📄 x509.h
字号:
/* crypto/x509/x509.h *//* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) * All rights reserved. * * This package is an SSL implementation written * by Eric Young (eay@cryptsoft.com). * The implementation was written so as to conform with Netscapes SSL. * * This library is free for commercial and non-commercial use as long as * the following conditions are aheared to. The following conditions * apply to all code found in this distribution, be it the RC4, RSA, * lhash, DES, etc., code; not just the SSL code. The SSL documentation * included with this distribution is covered by the same copyright terms * except that the holder is Tim Hudson (tjh@cryptsoft.com). * * Copyright remains Eric Young's, and as such any Copyright notices in * the code are not to be removed. * If this package is used in a product, Eric Young should be given attribution * as the author of the parts of the library used. * This can be in the form of a textual message at program startup or * in documentation (online or textual) provided with the package. * * Redistribution and use in source and binary forms, with or without * modification, are permitted provided that the following conditions * are met: * 1. Redistributions of source code must retain the copyright * notice, this list of conditions and the following disclaimer. * 2. Redistributions in binary form must reproduce the above copyright * notice, this list of conditions and the following disclaimer in the * documentation and/or other materials provided with the distribution. * 3. All advertising materials mentioning features or use of this software * must display the following acknowledgement: * "This product includes cryptographic software written by * Eric Young (eay@cryptsoft.com)" * The word 'cryptographic' can be left out if the rouines from the library * being used are not cryptographic related :-). * 4. If you include any Windows specific code (or a derivative thereof) from * the apps directory (application code) you must include an acknowledgement: * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" * * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF * SUCH DAMAGE. * * The licence and distribution terms for any publically available version or * derivative of this code cannot be changed. i.e. this code cannot simply be * copied and put under another distribution licence * [including the GNU Public Licence.] */#ifndef HEADER_X509_H#define HEADER_X509_H#include <openssl/symhacks.h>#ifndef NO_BUFFER#include <openssl/buffer.h>#endif#ifndef NO_EVP#include <openssl/evp.h>#endif#ifndef NO_BIO#include <openssl/bio.h>#endif#include <openssl/stack.h>#include <openssl/asn1.h>#include <openssl/safestack.h>#ifndef NO_RSA#include <openssl/rsa.h>#endif#ifndef NO_DSA#include <openssl/dsa.h>#endif#ifndef NO_DH#include <openssl/dh.h>#endif#include <openssl/evp.h>#ifdef __cplusplusextern "C" {#endif#ifdef WIN32/* Under Win32 this is defined in wincrypt.h */#undef X509_NAME#endif /* If placed in pkcs12.h, we end up with a circular depency with pkcs7.h */#define DECLARE_PKCS12_STACK_OF(type) /* Nothing */#define IMPLEMENT_PKCS12_STACK_OF(type) /* Nothing */#define X509_FILETYPE_PEM 1#define X509_FILETYPE_ASN1 2#define X509_FILETYPE_DEFAULT 3#define X509v3_KU_DIGITAL_SIGNATURE 0x0080#define X509v3_KU_NON_REPUDIATION 0x0040#define X509v3_KU_KEY_ENCIPHERMENT 0x0020#define X509v3_KU_DATA_ENCIPHERMENT 0x0010#define X509v3_KU_KEY_AGREEMENT 0x0008#define X509v3_KU_KEY_CERT_SIGN 0x0004#define X509v3_KU_CRL_SIGN 0x0002#define X509v3_KU_ENCIPHER_ONLY 0x0001#define X509v3_KU_DECIPHER_ONLY 0x8000#define X509v3_KU_UNDEF 0xfffftypedef struct X509_objects_st { int nid; int (*a2i)(); int (*i2a)(); } X509_OBJECTS;typedef struct X509_algor_st { ASN1_OBJECT *algorithm; ASN1_TYPE *parameter; } X509_ALGOR;DECLARE_STACK_OF(X509_ALGOR)DECLARE_ASN1_SET_OF(X509_ALGOR)typedef struct X509_val_st { ASN1_TIME *notBefore; ASN1_TIME *notAfter; } X509_VAL;typedef struct X509_pubkey_st { X509_ALGOR *algor; ASN1_BIT_STRING *public_key; EVP_PKEY *pkey; } X509_PUBKEY;typedef struct X509_sig_st { X509_ALGOR *algor; ASN1_OCTET_STRING *digest; } X509_SIG;typedef struct X509_name_entry_st { ASN1_OBJECT *object; ASN1_STRING *value; int set; int size; /* temp variable */ } X509_NAME_ENTRY;DECLARE_STACK_OF(X509_NAME_ENTRY)DECLARE_ASN1_SET_OF(X509_NAME_ENTRY)/* we always keep X509_NAMEs in 2 forms. */typedef struct X509_name_st { STACK_OF(X509_NAME_ENTRY) *entries; int modified; /* true if 'bytes' needs to be built */#ifndef NO_BUFFER BUF_MEM *bytes;#else char *bytes;#endif unsigned long hash; /* Keep the hash around for lookups */ } X509_NAME;DECLARE_STACK_OF(X509_NAME)#define X509_EX_V_NETSCAPE_HACK 0x8000#define X509_EX_V_INIT 0x0001typedef struct X509_extension_st { ASN1_OBJECT *object; short critical; short netscape_hack; ASN1_OCTET_STRING *value; struct v3_ext_method *method; /* V3 method to use */ void *ext_val; /* extension value */ } X509_EXTENSION;DECLARE_STACK_OF(X509_EXTENSION)DECLARE_ASN1_SET_OF(X509_EXTENSION)/* a sequence of these are used */typedef struct x509_attributes_st { ASN1_OBJECT *object; int set; /* 1 for a set, 0 for a single item (which is wrong) */ union { char *ptr;/* 1 */ STACK_OF(ASN1_TYPE) *set;/* 0 */ ASN1_TYPE *single; } value; } X509_ATTRIBUTE;DECLARE_STACK_OF(X509_ATTRIBUTE)DECLARE_ASN1_SET_OF(X509_ATTRIBUTE)typedef struct X509_req_info_st { unsigned char *asn1; int length; ASN1_INTEGER *version; X509_NAME *subject; X509_PUBKEY *pubkey; /* d=2 hl=2 l= 0 cons: cont: 00 */ STACK_OF(X509_ATTRIBUTE) *attributes; /* [ 0 ] */ int req_kludge; } X509_REQ_INFO;typedef struct X509_req_st { X509_REQ_INFO *req_info; X509_ALGOR *sig_alg; ASN1_BIT_STRING *signature; int references; } X509_REQ;typedef struct x509_cinf_st { ASN1_INTEGER *version; /* [ 0 ] default of v1 */ ASN1_INTEGER *serialNumber; X509_ALGOR *signature; X509_NAME *issuer; X509_VAL *validity; X509_NAME *subject; X509_PUBKEY *key; ASN1_BIT_STRING *issuerUID; /* [ 1 ] optional in v2 */ ASN1_BIT_STRING *subjectUID; /* [ 2 ] optional in v2 */ STACK_OF(X509_EXTENSION) *extensions; /* [ 3 ] optional in v3 */ } X509_CINF;/* This stuff is certificate "auxiliary info" * it contains details which are useful in certificate * stores and databases. When used this is tagged onto * the end of the certificate itself */typedef struct x509_cert_aux_st { STACK_OF(ASN1_OBJECT) *trust; /* trusted uses */ STACK_OF(ASN1_OBJECT) *reject; /* rejected uses */ ASN1_UTF8STRING *alias; /* "friendly name" */ ASN1_OCTET_STRING *keyid; /* key id of private key */ STACK_OF(X509_ALGOR) *other; /* other unspecified info */ } X509_CERT_AUX;typedef struct x509_st { X509_CINF *cert_info; X509_ALGOR *sig_alg; ASN1_BIT_STRING *signature; int valid; int references; char *name; CRYPTO_EX_DATA ex_data; /* These contain copies of various extension values */ long ex_pathlen; unsigned long ex_flags; unsigned long ex_kusage; unsigned long ex_xkusage; unsigned long ex_nscert; ASN1_OCTET_STRING *skid; struct AUTHORITY_KEYID_st *akid;#ifndef NO_SHA unsigned char sha1_hash[SHA_DIGEST_LENGTH];#endif X509_CERT_AUX *aux; } X509;DECLARE_STACK_OF(X509)DECLARE_ASN1_SET_OF(X509)/* This is used for a table of trust checking functions */typedef struct x509_trust_st { int trust; int flags; int (*check_trust)(struct x509_trust_st *, X509 *, int); char *name; int arg1; void *arg2;} X509_TRUST;DECLARE_STACK_OF(X509_TRUST)/* standard trust ids */#define X509_TRUST_DEFAULT -1 /* Only valid in purpose settings */#define X509_TRUST_COMPAT 1#define X509_TRUST_SSL_CLIENT 2#define X509_TRUST_SSL_SERVER 3#define X509_TRUST_EMAIL 4#define X509_TRUST_OBJECT_SIGN 5/* Keep these up to date! */#define X509_TRUST_MIN 1#define X509_TRUST_MAX 5/* trust_flags values */#define X509_TRUST_DYNAMIC 1#define X509_TRUST_DYNAMIC_NAME 2/* check_trust return codes */#define X509_TRUST_TRUSTED 1#define X509_TRUST_REJECTED 2#define X509_TRUST_UNTRUSTED 3/* Flags specific to X509_NAME_print_ex() */
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -