Skip to main content

revocation_status

Creates, updates, deletes, gets or lists a revocation_status resource.

Overview

Namerevocation_status
TypeResource
Idaws.signer.revocation_status

Fields

The following fields are returned by SELECT queries:

NameDatatypeDescription
revoked_entitystringA list of revoked entities (including zero or more of the signing profile ARN, signing job ARN, and certificate hashes) supplied as input to the API.

Methods

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
get_revocation_statusselectsignatureTimestamp, platformId, profileVersionArn, jobArn, certificateHashes, regionRetrieves the revocation status of one or more of the signing profile, signing job, and signing certificate.

Parameters

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
certificateHashesarrayA list of composite signed hashes that identify certificates. A certificate identifier consists of a subject certificate TBS hash (signed by the parent CA) combined with a parent CA TBS hash (signed by the parent CA’s CA). Root certificates are defined as their own CA. The following example shows how to calculate a hash for this parameter using OpenSSL commands: openssl asn1parse -in childCert.pem -strparse 4 -out childCert.tbs openssl sha384 < childCert.tbs -binary > childCertTbsHash openssl asn1parse -in parentCert.pem -strparse 4 -out parentCert.tbs openssl sha384 < parentCert.tbs -binary > parentCertTbsHash xxd -p childCertTbsHash > certificateHash.hex xxd -p parentCertTbsHash >> certificateHash.hex cat certificateHash.hex | tr -d '\n'
jobArnstringThe ARN of a signing job.
platformIdstringThe ID of a signing platform.
profileVersionArnstringThe version of a signing profile.
regionstringAWS region (default: us-east-1)
signatureTimestampstring (date-time)The timestamp of the signature that validates the profile or job.

SELECT examples

Retrieves the revocation status of one or more of the signing profile, signing job, and signing certificate.

SELECT
revoked_entity
FROM aws.signer.revocation_status
WHERE signatureTimestamp = '{{ signatureTimestamp }}' -- required
AND platformId = '{{ platformId }}' -- required
AND profileVersionArn = '{{ profileVersionArn }}' -- required
AND jobArn = '{{ jobArn }}' -- required
AND certificateHashes = '{{ certificateHashes }}' -- required
AND region = '{{ region }}' -- required
;