Sign in

    MoonBit-PKI

    Pure-MoonBit ASN.1 DER codec and X.509 certificate toolkit.

    asn1
    der
    x509
    pki
    certificate
    Download zip
    Version
    0.1.0
    License
    Apache-2.0
    Last updated
    8 hours ago
    Downloads
    2

    #MoonBit PKI

    A pure-MoonBit ASN.1 DER codec and X.509 certificate toolkit.

    The library is being built feature by feature. The ASN.1/DER foundation (package oilleelssq-wq/MoonBit-PKI/asn1) is implemented and tested; the X.509 layer, PEM support and the x509dump command line tool follow in later increments.

    #Why

    MoonBit has no general-purpose ASN.1 or PKI library. Everything in the ecosystem that touches certificates, TLS, code signing, x5c JWT headers or PKCS structures ends up needing a DER decoder and an X.509 parser. The only related package on mooncakes.io today is a minimal DER reader aimed at RSA private keys, which covers PKCS#1/PKCS#8 but not certificates, extensions, CSRs or CRLs.

    This module aims to fill that gap with a small, dependency-light, well-tested implementation:

    • A DER/BER-aware tag-length-value reader with strict DER canonical checks.
    • Primitive decoders for the types used by certificates and keys.
    • An object identifier type with dotted-decimal rendering.
    • Later: X.509 certificates (TBSCertificate, extensions, SAN, key usage), PEM, CSRs and a x509dump CLI.

    #Goals

    • Stay in pure MoonBit with no C, JS or WASI dependencies.
    • Work on every backend (wasm, wasm-gc, js, native).
    • Prefer zero-copy views over the input buffer.
    • Report malformed input through a precise error type instead of panicking.

    #Install

    moon add oilleelssq-wq/MoonBit-PKI

    #Usage

    Decode a value and inspect it:

    import { "oilleelssq-wq/MoonBit-PKI/asn1" @asn1 }

    ///|
    test "read a DER integer" {
    let reader = @asn1.DerReader::from_bytes(b"\x02\x01\x2a")
    let value = try! reader.read_single()
    inspect(value.to_string(), content="[UNIVERSAL 2 primitive] 1B 2a")
    }

    Decode a certificate-shaped structure and read the first fields:

    import { "oilleelssq-wq/MoonBit-PKI/asn1" @asn1 }

    ///|
    fn inspect_sequence(bytes : Bytes) -> Unit raise @asn1.DerError {
    let outer = try! @asn1.DerReader::from_bytes(bytes).read_single()
    let children = outer.children()
    println(children[0].tag().to_string())
    }

    #Packages

    PackageContents
    oilleelssq-wq/MoonBit-PKI/asn1DER reader, value tree, primitive decoders, object identifiers

    #API overview

    ItemPurpose
    DerReaderCursor over DER bytes: read_tlv, read_element, read_all, read_single
    DerDecoded tree of Primitive/Constructed values
    Tag, TagClassDecoded identifier octets
    decode_integer, decode_boolean, decode_bit_string, ...Primitive content decoders
    ObjectIdentifierDotted-decimal OIDs
    DerErrorDecode failures

    #Development

    moon check --target all --deny-warn moon test --target all moon fmt moon info

    #References

    • ITU-T X.680, Abstract Syntax Notation One (ASN.1): Specification of basic notation.
    • ITU-T X.690, ASN.1 encoding rules: BER, CER and DER.
    • RFC 5280, Internet X.509 Public Key Infrastructure Certificate and CRL Profile.

    #License

    Apache-2.0. See LICENSE.

    Powered by MoonBit

    Site sourceReport issuePackagesBuild queueSkillsStatistics

    © 2026 mooncakes.io