⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 x509_vfy.h

📁 OpenSSL 0.9.8k 最新版OpenSSL
💻 H
📖 第 1 页 / 共 2 页
字号:
/* crypto/x509/x509_vfy.h *//* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) * All rights reserved. * * This package is an SSL implementation written * by Eric Young (eay@cryptsoft.com). * The implementation was written so as to conform with Netscapes SSL. *  * This library is free for commercial and non-commercial use as long as * the following conditions are aheared to.  The following conditions * apply to all code found in this distribution, be it the RC4, RSA, * lhash, DES, etc., code; not just the SSL code.  The SSL documentation * included with this distribution is covered by the same copyright terms * except that the holder is Tim Hudson (tjh@cryptsoft.com). *  * Copyright remains Eric Young's, and as such any Copyright notices in * the code are not to be removed. * If this package is used in a product, Eric Young should be given attribution * as the author of the parts of the library used. * This can be in the form of a textual message at program startup or * in documentation (online or textual) provided with the package. *  * Redistribution and use in source and binary forms, with or without * modification, are permitted provided that the following conditions * are met: * 1. Redistributions of source code must retain the copyright *    notice, this list of conditions and the following disclaimer. * 2. Redistributions in binary form must reproduce the above copyright *    notice, this list of conditions and the following disclaimer in the *    documentation and/or other materials provided with the distribution. * 3. All advertising materials mentioning features or use of this software *    must display the following acknowledgement: *    "This product includes cryptographic software written by *     Eric Young (eay@cryptsoft.com)" *    The word 'cryptographic' can be left out if the rouines from the library *    being used are not cryptographic related :-). * 4. If you include any Windows specific code (or a derivative thereof) from  *    the apps directory (application code) you must include an acknowledgement: *    "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" *  * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF * SUCH DAMAGE. *  * The licence and distribution terms for any publically available version or * derivative of this code cannot be changed.  i.e. this code cannot simply be * copied and put under another distribution licence * [including the GNU Public Licence.] */#ifndef HEADER_X509_H#include <openssl/x509.h>/* openssl/x509.h ends up #include-ing this file at about the only * appropriate moment. */#endif#ifndef HEADER_X509_VFY_H#define HEADER_X509_VFY_H#include <openssl/opensslconf.h>#ifndef OPENSSL_NO_LHASH#include <openssl/lhash.h>#endif#include <openssl/bio.h>#include <openssl/crypto.h>#include <openssl/symhacks.h>#ifdef  __cplusplusextern "C" {#endif/* Outer object */typedef struct x509_hash_dir_st	{	int num_dirs;	char **dirs;	int *dirs_type;	int num_dirs_alloced;	} X509_HASH_DIR_CTX;typedef struct x509_file_st	{	int num_paths;	/* number of paths to files or directories */	int num_alloced;	char **paths;	/* the list of paths or directories */	int *path_type;	} X509_CERT_FILE_CTX;/*******************************//*SSL_CTX -> X509_STORE    		-> X509_LOOKUP			->X509_LOOKUP_METHOD		-> X509_LOOKUP			->X509_LOOKUP_METHOD SSL	-> X509_STORE_CTX		->X509_STORE    The X509_STORE holds the tables etc for verification stuff.A X509_STORE_CTX is used while validating a single certificate.The X509_STORE has X509_LOOKUPs for looking up certs.The X509_STORE then calls a function to actually verify thecertificate chain.*/#define X509_LU_RETRY		-1#define X509_LU_FAIL		0#define X509_LU_X509		1#define X509_LU_CRL		2#define X509_LU_PKEY		3typedef struct x509_object_st	{	/* one of the above types */	int type;	union	{		char *ptr;		X509 *x509;		X509_CRL *crl;		EVP_PKEY *pkey;		} data;	} X509_OBJECT;typedef struct x509_lookup_st X509_LOOKUP;DECLARE_STACK_OF(X509_LOOKUP)DECLARE_STACK_OF(X509_OBJECT)/* This is a static that defines the function interface */typedef struct x509_lookup_method_st	{	const char *name;	int (*new_item)(X509_LOOKUP *ctx);	void (*free)(X509_LOOKUP *ctx);	int (*init)(X509_LOOKUP *ctx);	int (*shutdown)(X509_LOOKUP *ctx);	int (*ctrl)(X509_LOOKUP *ctx,int cmd,const char *argc,long argl,			char **ret);	int (*get_by_subject)(X509_LOOKUP *ctx,int type,X509_NAME *name,			      X509_OBJECT *ret);	int (*get_by_issuer_serial)(X509_LOOKUP *ctx,int type,X509_NAME *name,				    ASN1_INTEGER *serial,X509_OBJECT *ret);	int (*get_by_fingerprint)(X509_LOOKUP *ctx,int type,				  unsigned char *bytes,int len,				  X509_OBJECT *ret);	int (*get_by_alias)(X509_LOOKUP *ctx,int type,char *str,int len,			    X509_OBJECT *ret);	} X509_LOOKUP_METHOD;/* This structure hold all parameters associated with a verify operation * by including an X509_VERIFY_PARAM structure in related structures the * parameters used can be customized */typedef struct X509_VERIFY_PARAM_st	{	char *name;	time_t check_time;	/* Time to use */	unsigned long inh_flags; /* Inheritance flags */	unsigned long flags;	/* Various verify flags */	int purpose;		/* purpose to check untrusted certificates */	int trust;		/* trust setting to check */	int depth;		/* Verify depth */	STACK_OF(ASN1_OBJECT) *policies;	/* Permissible policies */	} X509_VERIFY_PARAM;DECLARE_STACK_OF(X509_VERIFY_PARAM)/* This is used to hold everything.  It is used for all certificate * validation.  Once we have a certificate chain, the 'verify' * function is then called to actually check the cert chain. */struct x509_store_st	{	/* The following is a cache of trusted certs */	int cache; 	/* if true, stash any hits */	STACK_OF(X509_OBJECT) *objs;	/* Cache of all objects */	/* These are external lookup methods */	STACK_OF(X509_LOOKUP) *get_cert_methods;	X509_VERIFY_PARAM *param;	/* Callbacks for various operations */	int (*verify)(X509_STORE_CTX *ctx);	/* called to verify a certificate */	int (*verify_cb)(int ok,X509_STORE_CTX *ctx);	/* error callback */	int (*get_issuer)(X509 **issuer, X509_STORE_CTX *ctx, X509 *x);	/* get issuers cert from ctx */	int (*check_issued)(X509_STORE_CTX *ctx, X509 *x, X509 *issuer); /* check issued */	int (*check_revocation)(X509_STORE_CTX *ctx); /* Check revocation status of chain */	int (*get_crl)(X509_STORE_CTX *ctx, X509_CRL **crl, X509 *x); /* retrieve CRL */	int (*check_crl)(X509_STORE_CTX *ctx, X509_CRL *crl); /* Check CRL validity */	int (*cert_crl)(X509_STORE_CTX *ctx, X509_CRL *crl, X509 *x); /* Check certificate against CRL */	int (*cleanup)(X509_STORE_CTX *ctx);	CRYPTO_EX_DATA ex_data;	int references;	} /* X509_STORE */;int X509_STORE_set_depth(X509_STORE *store, int depth);#define X509_STORE_set_verify_cb_func(ctx,func) ((ctx)->verify_cb=(func))#define X509_STORE_set_verify_func(ctx,func)	((ctx)->verify=(func))/* This is the functions plus an instance of the local variables. */struct x509_lookup_st	{	int init;			/* have we been started */	int skip;			/* don't use us. */	X509_LOOKUP_METHOD *method;	/* the functions */	char *method_data;		/* method data */	X509_STORE *store_ctx;	/* who owns us */	} /* X509_LOOKUP */;/* This is a used when verifying cert chains.  Since the * gathering of the cert chain can take some time (and have to be * 'retried', this needs to be kept and passed around. */struct x509_store_ctx_st      /* X509_STORE_CTX */	{	X509_STORE *ctx;	int current_method;	/* used when looking up certs */	/* The following are set by the caller */	X509 *cert;		/* The cert to check */	STACK_OF(X509) *untrusted;	/* chain of X509s - untrusted - passed in */	STACK_OF(X509_CRL) *crls;	/* set of CRLs passed in */	X509_VERIFY_PARAM *param;	void *other_ctx;	/* Other info for use with get_issuer() */	/* Callbacks for various operations */	int (*verify)(X509_STORE_CTX *ctx);	/* called to verify a certificate */	int (*verify_cb)(int ok,X509_STORE_CTX *ctx);		/* error callback */	int (*get_issuer)(X509 **issuer, X509_STORE_CTX *ctx, X509 *x);	/* get issuers cert from ctx */	int (*check_issued)(X509_STORE_CTX *ctx, X509 *x, X509 *issuer); /* check issued */	int (*check_revocation)(X509_STORE_CTX *ctx); /* Check revocation status of chain */	int (*get_crl)(X509_STORE_CTX *ctx, X509_CRL **crl, X509 *x); /* retrieve CRL */	int (*check_crl)(X509_STORE_CTX *ctx, X509_CRL *crl); /* Check CRL validity */	int (*cert_crl)(X509_STORE_CTX *ctx, X509_CRL *crl, X509 *x); /* Check certificate against CRL */	int (*check_policy)(X509_STORE_CTX *ctx);	int (*cleanup)(X509_STORE_CTX *ctx);	/* The following is built up */	int valid;		/* if 0, rebuild chain */	int last_untrusted;	/* index of last untrusted cert */	STACK_OF(X509) *chain; 		/* chain of X509s - built up and trusted */	X509_POLICY_TREE *tree;	/* Valid policy tree */	int explicit_policy;	/* Require explicit policy value */	/* When something goes wrong, this is why */	int error_depth;	int error;	X509 *current_cert;	X509 *current_issuer;	/* cert currently being tested as valid issuer */	X509_CRL *current_crl;	/* current CRL */	CRYPTO_EX_DATA ex_data;

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -