Normalized inputs for issuance policy evaluation.
IssuanceInputs(PkiId, ParsedCertificationRequest, String, AttributeSet) - Constructor for record class zeroecho.pki.api.issuance.IssuanceInputs
Creates issuance inputs for policy evaluation.
issuanceIntent() - Method in record class zeroecho.pki.api.issuance.IssueEndEntityCommand
Returns the value of the issuanceIntent record component.
IssuanceIntent - Record Class in zeroecho.pki.api.issuance
Durable idempotency and frozen-selection authority for one issuance request.
IssuanceIntent(String, String, CertificateProfileRef, PkiId, PkiId, String) - Constructor for record class zeroecho.pki.api.issuance.IssuanceIntent
Validates the transport-neutral frozen issuance authority.
issuanceRecordId() - Method in record class zeroecho.pki.api.issuance.ReissueCommand
Returns the value of the issuanceRecordId record component.
IssuanceService - Interface in zeroecho.pki.api
Issues, renews, replaces, and reissues credentials, and builds distributable bundles.
ISSUE_INTERMEDIATE - Enum constant in enum class zeroecho.pki.impl.core.ValidatedCaCertificateRequest.Operation
Issues an additional intermediate CA credential.
IssueCredential(PkiId, PkiId, String) - Constructor for record class zeroecho.pki.application.PkiOperation.IssueCredential
Validates the issuance input.
ISSUED - Enum constant in enum class zeroecho.pki.api.credential.CredentialStatus
Credential is issued and not revoked.
issuedAfter() - Method in record class zeroecho.pki.api.transfer.ExportQuery
Returns the value of the issuedAfter record component.
issuedBefore() - Method in record class zeroecho.pki.api.transfer.ExportQuery
Returns the value of the issuedBefore record component.
issueEndEntity(IssueEndEntityCommand) - Method in interface zeroecho.pki.api.IssuanceService
Issues a new end-entity credential.
issueEndEntity(IssueEndEntityCommand) - Method in class zeroecho.pki.impl.core.DefaultIssuanceService
Issues a new end-entity credential and returns the resulting runtime bundle.
issueEndEntity(ValidatedCertificateRequest, DurableContentReference, KeyRef, BigInteger) - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialIssuerBackend
Issues an end-entity X.509 certificate and returns it as a credential bundle.
issueEndEntity(ValidatedCertificateRequest, DurableContentReference, KeyRef, BigInteger) - Method in interface zeroecho.pki.spi.framework.CredentialIssuerBackend
Issues an end-entity credential.
IssueEndEntityCommand - Record Class in zeroecho.pki.api.issuance
Command to issue an end-entity credential from a parsed certification request.
IssueEndEntityCommand(PkiId, ParsedCertificationRequest, String, Optional<Validity>) - Constructor for record class zeroecho.pki.api.issuance.IssueEndEntityCommand
Creates an ordinary non-correlated administrative issuance command.
IssueEndEntityCommand(PkiId, ParsedCertificationRequest, String, Optional<Validity>, Optional<IssuanceIntent>) - Constructor for record class zeroecho.pki.api.issuance.IssueEndEntityCommand
Creates an issuance command.
issueIntermediateCertificate(IntermediateCertIssueCommand) - Method in interface zeroecho.pki.api.CaService
Issues a new CA credential for an existing intermediate CA entity.
issueIntermediateCertificate(IntermediateCertIssueCommand) - Method in class zeroecho.pki.impl.core.DefaultCaService
Issues an additional intermediate CA certificate for an existing CA subject.
issueIntermediateCertificate(ValidatedCaCertificateRequest, DurableContentReference, KeyRef) - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialIssuerBackend
Issues an intermediate CA X.509 certificate.
issueIntermediateCertificate(ValidatedCaCertificateRequest, DurableContentReference, KeyRef) - Method in interface zeroecho.pki.spi.framework.CredentialIssuerBackend
Issues a CA credential for an existing CA subject entity.
issuer(PkiId) - Method in interface zeroecho.pki.application.PkiRepository
Returns an exact issuer generation.
ISSUER_CERT_DER - Static variable in class zeroecho.pki.impl.framework.x509.bc.BcX509Attributes
Attribute identifier for a DER-encoded issuer X.509 certificate.
ISSUER_KEYREF - Static variable in class zeroecho.pki.impl.framework.x509.bc.BcX509Attributes
Attribute identifier for the issuer signing key reference.
issuerCaId() - Method in record class zeroecho.pki.api.ca.CaKeyRotationCommand
Returns the value of the issuerCaId record component.
issuerCaId() - Method in record class zeroecho.pki.api.ca.CaRolloverCommand
Returns the value of the issuerCaId record component.
issuerCaId() - Method in record class zeroecho.pki.api.ca.IntermediateCertIssueCommand
Returns the value of the issuerCaId record component.
issuerCaId() - Method in record class zeroecho.pki.api.ca.IntermediateCreateCommand
Returns the value of the issuerCaId record component.
issuerCaId() - Method in record class zeroecho.pki.api.credential.CredentialQuery
Returns the value of the issuerCaId record component.
issuerCaId() - Method in record class zeroecho.pki.api.issuance.IssuanceInputs
Returns the value of the issuerCaId record component.
issuerCaId() - Method in record class zeroecho.pki.api.issuance.IssueEndEntityCommand
Returns the value of the issuerCaId record component.
issuerCaId() - Method in record class zeroecho.pki.api.revocation.RevocationQuery
Returns the value of the issuerCaId record component.
issuerCaId() - Method in record class zeroecho.pki.api.status.StatusObject
Returns the value of the issuerCaId record component.
issuerCaId() - Method in record class zeroecho.pki.api.status.StatusObjectGenerateCommand
Returns the value of the issuerCaId record component.
issuerCaId() - Method in record class zeroecho.pki.api.status.StatusObjectQuery
Returns the value of the issuerCaId record component.
issuerCaId() - Method in record class zeroecho.pki.api.transfer.ExportQuery
Returns the value of the issuerCaId record component.
issuerCaId() - Method in record class zeroecho.pki.application.PkiOperation.GenerateStatus
Returns the value of the issuerCaId record component.
issuerCaId() - Method in record class zeroecho.pki.application.PkiOperation.IssueCredential
Returns the value of the issuerCaId record component.
issuerCaId() - Method in record class zeroecho.pki.application.PkiOperation.ListStatus
Returns the value of the issuerCaId record component.
issuerCaId() - Method in class zeroecho.pki.impl.core.ValidatedCaCertificateRequest
Returns the issuing CA identifier.
issuerCaId() - Method in class zeroecho.pki.impl.core.ValidatedCertificateRequest
 
issuerCaId() - Method in class zeroecho.pki.impl.core.VerifiedIssuanceCandidate
Returns the store-authoritative issuing CA identifier.
IssuerChainPath - Record Class in zeroecho.pki.api.ca
Immutable explicitly ordered issuer chain from selected issuer certificate to its trust-anchor certificate.
IssuerChainPath(PkiId, PkiId, PkiId, List<PkiId>, String) - Constructor for record class zeroecho.pki.api.ca.IssuerChainPath
Creates and validates an immutable chain path.
issuerCredentialId() - Method in record class zeroecho.pki.application.OcspResponseService.Command
Returns the value of the issuerCredentialId record component.
IssuerGeneration - Record Class in zeroecho.pki.api.ca
Immutable authority record for one concrete CA issuer generation.
IssuerGeneration(PkiId, PkiId, PkiId, KeyRef, IssuerGenerationState, String, String) - Constructor for record class zeroecho.pki.api.ca.IssuerGeneration
Creates a validated issuer generation.
IssuerGenerationState - Enum Class in zeroecho.pki.api.ca
Durable lifecycle state of one concrete CA issuer generation.
issuerId() - Method in record class zeroecho.pki.api.ca.IssuerChainPath
Returns the value of the issuerId record component.
issuerId() - Method in record class zeroecho.pki.api.ca.IssuerGeneration
Returns the value of the issuerId record component.
issuerId() - Method in record class zeroecho.pki.api.IssuerRef
Returns the value of the issuerId record component.
issuerId() - Method in record class zeroecho.pki.application.OcspResponseService.Command
Returns the value of the issuerId record component.
issuerIds() - Method in record class zeroecho.pki.api.ca.CaRecord
Returns the value of the issuerIds record component.
issuerKeyHash() - Method in record class zeroecho.pki.application.OcspResponseService.CertId
Returns the value of the issuerKeyHash record component.
issuerKeyRef() - Method in record class zeroecho.pki.api.ca.CaRecord
Returns the value of the issuerKeyRef record component.
issuerLength() - Method in record class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectLayout
Returns the value of the issuerLength record component.
issuerNameHash() - Method in record class zeroecho.pki.application.OcspResponseService.CertId
Returns the value of the issuerNameHash record component.
issuerOffset() - Method in record class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectLayout
Returns the value of the issuerOffset record component.
issuerRef() - Method in record class zeroecho.pki.api.credential.Credential
Returns the value of the issuerRef record component.
IssuerRef - Record Class in zeroecho.pki.api
References the exact issuer generation that produced a credential.
IssuerRef(PkiId) - Constructor for record class zeroecho.pki.api.IssuerRef
Creates a transient unresolved reference used only at framework adapter boundaries.
IssuerRef(PkiId, PkiId, PkiId) - Constructor for record class zeroecho.pki.api.IssuerRef
Creates an issuer reference.
issues() - Method in record class zeroecho.pki.api.backup.BackupVerificationReport
Returns the value of the issues record component.
isTerminal() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.OperationStatus
Indicates whether this status represents a terminal lifecycle state.
isTerminal() - Method in record class zeroecho.pki.util.async.AsyncStatus
Returns whether this status is terminal.
isWithin(String, String) - Static method in class zeroecho.pki.impl.framework.x509.ImmutableX509AlgorithmBindingRegistry
Tests whether one OID is strictly below or exactly at an authorized root.

K

key() - Method in record class zeroecho.pki.spi.store.MetadataKey
Returns the value of the key record component.
key() - Method in interface zeroecho.pki.spi.store.MetadataSnapshot.Record
Returns the semantic record identity.
KEY_AGREEMENT - Enum constant in enum class zeroecho.pki.api.profile.LeafKeyUsage
keyAgreement.
KEY_CERT_SIGN - Enum constant in enum class zeroecho.pki.api.profile.CaKeyUsage
keyCertSign.
KEY_COMPROMISE - Enum constant in enum class zeroecho.pki.api.revocation.RevocationReason
Subject private key is compromised.
KEY_ENCIPHERMENT - Enum constant in enum class zeroecho.pki.api.profile.LeafKeyUsage
keyEncipherment.
KEY_INFO - Enum constant in enum class zeroecho.pki.api.attr.AttributeValueType
Public key information representation (e.g., SPKI).
KEY_LOG_PATH - Static variable in class zeroecho.pki.impl.async.FileBackedAsyncBusProvider
Configuration key for the log file path.
Key abstractions - Search tag in package zeroecho.pki.api.orch
Section
Key entry points - Search tag in package zeroecho.pki.api
Section
KeyRange(String, Optional<String>, Optional<String>) - Constructor for record class zeroecho.pki.spi.store.MetadataSnapshot.KeyRange
Creates a validated range.
keyRef() - Method in record class zeroecho.pki.api.ca.CaCreateCommand
Returns the value of the keyRef record component.
keyRef() - Method in record class zeroecho.pki.api.ca.CaImportCommand
Returns the value of the keyRef record component.
keyRef() - Method in record class zeroecho.pki.api.ca.IntermediateCreateCommand
Returns the value of the keyRef record component.
keyRef() - Method in record class zeroecho.pki.application.PkiOperation.CreateAuthority
Returns the value of the keyRef record component.
keyRef() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.SignRequest
Returns the value of the keyRef record component.
KeyRef - Record Class in zeroecho.pki.api
Opaque reference to private key material.
KeyRef(String) - Constructor for record class zeroecho.pki.api.KeyRef
Creates a key reference.
Key reference handling - Search tag in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
Section
KeyRef mapping - Search tag in package zeroecho.pki.impl.crypto.zeroecholib
Section
keyringUnlockProvider() - Method in record class zeroecho.pki.application.PkiSessionRuntimeDependencies
Returns the value of the keyringUnlockProvider record component.
keyringUnlockProvider() - Method in class zeroecho.pki.spi.crypto.SignatureWorkflowRuntimeDependencies
Returns the explicitly supplied software-keyring unlock provider.
keyUsageCritical() - Method in record class zeroecho.pki.api.profile.CaCertificatePolicy
Returns the value of the keyUsageCritical record component.
keyUsageCritical() - Method in record class zeroecho.pki.api.profile.LeafCertificatePolicy
Returns the value of the keyUsageCritical record component.
keyUsageCritical() - Method in class zeroecho.pki.impl.core.ValidatedCertificateRequest
 
keyUsages() - Method in record class zeroecho.pki.api.profile.CaCertificatePolicy
Returns the value of the keyUsages record component.
keyUsages() - Method in record class zeroecho.pki.api.profile.LeafCertificatePolicy
Returns the value of the keyUsages record component.
keyUsages() - Method in class zeroecho.pki.impl.core.ValidatedCertificateRequest
 
kind() - Method in record class zeroecho.pki.api.ca.CaQuery
Returns the value of the kind record component.
kind() - Method in record class zeroecho.pki.api.ca.CaRecord
Returns the value of the kind record component.
kind() - Method in record class zeroecho.pki.impl.framework.x509.X509ComponentCatalog.Component
Returns the value of the kind record component.
KNOWN_LENGTH_ONLY - Enum constant in enum class zeroecho.pki.spi.store.MetadataStoreCapabilities.ContentLengthModel
Every admitted value must declare its exact length.
KNOWN_OR_UNKNOWN_LENGTH - Enum constant in enum class zeroecho.pki.spi.store.MetadataStoreCapabilities.ContentLengthModel
Known and initially unknown lengths can be staged safely.

L

label() - Method in record class zeroecho.pki.api.backup.BackupRequest
Returns the value of the label record component.
layout() - Method in record class zeroecho.pki.impl.framework.x509.bc.BcX509SignedObjectValidator.CertificateBindings
Returns the value of the layout record component.
LDAP - Enum constant in enum class zeroecho.pki.api.attr.AttributeExportTarget
Export to LDAP directory.
LDAP - Enum constant in enum class zeroecho.pki.api.publication.PublicationTargetType
Publish to an LDAP directory.
LeafCertificatePolicy - Record Class in zeroecho.pki.api.profile
Complete issuer-controlled leaf certificate extension and identity policy.
LeafCertificatePolicy(SubjectAlternativeNamePolicy, Set<LeafKeyUsage>, Set<ExtendedKeyUsageId>, boolean, boolean, boolean, Set<String>) - Constructor for record class zeroecho.pki.api.profile.LeafCertificatePolicy
Validates and constructs the policy.
LeafKeyUsage - Enum Class in zeroecho.pki.api.profile
Closed X.509 key-usage bit set available to leaf certificate profiles.
leafPolicy() - Method in record class zeroecho.pki.api.profile.CertificateProfile
Returns the value of the leafPolicy record component.
leafPolicy() - Method in record class zeroecho.pki.api.profile.CertificateProfileDefinition
Returns the end-entity policy.
leaseUntil() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Returns the value of the leaseUntil record component.
length() - Method in interface zeroecho.pki.api.content.DurableContentReference
Returns the exact checked byte length.
length() - Method in class zeroecho.pki.application.PkiRepositoryContent
 
length() - Method in record class zeroecho.pki.spi.publish.PublicationAttempt
Returns the value of the length record component.
length() - Method in interface zeroecho.pki.spi.store.ContentSink
Returns the bytes accepted so far.
lifecycle() - Method in interface zeroecho.pki.api.content.DurableContentReference
Returns the immutable content purpose classification.
Lifecycle and ownership - Search tag in class zeroecho.pki.impl.framework.x509.bc.PkiBusContentSigner
Section
Lifecycle semantics - Search tag in class zeroecho.pki.util.async.impl.DurableAsyncBus
Section
limit() - Method in record class zeroecho.pki.application.PkiOperation.ListAlgorithmBindings
Returns the value of the limit record component.
limit() - Method in record class zeroecho.pki.application.PkiOperation.ListAuthorities
Returns the value of the limit record component.
limit() - Method in record class zeroecho.pki.application.PkiOperation.ListPublications
Returns the value of the limit record component.
limit() - Method in record class zeroecho.pki.application.PkiOperation.ListStatus
Returns the value of the limit record component.
limit() - Method in record class zeroecho.pki.application.PkiOperation.ReadRevocationHistory
Returns the value of the limit record component.
limit() - Method in record class zeroecho.pki.application.PkiOperation.SnapshotRevocations
Returns the value of the limit record component.
LIMIT_EXCEEDED - Enum constant in enum class zeroecho.pki.spi.store.MetadataCommitResult.FailureCategory
Adapter technical representability limit was exceeded.
LimitedTo(long) - Constructor for record class zeroecho.pki.api.content.ResourceLimit.LimitedTo
Creates a finite limit.
list(StatusObjectQuery) - Method in interface zeroecho.pki.api.StatusObjectService
Lists status objects matching query constraints.
list(StatusObjectQuery) - Method in class zeroecho.pki.impl.core.DefaultStatusObjectService
Lists status objects for one issuer CA filtered by the supplied query constraints.
ListAlgorithmBindings(Optional<String>, Optional<String>, int) - Constructor for record class zeroecho.pki.application.PkiOperation.ListAlgorithmBindings
Validates immutable filters and the presentation limit.
listAll() - Method in interface zeroecho.pki.api.attr.AttributeCatalogue
Lists all known definitions.
ListAuthorities(int) - Constructor for record class zeroecho.pki.application.PkiOperation.ListAuthorities
Validates the presentation limit.
listByPublicKeyId(PkiId) - Method in interface zeroecho.pki.api.CredentialInventoryService
Lists credentials bound to the same public key identifier.
listCas() - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
listCas() - Method in interface zeroecho.pki.spi.store.PkiStore
Lists all stored CA records.
listCas(CaQuery) - Method in interface zeroecho.pki.api.CaService
Lists CA records matching query constraints.
listCas(CaQuery) - Method in class zeroecho.pki.impl.core.DefaultCaService
Lists CA records matching the supplied query constraints.
listCasPage(Optional<PkiId>, int) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
listCasPage(Optional<PkiId>, int) - Method in interface zeroecho.pki.spi.store.PkiStore
Returns a bounded canonical keyset page of CA records.
listImportedVersions(String) - Method in interface zeroecho.pki.api.ProfileService
Lists immutable imported versions for one logical profile.
listImportedVersions(String) - Method in class zeroecho.pki.impl.core.DefaultProfileService
 
listIssuerChainPaths(PkiId) - Method in interface zeroecho.pki.api.CaService
Lists all explicit paths for an exact issuer generation.
listIssuerChainPaths(PkiId) - Method in class zeroecho.pki.impl.core.DefaultCaService
 
listIssuerChainPaths(PkiId) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
listIssuerChainPaths(PkiId) - Method in interface zeroecho.pki.spi.store.PkiStore
Lists explicit paths for an exact issuer generation.
listIssuerGenerations(PkiId) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
listIssuerGenerations(PkiId) - Method in interface zeroecho.pki.spi.store.PkiStore
Lists issuer generations owned by an exact logical authority.
listProfileVersions(String) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
listProfileVersions(String) - Method in interface zeroecho.pki.spi.store.PkiStore
Lists imported versions in ascending version order.
ListProfileVersions(String) - Constructor for record class zeroecho.pki.application.PkiOperation.ListProfileVersions
Validates the logical profile identity.
ListPublications(int) - Constructor for record class zeroecho.pki.application.PkiOperation.ListPublications
Validates the presentation limit.
listSignRecords() - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
listSignRecords() - Method in interface zeroecho.pki.spi.store.SignWorkflowStore
Returns a stable snapshot of retained signing records.
ListStatus(PkiId, int) - Constructor for record class zeroecho.pki.application.PkiOperation.ListStatus
Validates the issuer identity and presentation limit.
listStatusObjects(PkiId) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
listStatusObjects(PkiId) - Method in interface zeroecho.pki.spi.store.PkiStore
Lists status objects issued under a specific issuer CA.
ListValue(List<PkiOperationValue>) - Constructor for record class zeroecho.pki.application.PkiOperationValue.ListValue
Snapshots the list and rejects null entries.
listWorkflowStates() - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
listWorkflowStates() - Method in interface zeroecho.pki.spi.store.PkiStore
Lists workflow continuation state records.
load(ClassLoader) - Static method in class zeroecho.pki.api.profile.BuiltInCertificateProfileCatalog
Loads and validates the packaged built-in profile templates.
LOCAL_FAILURE - Enum constant in enum class zeroecho.pki.spi.store.SignWorkflowStore.ReconciliationFailureClass
Local durable reconciliation failed.
LOCALITY_NAME - Enum constant in enum class zeroecho.pki.api.profile.SubjectRdnType
X.520 locality name.
Logging - Search tag in class zeroecho.pki.impl.audit.DefaultAttributeGovernanceService
Section
Logging and sensitive data - Search tag in class zeroecho.pki.util.async.impl.DurableAsyncBus
Section
logSupportedKeys(ConfigurableProvider<T>) - Static method in class zeroecho.pki.spi.bootstrap.PkiBootstrap
Logs provider help information (supported keys) for diagnostics.
Lookup semantics - Search tag in class zeroecho.pki.impl.framework.x509.bc.SimpleAttributeSet
Section
Lookup semantics - Search tag in record class zeroecho.pki.impl.core.attr.SimpleAttributeSet
Section
lowerInclusive() - Method in record class zeroecho.pki.spi.store.MetadataSnapshot.KeyRange
Returns the value of the lowerInclusive record component.

M

main(String[]) - Static method in class zeroecho.pki.PkiApplication
Starts the PKI process.
MANIFEST_RESOURCE - Static variable in class zeroecho.pki.api.profile.BuiltInCertificateProfileCatalog
Fixed packaged catalogue manifest resource.
MASK_GENERATION - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509ComponentCatalog.Kind
Mask-generation AlgorithmIdentifier component.
matches(AuditQuery) - Method in record class zeroecho.pki.api.audit.AuditEvent
Evaluates whether this event matches a query constraint set.
matchesLeafExtensions(X509CertificateHolder, ValidatedCertificateRequest) - Static method in class zeroecho.pki.impl.framework.x509.bc.BcX509ProfileSupport
Verifies the complete allowed leaf extension set and exact values.
MAX_CERTIFICATES - Static variable in record class zeroecho.pki.api.ca.IssuerChainPath
Maximum supported certificates in one explicit PKI path.
maxEvents() - Method in class zeroecho.pki.impl.audit.InMemoryAuditSink
Returns the configured maximum number of retained events.
maximum() - Method in record class zeroecho.pki.api.content.ResourceLimit.LimitedTo
Returns the value of the maximum record component.
maximum() - Method in record class zeroecho.pki.api.profile.SubjectAlternativeNameRule
Returns the value of the maximum record component.
MAXIMUM_BYTES - Static variable in record class zeroecho.pki.api.request.SubjectAlternativeName.DnsName
Maximum encoded DNS name length.
MAXIMUM_BYTES - Static variable in record class zeroecho.pki.api.request.SubjectAlternativeName.Rfc822Name
Maximum encoded mailbox length.
MAXIMUM_BYTES - Static variable in record class zeroecho.pki.api.request.SubjectAlternativeName.UriName
Maximum encoded URI length.
MAXIMUM_DOCUMENT_BYTES - Static variable in class zeroecho.pki.api.profile.CertificateProfileDocumentCodec
Maximum accepted encoded document size.
MAXIMUM_IPV4_OCTET - Static variable in interface zeroecho.pki.api.request.SubjectAlternativeName
Maximum IPv4 octet value.
MAXIMUM_KEY_UTF8_BYTES - Static variable in record class zeroecho.pki.spi.store.MetadataKey
Maximum exact logical-key length in UTF-8 bytes.
MAXIMUM_NAMESPACE_UTF8_BYTES - Static variable in record class zeroecho.pki.spi.store.MetadataKey
Maximum canonical namespace length in UTF-8 bytes.
MAXIMUM_PATH_LENGTH - Static variable in record class zeroecho.pki.api.profile.CaCertificatePolicy
Maximum supported path-length constraint.
MAXIMUM_RESULT_ENTRIES - Static variable in interface zeroecho.pki.application.PkiOperation
Maximum finite entries returned by one presentation operation.
MAXIMUM_RESULT_ENTRIES - Static variable in record class zeroecho.pki.application.PkiOperation.ReadRevocationHistory
Maximum finite result entries for one invocation.
maximumIndividualRecordBytes() - Method in record class zeroecho.pki.spi.store.MetadataStoreCapabilities
Returns the value of the maximumIndividualRecordBytes record component.
maximumOccurrences() - Method in record class zeroecho.pki.api.profile.SubjectRdnRule
Returns the value of the maximumOccurrences record component.
maximumProviderCalls() - Method in record class zeroecho.pki.application.SigningReconciliationRequest
Returns the value of the maximumProviderCalls record component.
maximumRecords() - Method in record class zeroecho.pki.application.SigningReconciliationRequest
Returns the value of the maximumRecords record component.
maximumTotal() - Method in record class zeroecho.pki.api.profile.SubjectAlternativeNamePolicy
Returns the value of the maximumTotal record component.
maximumUtf8Bytes() - Method in record class zeroecho.pki.api.profile.SubjectRdnRule
Returns the value of the maximumUtf8Bytes record component.
maximumValidity() - Method in record class zeroecho.pki.api.profile.CertificateProfile
Returns the value of the maximumValidity record component.
maximumValidity() - Method in record class zeroecho.pki.api.profile.CertificateProfileDefinition
Returns the value of the maximumValidity record component.
Memory bound - Search tag in class zeroecho.pki.impl.audit.InMemoryAuditSink
Section
merge(List<X509BindingCatalog>) - Method in class zeroecho.pki.impl.framework.x509.X509BindingCatalog
Produces a new immutable additive snapshot.
merge(List<X509ComponentCatalog>) - Method in class zeroecho.pki.impl.framework.x509.X509ComponentCatalog
Produces a new immutable additive snapshot.
messages() - Method in record class zeroecho.pki.api.policy.PolicyDecision
Returns the value of the messages record component.
meta() - Method in record class zeroecho.pki.api.attr.AttributeDefinition
Returns the value of the meta record component.
MetadataCommitResult - Record Class in zeroecho.pki.spi.store
Immutable immediate or resolved metadata-transaction result.
MetadataCommitResult(MetadataTransactionId, MetadataCommitResult.Outcome, OptionalLong, Optional<MetadataCommitResult.FailureCategory>) - Constructor for record class zeroecho.pki.spi.store.MetadataCommitResult
Validates result invariants and checked revision semantics.
MetadataCommitResult.FailureCategory - Enum Class in zeroecho.pki.spi.store
Stable non-sensitive metadata failure categories.
MetadataCommitResult.Outcome - Enum Class in zeroecho.pki.spi.store
Closed commit-outcome model.
MetadataCursor - Interface in zeroecho.pki.spi.store
A closeable, snapshot-consistent streaming metadata cursor.
MetadataKey - Record Class in zeroecho.pki.spi.store
Immutable provider-neutral identity of one metadata record.
MetadataKey(String, String) - Constructor for record class zeroecho.pki.spi.store.MetadataKey
Validates both identity components.
MetadataSnapshot - Interface in zeroecho.pki.spi.store
An immutable, store-issued view of one committed metadata revision.
MetadataSnapshot.Integrity - Record Class in zeroecho.pki.spi.store
Stable content-integrity metadata without payload or storage details.
MetadataSnapshot.KeyRange - Record Class in zeroecho.pki.spi.store
An ordered range within one semantic namespace.
MetadataSnapshot.Record - Interface in zeroecho.pki.spi.store
A repeatable record view owned by a snapshot.
MetadataStoreCapabilities - Record Class in zeroecho.pki.spi.store
Immutable adapter capability declaration.
MetadataStoreCapabilities(MetadataStoreCapabilities.WriterModel, MetadataStoreCapabilities.ContentLengthModel, MetadataStoreCapabilities.OutcomeRetention, Set<MetadataStoreCapabilities.OptionalFeature>, OptionalLong) - Constructor for record class zeroecho.pki.spi.store.MetadataStoreCapabilities
Validates and defensively copies capability values.
MetadataStoreCapabilities.ContentLengthModel - Enum Class in zeroecho.pki.spi.store
Accepted repeatable-content length forms.
MetadataStoreCapabilities.OptionalFeature - Enum Class in zeroecho.pki.spi.store
Optional facilities that do not weaken required store semantics.
MetadataStoreCapabilities.OutcomeRetention - Enum Class in zeroecho.pki.spi.store
Authoritative transaction-outcome retention model.
MetadataStoreCapabilities.WriterModel - Enum Class in zeroecho.pki.spi.store
Adapter writer-concurrency model.
MetadataStoreException - Exception Class in zeroecho.pki.spi.store
Checked metadata-store failure carrying a stable, non-sensitive category.
MetadataStoreException(MetadataCommitResult.FailureCategory, String) - Constructor for exception class zeroecho.pki.spi.store.MetadataStoreException
Creates a categorized failure.
MetadataStoreException(MetadataCommitResult.FailureCategory, String, Throwable) - Constructor for exception class zeroecho.pki.spi.store.MetadataStoreException
Creates a categorized failure retaining its cause.
MetadataStoreId - Record Class in zeroecho.pki.spi.store
Stable provider-neutral metadata-store identity.
MetadataStoreId(String) - Constructor for record class zeroecho.pki.spi.store.MetadataStoreId
Validates the canonical identity.
MetadataTransaction - Interface in zeroecho.pki.spi.store
A single-use, store-issued metadata transaction.
MetadataTransactionId - Record Class in zeroecho.pki.spi.store
Canonical durable transaction identity issued by one metadata store.
MetadataTransactionId(MetadataStoreId, String) - Constructor for record class zeroecho.pki.spi.store.MetadataTransactionId
Validates the canonical identity components.
minimum() - Method in record class zeroecho.pki.api.profile.SubjectAlternativeNameRule
Returns the value of the minimum record component.
minimumOccurrences() - Method in record class zeroecho.pki.api.profile.SubjectRdnRule
Returns the value of the minimumOccurrences record component.
minimumTotal() - Method in record class zeroecho.pki.api.profile.SubjectAlternativeNamePolicy
Returns the value of the minimumTotal record component.
mode() - Method in record class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy
Returns the value of the mode record component.
multiValued() - Method in record class zeroecho.pki.api.attr.AttributeDefinition
Returns the value of the multiValued record component.

N

name() - Method in record class zeroecho.pki.api.audit.Principal
Returns the value of the name record component.
name() - Method in record class zeroecho.pki.application.PkiOperation.ActivateProfile
 
name() - Method in record class zeroecho.pki.application.PkiOperation.CreateAuthority
 
name() - Method in record class zeroecho.pki.application.PkiOperation.GenerateStatus
 
name() - Method in record class zeroecho.pki.application.PkiOperation.ImportRequest
 
name() - Method in record class zeroecho.pki.application.PkiOperation.InspectAlgorithmBinding
 
name() - Method in record class zeroecho.pki.application.PkiOperation.InspectAuthority
 
name() - Method in record class zeroecho.pki.application.PkiOperation.InspectCredential
 
name() - Method in record class zeroecho.pki.application.PkiOperation.InspectProfile
 
name() - Method in record class zeroecho.pki.application.PkiOperation.InspectPublication
 
name() - Method in record class zeroecho.pki.application.PkiOperation.InspectRequest
 
name() - Method in record class zeroecho.pki.application.PkiOperation.InspectRevocation
 
name() - Method in record class zeroecho.pki.application.PkiOperation.InspectStatus
 
name() - Method in record class zeroecho.pki.application.PkiOperation.IssueCredential
 
name() - Method in record class zeroecho.pki.application.PkiOperation.ListAlgorithmBindings
 
name() - Method in record class zeroecho.pki.application.PkiOperation.ListAuthorities
 
name() - Method in record class zeroecho.pki.application.PkiOperation.ListProfileVersions
 
name() - Method in record class zeroecho.pki.application.PkiOperation.ListPublications
 
name() - Method in record class zeroecho.pki.application.PkiOperation.ListStatus
 
name() - Method in interface zeroecho.pki.application.PkiOperation
 
name() - Method in record class zeroecho.pki.application.PkiOperation.ProcessPublication
 
name() - Method in record class zeroecho.pki.application.PkiOperation.ReadRevocationHistory
 
name() - Method in record class zeroecho.pki.application.PkiOperation.ReconcilePublication
 
name() - Method in record class zeroecho.pki.application.PkiOperation.RegisterProfile
 
name() - Method in record class zeroecho.pki.application.PkiOperation.RegisterPublication
 
name() - Method in record class zeroecho.pki.application.PkiOperation.RetryPublication
 
name() - Method in record class zeroecho.pki.application.PkiOperation.RevokeCredential
 
name() - Method in record class zeroecho.pki.application.PkiOperation.SnapshotRevocations
 
name() - Method in record class zeroecho.pki.application.PkiOperation.TransitionAuthority
 
name() - Method in record class zeroecho.pki.application.PkiOperation.ValidateAlgorithmBindings
 
name() - Method in record class zeroecho.pki.application.PkiOperation.ValidateConfiguration
 
name() - Method in record class zeroecho.pki.application.PkiOperation.ValidateProfile
 
name() - Method in record class zeroecho.pki.application.PkiOperation.VerifyRequest
 
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.ActivateProfile
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.CreateAuthority
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.GenerateStatus
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.ImportRequest
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.InspectAlgorithmBinding
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.InspectAuthority
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.InspectCredential
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.InspectProfile
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.InspectPublication
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.InspectRequest
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.InspectRevocation
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.InspectStatus
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.IssueCredential
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.ListAlgorithmBindings
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.ListAuthorities
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.ListProfileVersions
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.ListPublications
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.ListStatus
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.ProcessPublication
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.ReadRevocationHistory
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.ReconcilePublication
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.RegisterProfile
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.RegisterPublication
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.RetryPublication
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.RevokeCredential
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.SnapshotRevocations
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.TransitionAuthority
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.ValidateAlgorithmBindings
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.ValidateConfiguration
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.ValidateProfile
Stable operation name.
NAME - Static variable in record class zeroecho.pki.application.PkiOperation.VerifyRequest
Stable operation name.
NAMED_CURVE - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509ComponentCatalog.Kind
Named-curve OBJECT IDENTIFIER component.
namespace() - Method in record class zeroecho.pki.api.orch.SigningSubmissionId
Returns the value of the namespace record component.
namespace() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.SignRequest
Returns the value of the namespace record component.
namespace() - Method in record class zeroecho.pki.spi.store.MetadataKey
Returns the value of the namespace record component.
namespace() - Method in record class zeroecho.pki.spi.store.MetadataSnapshot.KeyRange
Returns the value of the namespace record component.
namespace() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Returns the value of the namespace record component.
NESTED_SPKI_DER - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.PublicKeyEncoding
Canonical native SPKI DER nested as the BIT STRING payload.
NESTED_SPKI_DER - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509BindingRule.PublicKeyEncoding
Canonical native SubjectPublicKeyInfo DER nested in the BIT STRING.
newKeyRef() - Method in record class zeroecho.pki.api.ca.CaKeyRotationCommand
Returns the value of the newKeyRef record component.
newRandomId() - Static method in class zeroecho.pki.util.PkiIds
Generates a new random PKI identifier.
newRequest() - Method in record class zeroecho.pki.api.issuance.ReplaceCommand
Returns the value of the newRequest record component.
newSubmissionId() - Method in class zeroecho.pki.impl.core.async.PkiSigningBus
Creates a stable provider-namespaced signing submission identifier.
next() - Method in interface zeroecho.pki.spi.framework.CrlEntrySource.Cursor
Advances the cursor.
next() - Method in interface zeroecho.pki.spi.store.RevocationHistory
Advances without external cancellation.
next() - Method in interface zeroecho.pki.spi.store.RevocationSnapshot.Cursor
Advances to the next current state.
next(CancellationSignal) - Method in interface zeroecho.pki.api.publication.PublicationCursor
Advances by at most one matching record.
next(CancellationSignal) - Method in interface zeroecho.pki.spi.store.MetadataCursor
Advances the cursor by at most one record.
next(CancellationSignal) - Method in interface zeroecho.pki.spi.store.RevocationHistory
Advances to the next transition.
next(CancellationSignal) - Method in interface zeroecho.pki.spi.store.RevocationSnapshot.Cursor
Advances with cancellation.
nextCursor() - Method in record class zeroecho.pki.application.SigningReconciliationResult
Returns the value of the nextCursor record component.
nextCursor() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Page
Returns the value of the nextCursor record component.
nextEligibleAt() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Returns the value of the nextEligibleAt record component.
nextUpdate() - Method in record class zeroecho.pki.api.status.StatusObject
Returns the value of the nextUpdate record component.
nextUpdate() - Method in record class zeroecho.pki.application.OcspResponseService.Command
Returns the value of the nextUpdate record component.
nextUpdate() - Method in record class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectLayout
Returns the value of the nextUpdate record component.
NO_BINDING - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Failure
No authoritative X.509 binding exists.
NO_CAPABILITY - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Failure
No installed implementation supports the tuple.
NO_EXECUTOR - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Failure
Semantic capability has no process-local executor binding.
nonce() - Method in record class zeroecho.pki.application.OcspResponseService.Command
Returns the value of the nonce record component.
none() - Static method in record class zeroecho.pki.application.PkiSessionRuntimeDependencies
 
none() - Static method in class zeroecho.pki.spi.crypto.SignatureWorkflowRuntimeDependencies
Returns dependencies without a software-keyring unlock provider.
none() - Static method in interface zeroecho.pki.util.async.codec.ResultCodec
Convenience: a codec that never persists any result.
normalize(AttributeSet) - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509FrameworkAttributeMapper
Normalizes the supplied framework attribute set.
normalize(AttributeSet) - Method in interface zeroecho.pki.spi.framework.FrameworkAttributeMapper
Normalizes and validates universal attributes for framework consumption.
NOT_APPLICABLE - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.PublicKeyEncoding
This binding is not an SPKI binding.
NOT_APPLICABLE - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.SignatureEncoding
This binding is not a signature binding.
NOT_APPLICABLE - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509BindingRule.PublicKeyEncoding
Not applicable to a signature-only rule.
NOT_APPLICABLE - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509BindingRule.SignatureEncoding
Not applicable to a public-key-only rule.
NOT_COMMITTED - Enum constant in enum class zeroecho.pki.spi.store.MetadataCommitResult.Outcome
No mutation from the transaction became committed.
NOT_FOUND - Enum constant in enum class zeroecho.pki.application.PkiOperationFailure
The selected authoritative object does not exist.
NOT_PRESENT - Enum constant in enum class zeroecho.pki.api.request.ProofOfPossessionStatus
Proof-of-possession evidence is not present.
NOT_SUPPORTED - Enum constant in enum class zeroecho.pki.api.request.ProofOfPossessionStatus
Proof-of-possession verification is not supported for the given request type or framework.
NOT_USABLE_CODE - Static variable in class zeroecho.pki.impl.core.StoreBackedEffectiveCredentialStatusResolver
Stable unusable-credential failure code.
NOT_YET_VALID - Enum constant in enum class zeroecho.pki.api.credential.EffectiveCredentialStatus
The credential validity interval has not started.
notAfter() - Method in record class zeroecho.pki.api.Validity
Returns the value of the notAfter record component.
notBefore() - Method in record class zeroecho.pki.api.Validity
Returns the value of the notBefore record component.
notes() - Method in record class zeroecho.pki.api.attr.AttributeMeta
Returns the value of the notes record component.
notes() - Method in record class zeroecho.pki.api.policy.PolicyTraceStep
Returns the value of the notes record component.
Notes - Search tag in package zeroecho.pki.api.credential
Section
Null and unsupported handling - Search tag in class zeroecho.pki.impl.framework.x509.bc.OidAlgorithmMapper
Section

O

OBJECT_STORE - Enum constant in enum class zeroecho.pki.api.publication.PublicationTargetType
Publish to an object store (S3-like).
objectId() - Method in record class zeroecho.pki.api.audit.AccessContext
Returns the value of the objectId record component.
objectId() - Method in record class zeroecho.pki.api.audit.AuditEvent
Returns the value of the objectId record component.
objectId() - Method in record class zeroecho.pki.api.audit.AuditQuery
Returns the value of the objectId record component.
objectId() - Method in class zeroecho.pki.application.PkiRepositoryContent
 
ObjectValue(Map<String, PkiOperationValue>) - Constructor for record class zeroecho.pki.application.PkiOperationValue.ObjectValue
Validates names and snapshots insertion order.
ocsp() - Method in interface zeroecho.pki.application.PkiSession
 
OCSP - Enum constant in enum class zeroecho.pki.api.status.StatusObjectType
OCSP response or responder data (representation is implementation-defined).
OCSP_REQUEST_SIGNATURE - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.Role
Signed OCSP request signature.
OcspResponseService - Interface in zeroecho.pki.application
Transport-neutral strict OCSP response generation through confined signing.
OcspResponseService.CertId - Record Class in zeroecho.pki.application
One strictly parsed CertID.
OcspResponseService.CertIdHash - Enum Class in zeroecho.pki.application
Supported RFC CertID digest identities.
OcspResponseService.Command - Record Class in zeroecho.pki.application
Exact already-authorized responder generation command.
OcspResponseService.ResponderId - Enum Class in zeroecho.pki.application
Exact responder identifier representation.
OcspResponseService.Response - Record Class in zeroecho.pki.application
Signed canonical response and stable revocation provenance.
of(Map<AttributeId, List<AttributeValue>>) - Static method in class zeroecho.pki.impl.framework.x509.bc.SimpleAttributeSet
Creates an immutable attribute set from the supplied map.
oid() - Method in record class zeroecho.pki.api.algorithm.X509AlgorithmBinding
Returns the value of the oid record component.
oid() - Method in record class zeroecho.pki.api.profile.ExtendedKeyUsageId
Returns the value of the oid record component.
oid() - Method in enum class zeroecho.pki.api.profile.SubjectRdnType
Returns the exact ASN.1 object identifier.
oid() - Method in class zeroecho.pki.impl.framework.x509.X509AlgorithmIdentifier
Returns the OID.
oid() - Method in interface zeroecho.pki.impl.framework.x509.X509BindingRule
Returns the OID domain owned by this rule.
oid() - Method in record class zeroecho.pki.impl.framework.x509.X509ComponentCatalog.Component
Returns the value of the oid record component.
oid(X509ComponentCatalog.Kind, AlgorithmIdentity) - Method in class zeroecho.pki.impl.framework.x509.X509ComponentCatalog
Resolves the OID of an exact component identity.
OID - Enum constant in enum class zeroecho.pki.api.attr.AttributeValueType
Object identifier string.
OID_EC_PUBLIC_KEY - Static variable in class zeroecho.pki.impl.framework.x509.StandardX509Bindings
EC public-key OID.
OID_ECDSA_SHA256 - Static variable in class zeroecho.pki.impl.framework.x509.StandardX509Bindings
ECDSA SHA-256 signature OID.
OID_ECDSA_SHA384 - Static variable in class zeroecho.pki.impl.framework.x509.StandardX509Bindings
ECDSA SHA-384 signature OID.
OID_ECDSA_SHA512 - Static variable in class zeroecho.pki.impl.framework.x509.StandardX509Bindings
ECDSA SHA-512 signature OID.
OID_ED25519 - Static variable in class zeroecho.pki.impl.framework.x509.StandardX509Bindings
Ed25519 OID.
OID_ED448 - Static variable in class zeroecho.pki.impl.framework.x509.StandardX509Bindings
Ed448 OID.
OID_P256 - Static variable in class zeroecho.pki.impl.framework.x509.StandardX509Bindings
P-256 named-curve OID.
OID_P384 - Static variable in class zeroecho.pki.impl.framework.x509.StandardX509Bindings
P-384 named-curve OID.
OID_P521 - Static variable in class zeroecho.pki.impl.framework.x509.StandardX509Bindings
P-521 named-curve OID.
OID_RSA_PSS - Static variable in class zeroecho.pki.impl.framework.x509.StandardX509Bindings
RSA-PSS signature OID.
OID_RSA_PUBLIC_KEY - Static variable in class zeroecho.pki.impl.framework.x509.StandardX509Bindings
RSA public-key OID.
OID_RSA_SHA256 - Static variable in class zeroecho.pki.impl.framework.x509.StandardX509Bindings
RSA PKCS#1 SHA-256 signature OID.
OID_RSA_SHA384 - Static variable in class zeroecho.pki.impl.framework.x509.StandardX509Bindings
RSA PKCS#1 SHA-384 signature OID.
OID_RSA_SHA512 - Static variable in class zeroecho.pki.impl.framework.x509.StandardX509Bindings
RSA PKCS#1 SHA-512 signature OID.
OidAlgorithmMapper - Class in zeroecho.pki.impl.framework.x509.bc
Internal mapper from X.509 and PKCS#10 signature algorithm identifiers to ZeroEcho canonical signature algorithm ids.
ON_WRITE - Enum constant in enum class zeroecho.pki.impl.fs.FsHistoryPolicy.CleanupStrategy
Cleanup happens during write operations only.
onEvent(AsyncEvent<OpId, Owner, Eid, Result>) - Method in interface zeroecho.pki.util.async.AsyncHandler
Receives an event notification.
onStatusChanged(PkiId, SignatureWorkflow.OperationStatus) - Method in interface zeroecho.pki.spi.crypto.SignatureWorkflow.NotificationSink
Notifies about a change in operation status.
onWrite(Optional<Duration>) - Static method in class zeroecho.pki.impl.fs.FsHistoryPolicy
Creates a history policy with FsHistoryPolicy.CleanupStrategy.ON_WRITE.
OPAQUE - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.SignatureEncoding
Algorithm-defined opaque signature bytes.
OPAQUE - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509BindingRule.SignatureEncoding
Algorithm-defined opaque signature bytes.
open(Path) - Static method in class zeroecho.pki.impl.fs.PosixTransactionalMetadataStore
Opens an existing append-only store without an adapter-specific record limit.
open(Path, OptionalLong) - Static method in class zeroecho.pki.impl.fs.PosixTransactionalMetadataStore
Opens an existing append-only store.
open(PkiSessionConfiguration) - Static method in interface zeroecho.pki.application.PkiSession
Opens a production session.
open(PkiSessionConfiguration, PkiSessionRuntimeDependencies) - Static method in interface zeroecho.pki.application.PkiSession
Opens a production session with explicit process-local security capabilities.
open(PkiSessionConfiguration, PkiSessionRuntimeDependencies, Clock) - Static method in interface zeroecho.pki.application.PkiSession
Opens a production session with explicit process-local capabilities and a lifecycle clock shared by every time-dependent backend service.
openAsyncBus() - Static method in class zeroecho.pki.spi.bootstrap.PkiBootstrap
Opens an async operation bus using AsyncBusProvider discovered via ServiceLoader.
openAudit() - Static method in class zeroecho.pki.spi.bootstrap.PkiBootstrap
Opens an AuditSink using AuditSinkProvider discovered via ServiceLoader.
openAudit(ProviderConfig) - Static method in class zeroecho.pki.spi.bootstrap.PkiBootstrap
Opens an audit sink from an explicit, strictly validated configuration.
openConfiguredSignatureWorkflow(ProviderConfig, SignatureWorkflowRuntimeDependencies) - Static method in class zeroecho.pki.spi.bootstrap.PkiBootstrap
Opens one explicitly configured signature workflow with process-local key access supplied outside persistent configuration.
openContent(DurableContentReference) - Method in class zeroecho.pki.impl.core.async.PkiSigningBus
Opens immutable repeatable content owned by this runtime.
openContent(DurableContentReference) - Method in class zeroecho.pki.impl.fs.FilesystemStagedContentStore
 
openContent(DurableContentReference) - Method in interface zeroecho.pki.spi.store.StagedContentStore
Resolves a completed reference to immutable repeatable content.
openCredential(PkiId) - Method in interface zeroecho.pki.application.PkiRepository
Opens validated immutable certificate content.
openCredentialFramework() - Static method in class zeroecho.pki.spi.bootstrap.PkiBootstrap
Opens a CredentialFramework using CredentialFrameworkProvider discovered via ServiceLoader.
openCursor() - Method in interface zeroecho.pki.spi.framework.CrlEntrySource
Opens a new cursor over the same logical snapshot.
openCursor() - Method in interface zeroecho.pki.spi.store.RevocationSnapshot
Opens a new pass over the same logical snapshot.
openPublicationRecords() - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
openPublicationRecords() - Method in interface zeroecho.pki.spi.store.PkiStore
Opens a stable ordered cursor over the complete publication namespace.
openPublications(PublicationQuery) - Method in interface zeroecho.pki.api.PublicationService
Opens a stable lazy query over publication operations.
openPublications(PublicationQuery) - Method in class zeroecho.pki.impl.core.DefaultPublicationService
 
openPublisher(ProviderConfig) - Static method in class zeroecho.pki.spi.bootstrap.PkiBootstrap
Opens one explicitly configured publication destination.
openRevocationHistory(PkiId) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
openRevocationHistory(PkiId) - Method in interface zeroecho.pki.spi.store.PkiStore
Opens a bounded-memory cursor over one credential's authoritative history.
openRevocationSnapshot() - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
openRevocationSnapshot() - Method in interface zeroecho.pki.spi.store.PkiStore
Opens a stable restartable streaming snapshot of authoritative revocations.
openRevocationView() - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
openRevocationView() - Method in interface zeroecho.pki.spi.store.PkiStore
Opens a stable direct-lookup current-state view for finite protocol work.
openSignatureWorkflow(SignatureWorkflowRuntimeDependencies) - Static method in class zeroecho.pki.spi.bootstrap.PkiBootstrap
Opens a SignatureWorkflow using SignatureWorkflowProvider discovered via ServiceLoader.
openStagedObjects() - Method in record class zeroecho.pki.api.content.DeploymentResourcePolicy
Returns the value of the openStagedObjects record component.
openStatusObject(PkiId) - Method in interface zeroecho.pki.application.PkiRepository
Opens validated immutable status-object content.
openStore() - Static method in class zeroecho.pki.spi.bootstrap.PkiBootstrap
Opens a PkiStore using PkiStoreProvider discovered via ServiceLoader.
openStore(ProviderConfig) - Static method in class zeroecho.pki.spi.bootstrap.PkiBootstrap
Opens a store from an explicit, strictly validated configuration.
openStream() - Method in class zeroecho.pki.application.PkiRepositoryContent
Opens a new integrity-checking sequential content stream.
operation() - Method in class zeroecho.pki.impl.core.ValidatedCaCertificateRequest
Returns the authorized operation.
OPERATION - Enum constant in enum class zeroecho.pki.api.content.DurableContentReference.Lifecycle
Content retained while a durable operation is pending.
Operational model - Search tag in class zeroecho.pki.util.async.impl.DurableAsyncBus
Section
Operational model - Search tag in package zeroecho.pki.util.async.impl
Section
OperationIdCodec - Class in zeroecho.pki.impl.core.async
Utility for constructing canonical PKI operation identifiers for asynchronous orchestration.
operationName() - Method in record class zeroecho.pki.application.PkiOperationOutcome.Failure
Returns the value of the operationName record component.
operationName() - Method in record class zeroecho.pki.application.PkiOperationResult
Returns the value of the operationName record component.
OperationResult(Optional<EncodedObject>, Optional<Boolean>) - Constructor for record class zeroecho.pki.spi.crypto.SignatureWorkflow.OperationResult
Creates an instance of a OperationResult record class.
operations() - Method in interface zeroecho.pki.application.PkiSession
 
OperationStatus(SignatureWorkflow.State, Instant, Optional<String>, Optional<SignatureWorkflow.OperationResult>) - Constructor for record class zeroecho.pki.spi.crypto.SignatureWorkflow.OperationStatus
Creates an instance of a OperationStatus record class.
opId() - Method in record class zeroecho.pki.api.orch.WorkflowStateRecord
Returns the value of the opId record component.
opId() - Method in record class zeroecho.pki.util.async.AsyncOperationSnapshot
Returns the value of the opId record component.
opIdType() - Static method in class zeroecho.pki.impl.async.PkiAsyncTypes
Returns the operation id type.
optionalFeatures() - Method in record class zeroecho.pki.spi.store.MetadataStoreCapabilities
Returns the value of the optionalFeatures record component.
OrchestrationDurabilityPolicy - Enum Class in zeroecho.pki.api.orch
Durability policy for workflow continuation data managed by orchestrators.
orderedCredentialIds() - Method in record class zeroecho.pki.api.ca.IssuerChainPath
Returns the value of the orderedCredentialIds record component.
ordinal() - Method in interface zeroecho.pki.spi.framework.CrlEntrySource.Cursor
Returns the current zero-based ordinal.
ordinal() - Method in interface zeroecho.pki.spi.store.RevocationSnapshot.Cursor
Returns the zero-based current ordinal.
ORGANIZATION_NAME - Enum constant in enum class zeroecho.pki.api.profile.SubjectRdnType
X.520 organization name.
ORGANIZATIONAL_UNIT_NAME - Enum constant in enum class zeroecho.pki.api.profile.SubjectRdnType
X.520 organizational unit name.
origin() - Method in record class zeroecho.pki.api.algorithm.X509AlgorithmBinding
Returns the value of the origin record component.
origin() - Method in record class zeroecho.pki.application.PkiOperation.ListAlgorithmBindings
Returns the value of the origin record component.
outcome() - Method in record class zeroecho.pki.api.policy.PolicyTraceStep
Returns the value of the outcome record component.
outcome() - Method in record class zeroecho.pki.spi.store.MetadataCommitResult
Returns the value of the outcome record component.
OUTCOME_UNKNOWN - Enum constant in enum class zeroecho.pki.api.publication.PublicationStatus
The external effect is unknown and requires explicit reconciliation.
outcomeRetention() - Method in record class zeroecho.pki.spi.store.MetadataStoreCapabilities
Returns the value of the outcomeRetention record component.
outerAlgorithmLength() - Method in record class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectLayout
Returns the value of the outerAlgorithmLength record component.
outerAlgorithmOffset() - Method in record class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectLayout
Returns the value of the outerAlgorithmOffset record component.
outputStream() - Method in interface zeroecho.pki.spi.store.ContentSink
Returns the sequential output stream owned by this sink.
overrides() - Method in record class zeroecho.pki.api.issuance.ReissueCommand
Returns the value of the overrides record component.
overrides() - Method in record class zeroecho.pki.api.issuance.RenewCommand
Returns the value of the overrides record component.
overrides() - Method in record class zeroecho.pki.api.issuance.ReplaceCommand
Returns the value of the overrides record component.
owner() - Method in record class zeroecho.pki.api.orch.WorkflowStateRecord
Returns the value of the owner record component.
owner() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Returns the value of the owner record component.
owner() - Method in record class zeroecho.pki.util.async.AsyncOperationSnapshot
Returns the value of the owner record component.
ownerType() - Static method in class zeroecho.pki.impl.async.PkiAsyncTypes
Returns the owner type.

P

Package structure - Search tag in package zeroecho.pki.util
Section
Page(List<SignWorkflowStore.Record>, Optional<String>, int, int, boolean) - Constructor for record class zeroecho.pki.spi.store.SignWorkflowStore.Page
Validates one immutable page.
pageSignRecords(Optional<String>, int, CancellationSignal) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
pageSignRecords(Optional<String>, int, CancellationSignal) - Method in interface zeroecho.pki.spi.store.SignWorkflowStore
Returns at most maximumRecords records after an advisory exclusive cursor, ordered by canonical submission identifier.
parameterForm() - Method in class zeroecho.pki.impl.framework.x509.X509AlgorithmIdentifier
Returns the exact parameter form.
parameterRule() - Method in record class zeroecho.pki.api.algorithm.X509AlgorithmBinding
Returns the value of the parameterRule record component.
parameters() - Method in class zeroecho.pki.impl.framework.x509.X509AlgorithmIdentifier
Returns independently owned parameter DER.
parse(byte[]) - Static method in class zeroecho.pki.api.profile.CertificateProfileDocumentCodec
Parses an encoded certificate-profile document.
parse(InputStream) - Static method in class zeroecho.pki.api.profile.CertificateProfileDocumentCodec
Reads and parses an encoded certificate-profile document.
parse(String) - Static method in record class zeroecho.pki.spi.store.MetadataKey
Parses one complete versioned length-framed identity.
parse(String) - Static method in record class zeroecho.pki.spi.store.MetadataTransactionId
Parses one complete current canonical representation.
parse(PkiId) - Static method in record class zeroecho.pki.api.orch.SigningSubmissionId
Parses and validates the version, namespace, timestamp, and random length.
parse(CertificationRequest) - Method in interface zeroecho.pki.api.CertificationRequestService
Parses and normalizes a certification request.
parse(CertificationRequest) - Method in class zeroecho.pki.impl.core.DefaultCertificationRequestService
Parses the supplied certification request using the active credential framework.
parse(CertificationRequest) - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509CertificationRequestParser
Parses a PKCS#10 certification request into the normalized PKI request representation.
parse(CertificationRequest) - Method in interface zeroecho.pki.spi.framework.CertificationRequestParser
Parses and normalizes a certification request.
ParsedCertificationRequest - Record Class in zeroecho.pki.api.request
Normalized representation of a certification request.
ParsedCertificationRequest(PkiId, FormatId, SubjectRef, EncodedObject, Optional<Validity>, Optional<String>, List<SubjectRdn>, List<SubjectAlternativeName>, boolean, AttributeSet) - Constructor for record class zeroecho.pki.api.request.ParsedCertificationRequest
Creates a parsed certification request.
ParsedCertificationRequest(PkiId, FormatId, SubjectRef, EncodedObject, Optional<Validity>, Optional<String>, AttributeSet) - Constructor for record class zeroecho.pki.api.request.ParsedCertificationRequest
Creates a diagnostic request without typed X.509 identity semantics.
pathCommitment() - Method in record class zeroecho.pki.api.ca.IssuerChainPath
Returns the value of the pathCommitment record component.
pathId() - Method in record class zeroecho.pki.api.ca.IssuerChainPath
Returns the value of the pathId record component.
pathLengthConstraint() - Method in record class zeroecho.pki.api.profile.CaCertificatePolicy
Returns the value of the pathLengthConstraint record component.
payload() - Method in record class zeroecho.pki.api.backup.BackupArtifact
Returns the value of the payload record component.
payload() - Method in record class zeroecho.pki.api.orch.WorkflowStateRecord
Returns the value of the payload record component.
payload() - Method in record class zeroecho.pki.api.transfer.ExportArtifact
Returns the value of the payload record component.
payloadEncoding() - Method in record class zeroecho.pki.api.orch.WorkflowStateRecord
Returns the value of the payloadEncoding record component.
PEM - Enum constant in enum class zeroecho.pki.api.Encoding
PEM armored textual representation.
PEM_BUNDLE - Enum constant in enum class zeroecho.pki.api.transfer.ExportFormat
Export as PEM bundle where applicable (e.g., certificate + chain).
PENDING - Enum constant in enum class zeroecho.pki.api.publication.PublicationStatus
The operation is registered and eligible for explicit processing.
PENDING - Enum constant in enum class zeroecho.pki.spi.crypto.SignatureWorkflow.State
 
PERMANENTLY_REVOKED - Enum constant in enum class zeroecho.pki.api.credential.EffectiveCredentialStatus
The credential is permanently revoked.
PERMANENTLY_REVOKED - Enum constant in enum class zeroecho.pki.api.revocation.RevocationState
Credential is permanently revoked.
permanentReason() - Method in record class zeroecho.pki.api.revocation.RevocationTransition
Returns the value of the permanentReason record component.
permits(AlgorithmSuite, AlgorithmExecutionCapability.Direction) - Method in interface zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Policy
Tests whether configured policy permits the exact operation.
PERSISTED - Enum constant in enum class zeroecho.pki.api.content.DurableContentReference.Lifecycle
Content owned by an immutable persisted PKI object.
Persistence - Search tag in package zeroecho.pki.impl.audit
Section
Persistence and lifecycle - Search tag in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
Section
Persistence and re-attach semantics - Search tag in package zeroecho.pki.impl.core.async
Section
Persistence considerations - Search tag in record class zeroecho.pki.impl.core.attr.SimpleAttributeSet
Section
Persistence model - Search tag in class zeroecho.pki.impl.core.DefaultStatusObjectService
Section
persistentCode() - Method in enum class zeroecho.pki.spi.store.SignWorkflowStore.State
Returns the stable filesystem persistence code.
persistsResults() - Method in class zeroecho.pki.impl.core.async.PkiAsyncCodecs.EncodedObjectResultCodec
Indicates whether async results should be durably persisted.
persistsResults() - Method in interface zeroecho.pki.util.async.codec.ResultCodec
Indicates whether this codec persists results in the bus log.
PKI_ID - Static variable in class zeroecho.pki.impl.async.PkiCodecs
Codec for PkiId.
PKI_SIGNATURE_DEFAULT_V1 - Static variable in class zeroecho.pki.impl.framework.x509.X509BuiltInDefaults
Historical and current version-one certificate, CRL, and CA-proof signing default.
PkiApplication - Class in zeroecho.pki
Minimal bootstrap entry point for the pki module.
PkiAsyncCodecs - Class in zeroecho.pki.impl.core.async
Collection of PKI-specific codecs used by the durable asynchronous orchestration layer.
PkiAsyncCodecs.EncodedObjectResultCodec - Class in zeroecho.pki.impl.core.async
Result codec for persisting EncodedObject values as &lt;ENCODING&gt;:&lt;base64url-without-padding&gt;.
PkiAsyncCodecs.PkiIdCodec - Class in zeroecho.pki.impl.core.async
Codec for representing PkiId values by their stable string form.
PkiAsyncCodecs.PrincipalCodec - Class in zeroecho.pki.impl.core.async
Codec for representing Principal values as type:name.
PkiAsyncCodecs.StringIdCodec - Class in zeroecho.pki.impl.core.async
Trivial identity codec for endpoint identifiers.
PkiAsyncTypes - Class in zeroecho.pki.impl.async
PKI-specific async bus type aliases.
PkiAsyncTypes.EndpointId - Class in zeroecho.pki.impl.async
Endpoint identifier type for PKI asynchronous operations.
PkiAsyncTypes.OpId - Class in zeroecho.pki.impl.async
Operation identifier type for PKI asynchronous operations.
PkiAsyncTypes.Owner - Class in zeroecho.pki.impl.async
Owner type for PKI asynchronous operations.
PkiAsyncTypes.Result - Class in zeroecho.pki.impl.async
Result type for PKI asynchronous operations.
PkiBootstrap - Class in zeroecho.pki.spi.bootstrap
PKI bootstrap utilities for ServiceLoader-based components.
PkiBusContentSigner - Class in zeroecho.pki.impl.framework.x509.bc
ContentSigner implementation that delegates the actual signature operation to PkiSigningBus.
PkiBusContentSigner(PkiSigningBus, KeyRef, String, Duration) - Constructor for class zeroecho.pki.impl.framework.x509.bc.PkiBusContentSigner
Creates a signer that routes signature generation through the PKI signing bus.
PkiBusContentSigner(PkiSigningBus, KeyRef, AlgorithmIdentity, String, Duration) - Constructor for class zeroecho.pki.impl.framework.x509.bc.PkiBusContentSigner
Creates a signer using one explicitly selected X.509 binding.
PkiBusContentSigner(PkiSigningBus, KeyRef, AlgorithmIdentity, Duration) - Constructor for class zeroecho.pki.impl.framework.x509.bc.PkiBusContentSigner
Creates a signer from an exact provider-independent signature identity.
PkiCodecs - Class in zeroecho.pki.impl.async
PKI-specific codecs used to instantiate the generic async bus.
PkiException - Exception Class in zeroecho.pki.api
Base runtime exception for PKI domain failures.
PkiException(String) - Constructor for exception class zeroecho.pki.api.PkiException
Creates a PKI exception with a message.
PkiException(String, Throwable) - Constructor for exception class zeroecho.pki.api.PkiException
Creates a PKI exception with a message and cause.
PkiId - Record Class in zeroecho.pki.api
Opaque identifier for PKI-managed entities.
PkiId(String) - Constructor for record class zeroecho.pki.api.PkiId
Creates an opaque PKI identifier.
PkiIdCodec() - Constructor for class zeroecho.pki.impl.core.async.PkiAsyncCodecs.PkiIdCodec
 
PkiIds - Class in zeroecho.pki.util
Utility methods for generating and validating PkiId values.
PkiOperation - Interface in zeroecho.pki.application
Closed set of typed synchronous PKI operations available to transports.
PkiOperation.ActivateProfile - Record Class in zeroecho.pki.application
Activates one already imported certificate-profile version.
PkiOperation.CreateAuthority - Record Class in zeroecho.pki.application
Creates one root certificate authority using an existing managed key reference.
PkiOperation.GenerateStatus - Record Class in zeroecho.pki.application
Generates one signed status object from a stable revocation view.
PkiOperation.ImportRequest - Record Class in zeroecho.pki.application
Strictly parses and durably imports one certification request.
PkiOperation.InspectAlgorithmBinding - Record Class in zeroecho.pki.application
Inspects one active X.509 algorithm binding by stable identifier.
PkiOperation.InspectAuthority - Record Class in zeroecho.pki.application
Reads safe metadata for one committed certificate authority.
PkiOperation.InspectCredential - Record Class in zeroecho.pki.application
Reads safe metadata for one committed credential.
PkiOperation.InspectProfile - Record Class in zeroecho.pki.application
Reads one exact imported certificate-profile version.
PkiOperation.InspectPublication - Record Class in zeroecho.pki.application
Reads safe durable state for one publication operation.
PkiOperation.InspectRequest - Record Class in zeroecho.pki.application
Reads safe metadata for one stored certification request.
PkiOperation.InspectRevocation - Record Class in zeroecho.pki.application
Reads the validated current revocation state for one credential.
PkiOperation.InspectStatus - Record Class in zeroecho.pki.application
Reads safe metadata for one committed status object.
PkiOperation.IssueCredential - Record Class in zeroecho.pki.application
Issues one end-entity credential from an already imported request.
PkiOperation.ListAlgorithmBindings - Record Class in zeroecho.pki.application
Lists active X.509 algorithm bindings with optional finite filters.
PkiOperation.ListAuthorities - Record Class in zeroecho.pki.application
Lists committed certificate authorities with a finite presentation limit.
PkiOperation.ListProfileVersions - Record Class in zeroecho.pki.application
Lists the finite imported versions of one logical profile.
PkiOperation.ListPublications - Record Class in zeroecho.pki.application
Lists publication records using a bounded-memory cursor and finite result page.
PkiOperation.ListStatus - Record Class in zeroecho.pki.application
Lists status objects for one issuer with a finite presentation limit.
PkiOperation.ProcessPublication - Record Class in zeroecho.pki.application
Processes one explicitly selected pending publication operation.
PkiOperation.ReadRevocationHistory - Record Class in zeroecho.pki.application
Reads a bounded prefix from one closeable authoritative history cursor.
PkiOperation.ReconcilePublication - Record Class in zeroecho.pki.application
Reconciles one publication operation whose external outcome is unknown.
PkiOperation.RegisterProfile - Record Class in zeroecho.pki.application
Imports one bounded validated certificate-profile document.
PkiOperation.RegisterPublication - Record Class in zeroecho.pki.application
Registers post-commit publication of one authoritative source object.
PkiOperation.RetryPublication - Record Class in zeroecho.pki.application
Explicitly retries one eligible publication operation.
PkiOperation.RevokeCredential - Record Class in zeroecho.pki.application
Permanently revokes one committed credential.
PkiOperation.SnapshotRevocations - Record Class in zeroecho.pki.application
Reads a bounded page from one immutable current-revocation snapshot.
PkiOperation.TransitionAuthority - Record Class in zeroecho.pki.application
Applies one explicit lifecycle transition to an existing authority.
PkiOperation.ValidateAlgorithmBindings - Record Class in zeroecho.pki.application
Validates the immutable active registry and optionally one exact binding.
PkiOperation.ValidateConfiguration - Record Class in zeroecho.pki.application
Validates the already-open session configuration.
PkiOperation.ValidateProfile - Record Class in zeroecho.pki.application
Validates one bounded certificate-profile JSON document without persisting it.
PkiOperation.VerifyRequest - Record Class in zeroecho.pki.application
Verifies proof of possession for one stored request.
PkiOperationExecutor - Interface in zeroecho.pki.application
Synchronous transport-neutral executor for the closed PKI operation model.
PkiOperationFailure - Enum Class in zeroecho.pki.application
Stable safe classifications for synchronous PKI operation failures.
PkiOperationOutcome - Interface in zeroecho.pki.application
Closed success-or-safe-failure outcome returned by the operation executor.
PkiOperationOutcome.Failure - Record Class in zeroecho.pki.application
Safely classified operation failure without a throwable graph.
PkiOperationOutcome.Success - Record Class in zeroecho.pki.application
Successful operation outcome.
PkiOperationResult - Record Class in zeroecho.pki.application
Finite structured result of one successful typed PKI operation.
PkiOperationResult(String, Map<String, PkiOperationValue>) - Constructor for record class zeroecho.pki.application.PkiOperationResult
Validates and snapshots the result.
PkiOperationValue - Interface in zeroecho.pki.application
Closed transport-neutral value model used by safe operation results and plan arguments.
PkiOperationValue.BooleanValue - Record Class in zeroecho.pki.application
Boolean scalar.
PkiOperationValue.IntegerValue - Record Class in zeroecho.pki.application
Signed 64-bit integer scalar.
PkiOperationValue.ListValue - Record Class in zeroecho.pki.application
Immutable ordered list value.
PkiOperationValue.ObjectValue - Record Class in zeroecho.pki.application
Deterministically ordered object value.
PkiOperationValue.Text - Record Class in zeroecho.pki.application
Text scalar.
PkiRepository - Interface in zeroecho.pki.application
Read-only authoritative repository facade owned by one PkiSession.
PkiRepositoryContent - Class in zeroecho.pki.application
Lifecycle-owned immutable repository content lease without store internals.
PkiRepositoryContent.Role - Enum Class in zeroecho.pki.application
Closed semantic role of public repository content.
PkiResourceScopeResolver - Interface in zeroecho.pki.application
Read-only transport-neutral resolver for authorization scope cross-checks.
PkiSession - Interface in zeroecho.pki.application
Lifecycle-owned synchronous PKI backend session.
PkiSessionConfiguration - Record Class in zeroecho.pki.application
Immutable, versioned configuration for one synchronous PKI backend session.
PkiSessionConfiguration(int, ProviderConfig, ProviderConfig) - Constructor for record class zeroecho.pki.application.PkiSessionConfiguration
Creates a read-only-compatible version-one configuration.
PkiSessionConfiguration(int, ProviderConfig, ProviderConfig, Optional<PkiSessionConfiguration.SigningConfiguration>, List<ProviderConfig>) - Constructor for record class zeroecho.pki.application.PkiSessionConfiguration
Creates a version-one or version-two configuration without custom bindings.
PkiSessionConfiguration(int, ProviderConfig, ProviderConfig, Optional<PkiSessionConfiguration.SigningConfiguration>, List<ProviderConfig>, List<PkiSessionConfiguration.BindingProviderConfiguration>) - Constructor for record class zeroecho.pki.application.PkiSessionConfiguration
Validates and snapshots the configuration.
PkiSessionConfiguration.BindingProviderConfiguration - Record Class in zeroecho.pki.application
Explicit activation and namespace authorization for one installed binding provider.
PkiSessionConfiguration.SigningConfiguration - Record Class in zeroecho.pki.application
Explicit signing and X.509 service-graph configuration.
PkiSessionRuntimeDependencies - Record Class in zeroecho.pki.application
Immutable process-local capabilities for one PKI session composition.
PkiSessionRuntimeDependencies(Optional<KeyringUnlockProvider>) - Constructor for record class zeroecho.pki.application.PkiSessionRuntimeDependencies
Creates dependencies without an externally composed audit sink.
PkiSessionRuntimeDependencies(Optional<KeyringUnlockProvider>, Optional<AuditSink>) - Constructor for record class zeroecho.pki.application.PkiSessionRuntimeDependencies
Validates the optional capability container.
PkiSigningBus - Class in zeroecho.pki.impl.core.async
PKI signing bus that orchestrates asynchronous signature operations.
PkiSigningBus(PkiStore, SignatureWorkflow, Path, int, OrchestrationDurabilityPolicy, X509AuthoritySnapshot) - Constructor for class zeroecho.pki.impl.core.async.PkiSigningBus
Creates a signing bus bound to one immutable algorithm authority snapshot.
PkiSigningBus(PkiStore, SignatureWorkflow, Path, X509AuthoritySnapshot) - Constructor for class zeroecho.pki.impl.core.async.PkiSigningBus
Creates a signing bus in an explicitly composed runtime authority graph.
PkiSigningBus.SignContinuation - Class in zeroecho.pki.impl.core.async
Persisted continuation payload for a PKI sign operation.
PkiStore - Interface in zeroecho.pki.spi.store
Persistence boundary for PKI state.
PkiStoreProvider - Interface in zeroecho.pki.spi.store
ServiceLoader provider for PkiStore implementations.
plan(AlgorithmIdentity, AlgorithmIdentity, AlgorithmExecutionCapability.Direction, Optional<String>, String, Class<E>) - Method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Resolves and authorizes one process-local execution plan.
plan(AlgorithmIdentity, AlgorithmIdentity, AlgorithmExecutionCapability.Direction, Optional<String>, String, String, Class<E>) - Method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Resolves and authorizes one plan through an explicit binding identity.
planSigning(String, Class<E>) - Method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Resolves a signing plan when exactly one implementation is available.
planSigning(String, String, Class<E>) - Method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Resolves a signing plan for a legacy upper API that carries only the signature identity.
planSigningWithBinding(String, String, Class<E>) - Method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Resolves a signing plan through one explicit binding.
policy() - Method in class zeroecho.pki.impl.core.ValidatedCaCertificateRequest
Returns the exact profile-derived CA policy.
POLICY - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Failure
Configured policy rejected the suite.
POLICY_REJECTION - Enum constant in enum class zeroecho.pki.application.PkiOperationFailure
A valid request is rejected by PKI policy.
PolicyDecision - Record Class in zeroecho.pki.api.policy
Policy decision including optional modifications to be applied to an operation.
PolicyDecision(PkiId, PolicyDecisionStatus, List<String>, AttributeSet) - Constructor for record class zeroecho.pki.api.policy.PolicyDecision
Creates a policy decision.
PolicyDecisionStatus - Enum Class in zeroecho.pki.api.policy
Outcome status of a policy evaluation.
PolicyService - Interface in zeroecho.pki.api
Policy evaluation and explainability.
PolicyTrace - Record Class in zeroecho.pki.api.policy
Explainability trace for a policy decision.
PolicyTrace(PkiId, List<PolicyTraceStep>) - Constructor for record class zeroecho.pki.api.policy.PolicyTrace
Creates a policy trace.
PolicyTraceStep - Record Class in zeroecho.pki.api.policy
Single evaluation step within a policy trace.
PolicyTraceStep(String, String, List<String>) - Constructor for record class zeroecho.pki.api.policy.PolicyTraceStep
Creates a policy trace step.
PosixTransactionalMetadataStore - Class in zeroecho.pki.impl.fs
POSIX exclusive-writer implementation of the transactional metadata-store SPI.
preferredSignatureEncoding() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.SignRequest
Returns the value of the preferredSignatureEncoding record component.
preferredTrustAnchorId() - Method in record class zeroecho.pki.api.issuance.BundleCommand
Returns the value of the preferredTrustAnchorId record component.
prefix(String, String) - Static method in record class zeroecho.pki.spi.store.MetadataSnapshot.KeyRange
Returns the total ordered range for a canonical key prefix.
principal() - Method in record class zeroecho.pki.api.audit.AccessContext
Returns the value of the principal record component.
principal() - Method in record class zeroecho.pki.api.audit.AuditEvent
Returns the value of the principal record component.
Principal - Record Class in zeroecho.pki.api.audit
Identifies an actor performing an operation or requesting access.
Principal(String, String) - Constructor for record class zeroecho.pki.api.audit.Principal
Creates a principal.
PRINCIPAL - Static variable in class zeroecho.pki.impl.async.PkiCodecs
Codec for Principal.
PrincipalCodec() - Constructor for class zeroecho.pki.impl.core.async.PkiAsyncCodecs.PrincipalCodec
 
principalName() - Method in record class zeroecho.pki.api.audit.AuditQuery
Returns the value of the principalName record component.
PRIVILEGE_WITHDRAWN - Enum constant in enum class zeroecho.pki.api.revocation.RevocationReason
Privileges granted to the subject have been withdrawn.
process(PkiId) - Method in interface zeroecho.pki.api.PublicationService
Processes one pending operation synchronously.
process(PkiId) - Method in class zeroecho.pki.impl.core.DefaultPublicationService
 
ProcessPublication(PkiId) - Constructor for record class zeroecho.pki.application.PkiOperation.ProcessPublication
Validates the publication identity.
producedAt() - Method in record class zeroecho.pki.application.OcspResponseService.Command
Returns the value of the producedAt record component.
profile() - Method in record class zeroecho.pki.api.profile.ActiveCertificateProfile
Returns the deterministic runtime projection of the authoritative definition.
PROFILE_ACTIVATION_FAILED - Enum constant in enum class zeroecho.pki.impl.ProfileLifecycleFailure.Code
 
PROFILE_ACTIVATION_HISTORY_UNAVAILABLE - Enum constant in enum class zeroecho.pki.impl.ProfileLifecycleFailure.Code
 
PROFILE_ACTIVE_POINTER_CORRUPT - Enum constant in enum class zeroecho.pki.impl.ProfileLifecycleFailure.Code
 
PROFILE_DOCUMENT_INVALID - Enum constant in enum class zeroecho.pki.impl.ProfileLifecycleFailure.Code
 
PROFILE_DURABILITY_UNCONFIRMED - Enum constant in enum class zeroecho.pki.impl.ProfileLifecycleFailure.Code
 
PROFILE_HASH_MISMATCH - Enum constant in enum class zeroecho.pki.impl.ProfileLifecycleFailure.Code
 
PROFILE_IMPORT_FAILED - Enum constant in enum class zeroecho.pki.impl.ProfileLifecycleFailure.Code
 
PROFILE_IMPORT_VALIDATION_FAILED - Enum constant in enum class zeroecho.pki.impl.ProfileLifecycleFailure.Code
 
PROFILE_KIND_CONFLICT - Enum constant in enum class zeroecho.pki.impl.ProfileLifecycleFailure.Code
 
PROFILE_NOT_ACTIVE - Enum constant in enum class zeroecho.pki.impl.ProfileLifecycleFailure.Code
 
PROFILE_STATE_CORRUPT - Enum constant in enum class zeroecho.pki.impl.ProfileLifecycleFailure.Code
 
PROFILE_STORE_FAILURE - Enum constant in enum class zeroecho.pki.impl.ProfileLifecycleFailure.Code
 
PROFILE_VERSION_CONFLICT - Enum constant in enum class zeroecho.pki.impl.ProfileLifecycleFailure.Code
 
PROFILE_VERSION_CORRUPT - Enum constant in enum class zeroecho.pki.impl.ProfileLifecycleFailure.Code
 
PROFILE_VERSION_NOT_FOUND - Enum constant in enum class zeroecho.pki.impl.ProfileLifecycleFailure.Code
 
profileBinding() - Method in record class zeroecho.pki.api.credential.Credential
Returns the value of the profileBinding record component.
profileHistoryPolicy() - Method in record class zeroecho.pki.impl.fs.FsPkiStoreOptions
Returns the value of the profileHistoryPolicy record component.
profileId() - Method in record class zeroecho.pki.api.ca.CaCreateCommand
Returns the value of the profileId record component.
profileId() - Method in record class zeroecho.pki.api.ca.CaImportCommand
Returns the value of the profileId record component.
profileId() - Method in record class zeroecho.pki.api.ca.IntermediateCertIssueCommand
Returns the value of the profileId record component.
profileId() - Method in record class zeroecho.pki.api.ca.IntermediateCreateCommand
Returns the value of the profileId record component.
profileId() - Method in record class zeroecho.pki.api.credential.CredentialQuery
Returns the value of the profileId record component.
profileId() - Method in record class zeroecho.pki.api.issuance.IssuanceInputs
Returns the value of the profileId record component.
profileId() - Method in record class zeroecho.pki.api.issuance.IssueEndEntityCommand
Returns the value of the profileId record component.
profileId() - Method in record class zeroecho.pki.api.issuance.ReplaceCommand
Returns the value of the profileId record component.
profileId() - Method in record class zeroecho.pki.api.profile.CertificateProfile
Returns the value of the profileId record component.
profileId() - Method in record class zeroecho.pki.api.profile.CertificateProfileDefinition
Returns the value of the profileId record component.
profileId() - Method in class zeroecho.pki.api.profile.CertificateProfileRef
 
profileId() - Method in record class zeroecho.pki.api.profile.ProfileQuery
Returns the value of the profileId record component.
profileId() - Method in record class zeroecho.pki.api.request.RequestQuery
Returns the value of the profileId record component.
profileId() - Method in record class zeroecho.pki.application.PkiOperation.ActivateProfile
Returns the value of the profileId record component.
profileId() - Method in record class zeroecho.pki.application.PkiOperation.CreateAuthority
Returns the value of the profileId record component.
profileId() - Method in record class zeroecho.pki.application.PkiOperation.InspectProfile
Returns the value of the profileId record component.
profileId() - Method in record class zeroecho.pki.application.PkiOperation.IssueCredential
Returns the value of the profileId record component.
profileId() - Method in record class zeroecho.pki.application.PkiOperation.ListProfileVersions
Returns the value of the profileId record component.
profileId() - Method in class zeroecho.pki.impl.core.ValidatedCertificateRequest
 
profileId() - Method in class zeroecho.pki.impl.core.VerifiedIssuanceCandidate
Returns the validated profile identifier.
ProfileLifecycleFailure - Exception Class in zeroecho.pki.impl
Internal typed classification for redacted profile lifecycle failures.
ProfileLifecycleFailure(ProfileLifecycleFailure.Code) - Constructor for exception class zeroecho.pki.impl.ProfileLifecycleFailure
Creates one cause-free failure with a stable code.
ProfileLifecycleFailure.Code - Enum Class in zeroecho.pki.impl
Closed profile lifecycle failure codes.
profilePolicyCommitment() - Method in record class zeroecho.pki.api.ca.IssuerGeneration
Returns the value of the profilePolicyCommitment record component.
ProfileQuery - Record Class in zeroecho.pki.api.profile
Query constraints for listing profiles.
ProfileQuery(Optional<FormatId>, Optional<String>, Optional<Boolean>) - Constructor for record class zeroecho.pki.api.profile.ProfileQuery
Creates a profile query.
profileReference() - Method in class zeroecho.pki.impl.core.ValidatedCaCertificateRequest
Returns the exact active profile reference.
profileReference() - Method in class zeroecho.pki.impl.core.ValidatedCertificateRequest
 
profiles() - Method in interface zeroecho.pki.application.PkiSession
 
ProfileService - Interface in zeroecho.pki.api
Versioned certificate-profile import, activation, and lookup service.
profileVersion() - Method in record class zeroecho.pki.api.profile.CertificateProfileDefinition
Returns the value of the profileVersion record component.
profileVersion() - Method in class zeroecho.pki.api.profile.CertificateProfileRef
 
profileVersion() - Method in record class zeroecho.pki.application.PkiOperation.ActivateProfile
Returns the value of the profileVersion record component.
profileVersion() - Method in record class zeroecho.pki.application.PkiOperation.InspectProfile
Returns the value of the profileVersion record component.
progressed() - Method in record class zeroecho.pki.application.SigningReconciliationResult
Returns the value of the progressed record component.
proofKind() - Method in class zeroecho.pki.impl.core.VerifiedIssuanceCandidate
Returns the proof result that authorized construction.
Proof of possession - Search tag in package zeroecho.pki.api.request
Section
ProofOfPossessionResult - Record Class in zeroecho.pki.api.request
Result of proof-of-possession (PoP) verification.
ProofOfPossessionResult(ProofOfPossessionStatus, Optional<String>) - Constructor for record class zeroecho.pki.api.request.ProofOfPossessionResult
Creates a PoP verification result.
ProofOfPossessionStatus - Enum Class in zeroecho.pki.api.request
Outcome of proof-of-possession (PoP) verification.
proofOfPossessionVerifier() - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFramework
Returns the proof-of-possession verifier used by this framework instance.
proofOfPossessionVerifier() - Method in interface zeroecho.pki.spi.framework.CredentialFramework
Returns the proof-of-possession verifier for this framework.
ProofOfPossessionVerifier - Interface in zeroecho.pki.spi.framework
Verifies proof-of-possession (PoP) for a parsed request in a framework-specific manner.
PROP_DISPLAY_SUFFIX_MAX_LEN - Static variable in class zeroecho.pki.impl.core.async.PkiSigningBus
System property controlling the maximum number of characters appended after '#' in the display operation identifier.
properties() - Method in record class zeroecho.pki.spi.ProviderConfig
Returns the value of the properties record component.
provenance() - Method in record class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Selection
Returns the value of the provenance record component.
providerCallTimeout() - Method in record class zeroecho.pki.application.SigningReconciliationRequest
Returns the value of the providerCallTimeout record component.
ProviderConfig - Record Class in zeroecho.pki.spi
Backend configuration for ConfigurableProvider instances.
ProviderConfig(String, Map<String, String>) - Constructor for record class zeroecho.pki.spi.ProviderConfig
Canonical constructor with validation and defensive wrapping.
providerId() - Method in record class zeroecho.pki.api.algorithm.X509AlgorithmBinding
Returns the value of the providerId record component.
providerId() - Method in record class zeroecho.pki.application.PkiSessionConfiguration.BindingProviderConfiguration
Returns the value of the providerId record component.
providerId() - Method in interface zeroecho.pki.spi.algorithm.X509AlgorithmBindingProvider
 
Provider identity - Search tag in interface zeroecho.pki.spi.ConfigurableProvider
Section
providerUpdatedAt() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Returns the value of the providerUpdatedAt record component.
PSEUDONYM - Enum constant in enum class zeroecho.pki.api.profile.SubjectRdnType
X.520 pseudonym.
PUBLIC - Enum constant in enum class zeroecho.pki.api.attr.AttributeSensitivity
Public value; can be disclosed broadly.
PublicationAttempt - Record Class in zeroecho.pki.spi.publish
Immutable non-secret identity and content commitment for one external attempt.
PublicationAttempt(PkiId, PublicationSourceType, PkiId, PublicationTarget, long, String, Encoding, long, String) - Constructor for record class zeroecho.pki.spi.publish.PublicationAttempt
Creates a validated immutable attempt descriptor.
publicationAuthority(PkiId) - Method in interface zeroecho.pki.application.PkiResourceScopeResolver
Returns the authority of the immutable source behind one publication operation.
publicationBytes() - Method in record class zeroecho.pki.api.content.DeploymentResourcePolicy
Returns the value of the publicationBytes record component.
PublicationCursor - Interface in zeroecho.pki.api.publication
Closeable snapshot-consistent cursor over publication records.
PublicationEvidence - Enum Class in zeroecho.pki.api.publication
Identifies how an exact attempt outcome was established.
PublicationFailure - Enum Class in zeroecho.pki.api.publication
Safe closed classifications for publication-operation failures.
publicationId() - Method in record class zeroecho.pki.api.publication.PublicationRecord
Returns the value of the publicationId record component.
publicationId() - Method in record class zeroecho.pki.api.publication.PublicationRequest
Returns the value of the publicationId record component.
publicationId() - Method in record class zeroecho.pki.api.publication.PublicationResult
Returns the value of the publicationId record component.
publicationId() - Method in record class zeroecho.pki.application.PkiOperation.InspectPublication
Returns the value of the publicationId record component.
publicationId() - Method in record class zeroecho.pki.application.PkiOperation.ProcessPublication
Returns the value of the publicationId record component.
publicationId() - Method in record class zeroecho.pki.application.PkiOperation.ReconcilePublication
Returns the value of the publicationId record component.
publicationId() - Method in record class zeroecho.pki.application.PkiOperation.RegisterPublication
Returns the value of the publicationId record component.
publicationId() - Method in record class zeroecho.pki.application.PkiOperation.RetryPublication
Returns the value of the publicationId record component.
publicationId() - Method in record class zeroecho.pki.spi.publish.PublicationAttempt
Returns the value of the publicationId record component.
PublicationOutcome - Enum Class in zeroecho.pki.spi.publish
Definitive outcomes a publisher may safely return for one exact attempt.
PublicationQuery - Record Class in zeroecho.pki.api.publication
Query constraints for listing publication records.
PublicationQuery(Optional<PublicationTargetType>, Optional<Instant>, Optional<Instant>, Optional<PublicationSourceType>) - Constructor for record class zeroecho.pki.api.publication.PublicationQuery
Creates a publication query.
PublicationRecord - Record Class in zeroecho.pki.api.publication
Persisted current state of one publication operation.
PublicationRecord(PkiId, PublicationSourceType, PkiId, DurableContentReference, PublicationTarget, PublicationStatus, long, Optional<String>, Instant, Instant, Optional<PublicationFailure>, Optional<PublicationEvidence>) - Constructor for record class zeroecho.pki.api.publication.PublicationRecord
Creates a publication record.
Publication recovery ownership - Search tag in interface zeroecho.pki.spi.store.PkiStore
Section
PublicationRequest - Record Class in zeroecho.pki.api.publication
Immutable request to register distribution of one already committed PKI object.
PublicationRequest(PkiId, PublicationSourceType, PkiId, PublicationTarget) - Constructor for record class zeroecho.pki.api.publication.PublicationRequest
Creates a validated publication request.
PublicationResult - Record Class in zeroecho.pki.api.publication
Result of a publish operation.
PublicationResult(PkiId, PublicationStatus, long) - Constructor for record class zeroecho.pki.api.publication.PublicationResult
Creates a publication result.
publications() - Method in interface zeroecho.pki.application.PkiSession
 
PublicationService - Interface in zeroecho.pki.api
Publication and distribution operations.
PublicationSourceType - Enum Class in zeroecho.pki.api.publication
Identifies the authoritative PKI object supplying publication content.
PublicationStatus - Enum Class in zeroecho.pki.api.publication
Durable publication-operation state.
PublicationTarget - Record Class in zeroecho.pki.api.publication
Describes where and how to publish an artifact.
PublicationTarget(PublicationTargetType, String) - Constructor for record class zeroecho.pki.api.publication.PublicationTarget
Creates a publication target.
PublicationTargetType - Enum Class in zeroecho.pki.api.publication
Classifies the publication destination type.
publicKeyEncoded() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.VerifyRequest
Returns the value of the publicKeyEncoded record component.
publicKeyEncoding() - Method in record class zeroecho.pki.api.algorithm.X509AlgorithmBinding
Returns the value of the publicKeyEncoding record component.
publicKeyEncoding() - Method in interface zeroecho.pki.impl.framework.x509.X509BindingRule
Returns the exact subject-public-key encoding rule.
publicKeyId() - Method in record class zeroecho.pki.api.credential.Credential
Returns the value of the publicKeyId record component.
publicKeyId() - Method in record class zeroecho.pki.api.credential.CredentialQuery
Returns the value of the publicKeyId record component.
publicKeyInfo() - Method in record class zeroecho.pki.api.request.ParsedCertificationRequest
Returns the value of the publicKeyInfo record component.
PublicKeyInfoResolver - Interface in zeroecho.pki.impl.core
Functional contract for resolving public key information for a KeyRef.
PublicKeyInfoSource - Interface in zeroecho.pki.spi.crypto
Resolves exportable public-key information from the same managed-key authority used by a signature workflow.
publicKeyRef() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.VerifyRequest
Returns the value of the publicKeyRef record component.
publish(PublicationAttempt, RepeatableContent) - Method in interface zeroecho.pki.spi.publish.Publisher
Publishes the payload for one durably prepared attempt.
Publisher - Interface in zeroecho.pki.spi.publish
Publishes an encoded artifact to a configured publication target.
PublisherProvider - Interface in zeroecho.pki.spi.publish
Service-provider contract for explicitly configured publication destinations.
publishers() - Method in record class zeroecho.pki.application.PkiSessionConfiguration
Returns the value of the publishers record component.
purgeExpiredSignRecords() - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
purgeExpiredSignRecords() - Method in interface zeroecho.pki.spi.store.SignWorkflowStore
Purges retired payload-bearing records after the configured horizon.
purpose() - Method in record class zeroecho.pki.api.audit.AccessContext
Returns the value of the purpose record component.
purpose() - Method in record class zeroecho.pki.api.audit.AuditEvent
Returns the value of the purpose record component.
Purpose - Record Class in zeroecho.pki.api.audit
Declares the purpose of an operation/access for governance and auditing.
Purpose(String) - Constructor for record class zeroecho.pki.api.audit.Purpose
Creates a purpose.
Purpose and scope - Search tag in package zeroecho.pki.spi.audit
Section
put(AttributeId, AttributeValue) - Method in class zeroecho.pki.impl.core.attr.SimpleAttributeSet.Builder
Associates the supplied identifier with exactly one value.
put(AttributeId, AttributeValue) - Method in class zeroecho.pki.impl.framework.x509.bc.SimpleAttributeSet.Builder
Associates the supplied attribute identifier with exactly one value.
putAll(AttributeSet) - Method in class zeroecho.pki.impl.core.attr.SimpleAttributeSet.Builder
Copies all attributes from the supplied set into this builder.
putAll(AttributeSet) - Method in class zeroecho.pki.impl.framework.x509.bc.SimpleAttributeSet.Builder
Copies all attributes from the supplied set into this builder.
putCa(CaRecord) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
putCa(CaRecord) - Method in interface zeroecho.pki.spi.store.PkiStore
Persists or updates a Certificate Authority (CA) record.
putCredential(Credential) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
putCredential(Credential) - Method in interface zeroecho.pki.spi.store.PkiStore
Persists a credential record.
putIssuerChainPath(IssuerChainPath) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
putIssuerChainPath(IssuerChainPath) - Method in interface zeroecho.pki.spi.store.PkiStore
Persists one immutable, already validated issuer chain path.
putIssuerGeneration(IssuerGeneration) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
putIssuerGeneration(IssuerGeneration) - Method in interface zeroecho.pki.spi.store.PkiStore
Persists one immutable canonical issuer-generation record.
putPolicyTrace(PolicyTrace) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
putPolicyTrace(PolicyTrace) - Method in interface zeroecho.pki.spi.store.PkiStore
Persists a policy trace.
putRequest(ParsedCertificationRequest) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
putRequest(ParsedCertificationRequest) - Method in interface zeroecho.pki.spi.store.PkiStore
Persists a parsed certification request.
putStatusObject(StatusObject) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
putStatusObject(StatusObject) - Method in interface zeroecho.pki.spi.store.PkiStore
Persists a status object.
putWorkflowState(WorkflowStateRecord) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
putWorkflowState(WorkflowStateRecord) - Method in interface zeroecho.pki.spi.store.PkiStore
Persists or updates an orchestrator workflow continuation record.

R

RAW - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.PublicKeyEncoding
Algorithm-defined raw public-key bytes.
RAW - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509BindingRule.PublicKeyEncoding
Algorithm-defined raw public-key bytes.
read(AttributeCatalogue, AttributeSet, AttributeId, AccessContext) - Method in interface zeroecho.pki.api.audit.AttributeGovernanceService
Reads an attribute value after applying access control.
read(AttributeCatalogue, AttributeSet, AttributeId, AccessContext) - Method in class zeroecho.pki.impl.audit.DefaultAttributeGovernanceService
 
READ - Enum constant in enum class zeroecho.pki.api.audit.AccessAction
Read an attribute value.
readAllLines() - Method in class zeroecho.pki.util.async.impl.AppendOnlyLineStore
Reads all lines from the store.
readPrefixed(String) - Static method in class zeroecho.pki.spi.bootstrap.SpiSystemProperties
Reads all string system properties with the given prefix.
ReadRevocationHistory(PkiId, int) - Constructor for record class zeroecho.pki.application.PkiOperation.ReadRevocationHistory
Validates the identifier and finite result limit.
reason() - Method in record class zeroecho.pki.api.revocation.RevocationCommand.RevokePermanently
Returns the value of the reason record component.
reason() - Method in record class zeroecho.pki.api.revocation.RevocationInputs
Returns the value of the reason record component.
reason() - Method in record class zeroecho.pki.api.revocation.RevocationQuery
Returns the value of the reason record component.
reason() - Method in record class zeroecho.pki.application.PkiOperation.RevokeCredential
Returns the value of the reason record component.
reason() - Method in record class zeroecho.pki.application.PkiOperation.TransitionAuthority
Returns the value of the reason record component.
reason() - Method in record class zeroecho.pki.spi.framework.CrlEntry
Returns the value of the reason record component.
reconcile(PkiId) - Method in interface zeroecho.pki.api.PublicationService
Reconciles one unknown external outcome using the original attempt token.
reconcile(PkiId) - Method in class zeroecho.pki.impl.core.DefaultPublicationService
 
reconcile(SigningReconciliationRequest) - Method in class zeroecho.pki.impl.core.async.PkiSigningBus
Performs one bounded synchronous recovery pass.
reconcile(PublicationAttempt) - Method in interface zeroecho.pki.spi.publish.Publisher
Resolves an existing unknown attempt without creating a new external effect.
ReconcilePublication(PkiId) - Constructor for record class zeroecho.pki.application.PkiOperation.ReconcilePublication
Validates the publication identity.
reconcileSigning(SigningReconciliationRequest) - Method in interface zeroecho.pki.application.PkiSession
Performs one synchronous, bounded signing-recovery pass.
RECONCILIATION_RESPONSE - Enum constant in enum class zeroecho.pki.api.publication.PublicationEvidence
The publisher resolved the existing attempt through reconciliation.
reconciliationFailureClass() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Returns the value of the reconciliationFailureClass record component.
record(AuditEvent) - Method in interface zeroecho.pki.api.audit.AuditService
Records an audit event.
record(AuditEvent) - Method in class zeroecho.pki.impl.audit.FileAuditSink
 
record(AuditEvent) - Method in class zeroecho.pki.impl.audit.InMemoryAuditSink
 
record(AuditEvent) - Method in class zeroecho.pki.impl.audit.StdoutAuditSink
 
record(AuditEvent) - Method in interface zeroecho.pki.spi.audit.AuditSink
Persists an audit event.
Record(PkiId, String, String, Principal, Instant, Instant, EncodedObject, SignWorkflowStore.State, long, long, Optional<Instant>, Optional<String>, Optional<EncodedObject>, Optional<Instant>, int, Optional<Instant>, Optional<SignWorkflowStore.ReconciliationFailureClass>) - Constructor for record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Creates an instance of a Record record class.
recordRevision() - Method in interface zeroecho.pki.spi.store.MetadataSnapshot.Record
Returns the non-negative record revision.
records() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Page
Returns the value of the records record component.
recoverContent(TemporaryUniqueIndex, TemporaryUniqueIndex) - Method in class zeroecho.pki.impl.fs.FilesystemStagedContentStore
 
recoverContent(TemporaryUniqueIndex, TemporaryUniqueIndex) - Method in interface zeroecho.pki.spi.store.StagedContentStore
Removes completed content not referenced by durable runtime state.
RECOVERY_REQUIRED - Enum constant in enum class zeroecho.pki.application.PkiOperationFailure
Durable recovery is required before the operation can continue.
reference() - Method in record class zeroecho.pki.api.credential.CaProfileBinding
Returns the value of the reference record component.
reference() - Method in record class zeroecho.pki.api.credential.EndEntityProfileBinding
Returns the value of the reference record component.
reference() - Method in record class zeroecho.pki.api.profile.ActiveCertificateProfile
Returns the value of the reference record component.
reference() - Method in class zeroecho.pki.api.profile.ImportedCertificateProfileVersion
 
register(PublicationRequest) - Method in interface zeroecho.pki.api.PublicationService
Registers one publication operation after its source object is committed.
register(PublicationRequest) - Method in class zeroecho.pki.impl.core.DefaultPublicationService
 
register(SignatureWorkflow.NotificationSink) - Method in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
Registers a notification sink that will be called on subsequent status changes observed by this provider instance.
register(SignatureWorkflow.NotificationSink) - Method in interface zeroecho.pki.spi.crypto.SignatureWorkflow
Registers a notification sink for status changes.
registerEndpoint(EndpointId, AsyncEndpoint<OpId, Result>) - Method in interface zeroecho.pki.util.async.AsyncBus
Registers an endpoint instance under an identifier.
registerEndpoint(EndpointId, AsyncEndpoint<OpId, Result>) - Method in class zeroecho.pki.util.async.impl.DurableAsyncBus
Registers an endpoint under the supplied endpoint identifier.
registerIssuerChainPath(PkiId, PkiId, PkiId) - Method in interface zeroecho.pki.api.CaService
Registers an additional explicit path for an existing issuer generation by appending one already-authoritative parent path.
registerIssuerChainPath(PkiId, PkiId, PkiId) - Method in class zeroecho.pki.impl.core.DefaultCaService
 
RegisterProfile(byte[]) - Constructor for record class zeroecho.pki.application.PkiOperation.RegisterProfile
Defensively snapshots the document.
RegisterPublication(PkiId, PublicationSourceType, PkiId, PublicationTarget) - Constructor for record class zeroecho.pki.application.PkiOperation.RegisterPublication
Validates the immutable publication registration fields.
reissue(ReissueCommand) - Method in interface zeroecho.pki.api.IssuanceService
Reissues based on a stored issuance record.
reissue(ReissueCommand) - Method in class zeroecho.pki.impl.core.DefaultIssuanceService
Requests credential reissuance.
ReissueCommand - Record Class in zeroecho.pki.api.issuance
Command to reissue based on a stored issuance record.
ReissueCommand(PkiId, AttributeSet) - Constructor for record class zeroecho.pki.api.issuance.ReissueCommand
Creates a reissue command.
Relation to other layers - Search tag in package zeroecho.pki.util
Section
releaseContent(DurableContentReference) - Method in class zeroecho.pki.impl.core.async.PkiSigningBus
Releases staged content from this runtime.
releaseContent(DurableContentReference, DurableContentOwner) - Method in class zeroecho.pki.impl.fs.FilesystemStagedContentStore
 
releaseContent(DurableContentReference, DurableContentOwner) - Method in interface zeroecho.pki.spi.store.StagedContentStore
Durably releases one exact owner and retires content after its last owner.
remove(byte[]) - Method in interface zeroecho.pki.spi.store.TemporaryUniqueIndex
Removes one exact bounded value after validating its physical record.
REMOVE_FROM_CRL - Enum constant in enum class zeroecho.pki.api.revocation.RevocationReason
Remove the credential from status list (unhold semantics).
renew(RenewCommand) - Method in interface zeroecho.pki.api.IssuanceService
Renews an existing credential according to policy-defined continuity semantics.
renew(RenewCommand) - Method in class zeroecho.pki.impl.core.DefaultIssuanceService
Requests credential renewal.
RenewCommand - Record Class in zeroecho.pki.api.issuance
Command to renew an existing credential.
RenewCommand(PkiId, Optional<Validity>, AttributeSet) - Constructor for record class zeroecho.pki.api.issuance.RenewCommand
Creates a renewal command.
renewSignClaim(PkiId, long, long, Duration) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
renewSignClaim(PkiId, long, long, Duration) - Method in interface zeroecho.pki.spi.store.SignWorkflowStore
Atomically renews an owned lease.
replace(ReplaceCommand) - Method in interface zeroecho.pki.api.IssuanceService
Replaces an existing credential (e.g., after compromise or attribute changes).
replace(ReplaceCommand) - Method in class zeroecho.pki.impl.core.DefaultIssuanceService
Requests credential replacement.
replace(MetadataKey, long, RepeatableContent, CancellationSignal) - Method in interface zeroecho.pki.spi.store.MetadataTransaction
Adds a compare-and-replace mutation.
ReplaceCommand - Record Class in zeroecho.pki.api.issuance
Command to replace an existing credential.
ReplaceCommand(PkiId, ParsedCertificationRequest, String, AttributeSet) - Constructor for record class zeroecho.pki.api.issuance.ReplaceCommand
Creates a replacement command.
replacePublicationRecord(PublicationRecord, PublicationRecord) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
replacePublicationRecord(PublicationRecord, PublicationRecord) - Method in interface zeroecho.pki.spi.store.PkiStore
Atomically replaces one exact observed publication state.
repository() - Method in interface zeroecho.pki.application.PkiSession
 
request() - Method in record class zeroecho.pki.api.issuance.IssuanceInputs
Returns the value of the request record component.
request() - Method in record class zeroecho.pki.api.issuance.IssueEndEntityCommand
Returns the value of the request record component.
request() - Method in class zeroecho.pki.impl.core.VerifiedIssuanceCandidate
Returns an immutable snapshot of the cryptographically verified request.
request() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Returns the value of the request record component.
requested() - Method in record class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Selection
Returns the value of the requested record component.
requestedOverrides() - Method in record class zeroecho.pki.api.issuance.IssuanceInputs
Returns the value of the requestedOverrides record component.
requestedProfileId() - Method in record class zeroecho.pki.api.request.ParsedCertificationRequest
Returns the value of the requestedProfileId record component.
requestedValidity() - Method in record class zeroecho.pki.api.ca.CaRolloverCommand
Returns the value of the requestedValidity record component.
requestedValidity() - Method in record class zeroecho.pki.api.ca.IntermediateCertIssueCommand
Returns the value of the requestedValidity record component.
requestedValidity() - Method in record class zeroecho.pki.api.request.ParsedCertificationRequest
Returns the value of the requestedValidity record component.
requesterSupplied() - Method in record class zeroecho.pki.api.profile.SubjectRdnRule
Returns the value of the requesterSupplied record component.
requestId() - Method in record class zeroecho.pki.api.request.ParsedCertificationRequest
Returns the value of the requestId record component.
requestId() - Method in record class zeroecho.pki.application.PkiOperation.InspectRequest
Returns the value of the requestId record component.
requestId() - Method in record class zeroecho.pki.application.PkiOperation.IssueCredential
Returns the value of the requestId record component.
requestId() - Method in record class zeroecho.pki.application.PkiOperation.VerifyRequest
Returns the value of the requestId record component.
requestParser() - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFramework
Returns the certification request parser used by this framework instance.
requestParser() - Method in interface zeroecho.pki.spi.framework.CredentialFramework
Returns the request parser for this framework.
RequestQuery - Record Class in zeroecho.pki.api.request
Query constraints for searching stored certification requests.
RequestQuery(Optional<FormatId>, Optional<SubjectRef>, Optional<Instant>, Optional<Instant>, Optional<String>) - Constructor for record class zeroecho.pki.api.request.RequestQuery
Creates a request query.
requests() - Method in record class zeroecho.pki.application.OcspResponseService.Command
Returns the value of the requests record component.
requests() - Method in interface zeroecho.pki.application.PkiSession
 
RequestStorePolicy - Enum Class in zeroecho.pki.api.request
Controls whether and when parsed certification requests are persisted for correlation and audit.
require(String) - Method in record class zeroecho.pki.spi.ProviderConfig
Returns a required non-blank value for the given key.
require(String, String) - Method in interface zeroecho.pki.api.algorithm.X509AlgorithmBindingRegistry
Requires that one explicit binding remains active with an exact commitment.
require(String, String) - Method in class zeroecho.pki.impl.framework.x509.ImmutableX509AlgorithmBindingRegistry
 
require(PkiId) - Static method in class zeroecho.pki.util.PkiIds
Validates that the provided identifier is non-null.
requireActive(Instant) - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.CallControl
Rejects work at or after the deadline or after cancellation.
requireActiveProfile(String) - Method in interface zeroecho.pki.api.ProfileService
Resolves and validates the exact active profile.
requireActiveProfile(String) - Method in class zeroecho.pki.impl.core.DefaultProfileService
 
requireActiveProfile(String) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
requireActiveProfile(String) - Method in interface zeroecho.pki.spi.store.PkiStore
Resolves the exact active version and validated runtime projection.
requireAllows(long) - Method in record class zeroecho.pki.api.content.ResourceLimit.LimitedTo
 
requireAllows(long) - Method in interface zeroecho.pki.api.content.ResourceLimit
Checks an incrementally observed non-negative value.
requireAllows(long) - Method in record class zeroecho.pki.api.content.ResourceLimit.UnrestrictedByDeployment
 
requireAuthority(X509AlgorithmResolver.Selection) - Method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Rejects a selection produced by a semantically different authority snapshot.
requireCompatible(AlgorithmIdentity, AlgorithmIdentity) - Static method in class zeroecho.pki.impl.framework.x509.X509SuiteCompatibility
Combines compatible signature and key identities.
requireEmailIdentity() - Method in record class zeroecho.pki.api.profile.SubjectAlternativeNamePolicy
Returns the value of the requireEmailIdentity record component.
requireExecutableSignature(String, AlgorithmExecutionCapability.Direction) - Method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Validates a persisted signature identity against the complete runtime authority intersection.
requirePermitted(AlgorithmIdentity) - Static method in class zeroecho.pki.impl.framework.x509.X509SecurityFloor
Enforces the immutable security floor.
requireProofOfPossession() - Method in record class zeroecho.pki.api.issuance.VerificationPolicy
Returns the value of the requireProofOfPossession record component.
requireServiceIdentity() - Method in record class zeroecho.pki.api.profile.SubjectAlternativeNamePolicy
Returns the value of the requireServiceIdentity record component.
requireStatusCompletion(X509SignedObjectCompletion) - Method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Validates and unwraps a status completion minted by this live authority.
requireStatusSigningPlan(X509SignedObjectCompletion) - Method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Returns the exact live SIGN plan after validating status completion provenance.
requireUsable(Credential, CredentialUse) - Method in interface zeroecho.pki.api.credential.EffectiveCredentialStatusResolver.Evaluation
Requires a credential to be usable for the supplied operation category.
RESOLUTION_FAILED_CODE - Static variable in class zeroecho.pki.impl.core.StoreBackedEffectiveCredentialStatusResolver
Stable status-resolution failure code.
resolve(String) - Static method in class zeroecho.pki.impl.framework.x509.X509BuiltInDefaults
Resolves one immutable built-in default.
resolve(String, AlgorithmIdentity, X509AlgorithmRole) - Method in class zeroecho.pki.impl.framework.x509.X509BindingCatalog
Resolves one exact identity through an explicitly selected binding.
resolve(AlgorithmIdentity, AlgorithmIdentity, AlgorithmExecutionCapability.Direction, Optional<String>, String) - Method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Resolves one effective operation and binds it to this snapshot fingerprint.
resolve(AlgorithmIdentity, AlgorithmIdentity, AlgorithmExecutionCapability.Direction, Optional<String>, String, String) - Method in class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver
Resolves an exact explicit selection.
resolve(AlgorithmIdentity, AlgorithmIdentity, AlgorithmExecutionCapability.Direction, Optional<String>, String, String) - Method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Resolves one operation through an explicitly selected role-specific binding.
resolve(AlgorithmIdentity, AlgorithmIdentity, AlgorithmExecutionCapability.Direction, Optional<String>, String, String, Optional<String>) - Method in class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver
Resolves an operation with an optional explicit X.509 binding identity.
resolve(AlgorithmIdentity, X509AlgorithmRole) - Method in class zeroecho.pki.impl.framework.x509.X509BindingCatalog
Resolves one exact identity for a closed role.
resolve(Credential) - Method in interface zeroecho.pki.api.credential.EffectiveCredentialStatusResolver.Evaluation
Resolves one credential using current revocation state and the captured evaluation time.
resolve(MetadataTransactionId) - Method in class zeroecho.pki.impl.fs.PosixTransactionalMetadataStore
Resolves a transaction outcome retained by this store.
resolve(MetadataTransactionId) - Method in interface zeroecho.pki.spi.store.TransactionalMetadataStore
Resolves a transaction outcome retained by this store.
resolveDefault(String) - Method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Resolves an immutable built-in default without extension override.
resolveIdentity(String) - Method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Resolves a canonical identity or finite built-in compatibility alias.
resolvePublicKeyInfo(KeyRef) - Method in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
 
resolvePublicKeyInfo(KeyRef) - Method in interface zeroecho.pki.spi.crypto.PublicKeyInfoSource
Resolves one managed key reference to canonical DER SubjectPublicKeyInfo.
resolver() - Method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Returns the owned effective resolver.
resolveSpkiDer(KeyRef) - Method in interface zeroecho.pki.impl.core.PublicKeyInfoResolver
Resolves the subject public key information for the supplied key reference.
RESOURCE - Static variable in class zeroecho.pki.impl.framework.x509.ZeroEchoPrivateX509Bindings
Versioned assignment resource.
RESOURCE_FAILURE - Enum constant in enum class zeroecho.pki.application.PkiOperationFailure
Filesystem, channel or another required resource failed.
ResourceLimit - Interface in zeroecho.pki.api.content
Explicit deployment-owned resource constraint.
ResourceLimit.LimitedTo - Record Class in zeroecho.pki.api.content
Positive finite deployment-owned limit.
ResourceLimit.ResourceLimitExceededException - Exception Class in zeroecho.pki.api.content
Stable non-sensitive failure for deployment resource rejection.
ResourceLimit.UnrestrictedByDeployment - Record Class in zeroecho.pki.api.content
Explicit absence of a deployment-owned limit.
resourceName() - Method in class zeroecho.pki.api.profile.BuiltInCertificateProfileTemplate
Returns the validated classpath resource name.
resourceScopes() - Method in interface zeroecho.pki.application.PkiSession
Returns the read-only authoritative identifier resolver used to cross-check realm and authority scopes before protected operations.
respond(OcspResponseService.Command) - Method in interface zeroecho.pki.application.OcspResponseService
Resolves one stable view and signs exactly one response.
responderCredentialId() - Method in record class zeroecho.pki.application.OcspResponseService.Command
Returns the value of the responderCredentialId record component.
responderId() - Method in record class zeroecho.pki.application.OcspResponseService.Command
Returns the value of the responderId record component.
Response(byte[], long, String, int, int, int) - Constructor for record class zeroecho.pki.application.OcspResponseService.Response
Defensively owns response DER.
responseChain() - Method in record class zeroecho.pki.application.OcspResponseService.Command
Returns the value of the responseChain record component.
Responsibilities - Search tag in package zeroecho.pki.api.ca
Section
restoreBackup(RestoreRequest) - Method in interface zeroecho.pki.api.BackupService
Restores PKI state from a backup artifact.
restoreContent(StagedContentStore) - Method in class zeroecho.pki.impl.core.async.PkiSigningBus.SignContinuation
Restores the committed reference through its owning store for delayed cleanup.
restoreId() - Method in record class zeroecho.pki.api.backup.RestoreReport
Returns the value of the restoreId record component.
restoreReference(String, String, Encoding, long, String, DurableContentReference.Lifecycle) - Method in class zeroecho.pki.impl.fs.FilesystemStagedContentStore
 
restoreReference(String, String, Encoding, long, String, DurableContentReference.Lifecycle) - Method in interface zeroecho.pki.spi.store.StagedContentStore
Restores one persisted reference through this owning store.
RestoreReport - Record Class in zeroecho.pki.api.backup
Result report for a restore operation.
RestoreReport(PkiId, boolean, List<String>, List<String>) - Constructor for record class zeroecho.pki.api.backup.RestoreReport
Creates a restore report.
RestoreRequest - Record Class in zeroecho.pki.api.backup
Requests restore of PKI state from a backup artifact.
RestoreRequest(BackupArtifact, AttributeSet) - Constructor for record class zeroecho.pki.api.backup.RestoreRequest
Creates a restore request.
result() - Method in record class zeroecho.pki.application.PkiOperationOutcome.Success
Returns the value of the result record component.
result() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.OperationStatus
Returns the value of the result record component.
result() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Returns the value of the result record component.
result() - Method in record class zeroecho.pki.util.async.AsyncEvent
Returns the value of the result record component.
result(OpId) - Method in interface zeroecho.pki.util.async.AsyncEndpoint
Returns a best-effort result for a successful operation.
RESULT_PERSISTENCE_UNKNOWN - Enum constant in enum class zeroecho.pki.api.publication.PublicationFailure
Durable persistence of a returned result could not be established.
ResultCodec<R> - Interface in zeroecho.pki.util.async.codec
Optional persistence codec for results.
Result retention - Search tag in interface zeroecho.pki.util.async.AsyncBus
Section
retainContent(DurableContentReference, DurableContentOwner) - Method in class zeroecho.pki.impl.fs.FilesystemStagedContentStore
 
retainContent(DurableContentReference, DurableContentOwner) - Method in interface zeroecho.pki.spi.store.StagedContentStore
Durably retains sealed content for one typed business owner.
retentionWindow() - Method in class zeroecho.pki.impl.fs.FsHistoryPolicy
Optional retention window.
retire(OpId) - Method in class zeroecho.pki.util.async.impl.DurableAsyncBus
Durably retires all bus state for an operation.
RETIRED - Enum constant in enum class zeroecho.pki.api.ca.CaState
CA is retired and must not issue new credentials.
RETIRED - Enum constant in enum class zeroecho.pki.api.ca.IssuerGenerationState
Retained for validation but unavailable for new issuance.
RETIRED - Enum constant in enum class zeroecho.pki.spi.store.SignWorkflowStore.State
 
retireSign(PkiId, long, long) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
retireSign(PkiId, long, long) - Method in interface zeroecho.pki.spi.store.SignWorkflowStore
Atomically retires a terminal current record while retaining its identity and any successful result.
retireSignOperation(PkiId, String) - Method in class zeroecho.pki.impl.core.async.PkiSigningBus
Best-effort retirement of a sign operation and all locally owned state.
retireUnownedContent(DurableContentReference) - Method in class zeroecho.pki.impl.fs.FilesystemStagedContentStore
 
retireUnownedContent(DurableContentReference) - Method in interface zeroecho.pki.spi.store.StagedContentStore
Retires sealed content that has no durable owner.
retry(PkiId) - Method in interface zeroecho.pki.api.PublicationService
Explicitly retries one retryable operation as a new numbered attempt.
retry(PkiId) - Method in class zeroecho.pki.impl.core.DefaultPublicationService
 
retryable() - Method in record class zeroecho.pki.application.SigningReconciliationResult
Returns the value of the retryable record component.
RETRYABLE_FAILURE - Enum constant in enum class zeroecho.pki.api.publication.PublicationStatus
The attempt definitively failed and an explicit retry is permitted.
RETRYABLE_FAILURE - Enum constant in enum class zeroecho.pki.spi.publish.PublicationOutcome
No unsafe duplicate effect exists and an explicit retry is permitted.
RetryPublication(PkiId) - Constructor for record class zeroecho.pki.application.PkiOperation.RetryPublication
Validates the publication identity.
reverse(X509AlgorithmIdentifier, X509AlgorithmRole) - Method in class zeroecho.pki.impl.framework.x509.X509BindingCatalog
Reverse-resolves an exact role-specific representation.
revision() - Method in record class zeroecho.pki.api.revocation.RevocationTransition
Returns the value of the revision record component.
revision() - Method in interface zeroecho.pki.spi.store.MetadataSnapshot
Returns the captured non-negative committed store revision.
revision() - Method in interface zeroecho.pki.spi.store.RevocationSnapshot
 
revision() - Method in interface zeroecho.pki.spi.store.RevocationView
 
revision() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Returns the value of the revision record component.
REVOCATION_LIST - Enum constant in enum class zeroecho.pki.api.status.StatusObjectType
Generic revocation list for non-X.509 frameworks.
RevocationCommand - Interface in zeroecho.pki.api.revocation
Closed, immutable commands accepted by the revocation state machine.
RevocationCommand.Hold - Record Class in zeroecho.pki.api.revocation
Places a credential on hold.
RevocationCommand.RevokePermanently - Record Class in zeroecho.pki.api.revocation
Permanently revokes a credential.
RevocationCommand.Unhold - Record Class in zeroecho.pki.api.revocation
Removes an existing hold.
revocationCommitment() - Method in record class zeroecho.pki.application.OcspResponseService.Response
Returns the value of the revocationCommitment record component.
RevocationHistory - Interface in zeroecho.pki.spi.store
Closeable one-pass history of one credential in credential-local revision order.
revocationHistoryPolicy() - Method in record class zeroecho.pki.impl.fs.FsPkiStoreOptions
Returns the value of the revocationHistoryPolicy record component.
RevocationInputs - Record Class in zeroecho.pki.api.revocation
Normalized inputs for revocation policy evaluation.
RevocationInputs(PkiId, RevocationReason, AttributeSet) - Constructor for record class zeroecho.pki.api.revocation.RevocationInputs
Creates revocation inputs.
RevocationQuery - Record Class in zeroecho.pki.api.revocation
Query constraints for searching revocation records.
RevocationQuery(Optional<PkiId>, Optional<RevocationReason>, Optional<Instant>, Optional<Instant>) - Constructor for record class zeroecho.pki.api.revocation.RevocationQuery
Creates a revocation query.
RevocationReason - Enum Class in zeroecho.pki.api.revocation
Revocation reason codes with PKIX-compatible semantics.
RevocationRecord - Record Class in zeroecho.pki.api.revocation
Immutable current revocation state for one credential.
RevocationRecord(PkiId, RevocationTransition) - Constructor for record class zeroecho.pki.api.revocation.RevocationRecord
Creates a current-state record.
revocationRevision() - Method in record class zeroecho.pki.application.OcspResponseService.Response
Returns the value of the revocationRevision record component.
revocations() - Method in interface zeroecho.pki.application.PkiSession
 
RevocationService - Interface in zeroecho.pki.api
Authoritative revocation transition, current-state, and history administration.
RevocationSnapshot - Interface in zeroecho.pki.spi.store
Stable, restartable ordered current-state view at one authoritative revision.
RevocationSnapshot.Cursor - Interface in zeroecho.pki.spi.store
One-pass current-state cursor.
RevocationState - Enum Class in zeroecho.pki.api.revocation
Effective state recorded by the authoritative global revocation log.
RevocationTransition - Record Class in zeroecho.pki.api.revocation
One committed transition in the authoritative global revocation log.
RevocationTransition(long, RevocationState, Instant, Optional<RevocationReason>, AttributeSet) - Constructor for record class zeroecho.pki.api.revocation.RevocationTransition
Validates structural transition fields.
RevocationView - Interface in zeroecho.pki.spi.store
Stable direct-lookup view of one authoritative revocation log revision.
RevokeCredential(PkiId, RevocationReason) - Constructor for record class zeroecho.pki.application.PkiOperation.RevokeCredential
Validates permanent-revocation inputs.
REVOKED - Enum constant in enum class zeroecho.pki.api.credential.CredentialStatus
Credential is revoked.
revokedAfter() - Method in record class zeroecho.pki.api.revocation.RevocationQuery
Returns the value of the revokedAfter record component.
revokedBefore() - Method in record class zeroecho.pki.api.revocation.RevocationQuery
Returns the value of the revokedBefore record component.
revokedCount() - Method in record class zeroecho.pki.application.OcspResponseService.Response
Returns the value of the revokedCount record component.
Revoked-entry handling - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509StatusObjectGenerator
Section
revokePermanently(RevocationCommand.RevokePermanently) - Method in interface zeroecho.pki.api.RevocationService
Permanently revokes a credential.
revokePermanently(RevocationCommand.RevokePermanently) - Method in class zeroecho.pki.impl.core.DefaultRevocationService
 
RevokePermanently(PkiId, RevocationReason, AttributeSet) - Constructor for record class zeroecho.pki.api.revocation.RevocationCommand.RevokePermanently
Validates and snapshots the command.
RFC822_NAME - Enum constant in enum class zeroecho.pki.api.profile.SubjectAlternativeNameType
RFC 822 mailbox name.
Rfc822Name(String) - Constructor for record class zeroecho.pki.api.request.SubjectAlternativeName.Rfc822Name
Canonicalizes and validates the mailbox.
role() - Method in record class zeroecho.pki.api.algorithm.X509AlgorithmBinding
Returns the value of the role record component.
role() - Method in record class zeroecho.pki.application.PkiOperation.ListAlgorithmBindings
Returns the value of the role record component.
role() - Method in class zeroecho.pki.application.PkiRepositoryContent
 
role() - Method in interface zeroecho.pki.impl.framework.x509.X509BindingRule
Returns the closed X.509 role.
rolloverCaCertificate(CaRolloverCommand) - Method in interface zeroecho.pki.api.CaService
Performs a CA credential rollover while keeping the same key reference.
rolloverCaCertificate(CaRolloverCommand) - Method in class zeroecho.pki.impl.core.DefaultCaService
Requests CA certificate rollover.
ROOT - Enum constant in enum class zeroecho.pki.api.ca.CaKind
Root CA (initial credential is typically self-issued).
ROOT_CA - Enum constant in enum class zeroecho.pki.api.profile.CertificateProfileKind
Self-signed root certification-authority certificate.
rotateCaKey(CaKeyRotationCommand) - Method in interface zeroecho.pki.api.CaService
Rotates the CA key reference and issues new corresponding CA credentials.
rotateCaKey(CaKeyRotationCommand) - Method in class zeroecho.pki.impl.core.DefaultCaService
Requests CA key rotation.
RSA_PKCS1_DER - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.PublicKeyEncoding
Standard RSA PKCS#1 public-key DER.
RSA_PKCS1_DER - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509BindingRule.PublicKeyEncoding
Algorithm-defined PKCS#1 RSA public-key structure.
ruleId() - Method in record class zeroecho.pki.api.policy.PolicyTraceStep
Returns the value of the ruleId record component.
rules() - Method in record class zeroecho.pki.api.profile.SubjectAlternativeNamePolicy
Returns the value of the rules record component.
rules() - Method in record class zeroecho.pki.api.profile.SubjectPolicy
Returns the value of the rules record component.
rules() - Method in class zeroecho.pki.impl.framework.x509.X509BindingCatalog
Returns deterministic immutable binding rules.
rules() - Method in interface zeroecho.pki.impl.framework.x509.X509BindingRuleProvider
Returns immutable additive binding rules.
rules() - Method in interface zeroecho.pki.spi.algorithm.X509AlgorithmBindingProvider
 
RUNNING - Enum constant in enum class zeroecho.pki.spi.crypto.SignatureWorkflow.State
 
RUNNING - Enum constant in enum class zeroecho.pki.util.async.AsyncState
The operation is currently being processed.

S

scan(MetadataSnapshot.KeyRange, CancellationSignal) - Method in interface zeroecho.pki.spi.store.MetadataSnapshot
Opens a lazy deterministic scan over this stable view.
SCHEMA_VERSION - Static variable in record class zeroecho.pki.api.profile.CertificateProfileDefinition
Current certificate-profile document schema version.
schemaVersion() - Method in class zeroecho.pki.api.profile.ImportedCertificateProfileVersion
 
Scope - Search tag in class zeroecho.pki.impl.framework.x509.bc.OidAlgorithmMapper
Section
Scope - Search tag in package zeroecho.pki.api.backup
Section
Scope - Search tag in package zeroecho.pki.impl.audit
Section
Scope - Search tag in package zeroecho.pki.impl.fs
Section
Scope and responsibilities - Search tag in package zeroecho.pki.api.orch
Section
search(AuditQuery) - Method in interface zeroecho.pki.api.audit.AuditService
Searches audit events by query constraints.
search(AuditQuery) - Method in class zeroecho.pki.impl.audit.FileAuditSink
 
search(AuditQuery) - Method in class zeroecho.pki.impl.audit.InMemoryAuditSink
 
search(CredentialQuery) - Method in interface zeroecho.pki.api.CredentialInventoryService
Searches credentials by query constraints.
search(RequestQuery) - Method in interface zeroecho.pki.api.CertificationRequestService
Searches stored requests.
search(RequestQuery) - Method in class zeroecho.pki.impl.core.DefaultCertificationRequestService
Searches stored certification requests matching the supplied query.
search(RevocationQuery) - Method in interface zeroecho.pki.api.RevocationService
Searches a stable ordered population view by current transition.
search(RevocationQuery) - Method in class zeroecho.pki.impl.core.DefaultRevocationService
 
SECRET - Enum constant in enum class zeroecho.pki.api.attr.AttributeSensitivity
Secret value; must not be disclosed outside the strictest trust boundary.
Security - Search tag in class zeroecho.pki.PkiApplication
Section
Security - Search tag in class zeroecho.pki.impl.async.FileBackedAsyncBusProvider
Section
Security - Search tag in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflowProvider
Section
Security - Search tag in class zeroecho.pki.util.PkiIds
Section
Security - Search tag in interface zeroecho.pki.spi.ConfigurableProvider
Section
Security - Search tag in interface zeroecho.pki.spi.store.PkiStore
Section
Security - Search tag in package zeroecho.pki.api.audit
Section
Security - Search tag in package zeroecho.pki.impl.async
Section
Security - Search tag in package zeroecho.pki.spi.async
Section
Security - Search tag in package zeroecho.pki.util.async
Section
Security - Search tag in package zeroecho.pki.util.async.codec
Section
Security - Search tag in package zeroecho.pki.util.async.impl
Section
Security - Search tag in record class zeroecho.pki.api.orch.WorkflowStateRecord
Section
SECURITY_FLOOR - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Failure
Non-overridable security floor rejected the identity.
Security and compliance requirements - Search tag in package zeroecho.pki.spi.audit
Section
Security considerations - Search tag in class zeroecho.pki.impl.core.DefaultCaService
Section
Security considerations - Search tag in class zeroecho.pki.impl.core.DefaultCertificationRequestService
Section
Security considerations - Search tag in class zeroecho.pki.impl.core.DefaultIssuanceService
Section
Security considerations - Search tag in class zeroecho.pki.impl.core.DefaultStatusObjectService
Section
Security considerations - Search tag in class zeroecho.pki.impl.core.async.OperationIdCodec
Section
Security considerations - Search tag in class zeroecho.pki.impl.core.async.PkiAsyncCodecs
Section
Security considerations - Search tag in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
Section
Security considerations - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509Attributes
Section
Security considerations - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509CertificationRequestParser
Section
Security considerations - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFramework
Section
Security considerations - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialIssuerBackend
Section
Security considerations - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509FrameworkAttributeMapper
Section
Security considerations - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509ProofOfPossessionVerifier
Section
Security considerations - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509StatusObjectGenerator
Section
Security considerations - Search tag in class zeroecho.pki.impl.framework.x509.bc.OidAlgorithmMapper
Section
Security considerations - Search tag in class zeroecho.pki.impl.framework.x509.bc.PkiBusContentSigner
Section
Security considerations - Search tag in class zeroecho.pki.impl.framework.x509.bc.WorkflowProofOfPossessionVerifier
Section
Security considerations - Search tag in interface zeroecho.pki.impl.core.PublicKeyInfoResolver
Section
Security considerations - Search tag in interface zeroecho.pki.spi.framework.CredentialIssuerBackend
Section
Security considerations - Search tag in package zeroecho.pki.impl.core
Section
Security considerations - Search tag in package zeroecho.pki.impl.core.async
Section
Security considerations - Search tag in package zeroecho.pki.impl.core.attr
Section
Security considerations - Search tag in package zeroecho.pki.impl.crypto.zeroecholib
Section
Security considerations - Search tag in package zeroecho.pki.impl.framework.x509.bc
Section
Security considerations - Search tag in package zeroecho.pki.impl.fs
Section
Security constraints - Search tag in package zeroecho.pki.spi.crypto
Section
Security Notes - Search tag in class zeroecho.pki.impl.fs.FilesystemPkiStore
Section
Security properties - Search tag in class zeroecho.pki.impl.audit.DefaultAttributeGovernanceService
Section
Security properties - Search tag in class zeroecho.pki.impl.audit.FileAuditSink
Section
Security properties - Search tag in class zeroecho.pki.impl.audit.InMemoryAuditSink
Section
Security properties - Search tag in class zeroecho.pki.impl.audit.StdoutAuditSink
Section
Security properties - Search tag in package zeroecho.pki.impl.audit
Section
Security properties - Search tag in record class zeroecho.pki.api.audit.AuditEvent
Section
select(Class<T>, String, SpiSelector.ProviderId<T>) - Static method in class zeroecho.pki.spi.bootstrap.SpiSelector
Selects a provider for the given service type.
selection() - Method in class zeroecho.pki.impl.framework.x509.X509ExecutionPlan
Returns the immutable semantic selection.
Selection - Search tag in package zeroecho.pki.spi.async
Section
Selection(AlgorithmIdentity, AlgorithmSuite, X509AlgorithmIdentifier, AlgorithmExecutionCapability, AlgorithmExecutionCapability.Direction, String, String) - Constructor for record class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Selection
Creates an immutable selection.
selectIssuancePath(PkiId, PkiId, PkiId, String) - Method in interface zeroecho.pki.api.CaService
Atomically selects the exact issuer generation and path used for future issuance and bundle construction.
selectIssuancePath(PkiId, PkiId, PkiId, String) - Method in class zeroecho.pki.impl.core.DefaultCaService
 
semanticCommitment() - Method in record class zeroecho.pki.api.algorithm.X509AlgorithmBinding
Returns the value of the semanticCommitment record component.
semanticCommitment() - Method in record class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy.BindingReference
Returns the value of the semanticCommitment record component.
semanticFingerprint() - Method in interface zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Policy
Returns stable non-secret policy semantics for snapshot provenance.
semanticFingerprint() - Method in class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Returns the stable snapshot fingerprint.
semanticFingerprint() - Method in interface zeroecho.pki.impl.framework.x509.X509BindingRule
Returns an immutable semantic fingerprint used for conflict diagnostics.
semanticFingerprint() - Method in class zeroecho.pki.impl.framework.x509.X509ComponentCatalog
Returns a deterministic semantic fingerprint.
semanticFingerprint() - Static method in class zeroecho.pki.impl.framework.x509.X509SecurityFloor
Returns immutable security-floor semantics for authority provenance.
semanticFingerprint() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.SignRequest
Returns the value of the semanticFingerprint record component.
semanticFingerprint(String, Instant) - Method in class zeroecho.pki.impl.core.async.PkiSigningBus.SignContinuation
Computes the canonical semantic fingerprint for this persisted request.
Semantics - Search tag in package zeroecho.pki.impl.core.attr
Section
SENSITIVE - Enum constant in enum class zeroecho.pki.api.attr.AttributeSensitivity
Sensitive value; disclosure may create security or privacy risk.
sensitivity() - Method in record class zeroecho.pki.api.attr.AttributeDefinition
Returns the value of the sensitivity record component.
SEQUENCE_TAG - Static variable in class zeroecho.pki.impl.framework.x509.StreamingDerWriter
DER universal SEQUENCE tag.
serial() - Method in record class zeroecho.pki.application.OcspResponseService.CertId
Returns the value of the serial record component.
serial() - Method in class zeroecho.pki.impl.core.ValidatedCaCertificateRequest
Returns the issuer-controlled serial.
SERIAL - Static variable in class zeroecho.pki.impl.framework.x509.bc.BcX509Attributes
Attribute identifier for an X.509 certificate serial number.
SERIAL_NUMBER - Enum constant in enum class zeroecho.pki.api.profile.SubjectRdnType
X.520 serial number attribute.
SERIALIZABLE_MULTI_WRITER - Enum constant in enum class zeroecho.pki.spi.store.MetadataStoreCapabilities.WriterModel
Concurrent writers have serializable transaction outcomes.
serialNumber() - Method in record class zeroecho.pki.spi.framework.CrlEntry
Returns the value of the serialNumber record component.
serialOrUniqueId() - Method in record class zeroecho.pki.api.credential.Credential
Returns the value of the serialOrUniqueId record component.
ServiceLoader compatibility - Search tag in class zeroecho.pki.impl.audit.FileAuditSink
Section
Service registration - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFrameworkProvider
Section
setCaState(PkiId, CaState, String) - Method in interface zeroecho.pki.api.CaService
Updates CA operational state.
setCaState(PkiId, CaState, String) - Method in class zeroecho.pki.impl.core.DefaultCaService
Updates the lifecycle state of an existing CA record.
SHA1 - Enum constant in enum class zeroecho.pki.application.OcspResponseService.CertIdHash
 
sha256() - Method in interface zeroecho.pki.api.content.DurableContentReference
Returns the canonical lowercase SHA-256 integrity value.
sha256() - Method in class zeroecho.pki.application.PkiRepositoryContent
 
sha256() - Method in record class zeroecho.pki.spi.publish.PublicationAttempt
Returns the value of the sha256 record component.
SHA256 - Enum constant in enum class zeroecho.pki.application.OcspResponseService.CertIdHash
 
shortFingerprint() - Method in class zeroecho.pki.api.profile.CertificateProfileRef
Returns a short non-authoritative fingerprint suitable for audit metadata.
signature() - Method in record class zeroecho.pki.impl.framework.x509.bc.BcX509SignedObjectValidator.CertificateBindings
Returns the value of the signature record component.
signature() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.OperationResult
Returns the value of the signature record component.
signature() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.VerifyRequest
Returns the value of the signature record component.
SIGNATURE_ALGORITHM - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509AlgorithmRole
Signature algorithm on a certificate, CRL, or certification request.
signatureAlgorithm() - Method in record class zeroecho.pki.application.OcspResponseService.Command
Returns the value of the signatureAlgorithm record component.
signatureAlgorithm() - Method in record class zeroecho.pki.application.PkiSessionConfiguration.SigningConfiguration
Returns the value of the signatureAlgorithm record component.
signatureBindingId() - Method in record class zeroecho.pki.application.OcspResponseService.Command
Returns the value of the signatureBindingId record component.
signatureEncoding() - Method in record class zeroecho.pki.api.algorithm.X509AlgorithmBinding
Returns the value of the signatureEncoding record component.
signatureEncoding() - Method in interface zeroecho.pki.impl.framework.x509.X509BindingRule
Returns the exact signature-byte encoding rule.
signatureLength() - Method in record class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectLayout
Returns the value of the signatureLength record component.
signatureOffset() - Method in record class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectLayout
Returns the value of the signatureOffset record component.
SignatureWorkflow - Interface in zeroecho.pki.spi.crypto
Asynchronous signature workflow boundary for PKI.
SignatureWorkflow.CallControl - Record Class in zeroecho.pki.spi.crypto
Immutable cooperative deadline and cancellation control for one provider invocation.
SignatureWorkflow.NotificationSink - Interface in zeroecho.pki.spi.crypto
Callback interface for receiving asynchronous status updates.
SignatureWorkflow.OperationResult - Record Class in zeroecho.pki.spi.crypto
Terminal result of a signature workflow operation.
SignatureWorkflow.OperationStatus - Record Class in zeroecho.pki.spi.crypto
Status of a long-running or asynchronous signature workflow operation.
SignatureWorkflow.Registration - Interface in zeroecho.pki.spi.crypto
Handle representing a registered SignatureWorkflow.NotificationSink.
SignatureWorkflow.SignRequest - Record Class in zeroecho.pki.spi.crypto
Signing request.
SignatureWorkflow.State - Enum Class in zeroecho.pki.spi.crypto
Lifecycle states of a signature workflow operation.
SignatureWorkflow.VerifyRequest - Record Class in zeroecho.pki.spi.crypto
Verification request.
SignatureWorkflowProvider - Interface in zeroecho.pki.spi.crypto
ServiceLoader provider for SignatureWorkflow.
SignatureWorkflowRuntimeDependencies - Class in zeroecho.pki.spi.crypto
Immutable runtime dependencies supplied when opening a signature workflow.
SignContinuation(AccessContext, String, DurableContentReference, KeyRef, Encoding, Optional<PkiId>) - Constructor for class zeroecho.pki.impl.core.async.PkiSigningBus.SignContinuation
Creates a continuation payload for a sign operation.
SignedObjectLayout(long, long, long, long, long, long, long, long, long, long, long, long, Optional<Instant>, Optional<Instant>) - Constructor for record class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectLayout
Creates an immutable layout for one validated signed object.
signerOpId() - Method in class zeroecho.pki.impl.core.async.PkiSigningBus.SignContinuation
Returns the downstream signer workflow operation identifier when it has already been assigned.
signing() - Method in record class zeroecho.pki.application.PkiSessionConfiguration
Returns the value of the signing record component.
SIGNING_OPERATION - Enum constant in enum class zeroecho.pki.api.content.DurableContentOwner.Category
Pending or recoverable signing operation.
SigningConfiguration(ProviderConfig, ProviderConfig, String, String, Duration, Optional<String>) - Constructor for record class zeroecho.pki.application.PkiSessionConfiguration.SigningConfiguration
Creates standard-mode signing configuration.
SigningConfiguration(ProviderConfig, ProviderConfig, String, String, Duration, Optional<String>, Optional<String>, Optional<String>, Optional<String>) - Constructor for record class zeroecho.pki.application.PkiSessionConfiguration.SigningConfiguration
Validates and snapshots the signing configuration.
signingHorizon() - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
signingHorizon() - Method in interface zeroecho.pki.spi.store.SignWorkflowStore
Returns configured retention/identity horizon.
signingIdPermittedSkew() - Method in record class zeroecho.pki.impl.fs.FsPkiStoreOptions
Returns the value of the signingIdPermittedSkew record component.
signingKeyRef() - Method in record class zeroecho.pki.api.ca.IssuerGeneration
Returns the value of the signingKeyRef record component.
signingKeyRef() - Method in record class zeroecho.pki.application.OcspResponseService.Command
Returns the value of the signingKeyRef record component.
Signing lifecycle and recovery - Search tag in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
Section
Signing model - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialIssuerBackend
Section
Signing model - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509StatusObjectGenerator
Section
signingNamespace() - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
signingNamespace() - Method in interface zeroecho.pki.spi.store.SignWorkflowStore
Returns the stable trusted namespace owned by this store.
signingNow() - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
signingNow() - Method in interface zeroecho.pki.spi.store.SignWorkflowStore
Returns store-authoritative time.
signingOperation(PkiId) - Static method in record class zeroecho.pki.api.content.DurableContentOwner
Creates the canonical owner for one signing operation.
signingOperationHorizon() - Method in record class zeroecho.pki.impl.fs.FsPkiStoreOptions
Returns the value of the signingOperationHorizon record component.
signingPermittedSkew() - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
signingPermittedSkew() - Method in interface zeroecho.pki.spi.store.SignWorkflowStore
Returns the accepted future clock skew for signing identifiers.
SigningReconciliationRequest - Record Class in zeroecho.pki.application
Immutable bounds for one transport-neutral signing reconciliation pass.
SigningReconciliationRequest(Optional<String>, int, int, Instant, Duration, CancellationSignal) - Constructor for record class zeroecho.pki.application.SigningReconciliationRequest
Validates and snapshots one pass request.
SigningReconciliationResult - Record Class in zeroecho.pki.application
Aggregate safe outcome of one bounded signing reconciliation pass.
SigningReconciliationResult(Optional<String>, int, int, int, int, boolean) - Constructor for record class zeroecho.pki.application.SigningReconciliationResult
Validates aggregate counts.
SigningSubmissionId - Record Class in zeroecho.pki.api.orch
Versioned ZeroEcho signing-submission identifier.
SigningSubmissionId(PkiId, String, Instant) - Constructor for record class zeroecho.pki.api.orch.SigningSubmissionId
Creates an instance of a SigningSubmissionId record class.
signingTtl() - Method in record class zeroecho.pki.application.PkiSessionConfiguration.SigningConfiguration
Returns the value of the signingTtl record component.
SignRequest(PkiId, String, String, long, AccessContext, KeyRef, String, RepeatableContent, Optional<Encoding>, Optional<Instant>, CancellationSignal) - Constructor for record class zeroecho.pki.spi.crypto.SignatureWorkflow.SignRequest
Creates an instance of a SignRequest record class.
SignWorkflowStore - Interface in zeroecho.pki.spi.store
Authoritative durable state machine for signing submissions.
SignWorkflowStore.CreateResult - Enum Class in zeroecho.pki.spi.store
Result of idempotent intent creation.
SignWorkflowStore.Page - Record Class in zeroecho.pki.spi.store
One bounded snapshot page ordered by canonical submission identifier.
SignWorkflowStore.ReconciliationFailureClass - Enum Class in zeroecho.pki.spi.store
Durable classification for one deferred reconciliation retry.
SignWorkflowStore.Record - Record Class in zeroecho.pki.spi.store
Complete durable signing state.
SignWorkflowStore.State - Enum Class in zeroecho.pki.spi.store
Signing orchestration states.
SimpleAttributeSet - Class in zeroecho.pki.impl.framework.x509.bc
Minimal immutable AttributeSet implementation used by the Bouncy Castle backed X.509 framework adapter.
SimpleAttributeSet - Record Class in zeroecho.pki.impl.core.attr
Minimal immutable AttributeSet implementation used by PKI core runtime services.
SimpleAttributeSet() - Constructor for record class zeroecho.pki.impl.core.attr.SimpleAttributeSet
Creates an empty attribute set.
SimpleAttributeSet() - Constructor for class zeroecho.pki.impl.framework.x509.bc.SimpleAttributeSet
Creates an empty attribute set.
SimpleAttributeSet(List<SimpleAttributeSet.Entry>) - Constructor for record class zeroecho.pki.impl.core.attr.SimpleAttributeSet
Creates an immutable attribute set from the supplied ordered entries.
SimpleAttributeSet.Builder - Class in zeroecho.pki.impl.core.attr
Mutable builder for SimpleAttributeSet.
SimpleAttributeSet.Builder - Class in zeroecho.pki.impl.framework.x509.bc
Mutable builder for SimpleAttributeSet.
SimpleAttributeSet.Entry - Record Class in zeroecho.pki.impl.core.attr
Immutable representation of one attribute entry.
snapshot() - Method in class zeroecho.pki.impl.audit.InMemoryAuditSink
Returns an immutable snapshot of all currently retained events in insertion order (oldest to newest).
snapshot() - Static method in class zeroecho.pki.impl.framework.x509.X509BuiltInDefaults
Returns a semantic fingerprint of all immutable defaults.
snapshot() - Method in class zeroecho.pki.impl.fs.PosixTransactionalMetadataStore
Opens a stable snapshot of the latest committed store revision.
snapshot() - Method in interface zeroecho.pki.spi.store.TransactionalMetadataStore
Opens a stable snapshot of the latest committed store revision.
snapshot() - Method in record class zeroecho.pki.util.async.AsyncEvent
Returns the value of the snapshot record component.
snapshot(OpId) - Method in interface zeroecho.pki.util.async.AsyncBus
Returns immutable operation metadata if present.
snapshot(OpId) - Method in class zeroecho.pki.util.async.impl.DurableAsyncBus
Returns the currently active snapshot for an operation.
snapshotId() - Method in interface zeroecho.pki.spi.store.RevocationSnapshot
Returns stable non-secret snapshot provenance.
SnapshotRevocations(int) - Constructor for record class zeroecho.pki.application.PkiOperation.SnapshotRevocations
Validates the presentation limit.
sourceId() - Method in record class zeroecho.pki.api.publication.PublicationRecord
Returns the value of the sourceId record component.
sourceId() - Method in record class zeroecho.pki.api.publication.PublicationRequest
Returns the value of the sourceId record component.
sourceId() - Method in record class zeroecho.pki.application.PkiOperation.RegisterPublication
Returns the value of the sourceId record component.
sourceId() - Method in record class zeroecho.pki.spi.publish.PublicationAttempt
Returns the value of the sourceId record component.
sourceType() - Method in record class zeroecho.pki.api.publication.PublicationQuery
Returns the value of the sourceType record component.
sourceType() - Method in record class zeroecho.pki.api.publication.PublicationRecord
Returns the value of the sourceType record component.
sourceType() - Method in record class zeroecho.pki.api.publication.PublicationRequest
Returns the value of the sourceType record component.
sourceType() - Method in record class zeroecho.pki.application.PkiOperation.RegisterPublication
Returns the value of the sourceType record component.
sourceType() - Method in record class zeroecho.pki.spi.publish.PublicationAttempt
Returns the value of the sourceType record component.
SpiSelector - Class in zeroecho.pki.spi.bootstrap
Utility for selecting ServiceLoader providers by a stable identifier.
SpiSelector.ProviderId<T> - Interface in zeroecho.pki.spi.bootstrap
Provider id accessor used by the selector.
SpiSystemProperties - Class in zeroecho.pki.spi.bootstrap
Reads component configuration from system properties using a prefix convention.
stability() - Method in record class zeroecho.pki.api.attr.AttributeDefinition
Returns the value of the stability record component.
Stability note - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509Attributes
Section
STABLE - Enum constant in enum class zeroecho.pki.api.attr.AttributeStability
Attribute is stable and recommended for general use.
stage(OneShotContent, Encoding, DurableContentReference.Lifecycle, CancellationSignal) - Method in interface zeroecho.pki.spi.store.StagedContentStore
Stages a one-shot input incrementally.
stagedContent() - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
stagedContent() - Method in interface zeroecho.pki.spi.store.PkiStore
Returns the runtime-owned durable streaming-content store.
stagedContentBytes() - Method in record class zeroecho.pki.api.content.DeploymentResourcePolicy
Returns the value of the stagedContentBytes record component.
StagedContentStore - Interface in zeroecho.pki.spi.store
Durable, runtime-owned staging boundary for signed-object content.
standard(AlgorithmIdentity, X509AlgorithmBinding.Role) - Method in interface zeroecho.pki.api.algorithm.X509AlgorithmBindingRegistry
Resolves the standard default for one identity and role.
standard(AlgorithmIdentity, X509AlgorithmBinding.Role) - Method in class zeroecho.pki.impl.framework.x509.ImmutableX509AlgorithmBindingRegistry
 
STANDARD - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.Origin
Published standards assignment.
STANDARD_INTEROPERABLE - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.Interoperability
Published standards ecosystems.
STANDARD_ONLY - Enum constant in enum class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy.Mode
Only sealed official bindings may be selected.
standardOnly() - Static method in record class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy
 
StandardX509Bindings - Class in zeroecho.pki.impl.framework.x509
Immutable authoritative standard X.509 bootstrap bindings.
state() - Method in record class zeroecho.pki.api.ca.CaQuery
Returns the value of the state record component.
state() - Method in record class zeroecho.pki.api.ca.CaRecord
Returns the value of the state record component.
state() - Method in record class zeroecho.pki.api.ca.IssuerGeneration
Returns the value of the state record component.
state() - Method in record class zeroecho.pki.api.revocation.RevocationTransition
Returns the value of the state record component.
state() - Method in record class zeroecho.pki.application.PkiOperation.TransitionAuthority
Returns the value of the state record component.
state() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.OperationStatus
Returns the value of the state record component.
state() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Returns the value of the state record component.
state() - Method in record class zeroecho.pki.util.async.AsyncStatus
Returns the value of the state record component.
STATE_OR_PROVINCE_NAME - Enum constant in enum class zeroecho.pki.api.profile.SubjectRdnType
X.520 state or province name.
State and consistency - Search tag in class zeroecho.pki.impl.core.DefaultCaService
Section
status() - Method in record class zeroecho.pki.api.credential.Credential
Returns the value of the status record component.
status() - Method in record class zeroecho.pki.api.credential.CredentialQuery
Returns the value of the status record component.
status() - Method in record class zeroecho.pki.api.policy.PolicyDecision
Returns the value of the status record component.
status() - Method in record class zeroecho.pki.api.publication.PublicationRecord
Returns the value of the status record component.
status() - Method in record class zeroecho.pki.api.publication.PublicationResult
Returns the value of the status record component.
status() - Method in record class zeroecho.pki.api.request.ProofOfPossessionResult
Returns the value of the status record component.
status() - Method in record class zeroecho.pki.api.transfer.ExportQuery
Returns the value of the status record component.
status() - Method in record class zeroecho.pki.util.async.AsyncEvent
Returns the value of the status record component.
status(OpId) - Method in interface zeroecho.pki.util.async.AsyncBus
Retrieves the latest known status for an operation.
status(OpId) - Method in interface zeroecho.pki.util.async.AsyncEndpoint
Returns a best-effort current status for a known operation.
status(OpId) - Method in class zeroecho.pki.util.async.impl.DurableAsyncBus
Returns the last known status for an operation.
status(PkiId) - Method in class zeroecho.pki.impl.core.async.PkiSigningBus
Returns current status if known.
status(PkiId, SignatureWorkflow.CallControl) - Method in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
Returns the current status of a previously submitted operation.
status(PkiId, SignatureWorkflow.CallControl) - Method in interface zeroecho.pki.spi.crypto.SignatureWorkflow
Reads current status of an operation.
STATUS_OBJECT - Enum constant in enum class zeroecho.pki.api.publication.PublicationSourceType
An immutable committed status object, such as a CRL or OCSP response.
STATUS_OBJECT - Enum constant in enum class zeroecho.pki.application.PkiRepositoryContent.Role
Other immutable status-object representation.
STATUS_OBJECT_ISSUER - Enum constant in enum class zeroecho.pki.api.credential.CredentialUse
Issuer credential used to sign a status object.
STATUS_OBJECT_RECORD - Enum constant in enum class zeroecho.pki.api.content.DurableContentOwner.Category
Persisted status-object record; integration is deferred.
STATUS_UNAVAILABLE - Enum constant in enum class zeroecho.pki.spi.store.SignWorkflowStore.ReconciliationFailureClass
Provider status could not be obtained.
statusObject() - Method in class zeroecho.pki.impl.framework.x509.X509SignedObjectCompletion
Returns the completed immutable status-object metadata.
statusObject(PkiId) - Method in interface zeroecho.pki.application.PkiRepository
Returns an exact status-object metadata record.
StatusObject - Record Class in zeroecho.pki.api.status
Generated status object used for revocation distribution.
StatusObject(PkiId, FormatId, PkiId, StatusObjectType, Instant, Optional<Instant>, DurableContentReference, AttributeSet) - Constructor for record class zeroecho.pki.api.status.StatusObject
Creates a status object.
statusObjectAuthority(PkiId) - Method in interface zeroecho.pki.application.PkiResourceScopeResolver
Returns the exact logical issuer authority of one committed status object.
StatusObjectGenerateCommand - Record Class in zeroecho.pki.api.status
Command to generate a new status object for an issuer CA.
StatusObjectGenerateCommand(PkiId, StatusObjectType, FormatId, AttributeSet) - Constructor for record class zeroecho.pki.api.status.StatusObjectGenerateCommand
Creates a status generation command.
statusObjectGenerator() - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFramework
Returns the status-object generator used by this framework instance.
statusObjectGenerator() - Method in interface zeroecho.pki.spi.framework.CredentialFramework
Returns the status object generator for this framework.
StatusObjectGenerator - Interface in zeroecho.pki.spi.framework
Generates status objects for a credential framework (e.g., CRL/delta CRL/OCSP for X.509).
statusObjectId() - Method in record class zeroecho.pki.api.status.StatusObject
Returns the value of the statusObjectId record component.
statusObjectId() - Method in record class zeroecho.pki.application.PkiOperation.InspectStatus
Returns the value of the statusObjectId record component.
StatusObjectQuery - Record Class in zeroecho.pki.api.status
Query constraints for listing status objects.
StatusObjectQuery(PkiId, Optional<StatusObjectType>, Optional<Instant>, Optional<Instant>) - Constructor for record class zeroecho.pki.api.status.StatusObjectQuery
Creates a status object query.
statusObjects() - Method in interface zeroecho.pki.application.PkiSession
 
StatusObjectService - Interface in zeroecho.pki.api
Status object generation and retrieval.
StatusObjectType - Enum Class in zeroecho.pki.api.status
Identifies the kind of published status object.
StdoutAuditSink - Class in zeroecho.pki.impl.audit
Reference AuditSink provider writing a deterministic summary line to standard output.
StdoutAuditSink() - Constructor for class zeroecho.pki.impl.audit.StdoutAuditSink
Public no-arg constructor required for ServiceLoader.
StdoutAuditSinkProvider - Class in zeroecho.pki.impl.audit
AuditSinkProvider for the standard-output audit sink.
StdoutAuditSinkProvider() - Constructor for class zeroecho.pki.impl.audit.StdoutAuditSinkProvider
 
steps() - Method in record class zeroecho.pki.api.policy.PolicyTrace
Returns the value of the steps record component.
STORAGE_FAILURE - Enum constant in enum class zeroecho.pki.spi.store.MetadataCommitResult.FailureCategory
Durable storage or content I/O failed.
Storage layout - Search tag in class zeroecho.pki.impl.audit.FileAuditSink
Section
Storage model - Search tag in record class zeroecho.pki.api.orch.WorkflowStateRecord
Section
store() - Method in record class zeroecho.pki.application.PkiSessionConfiguration
Returns the value of the store record component.
store(ParsedCertificationRequest, RequestStorePolicy) - Method in interface zeroecho.pki.api.CertificationRequestService
Stores a parsed request for later correlation and audit.
store(ParsedCertificationRequest, RequestStorePolicy) - Method in class zeroecho.pki.impl.core.DefaultCertificationRequestService
Persists a parsed certification request according to the supplied storage policy.
STORE_ALWAYS - Enum constant in enum class zeroecho.pki.api.request.RequestStorePolicy
Always persist parsed requests.
STORE_ON_ISSUE - Enum constant in enum class zeroecho.pki.api.request.RequestStorePolicy
Persist parsed requests only after successful issuance.
StoreBackedEffectiveCredentialStatusResolver - Class in zeroecho.pki.impl.core
Store-backed authoritative resolver for runtime credential status.
StoreBackedEffectiveCredentialStatusResolver(PkiStore, Clock) - Constructor for class zeroecho.pki.impl.core.StoreBackedEffectiveCredentialStatusResolver
Creates a resolver using the supplied authoritative store and clock.
storeId() - Method in interface zeroecho.pki.api.content.DurableContentReference
Returns the canonical logical identity of the owning store.
storeId() - Method in interface zeroecho.pki.spi.store.MetadataSnapshot
Returns the issuing store identity.
storeId() - Method in record class zeroecho.pki.spi.store.MetadataTransactionId
Returns the value of the storeId record component.
StreamingDerReader - Class in zeroecho.pki.impl.framework.x509
Focused incremental canonical-DER structural validator.
StreamingDerReader() - Constructor for class zeroecho.pki.impl.framework.x509.StreamingDerReader
 
StreamingDerReader.SignedObjectKind - Enum Class in zeroecho.pki.impl.framework.x509
Supported signed-object grammar.
StreamingDerReader.SignedObjectLayout - Record Class in zeroecho.pki.impl.framework.x509
Exact offsets into the validated original DER.
StreamingDerWriter - Class in zeroecho.pki.impl.framework.x509
Focused canonical DER streaming primitives used by signed-object adapters.
STRICT_ABORT_ON_RESTART - Enum constant in enum class zeroecho.pki.api.orch.OrchestrationDurabilityPolicy
Fail-closed behavior.
strictSnapshotExport() - Method in record class zeroecho.pki.impl.fs.FsPkiStoreOptions
Returns the value of the strictSnapshotExport record component.
STRING - Enum constant in enum class zeroecho.pki.api.attr.AttributeValueType
UTF-8 string value.
STRING - Static variable in class zeroecho.pki.impl.async.PkiCodecs
Codec for endpoint ids represented as strings.
StringIdCodec() - Constructor for class zeroecho.pki.impl.core.async.PkiAsyncCodecs.StringIdCodec
 
StringValue(String) - Constructor for record class zeroecho.pki.api.attr.AttributeValue.StringValue
Creates a string value.
STRUCT - Enum constant in enum class zeroecho.pki.api.attr.AttributeValueType
Structured composite value.
STRUCTURED_DER - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.ParameterRule
Parameters are a binding-owned canonical DER structure.
subject(List<SubjectRdn>) - Static method in class zeroecho.pki.impl.framework.x509.bc.BcX509ProfileSupport
Builds the exact ordered subject name.
SUBJECT_DN - Static variable in class zeroecho.pki.impl.framework.x509.bc.BcX509Attributes
Attribute identifier for the authoritative X.509 subject distinguished name.
SUBJECT_PUBLIC_KEY - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.Role
SubjectPublicKeyInfo algorithm and public-key BIT STRING.
SUBJECT_PUBLIC_KEY_ALGORITHM - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509AlgorithmRole
Public-key algorithm in SubjectPublicKeyInfo.
SUBJECT_SPKI_DER - Static variable in class zeroecho.pki.impl.framework.x509.bc.BcX509Attributes
Attribute identifier for DER-encoded subject SubjectPublicKeyInfo data.
SubjectAlternativeName - Interface in zeroecho.pki.api.request
Closed immutable canonical Subject Alternative Name representation.
SubjectAlternativeName.DnsName - Record Class in zeroecho.pki.api.request
Canonical DNS A-label name.
SubjectAlternativeName.IpAddress - Record Class in zeroecho.pki.api.request
Canonical raw IPv4 or IPv6 address.
SubjectAlternativeName.Rfc822Name - Record Class in zeroecho.pki.api.request
Canonical ASCII RFC 822 mailbox.
SubjectAlternativeName.UriName - Record Class in zeroecho.pki.api.request
Canonical ASCII hierarchical absolute URI.
subjectAlternativeNameCritical() - Method in class zeroecho.pki.impl.core.ValidatedCertificateRequest
 
subjectAlternativeNamePolicy() - Method in record class zeroecho.pki.api.profile.LeafCertificatePolicy
Returns the value of the subjectAlternativeNamePolicy record component.
SubjectAlternativeNamePolicy - Record Class in zeroecho.pki.api.profile
Deny-by-default Subject Alternative Name policy.
SubjectAlternativeNamePolicy(int, int, List<SubjectAlternativeNameRule>, boolean, Set<String>, boolean, boolean, boolean) - Constructor for record class zeroecho.pki.api.profile.SubjectAlternativeNamePolicy
Validates and constructs the policy.
subjectAlternativeNamePresent() - Method in record class zeroecho.pki.api.request.ParsedCertificationRequest
Returns the value of the subjectAlternativeNamePresent record component.
SubjectAlternativeNameRule - Record Class in zeroecho.pki.api.profile
Occurrence and IP-family rule for one supported SAN type.
SubjectAlternativeNameRule(SubjectAlternativeNameType, int, int, boolean, boolean) - Constructor for record class zeroecho.pki.api.profile.SubjectAlternativeNameRule
Validates and constructs the rule.
subjectAlternativeNames() - Method in record class zeroecho.pki.api.request.ParsedCertificationRequest
Returns the value of the subjectAlternativeNames record component.
subjectAlternativeNames() - Method in class zeroecho.pki.impl.core.ValidatedCertificateRequest
 
SubjectAlternativeNameType - Enum Class in zeroecho.pki.api.profile
Closed set of requester-supplied Subject Alternative Name types.
subjectCaId() - Method in record class zeroecho.pki.api.ca.IntermediateCertIssueCommand
Returns the value of the subjectCaId record component.
subjectCaId() - Method in class zeroecho.pki.impl.core.ValidatedCaCertificateRequest
Returns the subject CA identifier.
subjectPolicy() - Method in record class zeroecho.pki.api.profile.CertificateProfile
Returns the value of the subjectPolicy record component.
subjectPolicy() - Method in record class zeroecho.pki.api.profile.CertificateProfileDefinition
Returns the value of the subjectPolicy record component.
SubjectPolicy - Record Class in zeroecho.pki.api.profile
Deny-by-default subject distinguished-name policy.
SubjectPolicy(boolean, List<SubjectRdnRule>) - Constructor for record class zeroecho.pki.api.profile.SubjectPolicy
Validates and constructs the policy.
subjectPublicKey() - Method in record class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy
Returns the value of the subjectPublicKey record component.
subjectPublicKey() - Method in record class zeroecho.pki.impl.framework.x509.bc.BcX509SignedObjectValidator.CertificateBindings
Returns the value of the subjectPublicKey record component.
subjectPublicKeyBinding() - Method in record class zeroecho.pki.application.PkiSessionConfiguration.SigningConfiguration
Returns the value of the subjectPublicKeyBinding record component.
subjectPublicKeyInfoLength() - Method in record class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectLayout
Returns the value of the subjectPublicKeyInfoLength record component.
subjectPublicKeyInfoOffset() - Method in record class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectLayout
Returns the value of the subjectPublicKeyInfoOffset record component.
SubjectRdn - Record Class in zeroecho.pki.api.request
One ordered, single-valued, typed subject distinguished-name component.
SubjectRdn(SubjectRdnType, String) - Constructor for record class zeroecho.pki.api.request.SubjectRdn
Validates and constructs the component.
SubjectRdnRule - Record Class in zeroecho.pki.api.profile
Immutable occurrence and ownership rule for one supported subject RDN type.
SubjectRdnRule(SubjectRdnType, int, int, int, Optional<String>, boolean) - Constructor for record class zeroecho.pki.api.profile.SubjectRdnRule
Validates and constructs a rule.
subjectRdns() - Method in record class zeroecho.pki.api.request.ParsedCertificationRequest
Returns the value of the subjectRdns record component.
subjectRdns() - Method in class zeroecho.pki.impl.core.ValidatedCaCertificateRequest
Returns the ordered canonical subject components.
subjectRdns() - Method in class zeroecho.pki.impl.core.ValidatedCertificateRequest
 
SubjectRdnType - Enum Class in zeroecho.pki.api.profile
Closed set of X.509 subject distinguished-name attributes supported by end-entity certificate profiles.
subjectRef() - Method in record class zeroecho.pki.api.ca.CaCreateCommand
Returns the value of the subjectRef record component.
subjectRef() - Method in record class zeroecho.pki.api.ca.CaImportCommand
Returns the value of the subjectRef record component.
subjectRef() - Method in record class zeroecho.pki.api.ca.CaQuery
Returns the value of the subjectRef record component.
subjectRef() - Method in record class zeroecho.pki.api.ca.CaRecord
Returns the value of the subjectRef record component.
subjectRef() - Method in record class zeroecho.pki.api.ca.IntermediateCreateCommand
Returns the value of the subjectRef record component.
subjectRef() - Method in record class zeroecho.pki.api.credential.Credential
Returns the value of the subjectRef record component.
subjectRef() - Method in record class zeroecho.pki.api.credential.CredentialQuery
Returns the value of the subjectRef record component.
subjectRef() - Method in record class zeroecho.pki.api.request.ParsedCertificationRequest
Returns the value of the subjectRef record component.
subjectRef() - Method in record class zeroecho.pki.api.request.RequestQuery
Returns the value of the subjectRef record component.
subjectRef() - Method in record class zeroecho.pki.api.transfer.ExportQuery
Returns the value of the subjectRef record component.
subjectRef() - Method in record class zeroecho.pki.application.PkiOperation.CreateAuthority
Returns the value of the subjectRef record component.
subjectRef() - Method in class zeroecho.pki.impl.core.ValidatedCaCertificateRequest
Returns the canonical subject reference.
subjectRef() - Method in class zeroecho.pki.impl.core.ValidatedCertificateRequest
 
SubjectRef - Record Class in zeroecho.pki.api
Framework-agnostic subject identifier.
SubjectRef(String) - Constructor for record class zeroecho.pki.api.SubjectRef
Creates a subject reference.
SUBMISSION_UNCERTAIN - Enum constant in enum class zeroecho.pki.spi.store.SignWorkflowStore.ReconciliationFailureClass
Submission may have been accepted.
submissionId() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.SignRequest
Returns the value of the submissionId record component.
submissionId() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Returns the value of the submissionId record component.
submit(OpId, String, Owner, EndpointId, Instant, Duration) - Method in interface zeroecho.pki.util.async.AsyncBus
Creates a new operation record and sets initial status to AsyncState.SUBMITTED.
submit(OpId, String, Owner, EndpointId, Instant, Duration) - Method in class zeroecho.pki.util.async.impl.DurableAsyncBus
Submits a new async operation.
submitSign(PkiId, Principal, KeyRef, String, DurableContentReference, Duration, Optional<EncodedObject>) - Method in class zeroecho.pki.impl.core.async.PkiSigningBus
Submits a sign operation.
submitSign(SignatureWorkflow.SignRequest, SignatureWorkflow.CallControl) - Method in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
Submits a signing operation and returns its workflow operation identifier.
submitSign(SignatureWorkflow.SignRequest, SignatureWorkflow.CallControl) - Method in interface zeroecho.pki.spi.crypto.SignatureWorkflow
Submits a signing request.
SUBMITTED - Enum constant in enum class zeroecho.pki.util.async.AsyncState
The operation has been created and is awaiting processing.
submitVerify(SignatureWorkflow.VerifyRequest, SignatureWorkflow.CallControl) - Method in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
Submits a signature verification operation and returns its workflow operation identifier.
submitVerify(SignatureWorkflow.VerifyRequest, SignatureWorkflow.CallControl) - Method in interface zeroecho.pki.spi.crypto.SignatureWorkflow
Submits a verification request.
subscribe(AsyncHandler<OpId, Owner, EndpointId, Result>) - Method in interface zeroecho.pki.util.async.AsyncBus
Subscribes a handler to status change events.
subscribe(AsyncHandler<OpId, Owner, EndpointId, Result>) - Method in class zeroecho.pki.util.async.impl.DurableAsyncBus
Subscribes an event handler to async bus events.
SUCCEEDED - Enum constant in enum class zeroecho.pki.api.publication.PublicationStatus
The exact attempted operation has a confirmed successful outcome.
SUCCEEDED - Enum constant in enum class zeroecho.pki.spi.crypto.SignatureWorkflow.State
 
SUCCEEDED - Enum constant in enum class zeroecho.pki.spi.store.SignWorkflowStore.State
 
SUCCEEDED - Enum constant in enum class zeroecho.pki.util.async.AsyncState
The operation completed successfully and the result is available for retrieval.
success() - Method in record class zeroecho.pki.api.backup.RestoreReport
Returns the value of the success record component.
Success(PkiOperationResult) - Constructor for record class zeroecho.pki.application.PkiOperationOutcome.Success
Validates the result.
SUCCESS - Enum constant in enum class zeroecho.pki.spi.publish.PublicationOutcome
The exact attempt completed successfully.
suite() - Method in record class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Selection
Returns the value of the suite record component.
SUPERSEDED - Enum constant in enum class zeroecho.pki.api.revocation.RevocationReason
Credential has been superseded by a newer one.
supportedAlgorithms() - Method in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
Returns the set of signature algorithm identifiers known to this provider.
supportedAlgorithms() - Method in interface zeroecho.pki.spi.crypto.SignatureWorkflow
Returns supported algorithm identifiers.
Supported encodings - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509CertificationRequestParser
Section
supportedKeys() - Method in class zeroecho.pki.impl.async.FileBackedAsyncBusProvider
 
supportedKeys() - Method in class zeroecho.pki.impl.audit.FileAuditSinkProvider
 
supportedKeys() - Method in class zeroecho.pki.impl.audit.InMemoryAuditSinkProvider
 
supportedKeys() - Method in class zeroecho.pki.impl.audit.StdoutAuditSinkProvider
 
supportedKeys() - Method in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflowProvider
 
supportedKeys() - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFrameworkProvider
Returns the provider-specific configuration keys supported by this provider.
supportedKeys() - Method in class zeroecho.pki.impl.fs.FilesystemPkiStoreProvider
 
supportedKeys() - Method in class zeroecho.pki.impl.publish.FilesystemPublisherProvider
 
supportedKeys() - Method in interface zeroecho.pki.spi.ConfigurableProvider
Returns the configuration keys understood by this backend.
Supported operations - Search tag in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
Section
supportingObjects() - Method in record class zeroecho.pki.api.credential.CredentialBundle
Returns the value of the supportingObjects record component.
sweep(Instant) - Method in class zeroecho.pki.impl.core.async.PkiSigningBus
Sweeps the durable bus.
sweep(Instant) - Method in interface zeroecho.pki.util.async.AsyncBus
Performs periodic maintenance: expires operations past their deadline, polls endpoints for open operations (restart recovery), dispatches any discovered transitions.
sweep(Instant) - Method in class zeroecho.pki.util.async.impl.DurableAsyncBus
Performs one maintenance and polling sweep.
System property conventions - Search tag in class zeroecho.pki.spi.bootstrap.PkiBootstrap
Section

T

tags() - Method in record class zeroecho.pki.api.attr.AttributeMeta
Returns the value of the tags record component.
target() - Method in record class zeroecho.pki.api.publication.PublicationRecord
Returns the value of the target record component.
target() - Method in record class zeroecho.pki.api.publication.PublicationRequest
Returns the value of the target record component.
target() - Method in record class zeroecho.pki.application.PkiOperation.RegisterPublication
Returns the value of the target record component.
target() - Method in record class zeroecho.pki.spi.publish.PublicationAttempt
Returns the value of the target record component.
target() - Method in interface zeroecho.pki.spi.publish.Publisher
Returns the exact administrator-configured destination served by this instance.
targetId() - Method in record class zeroecho.pki.api.publication.PublicationTarget
Returns the value of the targetId record component.
targetType() - Method in record class zeroecho.pki.api.publication.PublicationQuery
Returns the value of the targetType record component.
tbsAlgorithmLength() - Method in record class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectLayout
Returns the value of the tbsAlgorithmLength record component.
tbsAlgorithmOffset() - Method in record class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectLayout
Returns the value of the tbsAlgorithmOffset record component.
tbsLength() - Method in record class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectLayout
Returns the value of the tbsLength record component.
tbsOffset() - Method in record class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectLayout
Returns the value of the tbsOffset record component.
TEMPORARY - Enum constant in enum class zeroecho.pki.api.content.DurableContentReference.Lifecycle
Content eligible for release after its immediate operation.
temporaryStorageBytes() - Method in record class zeroecho.pki.api.content.DeploymentResourcePolicy
Returns the value of the temporaryStorageBytes record component.
TemporaryUniqueIndex - Interface in zeroecho.pki.spi.store
Runtime-owned file-backed uniqueness index for bounded individual values.
TERMINAL_FAILURE - Enum constant in enum class zeroecho.pki.api.publication.PublicationStatus
The operation definitively failed and is terminal.
TERMINAL_FAILURE - Enum constant in enum class zeroecho.pki.spi.publish.PublicationOutcome
The exact attempt definitively failed and must not be retried.
Terminal states - Search tag in record class zeroecho.pki.spi.crypto.SignatureWorkflow.OperationStatus
Section
Terminology - Search tag in package zeroecho.pki.api.revocation
Section
Text(String) - Constructor for record class zeroecho.pki.application.PkiOperationValue.Text
Validates the value.
thisUpdate() - Method in record class zeroecho.pki.api.status.StatusObject
Returns the value of the thisUpdate record component.
thisUpdate() - Method in record class zeroecho.pki.application.OcspResponseService.Command
Returns the value of the thisUpdate record component.
thisUpdate() - Method in record class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectLayout
Returns the value of the thisUpdate record component.
Thread-safety - Search tag in class zeroecho.pki.impl.audit.InMemoryAuditSink
Section
Thread-safety - Search tag in class zeroecho.pki.impl.core.DefaultCaService
Section
Thread-safety - Search tag in class zeroecho.pki.impl.core.DefaultCertificationRequestService
Section
Thread-safety - Search tag in class zeroecho.pki.impl.core.DefaultIssuanceService
Section
Thread-safety - Search tag in class zeroecho.pki.impl.core.DefaultStatusObjectService
Section
Thread-safety - Search tag in class zeroecho.pki.impl.core.async.PkiSigningBus.SignContinuation
Section
Thread-safety - Search tag in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
Section
Thread-safety - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509CertificationRequestParser
Section
Thread-safety - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFramework
Section
Thread-safety - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFrameworkProvider
Section
Thread-safety - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialIssuerBackend
Section
Thread-safety - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509FrameworkAttributeMapper
Section
Thread-safety - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509ProofOfPossessionVerifier
Section
Thread-safety - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509StatusObjectGenerator
Section
Thread-safety - Search tag in class zeroecho.pki.impl.framework.x509.bc.PkiBusContentSigner
Section
Thread-safety - Search tag in class zeroecho.pki.impl.framework.x509.bc.SimpleAttributeSet
Section
Thread-safety - Search tag in class zeroecho.pki.impl.framework.x509.bc.WorkflowProofOfPossessionVerifier
Section
Thread-safety - Search tag in class zeroecho.pki.util.async.impl.DurableAsyncBus
Section
Thread-safety - Search tag in interface zeroecho.pki.impl.core.PublicKeyInfoResolver
Section
Thread-safety - Search tag in interface zeroecho.pki.spi.framework.CredentialIssuerBackend
Section
Thread-safety - Search tag in record class zeroecho.pki.impl.core.attr.SimpleAttributeSet
Section
Thread-safety and lifecycle - Search tag in package zeroecho.pki.spi.audit
Section
time() - Method in record class zeroecho.pki.api.audit.AuditEvent
Returns the value of the time record component.
time() - Method in record class zeroecho.pki.api.revocation.RevocationTransition
Returns the value of the time record component.
Time filtering semantics - Search tag in zeroecho.pki.impl.core.DefaultStatusObjectService.list(StatusObjectQuery)
Section
Time travel and snapshots - Search tag in package zeroecho.pki.impl.fs
Section
toBc(X509AlgorithmIdentifier) - Static method in class zeroecho.pki.impl.framework.x509.bc.BcX509AlgorithmAdapter
Converts a provider-neutral identifier to Bouncy Castle form.
toCanonicalBase(PkiId, Principal) - Static method in class zeroecho.pki.impl.core.async.OperationIdCodec
Computes the canonical base operation identifier for the supplied owner and client-provided operation identifier.
toDisplay(PkiId, Principal, int) - Static method in class zeroecho.pki.impl.core.async.OperationIdCodec
Creates a display-oriented operation identifier by appending a readable suffix after '#' to an already canonical base identifier.
token() - Method in record class zeroecho.pki.spi.store.MetadataTransactionId
Returns the value of the token record component.
toString() - Method in record class zeroecho.pki.api.algorithm.X509AlgorithmBinding
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.attr.AttributeAccessPolicy
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.attr.AttributeDefinition
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.attr.AttributeId
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.attr.AttributeMeta
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.attr.AttributeValue.BooleanValue
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.attr.AttributeValue.BytesValue
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.attr.AttributeValue.InstantValue
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.attr.AttributeValue.IntegerValue
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.attr.AttributeValue.StringValue
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.audit.AccessContext
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.audit.AuditEvent
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.audit.AuditQuery
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.audit.Principal
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.audit.Purpose
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.backup.BackupArtifact
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.backup.BackupRequest
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.backup.BackupVerificationReport
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.backup.RestoreReport
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.backup.RestoreRequest
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.ca.CaCreateCommand
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.ca.CaImportCommand
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.ca.CaKeyRotationCommand
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.ca.CaQuery
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.ca.CaRecord
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.ca.CaRolloverCommand
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.ca.IntermediateCertIssueCommand
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.ca.IntermediateCreateCommand
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.ca.IssuerChainPath
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.ca.IssuerGeneration
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.content.DeploymentResourcePolicy
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.content.DurableContentOwner
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.content.ResourceLimit.LimitedTo
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.content.ResourceLimit.UnrestrictedByDeployment
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.credential.CaProfileBinding
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.credential.Credential
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.credential.CredentialBundle
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.credential.CredentialQuery
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.credential.EndEntityProfileBinding
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.EncodedObject
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.FormatId
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.issuance.BundleCommand
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.issuance.IssuanceInputs
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.issuance.IssuanceIntent
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.issuance.IssueEndEntityCommand
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.issuance.ReissueCommand
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.issuance.RenewCommand
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.issuance.ReplaceCommand
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.issuance.VerificationPolicy
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.IssuerRef
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.KeyRef
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.orch.SigningSubmissionId
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.orch.WorkflowStateRecord
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.PkiId
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.policy.PolicyDecision
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.policy.PolicyTrace
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.policy.PolicyTraceStep
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.profile.ActiveCertificateProfile
Returns a string representation of this record class.
toString() - Method in class zeroecho.pki.api.profile.BuiltInCertificateProfileTemplate
 
toString() - Method in record class zeroecho.pki.api.profile.CaCertificatePolicy
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.profile.CertificateProfile
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.profile.CertificateProfileDefinition
Returns a string representation of this record class.
toString() - Method in class zeroecho.pki.api.profile.CertificateProfileRef
 
toString() - Method in record class zeroecho.pki.api.profile.ExtendedKeyUsageId
Returns a string representation of this record class.
toString() - Method in class zeroecho.pki.api.profile.ImportedCertificateProfileVersion
 
toString() - Method in record class zeroecho.pki.api.profile.LeafCertificatePolicy
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.profile.ProfileQuery
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.profile.SubjectAlternativeNamePolicy
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.profile.SubjectAlternativeNameRule
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.profile.SubjectPolicy
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.profile.SubjectRdnRule
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy.BindingReference
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.publication.PublicationQuery
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.publication.PublicationRecord
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.publication.PublicationRequest
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.publication.PublicationResult
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.publication.PublicationTarget
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.request.CertificationRequest
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.request.ParsedCertificationRequest
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.request.ProofOfPossessionResult
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.request.RequestQuery
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.DnsName
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.IpAddress
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.Rfc822Name
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.UriName
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.request.SubjectRdn
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.revocation.RevocationCommand.Hold
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.revocation.RevocationCommand.RevokePermanently
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.revocation.RevocationCommand.Unhold
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.revocation.RevocationInputs
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.revocation.RevocationQuery
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.revocation.RevocationRecord
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.revocation.RevocationTransition
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.status.StatusObject
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.status.StatusObjectGenerateCommand
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.status.StatusObjectQuery
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.SubjectRef
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.transfer.ExportArtifact
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.transfer.ExportQuery
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.transfer.ImportPolicy
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.api.Validity
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.OcspResponseService.CertId
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.OcspResponseService.Command
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.OcspResponseService.Response
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.ActivateProfile
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.CreateAuthority
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.GenerateStatus
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.ImportRequest
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.InspectAlgorithmBinding
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.InspectAuthority
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.InspectCredential
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.InspectProfile
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.InspectPublication
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.InspectRequest
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.InspectRevocation
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.InspectStatus
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.IssueCredential
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.ListAlgorithmBindings
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.ListAuthorities
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.ListProfileVersions
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.ListPublications
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.ListStatus
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.ProcessPublication
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.ReadRevocationHistory
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.ReconcilePublication
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.RegisterProfile
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.RegisterPublication
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.RetryPublication
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.RevokeCredential
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.SnapshotRevocations
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.TransitionAuthority
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.ValidateAlgorithmBindings
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.ValidateConfiguration
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.ValidateProfile
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperation.VerifyRequest
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperationOutcome.Failure
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperationOutcome.Success
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperationResult
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperationValue.BooleanValue
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperationValue.IntegerValue
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperationValue.ListValue
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperationValue.ObjectValue
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiOperationValue.Text
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiSessionConfiguration.BindingProviderConfiguration
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiSessionConfiguration.SigningConfiguration
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiSessionConfiguration
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.PkiSessionRuntimeDependencies
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.SigningReconciliationRequest
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.application.SigningReconciliationResult
Returns a string representation of this record class.
toString() - Method in class zeroecho.pki.impl.audit.InMemoryAuditSink
 
toString() - Method in record class zeroecho.pki.impl.core.attr.SimpleAttributeSet.Entry
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.impl.core.attr.SimpleAttributeSet
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.impl.framework.x509.bc.BcX509SignedObjectValidator.CertificateBindings
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectLayout
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Selection
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.impl.framework.x509.X509ComponentCatalog.Component
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.impl.fs.FsPkiStoreOptions
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.CallControl
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.OperationResult
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.OperationStatus
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.SignRequest
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.VerifyRequest
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.spi.framework.CrlEntry
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.spi.ProviderConfig
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.spi.publish.PublicationAttempt
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.spi.store.MetadataCommitResult
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.spi.store.MetadataKey
Returns the canonical serialized representation.
toString() - Method in record class zeroecho.pki.spi.store.MetadataSnapshot.Integrity
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.spi.store.MetadataSnapshot.KeyRange
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.spi.store.MetadataStoreCapabilities
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.spi.store.MetadataStoreId
Returns the canonical identity.
toString() - Method in record class zeroecho.pki.spi.store.MetadataTransactionId
Returns the complete current canonical representation.
toString() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Page
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.spi.store.SignWorkflowStore.Record
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.util.async.AsyncEvent
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.util.async.AsyncOperationSnapshot
Returns a string representation of this record class.
toString() - Method in record class zeroecho.pki.util.async.AsyncStatus
Returns a string representation of this record class.
toZeroEchoAlgorithmId(String, X509AuthoritySnapshot) - Static method in class zeroecho.pki.impl.framework.x509.bc.OidAlgorithmMapper
Maps a dotted-decimal signature algorithm OID string to a ZeroEcho canonical signature algorithm identifier.
toZeroEchoAlgorithmId(AlgorithmIdentifier, X509AuthoritySnapshot) - Static method in class zeroecho.pki.impl.framework.x509.bc.OidAlgorithmMapper
Maps an ASN.1 signature AlgorithmIdentifier to a ZeroEcho canonical signature algorithm identifier.
TRANSACTION_NOT_ISSUED - Enum constant in enum class zeroecho.pki.spi.store.MetadataCommitResult.FailureCategory
Transaction identity was never issued by this store.
TransactionalMetadataStore - Interface in zeroecho.pki.spi.store
Provider-neutral authority for finite transactional control metadata.
transactionId() - Method in record class zeroecho.pki.spi.store.MetadataCommitResult
Returns the value of the transactionId record component.
transition() - Method in record class zeroecho.pki.api.revocation.RevocationRecord
Returns the value of the transition record component.
TransitionAuthority(PkiId, CaState, String) - Constructor for record class zeroecho.pki.application.PkiOperation.TransitionAuthority
Validates the lifecycle-transition input.
transitionRevocation(RevocationCommand, Instant) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
transitionRevocation(RevocationCommand, Instant) - Method in interface zeroecho.pki.spi.store.PkiStore
Atomically validates and appends one legal revocation transition.
transitionSign(PkiId, long, long, SignWorkflowStore.State, Optional<String>, Optional<EncodedObject>, Optional<Instant>) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
transitionSign(PkiId, long, long, SignWorkflowStore.State, Optional<String>, Optional<EncodedObject>, Optional<Instant>) - Method in interface zeroecho.pki.spi.store.SignWorkflowStore
Atomically transitions state when revision and fence are current.
transitionTime() - Method in record class zeroecho.pki.spi.framework.CrlEntry
Returns the value of the transitionTime record component.
Trust boundary - Search tag in interface zeroecho.pki.spi.crypto.SignatureWorkflow
Section
Trust boundary - Search tag in package zeroecho.pki.spi.crypto
Section
tryClaimSign(PkiId, long, Duration) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStore
 
tryClaimSign(PkiId, long, Duration) - Method in interface zeroecho.pki.spi.store.SignWorkflowStore
Atomically claims an intent and increments its revision and fencing token.
type() - Method in record class zeroecho.pki.api.audit.Principal
Returns the value of the type record component.
type() - Method in record class zeroecho.pki.api.orch.WorkflowStateRecord
Returns the value of the type record component.
type() - Method in record class zeroecho.pki.api.profile.SubjectAlternativeNameRule
Returns the value of the type record component.
type() - Method in record class zeroecho.pki.api.profile.SubjectRdnRule
Returns the value of the type record component.
type() - Method in record class zeroecho.pki.api.publication.PublicationTarget
Returns the value of the type record component.
type() - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.DnsName
 
type() - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.IpAddress
 
type() - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.Rfc822Name
 
type() - Method in interface zeroecho.pki.api.request.SubjectAlternativeName
Returns the exact SAN type.
type() - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.UriName
 
type() - Method in record class zeroecho.pki.api.request.SubjectRdn
Returns the value of the type record component.
type() - Method in record class zeroecho.pki.api.status.StatusObject
Returns the value of the type record component.
type() - Method in record class zeroecho.pki.api.status.StatusObjectGenerateCommand
Returns the value of the type record component.
type() - Method in record class zeroecho.pki.api.status.StatusObjectQuery
Returns the value of the type record component.
type() - Method in record class zeroecho.pki.application.PkiOperation.GenerateStatus
Returns the value of the type record component.
type() - Method in record class zeroecho.pki.util.async.AsyncOperationSnapshot
Returns the value of the type record component.
TYPE_SIGN - Static variable in class zeroecho.pki.impl.core.async.PkiSigningBus
Operation type for signing.
Typical responsibilities - Search tag in package zeroecho.pki.api.attr
Section

U

UI - Enum constant in enum class zeroecho.pki.api.attr.AttributeExportTarget
Export for UI rendering.
unhold(RevocationCommand.Unhold) - Method in interface zeroecho.pki.api.RevocationService
Removes an existing hold.
unhold(RevocationCommand.Unhold) - Method in class zeroecho.pki.impl.core.DefaultRevocationService
 
Unhold(PkiId, AttributeSet) - Constructor for record class zeroecho.pki.api.revocation.RevocationCommand.Unhold
Validates and snapshots the command.
UNKNOWN - Enum constant in enum class zeroecho.pki.spi.store.MetadataCommitResult.Outcome
The immediate caller cannot yet determine the fixed durable outcome.
UNKNOWN_IMPLEMENTATION - Enum constant in enum class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Failure
Explicit implementation is unavailable for the tuple.
unknownCount() - Method in record class zeroecho.pki.application.OcspResponseService.Response
Returns the value of the unknownCount record component.
unlockEnvironmentVariable() - Method in record class zeroecho.pki.application.PkiSessionConfiguration.SigningConfiguration
Returns the value of the unlockEnvironmentVariable record component.
unresolved() - Method in record class zeroecho.pki.application.SigningReconciliationResult
Returns the value of the unresolved record component.
UnrestrictedByDeployment() - Constructor for record class zeroecho.pki.api.content.ResourceLimit.UnrestrictedByDeployment
Creates an instance of a UnrestrictedByDeployment record class.
UNSPECIFIED - Enum constant in enum class zeroecho.pki.api.revocation.RevocationReason
Reason not specified.
UNSUPPORTED_CAPABILITY - Enum constant in enum class zeroecho.pki.spi.store.MetadataCommitResult.FailureCategory
Adapter lacks an optional requested capability.
UNTIL_ACKNOWLEDGED - Enum constant in enum class zeroecho.pki.spi.store.MetadataStoreCapabilities.OutcomeRetention
Known terminal outcomes may be released after acknowledgement.
unwrap(SubjectPublicKeyInfo) - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509PublicKeyAdapter
Returns provider-native SPKI for verification or key import.
update(OpId, AsyncStatus, Optional<Result>) - Method in interface zeroecho.pki.util.async.AsyncBus
Updates status and optional result for an operation.
update(OpId, AsyncStatus, Optional<Result>) - Method in class zeroecho.pki.util.async.impl.DurableAsyncBus
Applies a status update and an optional result to an existing operation.
updatedAt() - Method in record class zeroecho.pki.api.orch.WorkflowStateRecord
Returns the value of the updatedAt record component.
updatedAt() - Method in record class zeroecho.pki.api.publication.PublicationRecord
Returns the value of the updatedAt record component.
updatedAt() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.OperationStatus
Returns the value of the updatedAt record component.
updatedAt() - Method in record class zeroecho.pki.util.async.AsyncStatus
Returns the value of the updatedAt record component.
Update semantics - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509StatusObjectGenerator
Section
upperExclusive() - Method in record class zeroecho.pki.spi.store.MetadataSnapshot.KeyRange
Returns the value of the upperExclusive record component.
URI - Enum constant in enum class zeroecho.pki.api.profile.SubjectAlternativeNameType
Hierarchical absolute URI.
UriName(String) - Constructor for record class zeroecho.pki.api.request.SubjectAlternativeName.UriName
Canonicalizes and validates the URI.
USABLE - Enum constant in enum class zeroecho.pki.api.credential.EffectiveCredentialStatus
The credential is issued, unrevoked, and within its validity interval.
Use cases - Search tag in package zeroecho.pki.api.transfer
Section

V

valid() - Method in record class zeroecho.pki.api.backup.BackupVerificationReport
Returns the value of the valid record component.
validAt() - Method in record class zeroecho.pki.api.credential.CredentialQuery
Returns the value of the validAt record component.
validate(byte[], int) - Method in class zeroecho.pki.impl.framework.x509.StreamingDerReader
Validates one complete canonical DER object held in an explicitly bounded byte array.
validate(String, Instant, Duration, Duration) - Method in record class zeroecho.pki.api.orch.SigningSubmissionId
Validates namespace and lifetime against store-authoritative time.
validate(RepeatableContent, CancellationSignal) - Method in class zeroecho.pki.impl.framework.x509.StreamingDerReader
Validates one complete canonical DER object.
ValidateAlgorithmBindings(Optional<String>, Optional<String>) - Constructor for record class zeroecho.pki.application.PkiOperation.ValidateAlgorithmBindings
Validates paired optional fields.
validateAuditConfiguration(ProviderConfig) - Static method in class zeroecho.pki.spi.bootstrap.PkiBootstrap
Validates an explicit audit configuration without allocating a sink.
validateBeforeImport() - Method in record class zeroecho.pki.api.transfer.ImportPolicy
Returns the value of the validateBeforeImport record component.
validateCertificate(RepeatableContent, Optional<AlgorithmIdentity>, CancellationSignal) - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509SignedObjectValidator
Validates one complete canonical certificate and its exact bindings.
validateConfig(ProviderConfig) - Method in class zeroecho.pki.impl.async.FileBackedAsyncBusProvider
Validates configuration for the durable file-backed async bus provider.
validateConfig(ProviderConfig) - Method in class zeroecho.pki.impl.audit.FileAuditSinkProvider
Validates configuration for the file-backed audit sink provider.
validateConfig(ProviderConfig) - Method in class zeroecho.pki.impl.audit.InMemoryAuditSinkProvider
Validates configuration for the in-memory audit sink provider.
validateConfig(ProviderConfig) - Method in class zeroecho.pki.impl.audit.StdoutAuditSinkProvider
Validates configuration for the standard-output audit sink provider.
validateConfig(ProviderConfig) - Method in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflowProvider
Validates configuration for the ZeroEcho-lib signature workflow provider.
validateConfig(ProviderConfig) - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFrameworkProvider
Validates configuration for the Bouncy Castle backed X.509 credential framework provider.
validateConfig(ProviderConfig) - Method in class zeroecho.pki.impl.fs.FilesystemPkiStoreProvider
Validates configuration for the filesystem-backed PKI store provider.
validateConfig(ProviderConfig) - Method in class zeroecho.pki.impl.publish.FilesystemPublisherProvider
 
validateConfig(ProviderConfig) - Method in interface zeroecho.pki.spi.ConfigurableProvider
Validates the provided configuration before allocation.
ValidateConfiguration() - Constructor for record class zeroecho.pki.application.PkiOperation.ValidateConfiguration
Creates an instance of a ValidateConfiguration record class.
validateCredentialFrameworkConfiguration(ProviderConfig) - Static method in class zeroecho.pki.spi.bootstrap.PkiBootstrap
Validates one explicit credential-framework provider configuration without constructing a framework instance.
ValidatedCaCertificateRequest - Class in zeroecho.pki.impl.core
Immutable gate-produced CA certificate request accepted by the issuer backend.
ValidatedCaCertificateRequest.Operation - Enum Class in zeroecho.pki.impl.core
Closed CA certificate operations authorized by this gate.
ValidatedCertificateRequest - Class in zeroecho.pki.impl.core
Immutable gate-produced end-entity certificate construction authority.
validateGeneratedCertificate(RepeatableContent, X509ExecutionPlan<SignatureWorkflow>, CancellationSignal) - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509SignedObjectValidator
Validates a generated certificate against its exact live signing plan.
validateGeneratedCrl(RepeatableContent, X509ExecutionPlan<SignatureWorkflow>, X509CertificateHolder, Instant, Optional<Instant>, CancellationSignal) - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509SignedObjectValidator
Validates a generated CRL against its exact live signing plan and issuer certificate.
validateNamespace() - Method in interface zeroecho.pki.spi.store.TemporaryUniqueIndex
Validates every committed entry before the namespace is trusted.
ValidateProfile(byte[]) - Constructor for record class zeroecho.pki.application.PkiOperation.ValidateProfile
Defensively snapshots the document.
validatePublisherConfiguration(ProviderConfig) - Static method in class zeroecho.pki.spi.bootstrap.PkiBootstrap
Validates one explicitly enabled publication destination without opening it.
validateSignatureWorkflowConfiguration(ProviderConfig) - Static method in class zeroecho.pki.spi.bootstrap.PkiBootstrap
Validates one explicit signature-workflow provider configuration without allocating key access or workflow resources.
validateSigningBinding(PkiId, KeyRef, String, Optional<String>) - Method in interface zeroecho.pki.application.OcspResponseService
Proves that one configured confined key capability signs as the exact responder certificate before a durable responder is activated.
validateSigningDomain(String, Duration, Duration) - Method in class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflow
 
validateSigningDomain(String, Duration, Duration) - Method in interface zeroecho.pki.spi.crypto.SignatureWorkflow
Validates the authoritative signing domain selected by orchestration.
validateStoreConfiguration(ProviderConfig) - Static method in class zeroecho.pki.spi.bootstrap.PkiBootstrap
Validates an explicit store configuration without allocating a store.
validateSubjectPublicKeyInfo(byte[], int) - Method in class zeroecho.pki.impl.framework.x509.StreamingDerReader
Validates one canonical DER SubjectPublicKeyInfo value, including the X.509 requirement that its public-key BIT STRING have zero unused bits.
Validation - Search tag in record class zeroecho.pki.api.audit.AuditEvent
Section
VALIDATION_FAILURE - Enum constant in enum class zeroecho.pki.application.PkiOperationFailure
Typed input or operation precondition is malformed.
validity() - Method in record class zeroecho.pki.api.credential.Credential
Returns the value of the validity record component.
validity() - Method in class zeroecho.pki.impl.core.ValidatedCaCertificateRequest
Returns the approved exact validity.
validity() - Method in class zeroecho.pki.impl.core.ValidatedCertificateRequest
 
Validity - Record Class in zeroecho.pki.api
Validity interval for an issued credential.
Validity(Instant, Instant) - Constructor for record class zeroecho.pki.api.Validity
Creates a validity interval.
validityOverride() - Method in record class zeroecho.pki.api.issuance.IssueEndEntityCommand
Returns the value of the validityOverride record component.
validityOverride() - Method in record class zeroecho.pki.api.issuance.RenewCommand
Returns the value of the validityOverride record component.
validityOverride() - Method in class zeroecho.pki.impl.core.VerifiedIssuanceCandidate
Returns the optional validated validity override.
value() - Method in record class zeroecho.pki.api.attr.AttributeId
Returns the value of the value record component.
value() - Method in record class zeroecho.pki.api.attr.AttributeValue.BooleanValue
Returns the value of the value record component.
value() - Method in record class zeroecho.pki.api.attr.AttributeValue.BytesValue
Returns the value of the value record component.
value() - Method in record class zeroecho.pki.api.attr.AttributeValue.InstantValue
Returns the value of the value record component.
value() - Method in record class zeroecho.pki.api.attr.AttributeValue.IntegerValue
Returns the value of the value record component.
value() - Method in record class zeroecho.pki.api.attr.AttributeValue.StringValue
Returns the value of the value record component.
value() - Method in record class zeroecho.pki.api.audit.Purpose
Returns the value of the value record component.
value() - Method in record class zeroecho.pki.api.FormatId
Returns the value of the value record component.
value() - Method in record class zeroecho.pki.api.KeyRef
Returns the value of the value record component.
value() - Method in record class zeroecho.pki.api.PkiId
Returns the value of the value record component.
value() - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.DnsName
Returns the value of the value record component.
value() - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.Rfc822Name
Returns the value of the value record component.
value() - Method in record class zeroecho.pki.api.request.SubjectAlternativeName.UriName
Returns the value of the value record component.
value() - Method in record class zeroecho.pki.api.request.SubjectRdn
Returns the value of the value record component.
value() - Method in record class zeroecho.pki.api.SubjectRef
Returns the value of the value record component.
value() - Method in record class zeroecho.pki.application.PkiOperationValue.BooleanValue
Returns the value of the value record component.
value() - Method in record class zeroecho.pki.application.PkiOperationValue.IntegerValue
Returns the value of the value record component.
value() - Method in record class zeroecho.pki.application.PkiOperationValue.Text
Returns the value of the value record component.
value() - Method in record class zeroecho.pki.spi.store.MetadataSnapshot.Integrity
Returns the value of the value record component.
value() - Method in record class zeroecho.pki.spi.store.MetadataStoreId
Returns the value of the value record component.
valueOf(String) - Static method in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.Interoperability
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.Origin
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.ParameterRule
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.PublicKeyEncoding
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.Role
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.SignatureEncoding
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.attr.AttributeExportTarget
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.attr.AttributeSensitivity
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.attr.AttributeStability
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.attr.AttributeValueType
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.audit.AccessAction
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.audit.AccessDecision
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.ca.CaKind
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.ca.CaState
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.ca.IssuerGenerationState
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.content.DurableContentOwner.Category
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.content.DurableContentReference.Lifecycle
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.credential.CredentialStatus
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.credential.CredentialUse
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.credential.EffectiveCredentialStatus
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.Encoding
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.orch.OrchestrationDurabilityPolicy
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.policy.PolicyDecisionStatus
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.profile.CaKeyUsage
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.profile.CertificateProfileKind
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.profile.LeafKeyUsage
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.profile.SubjectAlternativeNameType
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.profile.SubjectRdnType
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy.Mode
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.publication.PublicationEvidence
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.publication.PublicationFailure
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.publication.PublicationSourceType
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.publication.PublicationStatus
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.publication.PublicationTargetType
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.request.ProofOfPossessionStatus
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.request.RequestStorePolicy
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.revocation.RevocationReason
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.revocation.RevocationState
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.status.StatusObjectType
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.api.transfer.ExportFormat
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.application.OcspResponseService.CertIdHash
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.application.OcspResponseService.ResponderId
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.application.PkiOperationFailure
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.application.PkiRepositoryContent.Role
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.impl.core.ValidatedCaCertificateRequest.Operation
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectKind
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.impl.framework.x509.X509AlgorithmIdentifier.ParameterForm
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Failure
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.impl.framework.x509.X509AlgorithmRole
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.impl.framework.x509.X509BindingRule.PublicKeyEncoding
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.impl.framework.x509.X509BindingRule.SignatureEncoding
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.impl.framework.x509.X509ComponentCatalog.Kind
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.impl.fs.FsHistoryPolicy.CleanupStrategy
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.impl.ProfileLifecycleFailure.Code
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.spi.crypto.SignatureWorkflow.State
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.spi.publish.PublicationOutcome
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.spi.store.MetadataCommitResult.FailureCategory
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.spi.store.MetadataCommitResult.Outcome
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.spi.store.MetadataStoreCapabilities.ContentLengthModel
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.spi.store.MetadataStoreCapabilities.OptionalFeature
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.spi.store.MetadataStoreCapabilities.OutcomeRetention
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.spi.store.MetadataStoreCapabilities.WriterModel
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.spi.store.SignWorkflowStore.CreateResult
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.spi.store.SignWorkflowStore.ReconciliationFailureClass
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.spi.store.SignWorkflowStore.State
Returns the enum constant of this class with the specified name.
valueOf(String) - Static method in enum class zeroecho.pki.util.async.AsyncState
Returns the enum constant of this class with the specified name.
values() - Static method in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.Interoperability
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.Origin
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.ParameterRule
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.PublicKeyEncoding
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.Role
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.SignatureEncoding
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.attr.AttributeExportTarget
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.attr.AttributeSensitivity
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.attr.AttributeStability
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.attr.AttributeValueType
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.audit.AccessAction
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.audit.AccessDecision
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.ca.CaKind
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.ca.CaState
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.ca.IssuerGenerationState
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.content.DurableContentOwner.Category
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.content.DurableContentReference.Lifecycle
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.credential.CredentialStatus
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.credential.CredentialUse
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.credential.EffectiveCredentialStatus
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.Encoding
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.orch.OrchestrationDurabilityPolicy
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.policy.PolicyDecisionStatus
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.profile.CaKeyUsage
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.profile.CertificateProfileKind
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.profile.LeafKeyUsage
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.profile.SubjectAlternativeNameType
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.profile.SubjectRdnType
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy.Mode
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.publication.PublicationEvidence
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.publication.PublicationFailure
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.publication.PublicationSourceType
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.publication.PublicationStatus
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.publication.PublicationTargetType
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.request.ProofOfPossessionStatus
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.request.RequestStorePolicy
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.revocation.RevocationReason
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.revocation.RevocationState
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.status.StatusObjectType
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.api.transfer.ExportFormat
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.application.OcspResponseService.CertIdHash
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.application.OcspResponseService.ResponderId
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.application.PkiOperationFailure
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Method in record class zeroecho.pki.application.PkiOperationValue.ListValue
Returns the value of the values record component.
values() - Static method in enum class zeroecho.pki.application.PkiRepositoryContent.Role
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Method in record class zeroecho.pki.impl.core.attr.SimpleAttributeSet.Entry
Returns the value of the values record component.
values() - Static method in enum class zeroecho.pki.impl.core.ValidatedCaCertificateRequest.Operation
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.impl.framework.x509.StreamingDerReader.SignedObjectKind
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.impl.framework.x509.X509AlgorithmIdentifier.ParameterForm
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver.Failure
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.impl.framework.x509.X509AlgorithmRole
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.impl.framework.x509.X509BindingRule.PublicKeyEncoding
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.impl.framework.x509.X509BindingRule.SignatureEncoding
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.impl.framework.x509.X509ComponentCatalog.Kind
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.impl.fs.FsHistoryPolicy.CleanupStrategy
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.impl.ProfileLifecycleFailure.Code
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.spi.crypto.SignatureWorkflow.State
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.spi.publish.PublicationOutcome
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.spi.store.MetadataCommitResult.FailureCategory
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.spi.store.MetadataCommitResult.Outcome
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.spi.store.MetadataStoreCapabilities.ContentLengthModel
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.spi.store.MetadataStoreCapabilities.OptionalFeature
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.spi.store.MetadataStoreCapabilities.OutcomeRetention
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.spi.store.MetadataStoreCapabilities.WriterModel
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.spi.store.SignWorkflowStore.CreateResult
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.spi.store.SignWorkflowStore.ReconciliationFailureClass
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.spi.store.SignWorkflowStore.State
Returns an array containing the constants of this enum class, in the order they are declared.
values() - Static method in enum class zeroecho.pki.util.async.AsyncState
Returns an array containing the constants of this enum class, in the order they are declared.
valueType() - Method in record class zeroecho.pki.api.attr.AttributeDefinition
Returns the value of the valueType record component.
Value typing - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509Attributes
Section
VerificationPolicy - Record Class in zeroecho.pki.api.issuance
Constraints for certification request verification.
VerificationPolicy(boolean, Optional<String>) - Constructor for record class zeroecho.pki.api.issuance.VerificationPolicy
Creates a verification policy.
Verification policy handling - Search tag in class zeroecho.pki.impl.framework.x509.bc.BcX509ProofOfPossessionVerifier
Section
Verification policy handling - Search tag in class zeroecho.pki.impl.framework.x509.bc.WorkflowProofOfPossessionVerifier
Section
verified() - Method in record class zeroecho.pki.spi.crypto.SignatureWorkflow.OperationResult
Returns the value of the verified record component.
VERIFIED - Enum constant in enum class zeroecho.pki.api.request.ProofOfPossessionStatus
Proof-of-possession has been successfully verified.
VerifiedIssuanceCandidate - Class in zeroecho.pki.impl.core
Immutable internal authority for a request that passed the issuance PoP gate.
verify(ParsedCertificationRequest, VerificationPolicy) - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509ProofOfPossessionVerifier
Verifies proof of possession for a parsed PKCS#10 certification request.
verify(ParsedCertificationRequest, VerificationPolicy) - Method in class zeroecho.pki.impl.framework.x509.bc.WorkflowProofOfPossessionVerifier
Verifies proof of possession for a parsed PKCS#10 certification request by delegating signature verification to the configured workflow.
verify(ParsedCertificationRequest, VerificationPolicy) - Method in interface zeroecho.pki.spi.framework.ProofOfPossessionVerifier
Verifies proof-of-possession for the requested public key.
verify(X509AuthoritySnapshot, X509ExecutionPlan<BcX509VerificationExecutor>, SubjectPublicKeyInfo, AlgorithmIdentifier, RepeatableContent, byte[]) - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509VerificationExecutor
Verifies one signature using an already-authorized exact plan.
verifyBackup(BackupArtifact) - Method in interface zeroecho.pki.api.BackupService
Verifies a backup artifact for structural validity and integrity.
verifyProofOfPossession(ParsedCertificationRequest, VerificationPolicy) - Method in interface zeroecho.pki.api.CertificationRequestService
Verifies proof-of-possession (PoP) for the private key corresponding to the requested public key.
verifyProofOfPossession(ParsedCertificationRequest, VerificationPolicy) - Method in class zeroecho.pki.impl.core.DefaultCertificationRequestService
Verifies proof of possession for a previously parsed certification request.
VerifyRequest(AccessContext, String, RepeatableContent, EncodedObject, Optional<KeyRef>, Optional<EncodedObject>, Optional<Instant>, CancellationSignal) - Constructor for record class zeroecho.pki.spi.crypto.SignatureWorkflow.VerifyRequest
Creates an instance of a VerifyRequest record class.
VerifyRequest(PkiId) - Constructor for record class zeroecho.pki.application.PkiOperation.VerifyRequest
Validates the request identity.
version() - Method in record class zeroecho.pki.application.PkiSessionConfiguration
Returns the value of the version record component.

W

WAITING_APPROVAL - Enum constant in enum class zeroecho.pki.spi.crypto.SignatureWorkflow.State
 
warnings() - Method in record class zeroecho.pki.api.backup.RestoreReport
Returns the value of the warnings record component.
wired(BcX509StatusObjectGenerator) - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFramework
Creates a fully wired X.509 framework instance using the current parser, proof-of-possession verifier and attribute mapper together with the supplied status-object generator.
wired(BcX509StatusObjectGenerator, ProofOfPossessionVerifier) - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509CredentialFramework
Creates a fully wired X.509 framework instance with an explicitly supplied proof-of-possession verifier.
Wiring model - Search tag in package zeroecho.pki.impl.framework.x509.bc
Section
withAuditSink(AuditSink) - Method in record class zeroecho.pki.application.PkiSessionRuntimeDependencies
Returns a dependency set using one lifecycle-owned shared audit sink.
withKeyringUnlockProvider(KeyringUnlockProvider) - Static method in record class zeroecho.pki.application.PkiSessionRuntimeDependencies
Creates dependencies containing one explicit process-local unlock provider.
withKeyringUnlockProvider(KeyringUnlockProvider) - Static method in class zeroecho.pki.spi.crypto.SignatureWorkflowRuntimeDependencies
Creates dependencies containing an explicit software-keyring unlock provider.
withoutLiveContent() - Method in class zeroecho.pki.impl.core.async.PkiSigningBus.SignContinuation
Returns a terminal continuation retaining only immutable content commitment metadata.
withSignerOpId(PkiId) - Method in class zeroecho.pki.impl.core.async.PkiSigningBus.SignContinuation
Returns a new continuation with the downstream signer workflow operation identifier assigned.
workflow() - Method in record class zeroecho.pki.application.PkiSessionConfiguration.SigningConfiguration
Returns the value of the workflow record component.
workflowHistoryPolicy() - Method in record class zeroecho.pki.impl.fs.FsPkiStoreOptions
Returns the value of the workflowHistoryPolicy record component.
WorkflowProofOfPossessionVerifier - Class in zeroecho.pki.impl.framework.x509.bc
Proof-of-possession verifier for PKCS#10 certification requests that delegates signature verification to a SignatureWorkflow.
WorkflowProofOfPossessionVerifier(SignatureWorkflow, X509AuthoritySnapshot) - Constructor for class zeroecho.pki.impl.framework.x509.bc.WorkflowProofOfPossessionVerifier
Creates a verifier bound to the runtime's immutable authority snapshot.
WorkflowStateRecord - Record Class in zeroecho.pki.api.orch
Persisted continuation state for an orchestrated workflow.
WorkflowStateRecord(PkiId, String, Principal, OrchestrationDurabilityPolicy, Instant, Instant, Instant, Encoding, Optional<EncodedObject>) - Constructor for record class zeroecho.pki.api.orch.WorkflowStateRecord
Creates an instance of a WorkflowStateRecord record class.
wrap(byte[], AlgorithmIdentity, String) - Method in class zeroecho.pki.impl.framework.x509.bc.BcX509PublicKeyAdapter
Wraps canonical native SPKI DER under one explicit binding.
write(AttributeCatalogue, AttributeSet, AttributeId, AttributeValue, AccessContext) - Method in interface zeroecho.pki.api.audit.AttributeGovernanceService
Writes an attribute value after applying access control.
write(AttributeCatalogue, AttributeSet, AttributeId, AttributeValue, AccessContext) - Method in class zeroecho.pki.impl.audit.DefaultAttributeGovernanceService
 
WRITE - Enum constant in enum class zeroecho.pki.api.audit.AccessAction
Write or modify an attribute value.
writeCanonical(CertificateProfileDefinition) - Static method in class zeroecho.pki.api.profile.CertificateProfileDocumentCodec
Writes the canonical UTF-8 JSON representation.
writerModel() - Method in record class zeroecho.pki.spi.store.MetadataStoreCapabilities
Returns the value of the writerModel record component.
writeTagAndLength(OutputStream, int, long) - Static method in class zeroecho.pki.impl.framework.x509.StreamingDerWriter
Writes one canonical DER tag and definite length.

X

X509AlgorithmBinding - Record Class in zeroecho.pki.api.algorithm
Immutable safe descriptor of one role-specific X.509 algorithm binding.
X509AlgorithmBinding(String, AlgorithmIdentity, X509AlgorithmBinding.Role, String, X509AlgorithmBinding.Origin, int, X509AlgorithmBinding.ParameterRule, X509AlgorithmBinding.PublicKeyEncoding, X509AlgorithmBinding.SignatureEncoding, X509AlgorithmBinding.Interoperability, Optional<String>, String) - Constructor for record class zeroecho.pki.api.algorithm.X509AlgorithmBinding
Validates and snapshots one descriptor.
X509AlgorithmBinding.Interoperability - Enum Class in zeroecho.pki.api.algorithm
Relying-party interoperability expectation.
X509AlgorithmBinding.Origin - Enum Class in zeroecho.pki.api.algorithm
Authority that owns the OID assignment.
X509AlgorithmBinding.ParameterRule - Enum Class in zeroecho.pki.api.algorithm
Canonical AlgorithmIdentifier parameter representation.
X509AlgorithmBinding.PublicKeyEncoding - Enum Class in zeroecho.pki.api.algorithm
Subject-public-key BIT STRING representation.
X509AlgorithmBinding.Role - Enum Class in zeroecho.pki.api.algorithm
X.509 locations whose representations are independently authorized.
X509AlgorithmBinding.SignatureEncoding - Enum Class in zeroecho.pki.api.algorithm
Signature BIT STRING representation.
X509AlgorithmBindingPolicy - Record Class in zeroecho.pki.api.profile
Immutable explicit X.509 representation policy persisted with a certificate profile.
X509AlgorithmBindingPolicy(X509AlgorithmBindingPolicy.Mode, Optional<X509AlgorithmBindingPolicy.BindingReference>, Optional<X509AlgorithmBindingPolicy.BindingReference>, Optional<X509AlgorithmBindingPolicy.BindingReference>, Optional<X509AlgorithmBindingPolicy.BindingReference>) - Constructor for record class zeroecho.pki.api.profile.X509AlgorithmBindingPolicy
Validates and snapshots the policy.
X509AlgorithmBindingPolicy.BindingReference - Record Class in zeroecho.pki.api.profile
Stable reference to one immutable binding contract.
X509AlgorithmBindingPolicy.Mode - Enum Class in zeroecho.pki.api.profile
Selection mode.
X509AlgorithmBindingProvider - Interface in zeroecho.pki.spi.algorithm
Installed-code provider of deployer-owned immutable X.509 bindings.
X509AlgorithmBindingRegistry - Interface in zeroecho.pki.api.algorithm
Immutable active X.509 algorithm-binding registry shared by one PKI session.
X509AlgorithmIdentifier - Class in zeroecho.pki.impl.framework.x509
Provider-neutral canonical X.509 AlgorithmIdentifier representation.
X509AlgorithmIdentifier.ParameterForm - Enum Class in zeroecho.pki.impl.framework.x509
Exact parameter representation.
X509AlgorithmResolver - Class in zeroecho.pki.impl.framework.x509
Provider-independent intersection of exact identity, binding, installed execution capability, immutable security floor, configured policy, and key compatibility.
X509AlgorithmResolver(X509BindingCatalog, AlgorithmExecutionCapabilities, X509AlgorithmResolver.Policy) - Constructor for class zeroecho.pki.impl.framework.x509.X509AlgorithmResolver
Creates an immutable resolver snapshot.
X509AlgorithmResolver.Failure - Enum Class in zeroecho.pki.impl.framework.x509
Stable resolution failure categories.
X509AlgorithmResolver.Policy - Interface in zeroecho.pki.impl.framework.x509
Policy decision over exact identity data.
X509AlgorithmResolver.ResolutionException - Exception Class in zeroecho.pki.impl.framework.x509
Resolution exception with a stable non-sensitive category.
X509AlgorithmResolver.Selection - Record Class in zeroecho.pki.impl.framework.x509
Immutable effective selection.
X509AlgorithmRole - Enum Class in zeroecho.pki.impl.framework.x509
Closed semantic role of an algorithm representation in X.509.
X509AuthoritySnapshot - Class in zeroecho.pki.impl.framework.x509
One immutable internally consistent runtime authority snapshot.
X509AuthoritySnapshot(AlgorithmIdentityCatalog, X509ComponentCatalog, X509BindingCatalog, AlgorithmExecutionCapabilities, X509AlgorithmResolver.Policy) - Constructor for class zeroecho.pki.impl.framework.x509.X509AuthoritySnapshot
Creates a consistent authority snapshot.
X509AuthoritySnapshot.ExecutorBinding - Class in zeroecho.pki.impl.framework.x509
Immutable process-local executor contribution.
X509BindingCatalog - Class in zeroecho.pki.impl.framework.x509
Deeply immutable snapshot of authoritative X.509 binding rules.
x509BindingCommitment() - Method in record class zeroecho.pki.api.ca.IssuerGeneration
Returns the value of the x509BindingCommitment record component.
X509BindingRule - Interface in zeroecho.pki.impl.framework.x509
Immutable trusted-code rule between exact ZeroEcho identities and X.509 representations.
X509BindingRule.PublicKeyEncoding - Enum Class in zeroecho.pki.impl.framework.x509
Subject-public-key bit-string representation.
X509BindingRule.SignatureEncoding - Enum Class in zeroecho.pki.impl.framework.x509
Signature byte representation owned by a signature rule.
X509BindingRuleProvider - Interface in zeroecho.pki.impl.framework.x509
Trusted installed-code contribution of additive X.509 binding rules.
X509BuiltInDefaults - Class in zeroecho.pki.impl.framework.x509
Immutable code-owned PKI defaults.
X509ComponentCatalog - Class in zeroecho.pki.impl.framework.x509
Immutable additive catalog of X.509 component identities used inside parameterized binding rules.
X509ComponentCatalog.Component - Record Class in zeroecho.pki.impl.framework.x509
Immutable component binding.
X509ComponentCatalog.Kind - Enum Class in zeroecho.pki.impl.framework.x509
Closed component role.
X509ExecutionPlan<E> - Class in zeroecho.pki.impl.framework.x509
Immutable process-local authorization to execute one resolved X.509 operation.
X509SecurityFloor - Class in zeroecho.pki.impl.framework.x509
Non-overridable PKI algorithm security floor.
X509SignedObjectCompletion - Class in zeroecho.pki.impl.framework.x509
Non-forgeable live completion of one X.509 signed status-object operation.
X509SuiteCompatibility - Class in zeroecho.pki.impl.framework.x509
Contextual compatibility validation for current classic X.509 suites.

Z

ZEROECHO_ASSIGNMENT_ROOT - Static variable in class zeroecho.pki.impl.framework.x509.ImmutableX509AlgorithmBindingRegistry
Frozen ZeroEcho private assignment branch.
ZEROECHO_DEPLOYMENT_ROOT - Static variable in class zeroecho.pki.impl.framework.x509.ImmutableX509AlgorithmBindingRegistry
Deployment-local experimental branch.
ZEROECHO_ECOSYSTEM - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.Interoperability
Relying parties with matching ZeroEcho bindings.
ZEROECHO_PRIVATE - Enum constant in enum class zeroecho.pki.api.algorithm.X509AlgorithmBinding.Origin
Frozen ZeroEcho assignment under the Egothor PEN.
zeroecho.pki - package zeroecho.pki
 
zeroecho.pki.api - package zeroecho.pki.api
Public, framework-agnostic PKI API.
zeroecho.pki.api.algorithm - package zeroecho.pki.api.algorithm
 
zeroecho.pki.api.attr - package zeroecho.pki.api.attr
Attribute catalogue and attribute-level modeling.
zeroecho.pki.api.audit - package zeroecho.pki.api.audit
Audit and governance API.
zeroecho.pki.api.backup - package zeroecho.pki.api.backup
Backup and restore domain model.
zeroecho.pki.api.ca - package zeroecho.pki.api.ca
Certificate Authority (CA) domain model.
zeroecho.pki.api.content - package zeroecho.pki.api.content
 
zeroecho.pki.api.credential - package zeroecho.pki.api.credential
Credential inventory domain model.
zeroecho.pki.api.issuance - package zeroecho.pki.api.issuance
Credential issuance domain model.
zeroecho.pki.api.orch - package zeroecho.pki.api.orch
Orchestration and workflow durability API for ZeroEcho PKI.
zeroecho.pki.api.policy - package zeroecho.pki.api.policy
Policy decision and trace model.
zeroecho.pki.api.profile - package zeroecho.pki.api.profile
Certificate and credential profiles.
zeroecho.pki.api.publication - package zeroecho.pki.api.publication
Publication domain model.
zeroecho.pki.api.request - package zeroecho.pki.api.request
Certification request domain model.
zeroecho.pki.api.revocation - package zeroecho.pki.api.revocation
Revocation and suspension domain model.
zeroecho.pki.api.status - package zeroecho.pki.api.status
Status objects domain model.
zeroecho.pki.api.transfer - package zeroecho.pki.api.transfer
Import/export transfer domain model.
zeroecho.pki.application - package zeroecho.pki.application
Lifecycle-owned synchronous PKI sessions and transport-neutral typed operations.
zeroecho.pki.impl - package zeroecho.pki.impl
 
zeroecho.pki.impl.async - package zeroecho.pki.impl.async
Default implementations for the PKI async bus SPI.
zeroecho.pki.impl.audit - package zeroecho.pki.impl.audit
Audit logging reference implementations for ZeroEcho PKI.
zeroecho.pki.impl.core - package zeroecho.pki.impl.core
Default store-backed PKI core service implementations and supporting internal contracts.
zeroecho.pki.impl.core.async - package zeroecho.pki.impl.core.async
Internal asynchronous orchestration support for PKI signing workflows.
zeroecho.pki.impl.core.attr - package zeroecho.pki.impl.core.attr
Internal attribute-set implementation support for PKI core runtime services.
zeroecho.pki.impl.crypto.zeroecholib - package zeroecho.pki.impl.crypto.zeroecholib
ZeroEcho-lib backed cryptographic workflow implementation for PKI signing and signature verification.
zeroecho.pki.impl.framework.x509 - package zeroecho.pki.impl.framework.x509
 
zeroecho.pki.impl.framework.x509.bc - package zeroecho.pki.impl.framework.x509.bc
Internal Bouncy Castle backed X.509 credential framework implementation for the PKI runtime.
zeroecho.pki.impl.fs - package zeroecho.pki.impl.fs
Filesystem-based reference implementation of the PKI persistence layer.
zeroecho.pki.impl.publish - package zeroecho.pki.impl.publish
 
zeroecho.pki.spi - package zeroecho.pki.spi
Service Provider Interfaces (SPIs) for the PKI module.
zeroecho.pki.spi.algorithm - package zeroecho.pki.spi.algorithm
 
zeroecho.pki.spi.async - package zeroecho.pki.spi.async
Asynchronous operation bus SPI.
zeroecho.pki.spi.audit - package zeroecho.pki.spi.audit
Service Provider Interfaces (SPI) for PKI audit event persistence.
zeroecho.pki.spi.bootstrap - package zeroecho.pki.spi.bootstrap
Bootstrap utilities for ServiceLoader-based components in the PKI module.
zeroecho.pki.spi.crypto - package zeroecho.pki.spi.crypto
Crypto boundary SPI for the PKI module.
zeroecho.pki.spi.framework - package zeroecho.pki.spi.framework
Credential framework SPI.
zeroecho.pki.spi.publish - package zeroecho.pki.spi.publish
Publishing SPI for distributing PKI artifacts.
zeroecho.pki.spi.store - package zeroecho.pki.spi.store
Persistence SPI for PKI state.
zeroecho.pki.util - package zeroecho.pki.util
Utility types and helper functions for ZeroEcho PKI.
zeroecho.pki.util.async - package zeroecho.pki.util.async
Generic asynchronous operation bus with durable tracking and callback dispatch.
zeroecho.pki.util.async.codec - package zeroecho.pki.util.async.codec
Codecs for persisting identifiers and (optionally) results of async operations.
zeroecho.pki.util.async.impl - package zeroecho.pki.util.async.impl
Reference implementations for the generic async bus.
ZeroEchoLibSignatureWorkflow - Class in zeroecho.pki.impl.crypto.zeroecholib
ZeroEcho-lib backed implementation of SignatureWorkflow.
ZeroEchoLibSignatureWorkflowProvider - Class in zeroecho.pki.impl.crypto.zeroecholib
Production provider bridging PKI signature workflow to ZeroEcho lib based on KeyringStore.
ZeroEchoLibSignatureWorkflowProvider() - Constructor for class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflowProvider
Creates a service-loadable provider without unlock material.
ZeroEchoLibSignatureWorkflowProvider(KeyringUnlockProvider) - Constructor for class zeroecho.pki.impl.crypto.zeroecholib.ZeroEchoLibSignatureWorkflowProvider
Creates a provider with an explicit headless unlock source.
ZeroEchoPrivateX509Bindings - Class in zeroecho.pki.impl.framework.x509
Loads and locks the version-one ZeroEcho-owned private X.509 assignments.
A B C D E F G H I K L M N O P R S T U V W X Z 
All Classes and Interfaces|All Packages|Constant Field Values|Serialized Form