mirror of
https://git.gnunet.org/libmicrohttpd.git
synced 2026-10-07 04:02:18 +03:00
indenting
This commit is contained in:
1 parent
484e65d76e
commit
9181dd0a07
151 files changed
+3626
-3546
No files matched your search
@@ -440,7 +440,7 @@ _gnutls_x509_data2hex (const opaque * data,
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* TIME functions
|
||||
/* TIME functions
|
||||
* Convertions between generalized or UTC time to time_t
|
||||
*
|
||||
*/
|
||||
@@ -463,7 +463,7 @@ typedef struct fake_tm
|
||||
* who placed it under public domain:
|
||||
*/
|
||||
|
||||
/* The number of days in each month.
|
||||
/* The number of days in each month.
|
||||
*/
|
||||
static const int MONTHDAYS[] = { 31,
|
||||
28,
|
||||
@@ -498,12 +498,12 @@ mktime_utc (const struct fake_tm *tm)
|
||||
/* We do allow some ill-formed dates, but we don't do anything special
|
||||
* with them and our callers really shouldn't pass them to us. Do
|
||||
* explicitly disallow the ones that would cause invalid array accesses
|
||||
* or other algorithm problems.
|
||||
* or other algorithm problems.
|
||||
*/
|
||||
if (tm->tm_mon < 0 || tm->tm_mon > 11 || tm->tm_year < 1970)
|
||||
return (time_t) - 1;
|
||||
|
||||
/* Convert to a time_t.
|
||||
/* Convert to a time_t.
|
||||
*/
|
||||
for (i = 1970; i < tm->tm_year; i++)
|
||||
result += 365 + ISLEAP (i);
|
||||
@@ -1319,7 +1319,7 @@ _gnutls_x509_get_pk_algorithm (ASN1_TYPE src,
|
||||
return algo;
|
||||
}
|
||||
|
||||
/* Now read the parameters' bits
|
||||
/* Now read the parameters' bits
|
||||
*/
|
||||
mhd_gtls_str_cpy (name, sizeof (name), src_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".subjectPublicKey");
|
||||
@@ -1442,7 +1442,7 @@ _gnutls_x509_get_signature (ASN1_TYPE src,
|
||||
signature->data = NULL;
|
||||
signature->size = 0;
|
||||
|
||||
/* Read the signature
|
||||
/* Read the signature
|
||||
*/
|
||||
bits = 0;
|
||||
result = asn1_read_value (src, src_name, NULL, &bits);
|
||||
|
||||
@@ -63,13 +63,13 @@ time_t _gnutls_x509_generalTime2gtime (const char *ttime);
|
||||
int _gnutls_x509_set_time (ASN1_TYPE c2, const char *where, time_t tim);
|
||||
|
||||
int _gnutls_x509_decode_octet_string (const char *string_type,
|
||||
const opaque * der, size_t der_size,
|
||||
opaque * output, size_t * output_size);
|
||||
const opaque * der, size_t der_size,
|
||||
opaque * output, size_t * output_size);
|
||||
int _gnutls_x509_oid_data2string (const char *OID, void *value,
|
||||
int value_size, char *res,
|
||||
size_t * res_size);
|
||||
int value_size, char *res,
|
||||
size_t * res_size);
|
||||
int _gnutls_x509_data2hex (const opaque * data, size_t data_size,
|
||||
opaque * out, size_t * sizeof_out);
|
||||
opaque * out, size_t * sizeof_out);
|
||||
|
||||
const char *_gnutls_x509_oid2ldap_string (const char *OID);
|
||||
|
||||
@@ -81,46 +81,47 @@ time_t _gnutls_x509_get_time (ASN1_TYPE c2, const char *when);
|
||||
gnutls_x509_subject_alt_name_t _gnutls_x509_san_find_type (char *str_type);
|
||||
|
||||
int _gnutls_x509_der_encode_and_copy (ASN1_TYPE src, const char *src_name,
|
||||
ASN1_TYPE dest, const char *dest_name,
|
||||
int str);
|
||||
ASN1_TYPE dest, const char *dest_name,
|
||||
int str);
|
||||
int _gnutls_x509_der_encode (ASN1_TYPE src, const char *src_name,
|
||||
gnutls_datum_t * res, int str);
|
||||
gnutls_datum_t * res, int str);
|
||||
|
||||
int _gnutls_x509_export_int (ASN1_TYPE asn1_data,
|
||||
gnutls_x509_crt_fmt_t format, char *pem_header,
|
||||
unsigned char *output_data,
|
||||
size_t * output_data_size);
|
||||
gnutls_x509_crt_fmt_t format, char *pem_header,
|
||||
unsigned char *output_data,
|
||||
size_t * output_data_size);
|
||||
|
||||
int _gnutls_x509_read_value (ASN1_TYPE c, const char *root,
|
||||
gnutls_datum_t * ret, int str);
|
||||
gnutls_datum_t * ret, int str);
|
||||
int _gnutls_x509_write_value (ASN1_TYPE c, const char *root,
|
||||
const gnutls_datum_t * data, int str);
|
||||
const gnutls_datum_t * data, int str);
|
||||
|
||||
int _gnutls_x509_encode_and_write_attribute (const char *given_oid,
|
||||
ASN1_TYPE asn1_struct,
|
||||
const char *where,
|
||||
const void *data,
|
||||
int sizeof_data, int multi);
|
||||
ASN1_TYPE asn1_struct,
|
||||
const char *where,
|
||||
const void *data,
|
||||
int sizeof_data, int multi);
|
||||
int _gnutls_x509_decode_and_read_attribute (ASN1_TYPE asn1_struct,
|
||||
const char *where, char *oid,
|
||||
int oid_size,
|
||||
gnutls_datum_t * value, int multi,
|
||||
int octet);
|
||||
const char *where, char *oid,
|
||||
int oid_size,
|
||||
gnutls_datum_t * value, int multi,
|
||||
int octet);
|
||||
|
||||
int _gnutls_x509_get_pk_algorithm (ASN1_TYPE src, const char *src_name,
|
||||
unsigned int *bits);
|
||||
unsigned int *bits);
|
||||
|
||||
int _gnutls_x509_encode_and_copy_PKI_params (ASN1_TYPE dst,
|
||||
const char *dst_name,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm
|
||||
pk_algorithm, mpi_t * params,
|
||||
int params_size);
|
||||
const char *dst_name,
|
||||
enum
|
||||
MHD_GNUTLS_PublicKeyAlgorithm
|
||||
pk_algorithm, mpi_t * params,
|
||||
int params_size);
|
||||
int _gnutls_asn1_copy_node (ASN1_TYPE * dst, const char *dst_name,
|
||||
ASN1_TYPE src, const char *src_name);
|
||||
ASN1_TYPE src, const char *src_name);
|
||||
|
||||
int _gnutls_x509_get_signed_data (ASN1_TYPE src, const char *src_name,
|
||||
gnutls_datum_t * signed_data);
|
||||
gnutls_datum_t * signed_data);
|
||||
int _gnutls_x509_get_signature (ASN1_TYPE src, const char *src_name,
|
||||
gnutls_datum_t * signature);
|
||||
gnutls_datum_t * signature);
|
||||
|
||||
#endif
|
||||
@@ -73,7 +73,7 @@ gnutls_x509_crl_init (gnutls_x509_crl_t * crl)
|
||||
* gnutls_x509_crl_deinit - This function deinitializes memory used by a gnutls_x509_crl_t structure
|
||||
* @crl: The structure to be initialized
|
||||
*
|
||||
* This function will deinitialize a CRL structure.
|
||||
* This function will deinitialize a CRL structure.
|
||||
*
|
||||
**/
|
||||
void
|
||||
@@ -168,7 +168,7 @@ cleanup:
|
||||
* @buf: a pointer to a structure to hold the peer's name (may be null)
|
||||
* @sizeof_buf: initially holds the size of @buf
|
||||
*
|
||||
* This function will copy the name of the CRL issuer in the provided buffer. The name
|
||||
* This function will copy the name of the CRL issuer in the provided buffer. The name
|
||||
* will be in the form "C=xxxx,O=yyyy,CN=zzzz" as described in RFC2253. The output
|
||||
* string will be ASCII or UTF-8 encoded, depending on the certificate data.
|
||||
*
|
||||
@@ -208,7 +208,7 @@ gnutls_x509_crl_get_issuer_dn (const gnutls_x509_crl_t crl, char *buf,
|
||||
* string will be ASCII or UTF-8 encoded, depending on the certificate data.
|
||||
*
|
||||
* Some helper macros with popular OIDs can be found in gnutls/x509.h
|
||||
* If raw flag is zero, this function will only return known OIDs as text. Other OIDs
|
||||
* If raw flag is zero, this function will only return known OIDs as text. Other OIDs
|
||||
* will be DER encoded, as described in RFC2253 -- in hex format with a '\#' prefix.
|
||||
* You can check about known OIDs using gnutls_x509_dn_oid_known().
|
||||
*
|
||||
@@ -244,7 +244,7 @@ gnutls_x509_crl_get_issuer_dn_by_oid (gnutls_x509_crl_t crl,
|
||||
* @sizeof_oid: initially holds the size of 'oid'
|
||||
*
|
||||
* This function will extract the requested OID of the name of the CRL issuer, specified
|
||||
* by the given index.
|
||||
* by the given index.
|
||||
*
|
||||
* If oid is null then only the size will be filled.
|
||||
*
|
||||
@@ -273,8 +273,8 @@ gnutls_x509_crl_get_dn_oid (gnutls_x509_crl_t crl,
|
||||
* gnutls_x509_crl_get_signature_algorithm - This function returns the CRL's signature algorithm
|
||||
* @crl: should contain a gnutls_x509_crl_t structure
|
||||
*
|
||||
* This function will return a value of the gnutls_sign_algorithm_t enumeration that
|
||||
* is the signature algorithm.
|
||||
* This function will return a value of the gnutls_sign_algorithm_t enumeration that
|
||||
* is the signature algorithm.
|
||||
*
|
||||
* Returns a negative value on error.
|
||||
*
|
||||
@@ -651,7 +651,7 @@ gnutls_x509_crl_export (gnutls_x509_crl_t crl,
|
||||
* @dest: The structure where to copy
|
||||
* @src: The structure to be copied
|
||||
*
|
||||
* This function will copy an X.509 certificate structure.
|
||||
* This function will copy an X.509 certificate structure.
|
||||
*
|
||||
* Returns 0 on success.
|
||||
*
|
||||
|
||||
@@ -197,7 +197,7 @@ gnutls_x509_crl_set_next_update (gnutls_x509_crl_t crl, time_t exp_time)
|
||||
* @serial_size: Holds the size of the serial field.
|
||||
* @revocation_time: The time this certificate was revoked
|
||||
*
|
||||
* This function will set a revoked certificate's serial number to the CRL.
|
||||
* This function will set a revoked certificate's serial number to the CRL.
|
||||
*
|
||||
* Returns 0 on success, or a negative value in case of an error.
|
||||
*
|
||||
@@ -262,7 +262,7 @@ gnutls_x509_crl_set_crt_serial (gnutls_x509_crl_t crl,
|
||||
* @crt: should contain a gnutls_x509_crt_t structure with the revoked certificate
|
||||
* @revocation_time: The time this certificate was revoked
|
||||
*
|
||||
* This function will set a revoked certificate's serial number to the CRL.
|
||||
* This function will set a revoked certificate's serial number to the CRL.
|
||||
*
|
||||
* Returns 0 on success, or a negative value in case of an error.
|
||||
*
|
||||
|
||||
@@ -46,7 +46,7 @@
|
||||
* gnutls_x509_crq_init - This function initializes a gnutls_x509_crq_t structure
|
||||
* @crq: The structure to be initialized
|
||||
*
|
||||
* This function will initialize a PKCS10 certificate request structure.
|
||||
* This function will initialize a PKCS10 certificate request structure.
|
||||
*
|
||||
* Returns 0 on success.
|
||||
*
|
||||
@@ -76,7 +76,7 @@ gnutls_x509_crq_init (gnutls_x509_crq_t * crq)
|
||||
* gnutls_x509_crq_deinit - This function deinitializes memory used by a gnutls_x509_crq_t structure
|
||||
* @crq: The structure to be initialized
|
||||
*
|
||||
* This function will deinitialize a CRL structure.
|
||||
* This function will deinitialize a CRL structure.
|
||||
*
|
||||
**/
|
||||
void
|
||||
@@ -336,7 +336,7 @@ parse_attribute (ASN1_TYPE asn1_struct,
|
||||
|
||||
/* Move to the attibute type and values
|
||||
*/
|
||||
/* Read the OID
|
||||
/* Read the OID
|
||||
*/
|
||||
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer1);
|
||||
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
@@ -356,7 +356,7 @@ parse_attribute (ASN1_TYPE asn1_struct,
|
||||
if (strcmp (oid, given_oid) == 0)
|
||||
{ /* Found the OID */
|
||||
|
||||
/* Read the Value
|
||||
/* Read the Value
|
||||
*/
|
||||
snprintf (tmpbuffer3, sizeof (tmpbuffer3), "%s.values.?%u",
|
||||
tmpbuffer1, indx + 1);
|
||||
@@ -421,7 +421,7 @@ cleanup:
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_get_challenge_password - This function will get the challenge password
|
||||
* gnutls_x509_crq_get_challenge_password - This function will get the challenge password
|
||||
* @crq: should contain a gnutls_x509_crq_t structure
|
||||
* @pass: will hold a null terminated password
|
||||
* @sizeof_pass: Initially holds the size of @pass.
|
||||
@@ -499,7 +499,7 @@ gnutls_x509_crq_set_attribute_by_oid (gnutls_x509_crq_t crq,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_get_attribute_by_oid - This function will get an attribute of the request
|
||||
* gnutls_x509_crq_get_attribute_by_oid - This function will get an attribute of the request
|
||||
* @crq: should contain a gnutls_x509_crq_t structure
|
||||
* @oid: holds an Object Identified in null terminated string
|
||||
* @indx: In case multiple same OIDs exist in the attribute list, this specifies
|
||||
@@ -674,7 +674,7 @@ gnutls_x509_crq_set_key (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key)
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_set_challenge_password - This function will set a challenge password
|
||||
* gnutls_x509_crq_set_challenge_password - This function will set a challenge password
|
||||
* @crq: should contain a gnutls_x509_crq_t structure
|
||||
* @pass: holds a null terminated password
|
||||
*
|
||||
@@ -849,11 +849,11 @@ gnutls_x509_crq_export (gnutls_x509_crq_t crq,
|
||||
* @crq: should contain a gnutls_x509_crq_t structure
|
||||
* @bits: if bits is non null it will hold the size of the parameters' in bits
|
||||
*
|
||||
* This function will return the public key algorithm of a PKCS \#10
|
||||
* This function will return the public key algorithm of a PKCS \#10
|
||||
* certificate request.
|
||||
*
|
||||
* If bits is non null, it should have enough size to hold the parameters
|
||||
* size in bits. For RSA the bits returned is the modulus.
|
||||
* size in bits. For RSA the bits returned is the modulus.
|
||||
* For DSA the bits returned are of the public
|
||||
* exponent.
|
||||
*
|
||||
|
||||
+14
-13
@@ -37,7 +37,7 @@
|
||||
*/
|
||||
|
||||
/* Converts the given OID to an ldap acceptable string or
|
||||
* a dotted OID.
|
||||
* a dotted OID.
|
||||
*/
|
||||
static const char *
|
||||
oid2ldap_string (const char *oid)
|
||||
@@ -173,7 +173,7 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Read the OID
|
||||
/* Read the OID
|
||||
*/
|
||||
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
@@ -190,7 +190,7 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Read the Value
|
||||
/* Read the Value
|
||||
*/
|
||||
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".value");
|
||||
@@ -280,7 +280,8 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
gnutls_assert ();
|
||||
_gnutls_x509_log
|
||||
("Found OID: '%s' with value '%s'\n",
|
||||
oid, mhd_gtls_bin2hex (value2, len, escaped, sizeof_escaped));
|
||||
oid, mhd_gtls_bin2hex (value2, len, escaped,
|
||||
sizeof_escaped));
|
||||
goto cleanup;
|
||||
}
|
||||
STR_APPEND (str_escape (string, escaped, sizeof_escaped));
|
||||
@@ -416,7 +417,7 @@ _gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Read the OID
|
||||
/* Read the OID
|
||||
*/
|
||||
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
@@ -436,7 +437,7 @@ _gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
|
||||
if (strcmp (oid, given_oid) == 0 && indx == i++)
|
||||
{ /* Found the OID */
|
||||
|
||||
/* Read the Value
|
||||
/* Read the Value
|
||||
*/
|
||||
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".value");
|
||||
@@ -585,7 +586,7 @@ _gnutls_x509_get_dn_oid (ASN1_TYPE asn1_struct,
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Read the OID
|
||||
/* Read the OID
|
||||
*/
|
||||
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
@@ -722,7 +723,7 @@ _gnutls_x509_encode_and_write_attribute (const char *given_oid,
|
||||
|
||||
if (multi != 0)
|
||||
{ /* if not writing an AttributeTypeAndValue, but an Attribute */
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), "s"); /* values */
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), "s"); /* values */
|
||||
|
||||
result = asn1_write_value (asn1_struct, tmp, "NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
@@ -777,7 +778,7 @@ _gnutls_x509_write_attribute (const char *given_oid,
|
||||
|
||||
if (multi != 0)
|
||||
{ /* if not writing an AttributeTypeAndValue, but an Attribute */
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), "s"); /* values */
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), "s"); /* values */
|
||||
|
||||
result = asn1_write_value (asn1_struct, tmp, "NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
@@ -830,7 +831,7 @@ _gnutls_x509_decode_and_read_attribute (ASN1_TYPE asn1_struct,
|
||||
char tmpbuffer[128];
|
||||
int len, result;
|
||||
|
||||
/* Read the OID
|
||||
/* Read the OID
|
||||
*/
|
||||
mhd_gtls_str_cpy (tmpbuffer, sizeof (tmpbuffer), where);
|
||||
mhd_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), ".type");
|
||||
@@ -845,14 +846,14 @@ _gnutls_x509_decode_and_read_attribute (ASN1_TYPE asn1_struct,
|
||||
return result;
|
||||
}
|
||||
|
||||
/* Read the Value
|
||||
/* Read the Value
|
||||
*/
|
||||
|
||||
mhd_gtls_str_cpy (tmpbuffer, sizeof (tmpbuffer), where);
|
||||
mhd_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), ".value");
|
||||
|
||||
if (multi)
|
||||
mhd_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), "s.?1"); /* .values.?1 */
|
||||
mhd_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), "s.?1"); /* .values.?1 */
|
||||
|
||||
result =
|
||||
_gnutls_x509_read_value (asn1_struct, tmpbuffer, value, octet_string);
|
||||
@@ -899,7 +900,7 @@ _gnutls_x509_set_dn_oid (ASN1_TYPE asn1_struct,
|
||||
mhd_gtls_str_cpy (asn1_rdn_name, sizeof (asn1_rdn_name), asn1_name);
|
||||
mhd_gtls_str_cat (asn1_rdn_name, sizeof (asn1_rdn_name), ".rdnSequence");
|
||||
|
||||
/* create a new element
|
||||
/* create a new element
|
||||
*/
|
||||
result = asn1_write_value (asn1_struct, asn1_rdn_name, "NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
|
||||
@@ -38,21 +38,21 @@
|
||||
#define OID_PKCS9_EMAIL "1.2.840.113549.1.9.1"
|
||||
|
||||
int _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
const char *asn1_rdn_name, char *buf,
|
||||
size_t * sizeof_buf);
|
||||
const char *asn1_rdn_name, char *buf,
|
||||
size_t * sizeof_buf);
|
||||
|
||||
int _gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
|
||||
const char *asn1_rdn_name, const char *oid,
|
||||
int indx, unsigned int raw_flag, void *buf,
|
||||
size_t * sizeof_buf);
|
||||
const char *asn1_rdn_name, const char *oid,
|
||||
int indx, unsigned int raw_flag, void *buf,
|
||||
size_t * sizeof_buf);
|
||||
|
||||
int _gnutls_x509_set_dn_oid (ASN1_TYPE asn1_struct,
|
||||
const char *asn1_rdn_name, const char *oid,
|
||||
int raw_flag, const char *name, int sizeof_name);
|
||||
const char *asn1_rdn_name, const char *oid,
|
||||
int raw_flag, const char *name, int sizeof_name);
|
||||
|
||||
int _gnutls_x509_get_dn_oid (ASN1_TYPE asn1_struct,
|
||||
const char *asn1_rdn_name,
|
||||
int indx, void *_oid, size_t * sizeof_oid);
|
||||
const char *asn1_rdn_name,
|
||||
int indx, void *_oid, size_t * sizeof_oid);
|
||||
|
||||
|
||||
#endif
|
||||
@@ -59,7 +59,7 @@ _gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits)
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
}
|
||||
|
||||
/* generate the DSA key
|
||||
/* generate the DSA key
|
||||
*/
|
||||
ret = gcry_pk_genkey (&key, parms);
|
||||
gcry_sexp_release (parms);
|
||||
|
||||
@@ -99,11 +99,11 @@ _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
|
||||
return mhd_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
/* Handle Extension
|
||||
/* Handle Extension
|
||||
*/
|
||||
if (strcmp (extnID, extension_id) == 0 && indx == indx_counter++)
|
||||
{
|
||||
/* extension was found
|
||||
/* extension was found
|
||||
*/
|
||||
|
||||
/* read the critical status.
|
||||
@@ -170,7 +170,7 @@ _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
/* This function will attempt to return the requested extension OID found in
|
||||
* the given X509v3 certificate.
|
||||
* the given X509v3 certificate.
|
||||
*
|
||||
* If you have passed the last extension, GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE will
|
||||
* be returned.
|
||||
@@ -223,7 +223,7 @@ _gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
|
||||
return mhd_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
/* Handle Extension
|
||||
/* Handle Extension
|
||||
*/
|
||||
if (indx == indx_counter++)
|
||||
{
|
||||
@@ -260,7 +260,7 @@ _gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
/* This function will attempt to set the requested extension in
|
||||
* the given X509v3 certificate.
|
||||
* the given X509v3 certificate.
|
||||
*
|
||||
* Critical will be either 0 or 1.
|
||||
*/
|
||||
@@ -359,7 +359,7 @@ overwrite_extension (ASN1_TYPE asn, unsigned int indx,
|
||||
}
|
||||
|
||||
/* This function will attempt to overwrite the requested extension with
|
||||
* the given one.
|
||||
* the given one.
|
||||
*
|
||||
* Critical will be either 0 or 1.
|
||||
*/
|
||||
@@ -414,11 +414,11 @@ _gnutls_x509_crt_set_extension (gnutls_x509_crt_t cert,
|
||||
return mhd_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
/* Handle Extension
|
||||
/* Handle Extension
|
||||
*/
|
||||
if (strcmp (extnID, ext_id) == 0)
|
||||
{
|
||||
/* extension was found
|
||||
/* extension was found
|
||||
*/
|
||||
return overwrite_extension (cert->cert, k, ext_data, critical);
|
||||
}
|
||||
@@ -839,7 +839,7 @@ _gnutls_x509_ext_gen_auth_key_id (const void *id, size_t id_size,
|
||||
|
||||
|
||||
/* Creates and encodes the CRL Distribution points. data_string should be a name
|
||||
* and type holds the type of the name.
|
||||
* and type holds the type of the name.
|
||||
* reason_flags should be an or'ed sequence of GNUTLS_CRL_REASON_*.
|
||||
*
|
||||
*/
|
||||
|
||||
@@ -23,46 +23,46 @@
|
||||
*/
|
||||
|
||||
int _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
|
||||
const char *extension_id, int indx,
|
||||
gnutls_datum_t * ret,
|
||||
unsigned int *critical);
|
||||
const char *extension_id, int indx,
|
||||
gnutls_datum_t * ret,
|
||||
unsigned int *critical);
|
||||
|
||||
int _gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
|
||||
int indx, void *ret,
|
||||
size_t * ret_size);
|
||||
int indx, void *ret,
|
||||
size_t * ret_size);
|
||||
int _gnutls_x509_ext_extract_keyUsage (uint16_t * keyUsage,
|
||||
opaque * extnValue, int extnValueLen);
|
||||
opaque * extnValue, int extnValueLen);
|
||||
int _gnutls_x509_ext_extract_basicConstraints (int *CA,
|
||||
int *pathLenConstraint,
|
||||
opaque * extnValue,
|
||||
int extnValueLen);
|
||||
int *pathLenConstraint,
|
||||
opaque * extnValue,
|
||||
int extnValueLen);
|
||||
int _gnutls_x509_crt_set_extension (gnutls_x509_crt_t cert,
|
||||
const char *extension_id,
|
||||
const gnutls_datum_t * ext_data,
|
||||
unsigned int critical);
|
||||
const char *extension_id,
|
||||
const gnutls_datum_t * ext_data,
|
||||
unsigned int critical);
|
||||
int _gnutls_x509_ext_gen_basicConstraints (int CA, int pathLenConstraint,
|
||||
gnutls_datum_t * der_ext);
|
||||
gnutls_datum_t * der_ext);
|
||||
int _gnutls_x509_ext_gen_keyUsage (uint16_t usage, gnutls_datum_t * der_ext);
|
||||
int _gnutls_x509_ext_gen_subject_alt_name (gnutls_x509_subject_alt_name_t
|
||||
type, const char *data_string,
|
||||
gnutls_datum_t * der_ext);
|
||||
type, const char *data_string,
|
||||
gnutls_datum_t * der_ext);
|
||||
int _gnutls_x509_ext_gen_crl_dist_points (gnutls_x509_subject_alt_name_t
|
||||
type, const void *data_string,
|
||||
unsigned int reason_flags,
|
||||
gnutls_datum_t * der_ext);
|
||||
type, const void *data_string,
|
||||
unsigned int reason_flags,
|
||||
gnutls_datum_t * der_ext);
|
||||
int _gnutls_x509_ext_gen_key_id (const void *id, size_t id_size,
|
||||
gnutls_datum_t * der_data);
|
||||
gnutls_datum_t * der_data);
|
||||
int _gnutls_x509_ext_gen_auth_key_id (const void *id, size_t id_size,
|
||||
gnutls_datum_t * der_data);
|
||||
gnutls_datum_t * der_data);
|
||||
|
||||
int _gnutls_x509_ext_extract_proxyCertInfo (int *pathLenConstraint,
|
||||
char **policyLanguage,
|
||||
char **policy,
|
||||
size_t *sizeof_policy,
|
||||
opaque * extnValue,
|
||||
int extnValueLen);
|
||||
char **policyLanguage,
|
||||
char **policy,
|
||||
size_t * sizeof_policy,
|
||||
opaque * extnValue,
|
||||
int extnValueLen);
|
||||
int _gnutls_x509_ext_gen_proxyCertInfo (int pathLenConstraint,
|
||||
const char *policyLanguage,
|
||||
const char *policy,
|
||||
size_t sizeof_policy,
|
||||
gnutls_datum_t * der_ext);
|
||||
const char *policyLanguage,
|
||||
const char *policy,
|
||||
size_t sizeof_policy,
|
||||
gnutls_datum_t * der_ext);
|
||||
@@ -335,7 +335,8 @@ cleanup:asn1_delete_structure (&spk);
|
||||
int
|
||||
_gnutls_x509_write_sig_params (ASN1_TYPE dst,
|
||||
const char *dst_name,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm pk_algorithm,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm
|
||||
pk_algorithm,
|
||||
enum MHD_GNUTLS_HashAlgorithm dig,
|
||||
mpi_t * params, int params_size)
|
||||
{
|
||||
|
||||
+13
-13
@@ -26,32 +26,32 @@
|
||||
#include "x509.h"
|
||||
|
||||
int _gnutls_x509_crt_get_mpis (gnutls_x509_crt_t cert,
|
||||
mpi_t * params, int *params_size);
|
||||
mpi_t * params, int *params_size);
|
||||
int _gnutls_x509_read_rsa_params (opaque * der, int dersize, mpi_t * params);
|
||||
int _gnutls_x509_read_dsa_pubkey (opaque * der, int dersize, mpi_t * params);
|
||||
int _gnutls_x509_read_dsa_params (opaque * der, int dersize, mpi_t * params);
|
||||
|
||||
int _gnutls_x509_write_rsa_params (mpi_t * params, int params_size,
|
||||
gnutls_datum_t * der);
|
||||
gnutls_datum_t * der);
|
||||
int _gnutls_x509_write_dsa_params (mpi_t * params, int params_size,
|
||||
gnutls_datum_t * der);
|
||||
gnutls_datum_t * der);
|
||||
int _gnutls_x509_write_dsa_public_key (mpi_t * params, int params_size,
|
||||
gnutls_datum_t * der);
|
||||
gnutls_datum_t * der);
|
||||
|
||||
int _gnutls_x509_read_uint (ASN1_TYPE node, const char *value,
|
||||
unsigned int *ret);
|
||||
unsigned int *ret);
|
||||
|
||||
int
|
||||
_gnutls_x509_read_der_int (opaque * der, int dersize, mpi_t* out);
|
||||
int _gnutls_x509_read_der_int (opaque * der, int dersize, mpi_t * out);
|
||||
|
||||
int _gnutls_x509_read_int (ASN1_TYPE node, const char *value,
|
||||
mpi_t * ret_mpi);
|
||||
mpi_t * ret_mpi);
|
||||
int _gnutls_x509_write_int (ASN1_TYPE node, const char *value, mpi_t mpi,
|
||||
int lz);
|
||||
int lz);
|
||||
int _gnutls_x509_write_uint32 (ASN1_TYPE node, const char *value,
|
||||
uint32_t num);
|
||||
uint32_t num);
|
||||
|
||||
int _gnutls_x509_write_sig_params (ASN1_TYPE dst, const char *dst_name,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm pk_algorithm,
|
||||
enum MHD_GNUTLS_HashAlgorithm, mpi_t * params,
|
||||
int params_size);
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm
|
||||
pk_algorithm,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
mpi_t * params, int params_size);
|
||||
+82
-104
@@ -28,7 +28,7 @@
|
||||
|
||||
#ifdef __cplusplus
|
||||
extern "C"
|
||||
{
|
||||
{
|
||||
#endif
|
||||
|
||||
#include <x509.h>
|
||||
@@ -37,15 +37,15 @@ extern "C"
|
||||
|
||||
/* PKCS12 structures handling
|
||||
*/
|
||||
struct gnutls_pkcs12_int;
|
||||
struct gnutls_pkcs12_int;
|
||||
|
||||
struct gnutls_pkcs12_bag_int;
|
||||
typedef struct gnutls_pkcs12_int
|
||||
struct gnutls_pkcs12_bag_int;
|
||||
typedef struct gnutls_pkcs12_int
|
||||
{
|
||||
ASN1_TYPE pkcs12;
|
||||
} gnutls_pkcs12_int;
|
||||
|
||||
typedef enum gnutls_pkcs12_bag_type_t
|
||||
typedef enum gnutls_pkcs12_bag_type_t
|
||||
{
|
||||
GNUTLS_BAG_EMPTY = 0,
|
||||
|
||||
@@ -57,7 +57,7 @@ typedef enum gnutls_pkcs12_bag_type_t
|
||||
GNUTLS_BAG_UNKNOWN = 20
|
||||
} gnutls_pkcs12_bag_type_t;
|
||||
|
||||
struct bag_element
|
||||
struct bag_element
|
||||
{
|
||||
gnutls_datum_t data;
|
||||
gnutls_pkcs12_bag_type_t type;
|
||||
@@ -65,7 +65,7 @@ struct bag_element
|
||||
char *friendly_name;
|
||||
};
|
||||
|
||||
typedef struct gnutls_pkcs12_bag_int
|
||||
typedef struct gnutls_pkcs12_bag_int
|
||||
{
|
||||
struct bag_element element[MAX_BAG_ELEMENTS];
|
||||
int bag_elements;
|
||||
@@ -75,68 +75,54 @@ typedef struct gnutls_pkcs12_bag_int
|
||||
#define FRIENDLY_NAME_OID "1.2.840.113549.1.9.20"
|
||||
#define KEY_ID_OID "1.2.840.113549.1.9.21"
|
||||
|
||||
typedef struct gnutls_pkcs12_int *gnutls_pkcs12_t;
|
||||
typedef struct gnutls_pkcs12_bag_int *gnutls_pkcs12_bag_t;
|
||||
typedef struct gnutls_pkcs12_int *gnutls_pkcs12_t;
|
||||
typedef struct gnutls_pkcs12_bag_int *gnutls_pkcs12_bag_t;
|
||||
|
||||
int gnutls_pkcs12_init(gnutls_pkcs12_t * pkcs12);
|
||||
void gnutls_pkcs12_deinit(gnutls_pkcs12_t pkcs12);
|
||||
int gnutls_pkcs12_import(gnutls_pkcs12_t pkcs12,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
unsigned int flags);
|
||||
int gnutls_pkcs12_export(gnutls_pkcs12_t pkcs12,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
int gnutls_pkcs12_init (gnutls_pkcs12_t * pkcs12);
|
||||
void gnutls_pkcs12_deinit (gnutls_pkcs12_t pkcs12);
|
||||
int gnutls_pkcs12_import (gnutls_pkcs12_t pkcs12,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format, unsigned int flags);
|
||||
int gnutls_pkcs12_export (gnutls_pkcs12_t pkcs12,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
|
||||
int gnutls_pkcs12_get_bag(gnutls_pkcs12_t pkcs12,
|
||||
int indx,
|
||||
gnutls_pkcs12_bag_t bag);
|
||||
int gnutls_pkcs12_set_bag(gnutls_pkcs12_t pkcs12,
|
||||
gnutls_pkcs12_bag_t bag);
|
||||
int gnutls_pkcs12_get_bag (gnutls_pkcs12_t pkcs12,
|
||||
int indx, gnutls_pkcs12_bag_t bag);
|
||||
int gnutls_pkcs12_set_bag (gnutls_pkcs12_t pkcs12, gnutls_pkcs12_bag_t bag);
|
||||
|
||||
int gnutls_pkcs12_generate_mac(gnutls_pkcs12_t pkcs12,
|
||||
const char *pass);
|
||||
int gnutls_pkcs12_verify_mac(gnutls_pkcs12_t pkcs12,
|
||||
const char *pass);
|
||||
int gnutls_pkcs12_generate_mac (gnutls_pkcs12_t pkcs12, const char *pass);
|
||||
int gnutls_pkcs12_verify_mac (gnutls_pkcs12_t pkcs12, const char *pass);
|
||||
|
||||
int gnutls_pkcs12_bag_decrypt(gnutls_pkcs12_bag_t bag,
|
||||
const char *pass);
|
||||
int gnutls_pkcs12_bag_encrypt(gnutls_pkcs12_bag_t bag,
|
||||
const char *pass,
|
||||
unsigned int flags);
|
||||
int gnutls_pkcs12_bag_decrypt (gnutls_pkcs12_bag_t bag, const char *pass);
|
||||
int gnutls_pkcs12_bag_encrypt (gnutls_pkcs12_bag_t bag,
|
||||
const char *pass, unsigned int flags);
|
||||
|
||||
gnutls_pkcs12_bag_type_t gnutls_pkcs12_bag_get_type(gnutls_pkcs12_bag_t
|
||||
bag,
|
||||
int indx);
|
||||
int gnutls_pkcs12_bag_get_data(gnutls_pkcs12_bag_t bag,
|
||||
int indx,
|
||||
gnutls_datum_t * data);
|
||||
int gnutls_pkcs12_bag_set_data(gnutls_pkcs12_bag_t bag,
|
||||
gnutls_pkcs12_bag_type_t type,
|
||||
const gnutls_datum_t * data);
|
||||
int gnutls_pkcs12_bag_set_crl(gnutls_pkcs12_bag_t bag,
|
||||
gnutls_x509_crl_t crl);
|
||||
int gnutls_pkcs12_bag_set_crt(gnutls_pkcs12_bag_t bag,
|
||||
gnutls_x509_crt_t crt);
|
||||
gnutls_pkcs12_bag_type_t gnutls_pkcs12_bag_get_type (gnutls_pkcs12_bag_t
|
||||
bag, int indx);
|
||||
int gnutls_pkcs12_bag_get_data (gnutls_pkcs12_bag_t bag,
|
||||
int indx, gnutls_datum_t * data);
|
||||
int gnutls_pkcs12_bag_set_data (gnutls_pkcs12_bag_t bag,
|
||||
gnutls_pkcs12_bag_type_t type,
|
||||
const gnutls_datum_t * data);
|
||||
int gnutls_pkcs12_bag_set_crl (gnutls_pkcs12_bag_t bag,
|
||||
gnutls_x509_crl_t crl);
|
||||
int gnutls_pkcs12_bag_set_crt (gnutls_pkcs12_bag_t bag,
|
||||
gnutls_x509_crt_t crt);
|
||||
|
||||
int gnutls_pkcs12_bag_init(gnutls_pkcs12_bag_t * bag);
|
||||
void gnutls_pkcs12_bag_deinit(gnutls_pkcs12_bag_t bag);
|
||||
int gnutls_pkcs12_bag_get_count(gnutls_pkcs12_bag_t bag);
|
||||
int gnutls_pkcs12_bag_init (gnutls_pkcs12_bag_t * bag);
|
||||
void gnutls_pkcs12_bag_deinit (gnutls_pkcs12_bag_t bag);
|
||||
int gnutls_pkcs12_bag_get_count (gnutls_pkcs12_bag_t bag);
|
||||
|
||||
int gnutls_pkcs12_bag_get_key_id(gnutls_pkcs12_bag_t bag,
|
||||
int indx,
|
||||
gnutls_datum_t * id);
|
||||
int gnutls_pkcs12_bag_set_key_id(gnutls_pkcs12_bag_t bag,
|
||||
int indx,
|
||||
const gnutls_datum_t * id);
|
||||
int gnutls_pkcs12_bag_get_key_id (gnutls_pkcs12_bag_t bag,
|
||||
int indx, gnutls_datum_t * id);
|
||||
int gnutls_pkcs12_bag_set_key_id (gnutls_pkcs12_bag_t bag,
|
||||
int indx, const gnutls_datum_t * id);
|
||||
|
||||
int gnutls_pkcs12_bag_get_friendly_name(gnutls_pkcs12_bag_t bag,
|
||||
int indx,
|
||||
char **name);
|
||||
int gnutls_pkcs12_bag_set_friendly_name(gnutls_pkcs12_bag_t bag,
|
||||
int indx,
|
||||
const char *name);
|
||||
int gnutls_pkcs12_bag_get_friendly_name (gnutls_pkcs12_bag_t bag,
|
||||
int indx, char **name);
|
||||
int gnutls_pkcs12_bag_set_friendly_name (gnutls_pkcs12_bag_t bag,
|
||||
int indx, const char *name);
|
||||
|
||||
#ifdef __cplusplus
|
||||
}
|
||||
@@ -152,56 +138,48 @@ int gnutls_pkcs12_bag_set_friendly_name(gnutls_pkcs12_bag_t bag,
|
||||
#define DATA_OID "1.2.840.113549.1.7.1"
|
||||
#define ENC_DATA_OID "1.2.840.113549.1.7.6"
|
||||
|
||||
int gnutls_pkcs12_init(gnutls_pkcs12_t * pkcs12);
|
||||
void gnutls_pkcs12_deinit(gnutls_pkcs12_t pkcs12);
|
||||
int gnutls_pkcs12_import(gnutls_pkcs12_t pkcs12,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
unsigned int flags);
|
||||
int gnutls_pkcs12_init (gnutls_pkcs12_t * pkcs12);
|
||||
void gnutls_pkcs12_deinit (gnutls_pkcs12_t pkcs12);
|
||||
int gnutls_pkcs12_import (gnutls_pkcs12_t pkcs12,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format, unsigned int flags);
|
||||
|
||||
int gnutls_pkcs12_get_bag(gnutls_pkcs12_t pkcs12,
|
||||
int indx,
|
||||
gnutls_pkcs12_bag_t bag);
|
||||
int gnutls_pkcs12_get_bag (gnutls_pkcs12_t pkcs12,
|
||||
int indx, gnutls_pkcs12_bag_t bag);
|
||||
|
||||
int gnutls_pkcs12_bag_init(gnutls_pkcs12_bag_t * bag);
|
||||
void gnutls_pkcs12_bag_deinit(gnutls_pkcs12_bag_t bag);
|
||||
int gnutls_pkcs12_bag_init (gnutls_pkcs12_bag_t * bag);
|
||||
void gnutls_pkcs12_bag_deinit (gnutls_pkcs12_bag_t bag);
|
||||
|
||||
int _pkcs12_string_to_key(unsigned int id,
|
||||
const opaque * salt,
|
||||
unsigned int salt_size,
|
||||
unsigned int iter,
|
||||
const char *pw,
|
||||
unsigned int req_keylen,
|
||||
opaque * keybuf);
|
||||
int _pkcs12_string_to_key (unsigned int id,
|
||||
const opaque * salt,
|
||||
unsigned int salt_size,
|
||||
unsigned int iter,
|
||||
const char *pw,
|
||||
unsigned int req_keylen, opaque * keybuf);
|
||||
|
||||
int _gnutls_pkcs7_decrypt_data(const gnutls_datum_t * data,
|
||||
const char *password,
|
||||
gnutls_datum_t * dec);
|
||||
int _gnutls_pkcs7_decrypt_data (const gnutls_datum_t * data,
|
||||
const char *password, gnutls_datum_t * dec);
|
||||
|
||||
typedef enum schema_id
|
||||
{
|
||||
PBES2, /* the stuff in PKCS #5 */
|
||||
PKCS12_3DES_SHA1, /* the fucking stuff in PKCS #12 */
|
||||
PKCS12_ARCFOUR_SHA1,
|
||||
PKCS12_RC2_40_SHA1
|
||||
} schema_id;
|
||||
{
|
||||
PBES2, /* the stuff in PKCS #5 */
|
||||
PKCS12_3DES_SHA1, /* the fucking stuff in PKCS #12 */
|
||||
PKCS12_ARCFOUR_SHA1,
|
||||
PKCS12_RC2_40_SHA1
|
||||
} schema_id;
|
||||
|
||||
int _gnutls_pkcs7_encrypt_data(schema_id schema,
|
||||
const gnutls_datum_t * data,
|
||||
const char *password,
|
||||
gnutls_datum_t * enc);
|
||||
int _pkcs12_decode_safe_contents(const gnutls_datum_t * content,
|
||||
gnutls_pkcs12_bag_t bag);
|
||||
int _gnutls_pkcs7_encrypt_data (schema_id schema,
|
||||
const gnutls_datum_t * data,
|
||||
const char *password, gnutls_datum_t * enc);
|
||||
int _pkcs12_decode_safe_contents (const gnutls_datum_t * content,
|
||||
gnutls_pkcs12_bag_t bag);
|
||||
|
||||
int _pkcs12_encode_safe_contents(gnutls_pkcs12_bag_t bag,
|
||||
ASN1_TYPE * content,
|
||||
int *enc);
|
||||
int _pkcs12_encode_safe_contents (gnutls_pkcs12_bag_t bag,
|
||||
ASN1_TYPE * content, int *enc);
|
||||
|
||||
int _pkcs12_decode_crt_bag(gnutls_pkcs12_bag_type_t type,
|
||||
const gnutls_datum_t * in,
|
||||
gnutls_datum_t * out);
|
||||
int _pkcs12_encode_crt_bag(gnutls_pkcs12_bag_type_t type,
|
||||
const gnutls_datum_t * raw,
|
||||
gnutls_datum_t * out);
|
||||
int _pkcs12_decode_crt_bag (gnutls_pkcs12_bag_type_t type,
|
||||
const gnutls_datum_t * in, gnutls_datum_t * out);
|
||||
int _pkcs12_encode_crt_bag (gnutls_pkcs12_bag_type_t type,
|
||||
const gnutls_datum_t * raw, gnutls_datum_t * out);
|
||||
|
||||
#endif /* GNUTLS_PKCS12_H */
|
||||
#endif /* GNUTLS_PKCS12_H */
|
||||
@@ -80,7 +80,7 @@ _pkcs12_bag_free_data (gnutls_pkcs12_bag_t bag)
|
||||
* gnutls_pkcs12_bag_deinit - This function deinitializes memory used by a gnutls_pkcs12_t structure
|
||||
* @bag: The structure to be initialized
|
||||
*
|
||||
* This function will deinitialize a PKCS12 Bag structure.
|
||||
* This function will deinitialize a PKCS12 Bag structure.
|
||||
*
|
||||
**/
|
||||
void
|
||||
@@ -121,7 +121,7 @@ gnutls_pkcs12_bag_get_type (gnutls_pkcs12_bag_t bag, int indx)
|
||||
* gnutls_pkcs12_bag_get_count - This function returns the bag's elements count
|
||||
* @bag: The bag
|
||||
*
|
||||
* This function will return the number of the elements withing the bag.
|
||||
* This function will return the number of the elements withing the bag.
|
||||
*
|
||||
**/
|
||||
int
|
||||
@@ -332,7 +332,7 @@ cleanup:
|
||||
* @data: the data to be copied.
|
||||
*
|
||||
* This function will insert the given data of the given type into the
|
||||
* bag.
|
||||
* bag.
|
||||
*
|
||||
* Returns the index of the added bag on success, or a negative
|
||||
* value on error.
|
||||
@@ -475,7 +475,7 @@ gnutls_pkcs12_bag_set_crl (gnutls_pkcs12_bag_t bag, gnutls_x509_crl_t crl)
|
||||
* This function will add the given key ID, to the specified, by the index, bag
|
||||
* element. The key ID will be encoded as a 'Local key identifier' bag attribute,
|
||||
* which is usually used to distinguish the local private key and the certificate pair.
|
||||
*
|
||||
*
|
||||
* Returns 0 on success, or a negative value on error.
|
||||
*
|
||||
**/
|
||||
@@ -518,7 +518,7 @@ gnutls_pkcs12_bag_set_key_id (gnutls_pkcs12_bag_t bag, int indx,
|
||||
*
|
||||
* This function will return the key ID, of the specified bag element.
|
||||
* The key ID is usually used to distinguish the local private key and the certificate pair.
|
||||
*
|
||||
*
|
||||
* Returns 0 on success, or a negative value on error.
|
||||
*
|
||||
**/
|
||||
@@ -552,7 +552,7 @@ gnutls_pkcs12_bag_get_key_id (gnutls_pkcs12_bag_t bag, int indx,
|
||||
*
|
||||
* This function will return the friendly name, of the specified bag element.
|
||||
* The key ID is usually used to distinguish the local private key and the certificate pair.
|
||||
*
|
||||
*
|
||||
* Returns 0 on success, or a negative value on error.
|
||||
*
|
||||
**/
|
||||
@@ -587,7 +587,7 @@ gnutls_pkcs12_bag_get_friendly_name (gnutls_pkcs12_bag_t bag, int indx,
|
||||
* This function will add the given key friendly name, to the specified, by the index, bag
|
||||
* element. The name will be encoded as a 'Friendly name' bag attribute,
|
||||
* which is usually used to set a user name to the local private key and the certificate pair.
|
||||
*
|
||||
*
|
||||
* Returns 0 on success, or a negative value on error.
|
||||
*
|
||||
**/
|
||||
@@ -752,7 +752,7 @@ gnutls_pkcs12_bag_encrypt (gnutls_pkcs12_bag_t bag, const char *pass,
|
||||
return ret;
|
||||
}
|
||||
|
||||
/* encryption succeeded.
|
||||
/* encryption succeeded.
|
||||
*/
|
||||
|
||||
_pkcs12_bag_free_data (bag);
|
||||
|
||||
@@ -40,7 +40,7 @@
|
||||
|
||||
#define SIGNED_DATA_OID "1.2.840.113549.1.7.2"
|
||||
|
||||
/* Decodes the PKCS #7 signed data, and returns an ASN1_TYPE,
|
||||
/* Decodes the PKCS #7 signed data, and returns an ASN1_TYPE,
|
||||
* which holds them. If raw is non null then the raw decoded
|
||||
* data are copied (they are locally allocated) there.
|
||||
*/
|
||||
@@ -175,7 +175,7 @@ gnutls_pkcs7_init (gnutls_pkcs7_t * pkcs7)
|
||||
* gnutls_pkcs7_deinit - This function deinitializes memory used by a gnutls_pkcs7_t structure
|
||||
* @pkcs7: The structure to be initialized
|
||||
*
|
||||
* This function will deinitialize a PKCS7 structure.
|
||||
* This function will deinitialize a PKCS7 structure.
|
||||
*
|
||||
**/
|
||||
void
|
||||
@@ -298,7 +298,7 @@ gnutls_pkcs7_get_crt_raw (gnutls_pkcs7_t pkcs7,
|
||||
return result;
|
||||
}
|
||||
|
||||
/* Step 2. Parse the CertificateSet
|
||||
/* Step 2. Parse the CertificateSet
|
||||
*/
|
||||
|
||||
snprintf (root2, sizeof (root2), "certificates.?%u", indx + 1);
|
||||
@@ -320,7 +320,7 @@ gnutls_pkcs7_get_crt_raw (gnutls_pkcs7_t pkcs7,
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* if 'Certificate' is the choice found:
|
||||
/* if 'Certificate' is the choice found:
|
||||
*/
|
||||
if (strcmp (oid, "certificate") == 0)
|
||||
{
|
||||
@@ -369,7 +369,7 @@ cleanup:
|
||||
* gnutls_pkcs7_get_crt_count - This function returns the number of certificates in a PKCS7 certificate set
|
||||
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
|
||||
*
|
||||
* This function will return the number of certifcates in the PKCS7 or
|
||||
* This function will return the number of certifcates in the PKCS7 or
|
||||
* RFC2630 certificate set.
|
||||
*
|
||||
* Returns a negative value on failure.
|
||||
@@ -755,12 +755,12 @@ gnutls_pkcs7_get_crl_raw (gnutls_pkcs7_t pkcs7,
|
||||
return result;
|
||||
}
|
||||
|
||||
/* Step 2. Parse the CertificateSet
|
||||
/* Step 2. Parse the CertificateSet
|
||||
*/
|
||||
|
||||
snprintf (root2, sizeof (root2), "crls.?%u", indx + 1);
|
||||
|
||||
/* Get the raw CRL
|
||||
/* Get the raw CRL
|
||||
*/
|
||||
result = asn1_der_decoding_startEnd (c2, tmp.data, tmp.size,
|
||||
root2, &start, &end);
|
||||
@@ -799,7 +799,7 @@ cleanup:
|
||||
* gnutls_pkcs7_get_crl_count - This function returns the number of crls in a PKCS7 crl set
|
||||
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
|
||||
*
|
||||
* This function will return the number of certifcates in the PKCS7 or
|
||||
* This function will return the number of certifcates in the PKCS7 or
|
||||
* RFC2630 crl set.
|
||||
*
|
||||
* Returns a negative value on failure.
|
||||
|
||||
@@ -25,7 +25,7 @@
|
||||
#include "x509.h"
|
||||
|
||||
ASN1_TYPE _gnutls_privkey_decode_pkcs1_rsa_key (const gnutls_datum_t *
|
||||
raw_key,
|
||||
gnutls_x509_privkey_t pkey);
|
||||
raw_key,
|
||||
gnutls_x509_privkey_t pkey);
|
||||
|
||||
int _gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params);
|
||||
@@ -1284,7 +1284,7 @@ error:
|
||||
/* Converts an OID to a gnutls cipher type.
|
||||
*/
|
||||
inline static int
|
||||
oid2cipher (const char *oid, enum MHD_GNUTLS_CipherAlgorithm * algo)
|
||||
oid2cipher (const char *oid, enum MHD_GNUTLS_CipherAlgorithm *algo)
|
||||
{
|
||||
|
||||
*algo = 0;
|
||||
|
||||
@@ -132,8 +132,9 @@ encode_ber_digest_info (enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
* params[1] is public key
|
||||
*/
|
||||
static int
|
||||
pkcs1_rsa_sign (enum MHD_GNUTLS_HashAlgorithm hash, const gnutls_datum_t * text,
|
||||
mpi_t * params, int params_len, gnutls_datum_t * signature)
|
||||
pkcs1_rsa_sign (enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
const gnutls_datum_t * text, mpi_t * params, int params_len,
|
||||
gnutls_datum_t * signature)
|
||||
{
|
||||
int ret;
|
||||
opaque _digest[MAX_HASH_SIZE];
|
||||
@@ -163,7 +164,7 @@ pkcs1_rsa_sign (enum MHD_GNUTLS_HashAlgorithm hash, const gnutls_datum_t * text,
|
||||
|
||||
if ((ret =
|
||||
mhd_gtls_sign (MHD_GNUTLS_PK_RSA, params, params_len, &info,
|
||||
signature)) < 0)
|
||||
signature)) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_free_datum (&info);
|
||||
@@ -179,7 +180,7 @@ pkcs1_rsa_sign (enum MHD_GNUTLS_HashAlgorithm hash, const gnutls_datum_t * text,
|
||||
* private key.
|
||||
*
|
||||
* returns 0 on success.
|
||||
*
|
||||
*
|
||||
* 'tbs' is the data to be signed
|
||||
* 'signature' will hold the signature!
|
||||
* 'hash' is only used in PKCS1 RSA signing.
|
||||
@@ -327,7 +328,7 @@ _gnutls_x509_pkix_sign (ASN1_TYPE src, const char *src_name,
|
||||
}
|
||||
|
||||
/* Step 3. Move up and write the AlgorithmIdentifier, which is also
|
||||
* the same.
|
||||
* the same.
|
||||
*/
|
||||
|
||||
result = _gnutls_x509_write_sig_params (src, "signatureAlgorithm",
|
||||
|
||||
@@ -23,14 +23,14 @@
|
||||
*/
|
||||
|
||||
int _gnutls_x509_sign (const gnutls_datum_t * tbs,
|
||||
enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
gnutls_x509_privkey_t signer,
|
||||
gnutls_datum_t * signature);
|
||||
enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
gnutls_x509_privkey_t signer,
|
||||
gnutls_datum_t * signature);
|
||||
int _gnutls_x509_sign_tbs (ASN1_TYPE cert, const char *tbs_name,
|
||||
enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
gnutls_x509_privkey_t signer,
|
||||
gnutls_datum_t * signature);
|
||||
enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
gnutls_x509_privkey_t signer,
|
||||
gnutls_datum_t * signature);
|
||||
int _gnutls_x509_pkix_sign (ASN1_TYPE src, const char *src_name,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
gnutls_x509_crt_t issuer,
|
||||
gnutls_x509_privkey_t issuer_key);
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
gnutls_x509_crt_t issuer,
|
||||
gnutls_x509_privkey_t issuer_key);
|
||||
@@ -25,10 +25,10 @@
|
||||
#include "x509.h"
|
||||
|
||||
int gnutls_x509_crt_is_issuer (gnutls_x509_crt_t cert,
|
||||
gnutls_x509_crt_t issuer);
|
||||
gnutls_x509_crt_t issuer);
|
||||
int _gnutls_x509_verify_signature (const gnutls_datum_t * tbs,
|
||||
const gnutls_datum_t * signature,
|
||||
gnutls_x509_crt_t issuer);
|
||||
const gnutls_datum_t * signature,
|
||||
gnutls_x509_crt_t issuer);
|
||||
int _gnutls_x509_privkey_verify_signature (const gnutls_datum_t * tbs,
|
||||
const gnutls_datum_t * signature,
|
||||
gnutls_x509_privkey_t issuer);
|
||||
const gnutls_datum_t * signature,
|
||||
gnutls_x509_privkey_t issuer);
|
||||
@@ -76,7 +76,7 @@ gnutls_x509_crt_init (gnutls_x509_crt_t * cert)
|
||||
* @dest: The structure where to copy
|
||||
* @src: The structure to be copied
|
||||
*
|
||||
* This function will copy an X.509 certificate structure.
|
||||
* This function will copy an X.509 certificate structure.
|
||||
*
|
||||
* Returns 0 on success.
|
||||
*
|
||||
@@ -131,7 +131,7 @@ _gnutls_x509_crt_cpy (gnutls_x509_crt_t dest, gnutls_x509_crt_t src)
|
||||
* gnutls_x509_crt_deinit - This function deinitializes memory used by a gnutls_x509_crt_t structure
|
||||
* @cert: The structure to be initialized
|
||||
*
|
||||
* This function will deinitialize a CRL structure.
|
||||
* This function will deinitialize a CRL structure.
|
||||
*
|
||||
**/
|
||||
void
|
||||
@@ -456,8 +456,8 @@ gnutls_x509_crt_get_dn_oid (gnutls_x509_crt_t cert,
|
||||
* gnutls_x509_crt_get_signature_algorithm - This function returns the Certificate's signature algorithm
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
*
|
||||
* This function will return a value of the gnutls_sign_algorithm_t enumeration that
|
||||
* is the signature algorithm.
|
||||
* This function will return a value of the gnutls_sign_algorithm_t enumeration that
|
||||
* is the signature algorithm.
|
||||
*
|
||||
* Returns a negative value on error.
|
||||
*
|
||||
@@ -635,11 +635,11 @@ gnutls_x509_crt_get_expiration_time (gnutls_x509_crt_t cert)
|
||||
* @result: The place where the serial number will be copied
|
||||
* @result_size: Holds the size of the result field.
|
||||
*
|
||||
* This function will return the X.509 certificate's serial number.
|
||||
* This function will return the X.509 certificate's serial number.
|
||||
* This is obtained by the X509 Certificate serialNumber
|
||||
* field. Serial is not always a 32 or 64bit number. Some CAs use
|
||||
* large serial numbers, thus it may be wise to handle it as something
|
||||
* opaque.
|
||||
* opaque.
|
||||
*
|
||||
* Returns 0 on success and a negative value in case of an error.
|
||||
*
|
||||
@@ -680,7 +680,7 @@ gnutls_x509_crt_get_serial (gnutls_x509_crt_t cert,
|
||||
*
|
||||
* This function will return the X.509v3 certificate's subject key identifier.
|
||||
* This is obtained by the X.509 Subject Key identifier extension
|
||||
* field (2.5.29.14).
|
||||
* field (2.5.29.14).
|
||||
*
|
||||
* Returns 0 on success and a negative value in case of an error.
|
||||
*
|
||||
@@ -850,11 +850,11 @@ gnutls_x509_crt_get_authority_key_id (gnutls_x509_crt_t cert,
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* @bits: if bits is non null it will hold the size of the parameters' in bits
|
||||
*
|
||||
* This function will return the public key algorithm of an X.509
|
||||
* This function will return the public key algorithm of an X.509
|
||||
* certificate.
|
||||
*
|
||||
* If bits is non null, it should have enough size to hold the parameters
|
||||
* size in bits. For RSA the bits returned is the modulus.
|
||||
* size in bits. For RSA the bits returned is the modulus.
|
||||
* For DSA the bits returned are of the public
|
||||
* exponent.
|
||||
*
|
||||
@@ -1353,7 +1353,7 @@ gnutls_x509_crt_get_ca_status (gnutls_x509_crt_t cert, unsigned int *critical)
|
||||
* @key_usage: where the key usage bits will be stored
|
||||
* @critical: will be non zero if the extension is marked as critical
|
||||
*
|
||||
* This function will return certificate's key usage, by reading the
|
||||
* This function will return certificate's key usage, by reading the
|
||||
* keyUsage X.509 extension (2.5.29.15). The key usage value will ORed values of the:
|
||||
* GNUTLS_KEY_DIGITAL_SIGNATURE, GNUTLS_KEY_NON_REPUDIATION,
|
||||
* GNUTLS_KEY_KEY_ENCIPHERMENT, GNUTLS_KEY_DATA_ENCIPHERMENT,
|
||||
@@ -1547,7 +1547,7 @@ gnutls_x509_crt_get_extension_by_oid (gnutls_x509_crt_t cert,
|
||||
* The extension OID will be stored as a string in the provided buffer.
|
||||
*
|
||||
* A negative value may be returned in case of parsing error.
|
||||
* If your have reached the last extension available
|
||||
* If your have reached the last extension available
|
||||
* GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE will be returned.
|
||||
*
|
||||
**/
|
||||
@@ -2166,7 +2166,7 @@ gnutls_x509_crt_get_key_id (gnutls_x509_crt_t crt,
|
||||
}
|
||||
|
||||
result = MHD_gnutls_fingerprint (MHD_GNUTLS_MAC_SHA1, &pubkey, output_data,
|
||||
output_data_size);
|
||||
output_data_size);
|
||||
|
||||
gnutls_afree (pubkey.data);
|
||||
|
||||
@@ -2813,7 +2813,7 @@ gnutls_x509_crt_list_import (gnutls_x509_crt_t * certs,
|
||||
}
|
||||
}
|
||||
|
||||
/* now we move ptr after the pem header
|
||||
/* now we move ptr after the pem header
|
||||
*/
|
||||
ptr++;
|
||||
/* find the next certificate (if any)
|
||||
|
||||
+559
-628
@@ -29,7 +29,7 @@
|
||||
|
||||
#ifdef __cplusplus
|
||||
extern "C"
|
||||
{
|
||||
{
|
||||
#endif
|
||||
|
||||
#include <gnutls.h>
|
||||
@@ -78,7 +78,7 @@ extern "C"
|
||||
|
||||
/* Certificate handling functions.
|
||||
*/
|
||||
typedef enum gnutls_certificate_import_flags
|
||||
typedef enum gnutls_certificate_import_flags
|
||||
{
|
||||
/* Fail if the certificates in the buffer are more than the space
|
||||
* allocated for certificates. The error code will be
|
||||
@@ -87,71 +87,61 @@ typedef enum gnutls_certificate_import_flags
|
||||
GNUTLS_X509_CRT_LIST_IMPORT_FAIL_IF_EXCEED = 1
|
||||
} gnutls_certificate_import_flags;
|
||||
|
||||
int gnutls_x509_crt_init(gnutls_x509_crt_t * cert);
|
||||
void gnutls_x509_crt_deinit(gnutls_x509_crt_t cert);
|
||||
int gnutls_x509_crt_import(gnutls_x509_crt_t cert,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_crt_list_import(gnutls_x509_crt_t * certs,
|
||||
unsigned int *cert_max,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
unsigned int flags);
|
||||
int gnutls_x509_crt_export(gnutls_x509_crt_t cert,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
int gnutls_x509_crt_get_issuer_dn(gnutls_x509_crt_t cert,
|
||||
char *buf,
|
||||
size_t * sizeof_buf);
|
||||
int gnutls_x509_crt_get_issuer_dn_oid(gnutls_x509_crt_t cert,
|
||||
int indx,
|
||||
void *oid,
|
||||
size_t * sizeof_oid);
|
||||
int gnutls_x509_crt_get_issuer_dn_by_oid(gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int gnutls_x509_crt_init (gnutls_x509_crt_t * cert);
|
||||
void gnutls_x509_crt_deinit (gnutls_x509_crt_t cert);
|
||||
int gnutls_x509_crt_import (gnutls_x509_crt_t cert,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_crt_list_import (gnutls_x509_crt_t * certs,
|
||||
unsigned int *cert_max,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
unsigned int flags);
|
||||
int gnutls_x509_crt_export (gnutls_x509_crt_t cert,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
int gnutls_x509_crt_get_issuer_dn (gnutls_x509_crt_t cert,
|
||||
char *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crt_get_issuer_dn_oid (gnutls_x509_crt_t cert,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf,
|
||||
size_t * sizeof_buf);
|
||||
int gnutls_x509_crt_get_dn(gnutls_x509_crt_t cert,
|
||||
char *buf,
|
||||
size_t * sizeof_buf);
|
||||
int gnutls_x509_crt_get_dn_oid(gnutls_x509_crt_t cert,
|
||||
int indx,
|
||||
void *oid,
|
||||
size_t * sizeof_oid);
|
||||
int gnutls_x509_crt_get_dn_by_oid(gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf,
|
||||
size_t * sizeof_buf);
|
||||
int gnutls_x509_crt_check_hostname(gnutls_x509_crt_t cert,
|
||||
const char *hostname);
|
||||
void *oid, size_t * sizeof_oid);
|
||||
int gnutls_x509_crt_get_issuer_dn_by_oid (gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crt_get_dn (gnutls_x509_crt_t cert,
|
||||
char *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crt_get_dn_oid (gnutls_x509_crt_t cert,
|
||||
int indx, void *oid, size_t * sizeof_oid);
|
||||
int gnutls_x509_crt_get_dn_by_oid (gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crt_check_hostname (gnutls_x509_crt_t cert,
|
||||
const char *hostname);
|
||||
|
||||
int gnutls_x509_crt_get_signature_algorithm(gnutls_x509_crt_t cert);
|
||||
int gnutls_x509_crt_get_signature(gnutls_x509_crt_t cert,
|
||||
char *sig,
|
||||
size_t *sizeof_sig);
|
||||
int gnutls_x509_crt_get_version(gnutls_x509_crt_t cert);
|
||||
int gnutls_x509_crt_get_key_id(gnutls_x509_crt_t crt,
|
||||
unsigned int flags,
|
||||
unsigned char *output_data,
|
||||
size_t * output_data_size);
|
||||
int gnutls_x509_crt_get_signature_algorithm (gnutls_x509_crt_t cert);
|
||||
int gnutls_x509_crt_get_signature (gnutls_x509_crt_t cert,
|
||||
char *sig, size_t * sizeof_sig);
|
||||
int gnutls_x509_crt_get_version (gnutls_x509_crt_t cert);
|
||||
int gnutls_x509_crt_get_key_id (gnutls_x509_crt_t crt,
|
||||
unsigned int flags,
|
||||
unsigned char *output_data,
|
||||
size_t * output_data_size);
|
||||
|
||||
int gnutls_x509_crt_set_authority_key_id(gnutls_x509_crt_t cert,
|
||||
const void *id,
|
||||
size_t id_size);
|
||||
int gnutls_x509_crt_get_authority_key_id(gnutls_x509_crt_t cert,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_set_authority_key_id (gnutls_x509_crt_t cert,
|
||||
const void *id, size_t id_size);
|
||||
int gnutls_x509_crt_get_authority_key_id (gnutls_x509_crt_t cert,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *critical);
|
||||
|
||||
int gnutls_x509_crt_get_subject_key_id(gnutls_x509_crt_t cert,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_get_subject_key_id (gnutls_x509_crt_t cert,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *critical);
|
||||
|
||||
#define GNUTLS_CRL_REASON_UNUSED 128
|
||||
#define GNUTLS_CRL_REASON_KEY_COMPROMISE 64
|
||||
@@ -163,336 +153,303 @@ int gnutls_x509_crt_get_subject_key_id(gnutls_x509_crt_t cert,
|
||||
#define GNUTLS_CRL_REASON_PRIVILEGE_WITHDRAWN 1
|
||||
#define GNUTLS_CRL_REASON_AA_COMPROMISE 32768
|
||||
|
||||
int gnutls_x509_crt_get_crl_dist_points(gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *reason_flags,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_set_crl_dist_points(gnutls_x509_crt_t crt,
|
||||
gnutls_x509_subject_alt_name_t
|
||||
type,
|
||||
const void *data_string,
|
||||
unsigned int reason_flags);
|
||||
int gnutls_x509_crt_cpy_crl_dist_points(gnutls_x509_crt_t dst,
|
||||
gnutls_x509_crt_t src);
|
||||
int gnutls_x509_crt_get_crl_dist_points (gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *reason_flags,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_set_crl_dist_points (gnutls_x509_crt_t crt,
|
||||
gnutls_x509_subject_alt_name_t
|
||||
type,
|
||||
const void *data_string,
|
||||
unsigned int reason_flags);
|
||||
int gnutls_x509_crt_cpy_crl_dist_points (gnutls_x509_crt_t dst,
|
||||
gnutls_x509_crt_t src);
|
||||
|
||||
time_t gnutls_x509_crt_get_activation_time(gnutls_x509_crt_t cert);
|
||||
time_t gnutls_x509_crt_get_expiration_time(gnutls_x509_crt_t cert);
|
||||
int gnutls_x509_crt_get_serial(gnutls_x509_crt_t cert,
|
||||
void *result,
|
||||
size_t * result_size);
|
||||
time_t gnutls_x509_crt_get_activation_time (gnutls_x509_crt_t cert);
|
||||
time_t gnutls_x509_crt_get_expiration_time (gnutls_x509_crt_t cert);
|
||||
int gnutls_x509_crt_get_serial (gnutls_x509_crt_t cert,
|
||||
void *result, size_t * result_size);
|
||||
|
||||
int gnutls_x509_crt_get_pk_algorithm(gnutls_x509_crt_t cert,
|
||||
unsigned int *bits);
|
||||
int gnutls_x509_crt_get_pk_rsa_raw(gnutls_x509_crt_t crt,
|
||||
gnutls_datum_t * m,
|
||||
gnutls_datum_t * e);
|
||||
int gnutls_x509_crt_get_pk_dsa_raw(gnutls_x509_crt_t crt,
|
||||
gnutls_datum_t * p,
|
||||
gnutls_datum_t * q,
|
||||
gnutls_datum_t * g,
|
||||
gnutls_datum_t * y);
|
||||
int gnutls_x509_crt_get_pk_algorithm (gnutls_x509_crt_t cert,
|
||||
unsigned int *bits);
|
||||
int gnutls_x509_crt_get_pk_rsa_raw (gnutls_x509_crt_t crt,
|
||||
gnutls_datum_t * m, gnutls_datum_t * e);
|
||||
int gnutls_x509_crt_get_pk_dsa_raw (gnutls_x509_crt_t crt,
|
||||
gnutls_datum_t * p,
|
||||
gnutls_datum_t * q,
|
||||
gnutls_datum_t * g, gnutls_datum_t * y);
|
||||
|
||||
int gnutls_x509_crt_get_subject_alt_name(gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_get_subject_alt_name2(gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int* ret_type,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_get_subject_alt_name (gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_get_subject_alt_name2 (gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *ret_type,
|
||||
unsigned int *critical);
|
||||
|
||||
int gnutls_x509_crt_get_subject_alt_othername_oid(gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size);
|
||||
int gnutls_x509_crt_get_subject_alt_othername_oid (gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size);
|
||||
|
||||
int gnutls_x509_crt_get_ca_status(gnutls_x509_crt_t cert,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_get_basic_constraints(gnutls_x509_crt_t cert,
|
||||
unsigned int *critical,
|
||||
int *ca,
|
||||
int *pathlen);
|
||||
int gnutls_x509_crt_get_ca_status (gnutls_x509_crt_t cert,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_get_basic_constraints (gnutls_x509_crt_t cert,
|
||||
unsigned int *critical,
|
||||
int *ca, int *pathlen);
|
||||
|
||||
/* The key_usage flags are defined in gnutls.h. They are the
|
||||
* GNUTLS_KEY_* definitions.
|
||||
*/
|
||||
int gnutls_x509_crt_get_key_usage(gnutls_x509_crt_t cert,
|
||||
unsigned int *key_usage,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_set_key_usage(gnutls_x509_crt_t crt,
|
||||
unsigned int usage);
|
||||
int gnutls_x509_crt_get_key_usage (gnutls_x509_crt_t cert,
|
||||
unsigned int *key_usage,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_set_key_usage (gnutls_x509_crt_t crt,
|
||||
unsigned int usage);
|
||||
|
||||
int gnutls_x509_crt_get_proxy(gnutls_x509_crt_t cert,
|
||||
unsigned int *critical,
|
||||
int *pathlen,
|
||||
char **policyLanguage,
|
||||
char **policy,
|
||||
size_t *sizeof_policy);
|
||||
int gnutls_x509_crt_get_proxy (gnutls_x509_crt_t cert,
|
||||
unsigned int *critical,
|
||||
int *pathlen,
|
||||
char **policyLanguage,
|
||||
char **policy, size_t * sizeof_policy);
|
||||
|
||||
int gnutls_x509_dn_oid_known(const char *oid);
|
||||
int gnutls_x509_dn_oid_known (const char *oid);
|
||||
|
||||
/* Read extensions by OID. */
|
||||
int gnutls_x509_crt_get_extension_oid(gnutls_x509_crt_t cert,
|
||||
int indx,
|
||||
void *oid,
|
||||
size_t * sizeof_oid);
|
||||
int gnutls_x509_crt_get_extension_by_oid(gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
|
||||
int indx,
|
||||
void *buf,
|
||||
size_t * sizeof_buf,
|
||||
unsigned int *critical);
|
||||
void *oid, size_t * sizeof_oid);
|
||||
int gnutls_x509_crt_get_extension_by_oid (gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int indx,
|
||||
void *buf,
|
||||
size_t * sizeof_buf,
|
||||
unsigned int *critical);
|
||||
|
||||
/* Read extensions by sequence number. */
|
||||
int gnutls_x509_crt_get_extension_info(gnutls_x509_crt_t cert,
|
||||
int indx,
|
||||
void *oid,
|
||||
size_t * sizeof_oid,
|
||||
int *critical);
|
||||
int gnutls_x509_crt_get_extension_data(gnutls_x509_crt_t cert,
|
||||
int indx,
|
||||
void *data,
|
||||
size_t * sizeof_data);
|
||||
int gnutls_x509_crt_get_extension_info (gnutls_x509_crt_t cert,
|
||||
int indx,
|
||||
void *oid,
|
||||
size_t * sizeof_oid, int *critical);
|
||||
int gnutls_x509_crt_get_extension_data (gnutls_x509_crt_t cert,
|
||||
int indx,
|
||||
void *data, size_t * sizeof_data);
|
||||
|
||||
int gnutls_x509_crt_set_extension_by_oid(gnutls_x509_crt_t crt,
|
||||
const char *oid,
|
||||
const void *buf,
|
||||
size_t sizeof_buf,
|
||||
unsigned int critical);
|
||||
int gnutls_x509_crt_set_extension_by_oid (gnutls_x509_crt_t crt,
|
||||
const char *oid,
|
||||
const void *buf,
|
||||
size_t sizeof_buf,
|
||||
unsigned int critical);
|
||||
|
||||
/* X.509 Certificate writing.
|
||||
*/
|
||||
int gnutls_x509_crt_set_dn_by_oid(gnutls_x509_crt_t crt,
|
||||
const char *oid,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
int gnutls_x509_crt_set_issuer_dn_by_oid(gnutls_x509_crt_t crt,
|
||||
const char *oid,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
int gnutls_x509_crt_set_version(gnutls_x509_crt_t crt,
|
||||
unsigned int version);
|
||||
int gnutls_x509_crt_set_key(gnutls_x509_crt_t crt,
|
||||
gnutls_x509_privkey_t key);
|
||||
int gnutls_x509_crt_set_ca_status(gnutls_x509_crt_t crt,
|
||||
unsigned int ca);
|
||||
int gnutls_x509_crt_set_basic_constraints(gnutls_x509_crt_t crt,
|
||||
unsigned int ca,
|
||||
int pathLenConstraint);
|
||||
int gnutls_x509_crt_set_subject_alternative_name(gnutls_x509_crt_t crt,
|
||||
gnutls_x509_subject_alt_name_t
|
||||
type,
|
||||
const char *data_string);
|
||||
int gnutls_x509_crt_sign(gnutls_x509_crt_t crt,
|
||||
gnutls_x509_crt_t issuer,
|
||||
gnutls_x509_privkey_t issuer_key);
|
||||
int gnutls_x509_crt_sign2(gnutls_x509_crt_t crt,
|
||||
gnutls_x509_crt_t issuer,
|
||||
gnutls_x509_privkey_t issuer_key,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
unsigned int flags);
|
||||
int gnutls_x509_crt_set_activation_time(gnutls_x509_crt_t cert,
|
||||
time_t act_time);
|
||||
int gnutls_x509_crt_set_expiration_time(gnutls_x509_crt_t cert,
|
||||
time_t exp_time);
|
||||
int gnutls_x509_crt_set_serial(gnutls_x509_crt_t cert,
|
||||
const void *serial,
|
||||
size_t serial_size);
|
||||
int gnutls_x509_crt_set_dn_by_oid (gnutls_x509_crt_t crt,
|
||||
const char *oid,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
int gnutls_x509_crt_set_issuer_dn_by_oid (gnutls_x509_crt_t crt,
|
||||
const char *oid,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
int gnutls_x509_crt_set_version (gnutls_x509_crt_t crt,
|
||||
unsigned int version);
|
||||
int gnutls_x509_crt_set_key (gnutls_x509_crt_t crt,
|
||||
gnutls_x509_privkey_t key);
|
||||
int gnutls_x509_crt_set_ca_status (gnutls_x509_crt_t crt, unsigned int ca);
|
||||
int gnutls_x509_crt_set_basic_constraints (gnutls_x509_crt_t crt,
|
||||
unsigned int ca,
|
||||
int pathLenConstraint);
|
||||
int gnutls_x509_crt_set_subject_alternative_name (gnutls_x509_crt_t crt,
|
||||
gnutls_x509_subject_alt_name_t
|
||||
type,
|
||||
const char *data_string);
|
||||
int gnutls_x509_crt_sign (gnutls_x509_crt_t crt,
|
||||
gnutls_x509_crt_t issuer,
|
||||
gnutls_x509_privkey_t issuer_key);
|
||||
int gnutls_x509_crt_sign2 (gnutls_x509_crt_t crt,
|
||||
gnutls_x509_crt_t issuer,
|
||||
gnutls_x509_privkey_t issuer_key,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
unsigned int flags);
|
||||
int gnutls_x509_crt_set_activation_time (gnutls_x509_crt_t cert,
|
||||
time_t act_time);
|
||||
int gnutls_x509_crt_set_expiration_time (gnutls_x509_crt_t cert,
|
||||
time_t exp_time);
|
||||
int gnutls_x509_crt_set_serial (gnutls_x509_crt_t cert,
|
||||
const void *serial, size_t serial_size);
|
||||
|
||||
int gnutls_x509_crt_set_subject_key_id(gnutls_x509_crt_t cert,
|
||||
const void *id,
|
||||
size_t id_size);
|
||||
int gnutls_x509_crt_set_subject_key_id (gnutls_x509_crt_t cert,
|
||||
const void *id, size_t id_size);
|
||||
|
||||
int gnutls_x509_crt_set_proxy_dn(gnutls_x509_crt_t crt,
|
||||
gnutls_x509_crt_t eecrt,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
int gnutls_x509_crt_set_proxy(gnutls_x509_crt_t crt,
|
||||
int pathLenConstraint,
|
||||
const char *policyLanguage,
|
||||
const char *policy,
|
||||
size_t sizeof_policy);
|
||||
int gnutls_x509_crt_set_proxy_dn (gnutls_x509_crt_t crt,
|
||||
gnutls_x509_crt_t eecrt,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
int gnutls_x509_crt_set_proxy (gnutls_x509_crt_t crt,
|
||||
int pathLenConstraint,
|
||||
const char *policyLanguage,
|
||||
const char *policy, size_t sizeof_policy);
|
||||
|
||||
typedef enum gnutls_certificate_print_formats
|
||||
typedef enum gnutls_certificate_print_formats
|
||||
{
|
||||
GNUTLS_X509_CRT_FULL,
|
||||
GNUTLS_X509_CRT_ONELINE,
|
||||
GNUTLS_X509_CRT_UNSIGNED_FULL
|
||||
} gnutls_certificate_print_formats_t;
|
||||
|
||||
int gnutls_x509_crt_print(gnutls_x509_crt_t cert,
|
||||
gnutls_certificate_print_formats_t format,
|
||||
gnutls_datum_t *out);
|
||||
int gnutls_x509_crl_print(gnutls_x509_crl_t crl,
|
||||
gnutls_certificate_print_formats_t format,
|
||||
gnutls_datum_t *out);
|
||||
int gnutls_x509_crt_print (gnutls_x509_crt_t cert,
|
||||
gnutls_certificate_print_formats_t format,
|
||||
gnutls_datum_t * out);
|
||||
int gnutls_x509_crl_print (gnutls_x509_crl_t crl,
|
||||
gnutls_certificate_print_formats_t format,
|
||||
gnutls_datum_t * out);
|
||||
|
||||
/* Access to internal Certificate fields.
|
||||
*/
|
||||
int gnutls_x509_crt_get_raw_issuer_dn(gnutls_x509_crt_t cert,
|
||||
gnutls_datum_t * start);
|
||||
int gnutls_x509_crt_get_raw_dn(gnutls_x509_crt_t cert,
|
||||
gnutls_datum_t * start);
|
||||
int gnutls_x509_crt_get_raw_issuer_dn (gnutls_x509_crt_t cert,
|
||||
gnutls_datum_t * start);
|
||||
int gnutls_x509_crt_get_raw_dn (gnutls_x509_crt_t cert,
|
||||
gnutls_datum_t * start);
|
||||
|
||||
/* RDN handling.
|
||||
*/
|
||||
int gnutls_x509_rdn_get(const gnutls_datum_t * idn,
|
||||
char *buf,
|
||||
size_t * sizeof_buf);
|
||||
int gnutls_x509_rdn_get_oid(const gnutls_datum_t * idn,
|
||||
int indx,
|
||||
void *buf,
|
||||
size_t * sizeof_buf);
|
||||
int gnutls_x509_rdn_get (const gnutls_datum_t * idn,
|
||||
char *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_rdn_get_oid (const gnutls_datum_t * idn,
|
||||
int indx, void *buf, size_t * sizeof_buf);
|
||||
|
||||
int gnutls_x509_rdn_get_by_oid(const gnutls_datum_t * idn,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf,
|
||||
size_t * sizeof_buf);
|
||||
int gnutls_x509_rdn_get_by_oid (const gnutls_datum_t * idn,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
|
||||
typedef void *gnutls_x509_dn_t;
|
||||
typedef void *gnutls_x509_dn_t;
|
||||
|
||||
typedef struct gnutls_x509_ava_st
|
||||
typedef struct gnutls_x509_ava_st
|
||||
{
|
||||
gnutls_datum_t oid;
|
||||
gnutls_datum_t value;
|
||||
unsigned long value_tag;
|
||||
} gnutls_x509_ava_st;
|
||||
|
||||
int gnutls_x509_crt_get_subject(gnutls_x509_crt_t cert,
|
||||
gnutls_x509_dn_t *dn);
|
||||
int gnutls_x509_crt_get_issuer(gnutls_x509_crt_t cert,
|
||||
gnutls_x509_dn_t *dn);
|
||||
int gnutls_x509_dn_get_rdn_ava(gnutls_x509_dn_t dn,
|
||||
int irdn,
|
||||
int iava,
|
||||
gnutls_x509_ava_st *avast);
|
||||
int gnutls_x509_crt_get_subject (gnutls_x509_crt_t cert,
|
||||
gnutls_x509_dn_t * dn);
|
||||
int gnutls_x509_crt_get_issuer (gnutls_x509_crt_t cert,
|
||||
gnutls_x509_dn_t * dn);
|
||||
int gnutls_x509_dn_get_rdn_ava (gnutls_x509_dn_t dn,
|
||||
int irdn,
|
||||
int iava, gnutls_x509_ava_st * avast);
|
||||
|
||||
/* CRL handling functions.
|
||||
*/
|
||||
int gnutls_x509_crl_init(gnutls_x509_crl_t * crl);
|
||||
void gnutls_x509_crl_deinit(gnutls_x509_crl_t crl);
|
||||
int gnutls_x509_crl_init (gnutls_x509_crl_t * crl);
|
||||
void gnutls_x509_crl_deinit (gnutls_x509_crl_t crl);
|
||||
|
||||
int gnutls_x509_crl_import(gnutls_x509_crl_t crl,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_crl_export(gnutls_x509_crl_t crl,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
int gnutls_x509_crl_import (gnutls_x509_crl_t crl,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_crl_export (gnutls_x509_crl_t crl,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
|
||||
int gnutls_x509_crl_get_issuer_dn(const gnutls_x509_crl_t crl,
|
||||
char *buf,
|
||||
size_t * sizeof_buf);
|
||||
int gnutls_x509_crl_get_issuer_dn_by_oid(gnutls_x509_crl_t crl,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf,
|
||||
size_t * sizeof_buf);
|
||||
int gnutls_x509_crl_get_dn_oid(gnutls_x509_crl_t crl,
|
||||
int indx,
|
||||
void *oid,
|
||||
size_t * sizeof_oid);
|
||||
int gnutls_x509_crl_get_issuer_dn (const gnutls_x509_crl_t crl,
|
||||
char *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crl_get_issuer_dn_by_oid (gnutls_x509_crl_t crl,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crl_get_dn_oid (gnutls_x509_crl_t crl,
|
||||
int indx, void *oid, size_t * sizeof_oid);
|
||||
|
||||
int gnutls_x509_crl_get_signature_algorithm(gnutls_x509_crl_t crl);
|
||||
int gnutls_x509_crl_get_signature(gnutls_x509_crl_t crl,
|
||||
char *sig,
|
||||
size_t *sizeof_sig);
|
||||
int gnutls_x509_crl_get_version(gnutls_x509_crl_t crl);
|
||||
int gnutls_x509_crl_get_signature_algorithm (gnutls_x509_crl_t crl);
|
||||
int gnutls_x509_crl_get_signature (gnutls_x509_crl_t crl,
|
||||
char *sig, size_t * sizeof_sig);
|
||||
int gnutls_x509_crl_get_version (gnutls_x509_crl_t crl);
|
||||
|
||||
time_t gnutls_x509_crl_get_this_update(gnutls_x509_crl_t crl);
|
||||
time_t gnutls_x509_crl_get_next_update(gnutls_x509_crl_t crl);
|
||||
time_t gnutls_x509_crl_get_this_update (gnutls_x509_crl_t crl);
|
||||
time_t gnutls_x509_crl_get_next_update (gnutls_x509_crl_t crl);
|
||||
|
||||
int gnutls_x509_crl_get_crt_count(gnutls_x509_crl_t crl);
|
||||
int gnutls_x509_crl_get_crt_serial(gnutls_x509_crl_t crl,
|
||||
int indx,
|
||||
unsigned char *serial,
|
||||
size_t * serial_size,
|
||||
time_t * t);
|
||||
int gnutls_x509_crl_get_crt_count (gnutls_x509_crl_t crl);
|
||||
int gnutls_x509_crl_get_crt_serial (gnutls_x509_crl_t crl,
|
||||
int indx,
|
||||
unsigned char *serial,
|
||||
size_t * serial_size, time_t * t);
|
||||
#define gnutls_x509_crl_get_certificate_count gnutls_x509_crl_get_crt_count
|
||||
#define gnutls_x509_crl_get_certificate gnutls_x509_crl_get_crt_serial
|
||||
|
||||
int gnutls_x509_crl_check_issuer(gnutls_x509_crl_t crl,
|
||||
gnutls_x509_crt_t issuer);
|
||||
int gnutls_x509_crl_check_issuer (gnutls_x509_crl_t crl,
|
||||
gnutls_x509_crt_t issuer);
|
||||
|
||||
/* CRL writing.
|
||||
*/
|
||||
int gnutls_x509_crl_set_version(gnutls_x509_crl_t crl,
|
||||
unsigned int version);
|
||||
int gnutls_x509_crl_sign(gnutls_x509_crl_t crl,
|
||||
gnutls_x509_crt_t issuer,
|
||||
gnutls_x509_privkey_t issuer_key);
|
||||
int gnutls_x509_crl_sign2(gnutls_x509_crl_t crl,
|
||||
gnutls_x509_crt_t issuer,
|
||||
gnutls_x509_privkey_t issuer_key,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
unsigned int flags);
|
||||
int gnutls_x509_crl_set_this_update(gnutls_x509_crl_t crl,
|
||||
time_t act_time);
|
||||
int gnutls_x509_crl_set_next_update(gnutls_x509_crl_t crl,
|
||||
time_t exp_time);
|
||||
int gnutls_x509_crl_set_crt_serial(gnutls_x509_crl_t crl,
|
||||
const void *serial,
|
||||
size_t serial_size,
|
||||
time_t revocation_time);
|
||||
int gnutls_x509_crl_set_crt(gnutls_x509_crl_t crl,
|
||||
gnutls_x509_crt_t crt,
|
||||
time_t revocation_time);
|
||||
int gnutls_x509_crl_set_version (gnutls_x509_crl_t crl,
|
||||
unsigned int version);
|
||||
int gnutls_x509_crl_sign (gnutls_x509_crl_t crl,
|
||||
gnutls_x509_crt_t issuer,
|
||||
gnutls_x509_privkey_t issuer_key);
|
||||
int gnutls_x509_crl_sign2 (gnutls_x509_crl_t crl,
|
||||
gnutls_x509_crt_t issuer,
|
||||
gnutls_x509_privkey_t issuer_key,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
unsigned int flags);
|
||||
int gnutls_x509_crl_set_this_update (gnutls_x509_crl_t crl,
|
||||
time_t act_time);
|
||||
int gnutls_x509_crl_set_next_update (gnutls_x509_crl_t crl,
|
||||
time_t exp_time);
|
||||
int gnutls_x509_crl_set_crt_serial (gnutls_x509_crl_t crl,
|
||||
const void *serial,
|
||||
size_t serial_size,
|
||||
time_t revocation_time);
|
||||
int gnutls_x509_crl_set_crt (gnutls_x509_crl_t crl,
|
||||
gnutls_x509_crt_t crt, time_t revocation_time);
|
||||
|
||||
/* PKCS7 structures handling
|
||||
*/
|
||||
struct gnutls_pkcs7_int;
|
||||
typedef struct gnutls_pkcs7_int *gnutls_pkcs7_t;
|
||||
struct gnutls_pkcs7_int;
|
||||
typedef struct gnutls_pkcs7_int *gnutls_pkcs7_t;
|
||||
|
||||
int gnutls_pkcs7_init(gnutls_pkcs7_t * pkcs7);
|
||||
void gnutls_pkcs7_deinit(gnutls_pkcs7_t pkcs7);
|
||||
int gnutls_pkcs7_import(gnutls_pkcs7_t pkcs7,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_pkcs7_export(gnutls_pkcs7_t pkcs7,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
int gnutls_pkcs7_init (gnutls_pkcs7_t * pkcs7);
|
||||
void gnutls_pkcs7_deinit (gnutls_pkcs7_t pkcs7);
|
||||
int gnutls_pkcs7_import (gnutls_pkcs7_t pkcs7,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_pkcs7_export (gnutls_pkcs7_t pkcs7,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
|
||||
int gnutls_pkcs7_get_crt_count(gnutls_pkcs7_t pkcs7);
|
||||
int gnutls_pkcs7_get_crt_raw(gnutls_pkcs7_t pkcs7,
|
||||
int indx,
|
||||
void *certificate,
|
||||
size_t * certificate_size);
|
||||
int gnutls_pkcs7_get_crt_count (gnutls_pkcs7_t pkcs7);
|
||||
int gnutls_pkcs7_get_crt_raw (gnutls_pkcs7_t pkcs7,
|
||||
int indx,
|
||||
void *certificate, size_t * certificate_size);
|
||||
|
||||
int gnutls_pkcs7_set_crt_raw(gnutls_pkcs7_t pkcs7,
|
||||
const gnutls_datum_t * crt);
|
||||
int gnutls_pkcs7_set_crt(gnutls_pkcs7_t pkcs7,
|
||||
gnutls_x509_crt_t crt);
|
||||
int gnutls_pkcs7_delete_crt(gnutls_pkcs7_t pkcs7,
|
||||
int indx);
|
||||
int gnutls_pkcs7_set_crt_raw (gnutls_pkcs7_t pkcs7,
|
||||
const gnutls_datum_t * crt);
|
||||
int gnutls_pkcs7_set_crt (gnutls_pkcs7_t pkcs7, gnutls_x509_crt_t crt);
|
||||
int gnutls_pkcs7_delete_crt (gnutls_pkcs7_t pkcs7, int indx);
|
||||
|
||||
int gnutls_pkcs7_get_crl_raw(gnutls_pkcs7_t pkcs7,
|
||||
int indx,
|
||||
void *crl,
|
||||
size_t * crl_size);
|
||||
int gnutls_pkcs7_get_crl_count(gnutls_pkcs7_t pkcs7);
|
||||
int gnutls_pkcs7_get_crl_raw (gnutls_pkcs7_t pkcs7,
|
||||
int indx, void *crl, size_t * crl_size);
|
||||
int gnutls_pkcs7_get_crl_count (gnutls_pkcs7_t pkcs7);
|
||||
|
||||
int gnutls_pkcs7_set_crl_raw(gnutls_pkcs7_t pkcs7,
|
||||
const gnutls_datum_t * crt);
|
||||
int gnutls_pkcs7_set_crl(gnutls_pkcs7_t pkcs7,
|
||||
gnutls_x509_crl_t crl);
|
||||
int gnutls_pkcs7_delete_crl(gnutls_pkcs7_t pkcs7,
|
||||
int indx);
|
||||
int gnutls_pkcs7_set_crl_raw (gnutls_pkcs7_t pkcs7,
|
||||
const gnutls_datum_t * crt);
|
||||
int gnutls_pkcs7_set_crl (gnutls_pkcs7_t pkcs7, gnutls_x509_crl_t crl);
|
||||
int gnutls_pkcs7_delete_crl (gnutls_pkcs7_t pkcs7, int indx);
|
||||
|
||||
/* X.509 Certificate verification functions.
|
||||
*/
|
||||
typedef enum gnutls_certificate_verify_flags
|
||||
typedef enum gnutls_certificate_verify_flags
|
||||
{
|
||||
/* If set a signer does not have to be a certificate authority. This
|
||||
* flag should normaly be disabled, unless you know what this means.
|
||||
@@ -527,58 +484,53 @@ typedef enum gnutls_certificate_verify_flags
|
||||
GNUTLS_VERIFY_ALLOW_SIGN_RSA_MD5 = 32
|
||||
} gnutls_certificate_verify_flags;
|
||||
|
||||
int gnutls_x509_crt_check_issuer(gnutls_x509_crt_t cert,
|
||||
gnutls_x509_crt_t issuer);
|
||||
int gnutls_x509_crt_check_issuer (gnutls_x509_crt_t cert,
|
||||
gnutls_x509_crt_t issuer);
|
||||
|
||||
int gnutls_x509_crt_list_verify(const gnutls_x509_crt_t * cert_list,
|
||||
int cert_list_length,
|
||||
const gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
const gnutls_x509_crl_t * CRL_list,
|
||||
int CRL_list_length,
|
||||
unsigned int flags,
|
||||
unsigned int *verify);
|
||||
int gnutls_x509_crt_list_verify (const gnutls_x509_crt_t * cert_list,
|
||||
int cert_list_length,
|
||||
const gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
const gnutls_x509_crl_t * CRL_list,
|
||||
int CRL_list_length,
|
||||
unsigned int flags, unsigned int *verify);
|
||||
|
||||
int gnutls_x509_crt_verify(gnutls_x509_crt_t cert,
|
||||
const gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
unsigned int flags,
|
||||
unsigned int *verify);
|
||||
int gnutls_x509_crl_verify(gnutls_x509_crl_t crl,
|
||||
const gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
unsigned int flags,
|
||||
unsigned int *verify);
|
||||
int gnutls_x509_crt_verify (gnutls_x509_crt_t cert,
|
||||
const gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
unsigned int flags, unsigned int *verify);
|
||||
int gnutls_x509_crl_verify (gnutls_x509_crl_t crl,
|
||||
const gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
unsigned int flags, unsigned int *verify);
|
||||
|
||||
int gnutls_x509_crt_check_revocation(gnutls_x509_crt_t cert,
|
||||
const gnutls_x509_crl_t *
|
||||
crl_list,
|
||||
int crl_list_length);
|
||||
int gnutls_x509_crt_check_revocation (gnutls_x509_crt_t cert,
|
||||
const gnutls_x509_crl_t *
|
||||
crl_list, int crl_list_length);
|
||||
|
||||
int gnutls_x509_crt_get_fingerprint(gnutls_x509_crt_t cert,
|
||||
enum MHD_GNUTLS_HashAlgorithm algo,
|
||||
void *buf,
|
||||
size_t * sizeof_buf);
|
||||
int gnutls_x509_crt_get_fingerprint (gnutls_x509_crt_t cert,
|
||||
enum MHD_GNUTLS_HashAlgorithm algo,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
|
||||
int gnutls_x509_crt_get_key_purpose_oid(gnutls_x509_crt_t cert,
|
||||
int indx,
|
||||
void *oid,
|
||||
size_t * sizeof_oid,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_set_key_purpose_oid(gnutls_x509_crt_t cert,
|
||||
const void *oid,
|
||||
unsigned int critical);
|
||||
int gnutls_x509_crt_get_key_purpose_oid (gnutls_x509_crt_t cert,
|
||||
int indx,
|
||||
void *oid,
|
||||
size_t * sizeof_oid,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_set_key_purpose_oid (gnutls_x509_crt_t cert,
|
||||
const void *oid,
|
||||
unsigned int critical);
|
||||
|
||||
/* Private key handling.
|
||||
*/
|
||||
|
||||
/* Flags for the gnutls_x509_privkey_export_pkcs8() function.
|
||||
*/
|
||||
typedef enum gnutls_pkcs_encrypt_flags_t
|
||||
typedef enum gnutls_pkcs_encrypt_flags_t
|
||||
{
|
||||
GNUTLS_PKCS_PLAIN = 1, /* if set the private key will not
|
||||
* be encrypted.
|
||||
*/
|
||||
GNUTLS_PKCS_PLAIN = 1, /* if set the private key will not
|
||||
* be encrypted.
|
||||
*/
|
||||
GNUTLS_PKCS_USE_PKCS12_3DES = 2,
|
||||
GNUTLS_PKCS_USE_PKCS12_ARCFOUR = 4,
|
||||
GNUTLS_PKCS_USE_PKCS12_RC2_40 = 8,
|
||||
@@ -590,154 +542,143 @@ typedef enum gnutls_pkcs_encrypt_flags_t
|
||||
#define GNUTLS_PKCS8_USE_PKCS12_ARCFOUR GNUTLS_PKCS_USE_PKCS12_ARCFOUR
|
||||
#define GNUTLS_PKCS8_USE_PKCS12_RC2_40 GNUTLS_PKCS_USE_PKCS12_RC2_40
|
||||
|
||||
int gnutls_x509_privkey_init(gnutls_x509_privkey_t * key);
|
||||
void gnutls_x509_privkey_deinit(gnutls_x509_privkey_t key);
|
||||
int gnutls_x509_privkey_cpy(gnutls_x509_privkey_t dst,
|
||||
gnutls_x509_privkey_t src);
|
||||
int gnutls_x509_privkey_import(gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_privkey_import_pkcs8(gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
const char *pass,
|
||||
unsigned int flags);
|
||||
int gnutls_x509_privkey_import_rsa_raw(gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * m,
|
||||
const gnutls_datum_t * e,
|
||||
const gnutls_datum_t * d,
|
||||
const gnutls_datum_t * p,
|
||||
const gnutls_datum_t * q,
|
||||
const gnutls_datum_t * u);
|
||||
int gnutls_x509_privkey_fix(gnutls_x509_privkey_t key);
|
||||
int gnutls_x509_privkey_init (gnutls_x509_privkey_t * key);
|
||||
void gnutls_x509_privkey_deinit (gnutls_x509_privkey_t key);
|
||||
int gnutls_x509_privkey_cpy (gnutls_x509_privkey_t dst,
|
||||
gnutls_x509_privkey_t src);
|
||||
int gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_privkey_import_pkcs8 (gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
const char *pass, unsigned int flags);
|
||||
int gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * m,
|
||||
const gnutls_datum_t * e,
|
||||
const gnutls_datum_t * d,
|
||||
const gnutls_datum_t * p,
|
||||
const gnutls_datum_t * q,
|
||||
const gnutls_datum_t * u);
|
||||
int gnutls_x509_privkey_fix (gnutls_x509_privkey_t key);
|
||||
|
||||
int gnutls_x509_privkey_export_dsa_raw(gnutls_x509_privkey_t key,
|
||||
gnutls_datum_t * p,
|
||||
gnutls_datum_t * q,
|
||||
gnutls_datum_t * g,
|
||||
gnutls_datum_t * y,
|
||||
gnutls_datum_t * x);
|
||||
int gnutls_x509_privkey_import_dsa_raw(gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * p,
|
||||
const gnutls_datum_t * q,
|
||||
const gnutls_datum_t * g,
|
||||
const gnutls_datum_t * y,
|
||||
const gnutls_datum_t * x);
|
||||
int gnutls_x509_privkey_export_dsa_raw (gnutls_x509_privkey_t key,
|
||||
gnutls_datum_t * p,
|
||||
gnutls_datum_t * q,
|
||||
gnutls_datum_t * g,
|
||||
gnutls_datum_t * y,
|
||||
gnutls_datum_t * x);
|
||||
int gnutls_x509_privkey_import_dsa_raw (gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * p,
|
||||
const gnutls_datum_t * q,
|
||||
const gnutls_datum_t * g,
|
||||
const gnutls_datum_t * y,
|
||||
const gnutls_datum_t * x);
|
||||
|
||||
int gnutls_x509_privkey_get_pk_algorithm(gnutls_x509_privkey_t key);
|
||||
int gnutls_x509_privkey_get_key_id(gnutls_x509_privkey_t key,
|
||||
unsigned int flags,
|
||||
unsigned char *output_data,
|
||||
size_t * output_data_size);
|
||||
int gnutls_x509_privkey_get_pk_algorithm (gnutls_x509_privkey_t key);
|
||||
int gnutls_x509_privkey_get_key_id (gnutls_x509_privkey_t key,
|
||||
unsigned int flags,
|
||||
unsigned char *output_data,
|
||||
size_t * output_data_size);
|
||||
|
||||
int gnutls_x509_privkey_generate(gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm algo,
|
||||
unsigned int bits,
|
||||
unsigned int flags);
|
||||
int gnutls_x509_privkey_generate (gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm algo,
|
||||
unsigned int bits, unsigned int flags);
|
||||
|
||||
int gnutls_x509_privkey_export(gnutls_x509_privkey_t key,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
int gnutls_x509_privkey_export_pkcs8(gnutls_x509_privkey_t key,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
const char *password,
|
||||
unsigned int flags,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
int gnutls_x509_privkey_export_rsa_raw(gnutls_x509_privkey_t key,
|
||||
gnutls_datum_t * m,
|
||||
gnutls_datum_t * e,
|
||||
gnutls_datum_t * d,
|
||||
gnutls_datum_t * p,
|
||||
gnutls_datum_t * q,
|
||||
gnutls_datum_t * u);
|
||||
int gnutls_x509_privkey_export (gnutls_x509_privkey_t key,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
int gnutls_x509_privkey_export_pkcs8 (gnutls_x509_privkey_t key,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
const char *password,
|
||||
unsigned int flags,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
int gnutls_x509_privkey_export_rsa_raw (gnutls_x509_privkey_t key,
|
||||
gnutls_datum_t * m,
|
||||
gnutls_datum_t * e,
|
||||
gnutls_datum_t * d,
|
||||
gnutls_datum_t * p,
|
||||
gnutls_datum_t * q,
|
||||
gnutls_datum_t * u);
|
||||
|
||||
/* Signing stuff.
|
||||
*/
|
||||
int gnutls_x509_privkey_sign_data(gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_HashAlgorithm digest,
|
||||
unsigned int flags,
|
||||
const gnutls_datum_t * data,
|
||||
void *signature,
|
||||
size_t * signature_size);
|
||||
int gnutls_x509_privkey_verify_data(gnutls_x509_privkey_t key,
|
||||
unsigned int flags,
|
||||
const gnutls_datum_t * data,
|
||||
const gnutls_datum_t * signature);
|
||||
int gnutls_x509_crt_verify_data(gnutls_x509_crt_t crt,
|
||||
unsigned int flags,
|
||||
const gnutls_datum_t * data,
|
||||
const gnutls_datum_t * signature);
|
||||
int gnutls_x509_privkey_sign_data (gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_HashAlgorithm digest,
|
||||
unsigned int flags,
|
||||
const gnutls_datum_t * data,
|
||||
void *signature,
|
||||
size_t * signature_size);
|
||||
int gnutls_x509_privkey_verify_data (gnutls_x509_privkey_t key,
|
||||
unsigned int flags,
|
||||
const gnutls_datum_t * data,
|
||||
const gnutls_datum_t * signature);
|
||||
int gnutls_x509_crt_verify_data (gnutls_x509_crt_t crt,
|
||||
unsigned int flags,
|
||||
const gnutls_datum_t * data,
|
||||
const gnutls_datum_t * signature);
|
||||
|
||||
int gnutls_x509_privkey_sign_hash(gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * hash,
|
||||
gnutls_datum_t * signature);
|
||||
int gnutls_x509_privkey_sign_hash (gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * hash,
|
||||
gnutls_datum_t * signature);
|
||||
|
||||
/* Certificate request stuff.
|
||||
*/
|
||||
struct gnutls_x509_crq_int;
|
||||
typedef struct gnutls_x509_crq_int *gnutls_x509_crq_t;
|
||||
struct gnutls_x509_crq_int;
|
||||
typedef struct gnutls_x509_crq_int *gnutls_x509_crq_t;
|
||||
|
||||
int gnutls_x509_crq_init(gnutls_x509_crq_t * crq);
|
||||
void gnutls_x509_crq_deinit(gnutls_x509_crq_t crq);
|
||||
int gnutls_x509_crq_import(gnutls_x509_crq_t crq,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_crq_get_pk_algorithm(gnutls_x509_crq_t crq,
|
||||
unsigned int *bits);
|
||||
int gnutls_x509_crq_get_dn(gnutls_x509_crq_t crq,
|
||||
char *buf,
|
||||
size_t * sizeof_buf);
|
||||
int gnutls_x509_crq_get_dn_oid(gnutls_x509_crq_t crq,
|
||||
int indx,
|
||||
void *oid,
|
||||
size_t * sizeof_oid);
|
||||
int gnutls_x509_crq_get_dn_by_oid(gnutls_x509_crq_t crq,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf,
|
||||
size_t * sizeof_buf);
|
||||
int gnutls_x509_crq_set_dn_by_oid(gnutls_x509_crq_t crq,
|
||||
const char *oid,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
int gnutls_x509_crq_set_version(gnutls_x509_crq_t crq,
|
||||
unsigned int version);
|
||||
int gnutls_x509_crq_set_key(gnutls_x509_crq_t crq,
|
||||
gnutls_x509_privkey_t key);
|
||||
int gnutls_x509_crq_sign2(gnutls_x509_crq_t crq,
|
||||
gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
unsigned int flags);
|
||||
int gnutls_x509_crq_sign(gnutls_x509_crq_t crq,
|
||||
gnutls_x509_privkey_t key);
|
||||
int gnutls_x509_crq_init (gnutls_x509_crq_t * crq);
|
||||
void gnutls_x509_crq_deinit (gnutls_x509_crq_t crq);
|
||||
int gnutls_x509_crq_import (gnutls_x509_crq_t crq,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_crq_get_pk_algorithm (gnutls_x509_crq_t crq,
|
||||
unsigned int *bits);
|
||||
int gnutls_x509_crq_get_dn (gnutls_x509_crq_t crq,
|
||||
char *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crq_get_dn_oid (gnutls_x509_crq_t crq,
|
||||
int indx, void *oid, size_t * sizeof_oid);
|
||||
int gnutls_x509_crq_get_dn_by_oid (gnutls_x509_crq_t crq,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crq_set_dn_by_oid (gnutls_x509_crq_t crq,
|
||||
const char *oid,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
int gnutls_x509_crq_set_version (gnutls_x509_crq_t crq,
|
||||
unsigned int version);
|
||||
int gnutls_x509_crq_set_key (gnutls_x509_crq_t crq,
|
||||
gnutls_x509_privkey_t key);
|
||||
int gnutls_x509_crq_sign2 (gnutls_x509_crq_t crq,
|
||||
gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
unsigned int flags);
|
||||
int gnutls_x509_crq_sign (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key);
|
||||
|
||||
int gnutls_x509_crq_set_challenge_password(gnutls_x509_crq_t crq,
|
||||
const char *pass);
|
||||
int gnutls_x509_crq_get_challenge_password(gnutls_x509_crq_t crq,
|
||||
char *pass,
|
||||
size_t * sizeof_pass);
|
||||
int gnutls_x509_crq_set_challenge_password (gnutls_x509_crq_t crq,
|
||||
const char *pass);
|
||||
int gnutls_x509_crq_get_challenge_password (gnutls_x509_crq_t crq,
|
||||
char *pass,
|
||||
size_t * sizeof_pass);
|
||||
|
||||
int gnutls_x509_crq_set_attribute_by_oid(gnutls_x509_crq_t crq,
|
||||
const char *oid,
|
||||
void *buf,
|
||||
size_t sizeof_buf);
|
||||
int gnutls_x509_crq_get_attribute_by_oid(gnutls_x509_crq_t crq,
|
||||
const char *oid,
|
||||
int indx,
|
||||
void *buf,
|
||||
size_t * sizeof_buf);
|
||||
int gnutls_x509_crq_set_attribute_by_oid (gnutls_x509_crq_t crq,
|
||||
const char *oid,
|
||||
void *buf, size_t sizeof_buf);
|
||||
int gnutls_x509_crq_get_attribute_by_oid (gnutls_x509_crq_t crq,
|
||||
const char *oid,
|
||||
int indx,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
|
||||
int gnutls_x509_crq_export(gnutls_x509_crq_t crq,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
int gnutls_x509_crq_export (gnutls_x509_crq_t crq,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
|
||||
int gnutls_x509_crt_set_crq(gnutls_x509_crt_t crt,
|
||||
gnutls_x509_crq_t crq);
|
||||
int gnutls_x509_crt_set_crq (gnutls_x509_crt_t crt, gnutls_x509_crq_t crq);
|
||||
|
||||
#ifdef __cplusplus
|
||||
}
|
||||
@@ -752,17 +693,17 @@ int gnutls_x509_crt_set_crq(gnutls_x509_crt_t crt,
|
||||
#define HASH_OID_SHA512 "2.16.840.1.101.3.4.2.3"
|
||||
|
||||
typedef struct gnutls_x509_crl_int
|
||||
{
|
||||
ASN1_TYPE crl;
|
||||
} gnutls_x509_crl_int;
|
||||
{
|
||||
ASN1_TYPE crl;
|
||||
} gnutls_x509_crl_int;
|
||||
|
||||
typedef struct gnutls_x509_crt_int
|
||||
{
|
||||
ASN1_TYPE cert;
|
||||
int use_extensions;
|
||||
} gnutls_x509_crt_int;
|
||||
{
|
||||
ASN1_TYPE cert;
|
||||
int use_extensions;
|
||||
} gnutls_x509_crt_int;
|
||||
|
||||
#define MAX_PRIV_PARAMS_SIZE 6 /* ok for RSA and DSA */
|
||||
#define MAX_PRIV_PARAMS_SIZE 6 /* ok for RSA and DSA */
|
||||
|
||||
/* parameters should not be larger than this limit */
|
||||
#define DSA_PRIVATE_PARAMS 5
|
||||
@@ -779,140 +720,130 @@ typedef struct gnutls_x509_crt_int
|
||||
#endif
|
||||
|
||||
typedef struct MHD_gtls_x509_privkey_int
|
||||
{
|
||||
mpi_t params[MAX_PRIV_PARAMS_SIZE]; /* the size of params depends on the public
|
||||
* key algorithm
|
||||
*/
|
||||
/*
|
||||
* RSA: [0] is modulus
|
||||
* [1] is public exponent
|
||||
* [2] is private exponent
|
||||
* [3] is prime1 (p)
|
||||
* [4] is prime2 (q)
|
||||
* [5] is coefficient (u == inverse of p mod q)
|
||||
* note that other packages used inverse of q mod p,
|
||||
* so we need to perform conversions.
|
||||
* DSA: [0] is p
|
||||
* [1] is q
|
||||
* [2] is g
|
||||
* [3] is y (public key)
|
||||
* [4] is x (private key)
|
||||
*/
|
||||
int params_size; /* holds the number of params */
|
||||
{
|
||||
mpi_t params[MAX_PRIV_PARAMS_SIZE]; /* the size of params depends on the public
|
||||
* key algorithm
|
||||
*/
|
||||
/*
|
||||
* RSA: [0] is modulus
|
||||
* [1] is public exponent
|
||||
* [2] is private exponent
|
||||
* [3] is prime1 (p)
|
||||
* [4] is prime2 (q)
|
||||
* [5] is coefficient (u == inverse of p mod q)
|
||||
* note that other packages used inverse of q mod p,
|
||||
* so we need to perform conversions.
|
||||
* DSA: [0] is p
|
||||
* [1] is q
|
||||
* [2] is g
|
||||
* [3] is y (public key)
|
||||
* [4] is x (private key)
|
||||
*/
|
||||
int params_size; /* holds the number of params */
|
||||
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm pk_algorithm;
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm pk_algorithm;
|
||||
|
||||
int crippled; /* The crippled keys will not use the ASN1_TYPE key.
|
||||
* The encoding will only be performed at the export
|
||||
* phase, to optimize copying etc. Cannot be used with
|
||||
* the exported API (used internally only).
|
||||
*/
|
||||
ASN1_TYPE key;
|
||||
} gnutls_x509_privkey_int;
|
||||
int crippled; /* The crippled keys will not use the ASN1_TYPE key.
|
||||
* The encoding will only be performed at the export
|
||||
* phase, to optimize copying etc. Cannot be used with
|
||||
* the exported API (used internally only).
|
||||
*/
|
||||
ASN1_TYPE key;
|
||||
} gnutls_x509_privkey_int;
|
||||
|
||||
int gnutls_x509_crt_get_issuer_dn_by_oid(gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf,
|
||||
size_t * sizeof_buf);
|
||||
int gnutls_x509_crt_get_subject_alt_name(gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_get_dn_by_oid(gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf,
|
||||
size_t * sizeof_buf);
|
||||
int gnutls_x509_crt_get_ca_status(gnutls_x509_crt_t cert,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_get_pk_algorithm(gnutls_x509_crt_t cert,
|
||||
unsigned int *bits);
|
||||
|
||||
int _gnutls_x509_crt_cpy(gnutls_x509_crt_t dest,
|
||||
gnutls_x509_crt_t src);
|
||||
|
||||
int gnutls_x509_crt_get_serial(gnutls_x509_crt_t cert,
|
||||
void *result,
|
||||
size_t * result_size);
|
||||
|
||||
int _gnutls_x509_compare_raw_dn(const gnutls_datum_t * dn1,
|
||||
const gnutls_datum_t * dn2);
|
||||
|
||||
int gnutls_x509_crt_check_revocation(gnutls_x509_crt_t cert,
|
||||
const gnutls_x509_crl_t * crl_list,
|
||||
int crl_list_length);
|
||||
|
||||
int _gnutls_x509_crl_cpy(gnutls_x509_crl_t dest,
|
||||
gnutls_x509_crl_t src);
|
||||
int _gnutls_x509_crl_get_raw_issuer_dn(gnutls_x509_crl_t crl,
|
||||
gnutls_datum_t * dn);
|
||||
int gnutls_x509_crl_get_crt_count(gnutls_x509_crl_t crl);
|
||||
int gnutls_x509_crl_get_crt_serial(gnutls_x509_crl_t crl,
|
||||
int gnutls_x509_crt_get_issuer_dn_by_oid (gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crt_get_subject_alt_name (gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_get_dn_by_oid (gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned char *serial,
|
||||
size_t * serial_size,
|
||||
time_t * t);
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crt_get_ca_status (gnutls_x509_crt_t cert,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_get_pk_algorithm (gnutls_x509_crt_t cert,
|
||||
unsigned int *bits);
|
||||
|
||||
void gnutls_x509_crl_deinit(gnutls_x509_crl_t crl);
|
||||
int gnutls_x509_crl_init(gnutls_x509_crl_t * crl);
|
||||
int gnutls_x509_crl_import(gnutls_x509_crl_t crl,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_crl_export(gnutls_x509_crl_t crl,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
int _gnutls_x509_crt_cpy (gnutls_x509_crt_t dest, gnutls_x509_crt_t src);
|
||||
|
||||
int gnutls_x509_crt_init(gnutls_x509_crt_t * cert);
|
||||
void gnutls_x509_crt_deinit(gnutls_x509_crt_t cert);
|
||||
int gnutls_x509_crt_import(gnutls_x509_crt_t cert,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_crt_export(gnutls_x509_crt_t cert,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
int gnutls_x509_crt_get_serial (gnutls_x509_crt_t cert,
|
||||
void *result, size_t * result_size);
|
||||
|
||||
int gnutls_x509_crt_get_key_usage(gnutls_x509_crt_t cert,
|
||||
unsigned int *key_usage,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_get_signature_algorithm(gnutls_x509_crt_t cert);
|
||||
int gnutls_x509_crt_get_version(gnutls_x509_crt_t cert);
|
||||
int _gnutls_x509_compare_raw_dn (const gnutls_datum_t * dn1,
|
||||
const gnutls_datum_t * dn2);
|
||||
|
||||
int gnutls_x509_privkey_init(gnutls_x509_privkey_t * key);
|
||||
void gnutls_x509_privkey_deinit(gnutls_x509_privkey_t key);
|
||||
int gnutls_x509_crt_check_revocation (gnutls_x509_crt_t cert,
|
||||
const gnutls_x509_crl_t * crl_list,
|
||||
int crl_list_length);
|
||||
|
||||
int gnutls_x509_privkey_generate(gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm algo,
|
||||
unsigned int bits,
|
||||
unsigned int flags);
|
||||
int _gnutls_x509_crl_cpy (gnutls_x509_crl_t dest, gnutls_x509_crl_t src);
|
||||
int _gnutls_x509_crl_get_raw_issuer_dn (gnutls_x509_crl_t crl,
|
||||
gnutls_datum_t * dn);
|
||||
int gnutls_x509_crl_get_crt_count (gnutls_x509_crl_t crl);
|
||||
int gnutls_x509_crl_get_crt_serial (gnutls_x509_crl_t crl,
|
||||
int indx,
|
||||
unsigned char *serial,
|
||||
size_t * serial_size, time_t * t);
|
||||
|
||||
int gnutls_x509_privkey_import(gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_privkey_get_pk_algorithm(gnutls_x509_privkey_t key);
|
||||
int gnutls_x509_privkey_import_rsa_raw(gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * m,
|
||||
const gnutls_datum_t * e,
|
||||
const gnutls_datum_t * d,
|
||||
const gnutls_datum_t * p,
|
||||
const gnutls_datum_t * q,
|
||||
const gnutls_datum_t * u);
|
||||
int gnutls_x509_privkey_export_rsa_raw(gnutls_x509_privkey_t key,
|
||||
gnutls_datum_t * m,
|
||||
gnutls_datum_t * e,
|
||||
gnutls_datum_t * d,
|
||||
gnutls_datum_t * p,
|
||||
gnutls_datum_t * q,
|
||||
gnutls_datum_t * u);
|
||||
int gnutls_x509_privkey_export(gnutls_x509_privkey_t key,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
void gnutls_x509_crl_deinit (gnutls_x509_crl_t crl);
|
||||
int gnutls_x509_crl_init (gnutls_x509_crl_t * crl);
|
||||
int gnutls_x509_crl_import (gnutls_x509_crl_t crl,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_crl_export (gnutls_x509_crl_t crl,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
|
||||
int gnutls_x509_crt_init (gnutls_x509_crt_t * cert);
|
||||
void gnutls_x509_crt_deinit (gnutls_x509_crt_t cert);
|
||||
int gnutls_x509_crt_import (gnutls_x509_crt_t cert,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_crt_export (gnutls_x509_crt_t cert,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
|
||||
int gnutls_x509_crt_get_key_usage (gnutls_x509_crt_t cert,
|
||||
unsigned int *key_usage,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_get_signature_algorithm (gnutls_x509_crt_t cert);
|
||||
int gnutls_x509_crt_get_version (gnutls_x509_crt_t cert);
|
||||
|
||||
int gnutls_x509_privkey_init (gnutls_x509_privkey_t * key);
|
||||
void gnutls_x509_privkey_deinit (gnutls_x509_privkey_t key);
|
||||
|
||||
int gnutls_x509_privkey_generate (gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm algo,
|
||||
unsigned int bits, unsigned int flags);
|
||||
|
||||
int gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_privkey_get_pk_algorithm (gnutls_x509_privkey_t key);
|
||||
int gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * m,
|
||||
const gnutls_datum_t * e,
|
||||
const gnutls_datum_t * d,
|
||||
const gnutls_datum_t * p,
|
||||
const gnutls_datum_t * q,
|
||||
const gnutls_datum_t * u);
|
||||
int gnutls_x509_privkey_export_rsa_raw (gnutls_x509_privkey_t key,
|
||||
gnutls_datum_t * m,
|
||||
gnutls_datum_t * e,
|
||||
gnutls_datum_t * d,
|
||||
gnutls_datum_t * p,
|
||||
gnutls_datum_t * q,
|
||||
gnutls_datum_t * u);
|
||||
int gnutls_x509_privkey_export (gnutls_x509_privkey_t key,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
|
||||
#define GNUTLS_CRL_REASON_UNUSED 128
|
||||
#define GNUTLS_CRL_REASON_KEY_COMPROMISE 64
|
||||
|
||||
@@ -446,7 +446,7 @@ gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
|
||||
*
|
||||
* This function will convert the given RSA raw parameters
|
||||
* to the native gnutls_x509_privkey_t format. The output will be stored in @key.
|
||||
*
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
|
||||
@@ -646,7 +646,7 @@ gnutls_x509_privkey_export (gnutls_x509_privkey_t key,
|
||||
* This function will export the RSA private key's parameters found in the given
|
||||
* structure. The new parameters will be allocated using
|
||||
* gnutls_malloc() and will be stored in the appropriate datum.
|
||||
*
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_privkey_export_rsa_raw (gnutls_x509_privkey_t key,
|
||||
@@ -760,7 +760,7 @@ error:_gnutls_free_datum (m);
|
||||
* This function will export the DSA private key's parameters found in the given
|
||||
* structure. The new parameters will be allocated using
|
||||
* gnutls_malloc() and will be stored in the appropriate datum.
|
||||
*
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_privkey_export_dsa_raw (gnutls_x509_privkey_t key,
|
||||
@@ -960,7 +960,7 @@ _gnutls_asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Write PRIME
|
||||
/* Write PRIME
|
||||
*/
|
||||
if ((result = asn1_write_value (*c2, "modulus", m_data, size[0]))
|
||||
!= ASN1_SUCCESS)
|
||||
@@ -1120,7 +1120,7 @@ _gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Write PRIME
|
||||
/* Write PRIME
|
||||
*/
|
||||
if ((result = asn1_write_value (*c2, "p", p_data, size[0])) != ASN1_SUCCESS)
|
||||
{
|
||||
@@ -1183,7 +1183,7 @@ cleanup:asn1_delete_structure (c2);
|
||||
* @flags: unused for now. Must be 0.
|
||||
*
|
||||
* This function will generate a random private key. Note that
|
||||
* this function must be called on an empty private key.
|
||||
* this function must be called on an empty private key.
|
||||
*
|
||||
* Returns 0 on success or a negative value on error.
|
||||
*
|
||||
@@ -1409,7 +1409,7 @@ gnutls_x509_privkey_sign_hash (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
result = mhd_gtls_sign (key->pk_algorithm, key->params,
|
||||
key->params_size, hash, signature);
|
||||
key->params_size, hash, signature);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
|
||||
@@ -201,7 +201,7 @@ find_issuer (gnutls_x509_crt_t cert,
|
||||
{
|
||||
int i;
|
||||
|
||||
/* this is serial search.
|
||||
/* this is serial search.
|
||||
*/
|
||||
|
||||
for (i = 0; i < tcas_size; i++)
|
||||
@@ -214,11 +214,11 @@ find_issuer (gnutls_x509_crt_t cert,
|
||||
return NULL;
|
||||
}
|
||||
|
||||
/*
|
||||
/*
|
||||
* Verifies the given certificate again a certificate list of
|
||||
* trusted CAs.
|
||||
*
|
||||
* Returns only 0 or 1. If 1 it means that the certificate
|
||||
* Returns only 0 or 1. If 1 it means that the certificate
|
||||
* was successfuly verified.
|
||||
*
|
||||
* 'flags': an OR of the gnutls_certificate_verify_flags enumeration.
|
||||
@@ -435,7 +435,7 @@ _gnutls_x509_verify_certificate (const gnutls_x509_crt_t * certificate_list,
|
||||
clist_size--;
|
||||
}
|
||||
|
||||
/* Verify the certificate path (chain)
|
||||
/* Verify the certificate path (chain)
|
||||
*/
|
||||
for (i = clist_size - 1; i > 0; i--)
|
||||
{
|
||||
@@ -465,7 +465,7 @@ _gnutls_x509_verify_certificate (const gnutls_x509_crt_t * certificate_list,
|
||||
*/
|
||||
static int
|
||||
decode_ber_digest_info (const gnutls_datum_t * info,
|
||||
enum MHD_GNUTLS_HashAlgorithm * hash,
|
||||
enum MHD_GNUTLS_HashAlgorithm *hash,
|
||||
opaque * digest, int *digest_size)
|
||||
{
|
||||
ASN1_TYPE dinfo = ASN1_TYPE_EMPTY;
|
||||
@@ -664,7 +664,7 @@ verify_sig (const gnutls_datum_t * tbs,
|
||||
|
||||
/* verifies if the certificate is properly signed.
|
||||
* returns 0 on failure and 1 on success.
|
||||
*
|
||||
*
|
||||
* 'tbs' is the signed data
|
||||
* 'signature' is the signature!
|
||||
*/
|
||||
@@ -707,7 +707,7 @@ _gnutls_x509_verify_signature (const gnutls_datum_t * tbs,
|
||||
|
||||
/* verifies if the certificate is properly signed.
|
||||
* returns 0 on failure and 1 on success.
|
||||
*
|
||||
*
|
||||
* 'tbs' is the signed data
|
||||
* 'signature' is the signature!
|
||||
*/
|
||||
@@ -743,12 +743,12 @@ _gnutls_x509_privkey_verify_signature (const gnutls_datum_t * tbs,
|
||||
* Note that expiration and activation dates are not checked
|
||||
* by this function, you should check them using the appropriate functions.
|
||||
*
|
||||
* If no flags are specified (0), this function will use the
|
||||
* basicConstraints (2.5.29.19) PKIX extension. This means that only a certificate
|
||||
* If no flags are specified (0), this function will use the
|
||||
* basicConstraints (2.5.29.19) PKIX extension. This means that only a certificate
|
||||
* authority is allowed to sign a certificate.
|
||||
*
|
||||
* You must also check the peer's name in order to check if the verified
|
||||
* certificate belongs to the actual peer.
|
||||
* You must also check the peer's name in order to check if the verified
|
||||
* certificate belongs to the actual peer.
|
||||
*
|
||||
* The certificate verification output will be put in @verify and will be
|
||||
* one or more of the gnutls_certificate_status_t enumerated elements bitwise or'd.
|
||||
@@ -774,7 +774,7 @@ gnutls_x509_crt_list_verify (const gnutls_x509_crt_t * cert_list,
|
||||
if (cert_list == NULL || cert_list_length == 0)
|
||||
return GNUTLS_E_NO_CERTIFICATE_FOUND;
|
||||
|
||||
/* Verify certificate
|
||||
/* Verify certificate
|
||||
*/
|
||||
*verify = _gnutls_x509_verify_certificate (cert_list, cert_list_length,
|
||||
CA_list, CA_list_length,
|
||||
@@ -792,7 +792,7 @@ gnutls_x509_crt_list_verify (const gnutls_x509_crt_t * cert_list,
|
||||
* @flags: Flags that may be used to change the verification algorithm. Use OR of the gnutls_certificate_verify_flags enumerations.
|
||||
* @verify: will hold the certificate verification output.
|
||||
*
|
||||
* This function will try to verify the given certificate and return its status.
|
||||
* This function will try to verify the given certificate and return its status.
|
||||
* The verification output in this functions cannot be GNUTLS_CERT_NOT_VALID.
|
||||
*
|
||||
* Returns 0 on success and a negative value in case of an error.
|
||||
@@ -805,7 +805,7 @@ gnutls_x509_crt_verify (gnutls_x509_crt_t cert,
|
||||
unsigned int flags, unsigned int *verify)
|
||||
{
|
||||
int ret;
|
||||
/* Verify certificate
|
||||
/* Verify certificate
|
||||
*/
|
||||
ret = _gnutls_verify_certificate2 (cert, CA_list, CA_list_length, flags,
|
||||
verify);
|
||||
@@ -861,7 +861,7 @@ gnutls_x509_crl_verify (gnutls_x509_crl_t crl,
|
||||
unsigned int *verify)
|
||||
{
|
||||
int ret;
|
||||
/* Verify crl
|
||||
/* Verify crl
|
||||
*/
|
||||
ret = _gnutls_verify_crl2 (crl, CA_list, CA_list_length, flags, verify);
|
||||
if (ret < 0)
|
||||
@@ -912,7 +912,7 @@ find_crl_issuer (gnutls_x509_crl_t crl,
|
||||
{
|
||||
int i;
|
||||
|
||||
/* this is serial search.
|
||||
/* this is serial search.
|
||||
*/
|
||||
|
||||
for (i = 0; i < tcas_size; i++)
|
||||
@@ -925,14 +925,14 @@ find_crl_issuer (gnutls_x509_crl_t crl,
|
||||
return NULL;
|
||||
}
|
||||
|
||||
/*
|
||||
/*
|
||||
* Returns only 0 or 1. If 1 it means that the CRL
|
||||
* was successfuly verified.
|
||||
*
|
||||
* 'flags': an OR of the gnutls_certificate_verify_flags enumeration.
|
||||
*
|
||||
* Output will hold information about the verification
|
||||
* procedure.
|
||||
* procedure.
|
||||
*/
|
||||
static int
|
||||
_gnutls_verify_crl2 (gnutls_x509_crl_t crl,
|
||||
|
||||
@@ -118,7 +118,7 @@ gnutls_x509_crt_set_issuer_dn_by_oid (gnutls_x509_crt_t crt,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_set_proxy_dn - Set Proxy Certificate subject's distinguished name
|
||||
* gnutls_x509_crt_set_proxy_dn - Set Proxy Certificate subject's distinguished name
|
||||
* @crt: a gnutls_x509_crt_t structure with the new proxy cert
|
||||
* @eecrt: the end entity certificate that will be issuing the proxy
|
||||
* @raw_flag: must be 0, or 1 if the CN is DER encoded
|
||||
@@ -407,7 +407,7 @@ gnutls_x509_crt_set_ca_status (gnutls_x509_crt_t crt, unsigned int ca)
|
||||
* @crt: should contain a gnutls_x509_crt_t structure
|
||||
* @usage: an ORed sequence of the GNUTLS_KEY_* elements.
|
||||
*
|
||||
* This function will set the keyUsage certificate extension.
|
||||
* This function will set the keyUsage certificate extension.
|
||||
*
|
||||
* Returns 0 on success.
|
||||
*
|
||||
@@ -454,7 +454,7 @@ gnutls_x509_crt_set_key_usage (gnutls_x509_crt_t crt, unsigned int usage)
|
||||
* @type: is one of the gnutls_x509_subject_alt_name_t enumerations
|
||||
* @data_string: The data to be set
|
||||
*
|
||||
* This function will set the subject alternative name certificate extension.
|
||||
* This function will set the subject alternative name certificate extension.
|
||||
*
|
||||
* Returns 0 on success.
|
||||
*
|
||||
@@ -520,7 +520,7 @@ gnutls_x509_crt_set_subject_alternative_name (gnutls_x509_crt_t crt,
|
||||
* and negative values indicate that the pathLenConstraints field should
|
||||
* not be present.
|
||||
* @policyLanguage: OID describing the language of @policy.
|
||||
* @policy: opaque byte array with policy language, can be %NULL
|
||||
* @policy: opaque byte array with policy language, can be %NULL
|
||||
* @sizeof_policy: size of @policy.
|
||||
*
|
||||
* This function will set the proxyCertInfo extension.
|
||||
@@ -688,10 +688,10 @@ gnutls_x509_crt_set_expiration_time (gnutls_x509_crt_t cert, time_t exp_time)
|
||||
* @serial: The serial number
|
||||
* @serial_size: Holds the size of the serial field.
|
||||
*
|
||||
* This function will set the X.509 certificate's serial number.
|
||||
* This function will set the X.509 certificate's serial number.
|
||||
* Serial is not always a 32 or 64bit number. Some CAs use
|
||||
* large serial numbers, thus it may be wise to handle it as something
|
||||
* opaque.
|
||||
* opaque.
|
||||
*
|
||||
* Returns 0 on success, or a negative value in case of an error.
|
||||
*
|
||||
@@ -748,7 +748,7 @@ disable_optional_stuff (gnutls_x509_crt_t cert)
|
||||
* @data_string: The data to be set
|
||||
* @reason_flags: revocation reasons
|
||||
*
|
||||
* This function will set the CRL distribution points certificate extension.
|
||||
* This function will set the CRL distribution points certificate extension.
|
||||
*
|
||||
* Returns 0 on success.
|
||||
*
|
||||
@@ -814,7 +814,7 @@ gnutls_x509_crt_set_crl_dist_points (gnutls_x509_crt_t crt,
|
||||
* @dst: should contain a gnutls_x509_crt_t structure
|
||||
* @src: the certificate where the dist points will be copied from
|
||||
*
|
||||
* This function will copy the CRL distribution points certificate
|
||||
* This function will copy the CRL distribution points certificate
|
||||
* extension, from the source to the destination certificate.
|
||||
* This may be useful to copy from a CA certificate to issued ones.
|
||||
*
|
||||
|
||||
Reference in new issue
Block a user