Documentation · Widgets

Certificates

The cert widget is a certificate inspector and status checker. It is secret-free (it works only with public data) and is convenient to embed as a panel.

Example

import { embed } from 'https://dstucrypt.io/embed/dstucrypt-embed.mjs';

const cert = await embed('cert', { mount: '#cert-box' });

const info = await cert.inspect(certFile);
//  info = { subject, issuer, serial, validFrom, validTo, keyUsage[],
//           ocspUrl, caIssuersUrl, tspUrl }

const verdict = await cert.verify(certFile, { via: 'ocsp' });
//  verdict = { status: 'GOOD' | 'REVOKED' | …, … }

API

inspect(cert) — parse a certificate

Returns the key fields:

Field Description
subject owner (full name / organization name)
issuer the accredited CA that issued the certificate
serial serial number
validFrom / validTo validity period
keyUsage key purpose (digitalSignature, keyAgreement, …)
accredited whether it was issued by an accredited CA (true/false/null) — i.e. whether it is a QES certificate or not
ocspUrl status-check service URL
caIssuersUrl certificate chain URL (AIA)
tspUrl TSP URL of this accredited CA

verify(cert, { via }) — check the status

  • via: 'ocsp' — online check with the accredited CA (recommended);
  • via: 'crl' — against the certificate revocation list.

Returns { status }: GOOD — valid, REVOKED — revoked.

loadChain(cert) — fetch the chain

Downloads the issuer certificates via AIA and adds them to the cache of the widget's current session — useful before verification when the accredited CA is exotic. Returns { added } — the number of certificates added.

Network requests (OCSP/CRL/AIA) go through our built-in proxy — nothing needs to be configured.

Backend verification

For authoritative certificate verification on the server (accreditation + OCSP + subject) there is the POST /api/verify endpoint with the body { "cert": "<base64>" } — see Server-side verification.