toCoseX5Chain

fun toCoseX5Chain(excludeRoot: Boolean = true): DataItem

Encodes the certificate chain as CBOR for use in COSE 'x5chain' header parameter (label 33) according to RFC 9360 Section 2.

If excludeRoot is true, the certificate chain has more than one certificate, and the last certificate is a root certificate (self-signed), it is excluded.

If the resulting chain has only one certificate, a Bstr containing the DER-encoded certificate is returned. Otherwise, a CborArray of Bstrs containing each DER-encoded certificate is returned.

Return

a DataItem representing the COSE 'x5chain'.

Parameters

excludeRoot

whether to exclude a self-signed root certificate if the chain has more than one certificate.