📄 d2i_x509.pod
字号:
=pod=head1 NAMEd2i_X509, i2d_X509, d2i_X509_bio, d2i_X509_fp, i2d_X509_bio,i2d_X509_fp - X509 encode and decode functions=head1 SYNOPSIS #include <openssl/x509.h> X509 *d2i_X509(X509 **px, const unsigned char **in, int len); int i2d_X509(X509 *x, unsigned char **out); X509 *d2i_X509_bio(BIO *bp, X509 **x); X509 *d2i_X509_fp(FILE *fp, X509 **x); int i2d_X509_bio(X509 *x, BIO *bp); int i2d_X509_fp(X509 *x, FILE *fp);=head1 DESCRIPTIONThe X509 encode and decode routines encode and parse anB<X509> structure, which represents an X509 certificate.d2i_X509() attempts to decode B<len> bytes at B<*in>. If successful a pointer to the B<X509> structure is returned. If an erroroccurred then B<NULL> is returned. If B<px> is not B<NULL> then thereturned structure is written to B<*px>. If B<*px> is not B<NULL>then it is assumed that B<*px> contains a valid B<X509>structure and an attempt is made to reuse it. If the call issuccessful B<*in> is incremented to the byte following theparsed data.i2d_X509() encodes the structure pointed to by B<x> into DER format.If B<out> is not B<NULL> is writes the DER encoded data to the bufferat B<*out>, and increments it to point after the data just written.If the return value is negative an error occurred, otherwise itreturns the length of the encoded data. For OpenSSL 0.9.7 and later if B<*out> is B<NULL> memory will beallocated for a buffer and the encoded data written to it. In thiscase B<*out> is not incremented and it points to the start of thedata just written.d2i_X509_bio() is similar to d2i_X509() except it attemptsto parse data from BIO B<bp>.d2i_X509_fp() is similar to d2i_X509() except it attemptsto parse data from FILE pointer B<fp>.i2d_X509_bio() is similar to i2d_X509() except it writesthe encoding of the structure B<x> to BIO B<bp> and itreturns 1 for success and 0 for failure.i2d_X509_fp() is similar to i2d_X509() except it writesthe encoding of the structure B<x> to BIO B<bp> and itreturns 1 for success and 0 for failure.=head1 NOTESThe letters B<i> and B<d> in for example B<i2d_X509> stand for"internal" (that is an internal C structure) and "DER". So thatB<i2d_X509> converts from internal to DER.The functions can also understand B<BER> forms.The actual X509 structure passed to i2d_X509() must be a validpopulated B<X509> structure it can B<not> simply be fed with anempty structure such as that returned by X509_new().The encoded data is in binary form and may contain embedded zeroes.Therefore any FILE pointers or BIOs should be opened in binary mode.Functions such as B<strlen()> will B<not> return the correct lengthof the encoded structure.The ways that B<*in> and B<*out> are incremented after the operationcan trap the unwary. See the B<WARNINGS> section for some commonerrors.The reason for the auto increment behaviour is to reflect a typicalusage of ASN1 functions: after one structure is encoded or decodedanother will processed after it.=head1 EXAMPLESAllocate and encode the DER encoding of an X509 structure: int len; unsigned char *buf, *p; len = i2d_X509(x, NULL); buf = OPENSSL_malloc(len); if (buf == NULL) /* error */ p = buf; i2d_X509(x, &p);If you are using OpenSSL 0.9.7 or later then this can besimplified to: int len; unsigned char *buf; buf = NULL; len = i2d_X509(x, &buf); if (len < 0) /* error */Attempt to decode a buffer: X509 *x; unsigned char *buf, *p; int len; /* Something to setup buf and len */ p = buf; x = d2i_X509(NULL, &p, len); if (x == NULL) /* Some error */Alternative technique: X509 *x; unsigned char *buf, *p; int len; /* Something to setup buf and len */ p = buf; x = NULL; if(!d2i_X509(&x, &p, len)) /* Some error */=head1 WARNINGSThe use of temporary variable is mandatory. A commonmistake is to attempt to use a buffer directly as follows: int len; unsigned char *buf; len = i2d_X509(x, NULL); buf = OPENSSL_malloc(len); if (buf == NULL) /* error */ i2d_X509(x, &buf); /* Other stuff ... */ OPENSSL_free(buf);This code will result in B<buf> apparently containing garbage becauseit was incremented after the call to point after the data just written.Also B<buf> will no longer contain the pointer allocated by B<OPENSSL_malloc()>and the subsequent call to B<OPENSSL_free()> may well crash.The auto allocation feature (setting buf to NULL) only works on OpenSSL0.9.7 and later. Attempts to use it on earlier versions will typicallycause a segmentation violation.Another trap to avoid is misuse of the B<xp> argument to B<d2i_X509()>: X509 *x; if (!d2i_X509(&x, &p, len)) /* Some error */This will probably crash somewhere in B<d2i_X509()>. The reason for thisis that the variable B<x> is uninitialized and an attempt will be made tointerpret its (invalid) value as an B<X509> structure, typically causinga segmentation violation. If B<x> is set to NULL first then this will nothappen.=head1 BUGSIn some versions of OpenSSL the "reuse" behaviour of d2i_X509() when B<*px> is valid is broken and some parts of the reused structure maypersist if they are not present in the new one. As a result the useof this "reuse" behaviour is strongly discouraged.i2d_X509() will not return an error in many versions of OpenSSL,if mandatory fields are not initialized due to a programming errorthen the encoded structure may contain invalid data or omit thefields entirely and will not be parsed by d2i_X509(). This may befixed in future so code should not assume that i2d_X509() willalways succeed.=head1 RETURN VALUESd2i_X509(), d2i_X509_bio() and d2i_X509_fp() return a valid B<X509> structureor B<NULL> if an error occurs. The error code that can be obtained byL<ERR_get_error(3)|ERR_get_error(3)>. i2d_X509(), i2d_X509_bio() and i2d_X509_fp() return a the number of bytessuccessfully encoded or a negative value if an error occurs. The error codecan be obtained by L<ERR_get_error(3)|ERR_get_error(3)>. i2d_X509_bio() and i2d_X509_fp() returns 1 for success and 0 if an error occurs The error code can be obtained by L<ERR_get_error(3)|ERR_get_error(3)>. =head1 SEE ALSOL<ERR_get_error(3)|ERR_get_error(3)>=head1 HISTORYd2i_X509, i2d_X509, d2i_X509_bio, d2i_X509_fp, i2d_X509_bio and i2d_X509_fpare available in all versions of SSLeay and OpenSSL.=cut
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -