Deleted Added
full compact
SSL_CTX_set_cert_verify_callback.3 (206048) SSL_CTX_set_cert_verify_callback.3 (215698)
1.\" Automatically generated by Pod::Man v1.37, Pod::Parser v1.37
1.\" Automatically generated by Pod::Man 2.22 (Pod::Simple 3.07)
2.\"
3.\" Standard preamble:
4.\" ========================================================================
2.\"
3.\" Standard preamble:
4.\" ========================================================================
5.de Sh \" Subsection heading
6.br
7.if t .Sp
8.ne 5
9.PP
10\fB\\$1\fR
11.PP
12..
13.de Sp \" Vertical space (when we can't use .PP)
14.if t .sp .5v
15.if n .sp
16..
17.de Vb \" Begin verbatim text
18.ft CW
19.nf
20.ne \\$1
21..
22.de Ve \" End verbatim text
23.ft R
24.fi
25..
26.\" Set up some character translations and predefined strings. \*(-- will
27.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left
5.de Sp \" Vertical space (when we can't use .PP)
6.if t .sp .5v
7.if n .sp
8..
9.de Vb \" Begin verbatim text
10.ft CW
11.nf
12.ne \\$1
13..
14.de Ve \" End verbatim text
15.ft R
16.fi
17..
18.\" Set up some character translations and predefined strings. \*(-- will
19.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left
28.\" double quote, and \*(R" will give a right double quote. | will give a
29.\" real vertical bar. \*(C+ will give a nicer C++. Capital omega is used to
30.\" do unbreakable dashes and therefore won't be available. \*(C` and \*(C'
31.\" expand to `' in nroff, nothing in troff, for use with C<>.
32.tr \(*W-|\(bv\*(Tr
20.\" double quote, and \*(R" will give a right double quote. \*(C+ will
21.\" give a nicer C++. Capital omega is used to do unbreakable dashes and
22.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff,
23.\" nothing in troff, for use with C<>.
24.tr \(*W-
33.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p'
34.ie n \{\
35. ds -- \(*W-
36. ds PI pi
37. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch
38. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch
39. ds L" ""
40. ds R" ""
41. ds C` ""
42. ds C' ""
43'br\}
44.el\{\
45. ds -- \|\(em\|
46. ds PI \(*p
47. ds L" ``
48. ds R" ''
49'br\}
50.\"
25.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p'
26.ie n \{\
27. ds -- \(*W-
28. ds PI pi
29. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch
30. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch
31. ds L" ""
32. ds R" ""
33. ds C` ""
34. ds C' ""
35'br\}
36.el\{\
37. ds -- \|\(em\|
38. ds PI \(*p
39. ds L" ``
40. ds R" ''
41'br\}
42.\"
43.\" Escape single quotes in literal strings from groff's Unicode transform.
44.ie \n(.g .ds Aq \(aq
45.el .ds Aq '
46.\"
51.\" If the F register is turned on, we'll generate index entries on stderr for
47.\" If the F register is turned on, we'll generate index entries on stderr for
52.\" titles (.TH), headers (.SH), subsections (.Sh), items (.Ip), and index
48.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index
53.\" entries marked with X<> in POD. Of course, you'll have to process the
54.\" output yourself in some meaningful fashion.
49.\" entries marked with X<> in POD. Of course, you'll have to process the
50.\" output yourself in some meaningful fashion.
55.if \nF \{\
51.ie \nF \{\
56. de IX
57. tm Index:\\$1\t\\n%\t"\\$2"
58..
59. nr % 0
60. rr F
61.\}
52. de IX
53. tm Index:\\$1\t\\n%\t"\\$2"
54..
55. nr % 0
56. rr F
57.\}
58.el \{\
59. de IX
60..
61.\}
62.\"
62.\"
63.\" For nroff, turn off justification. Always turn off hyphenation; it makes
64.\" way too many mistakes in technical documents.
65.hy 0
66.if n .na
67.\"
68.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2).
69.\" Fear. Run. Save yourself. No user-serviceable parts.
70. \" fudge factors for nroff and troff
71.if n \{\
72. ds #H 0
73. ds #V .8m
74. ds #F .3m
75. ds #[ \f1

--- 48 unchanged lines hidden (view full) ---

124. ds Th \o'LP'
125. ds ae ae
126. ds Ae AE
127.\}
128.rm #[ #] #H #V #F C
129.\" ========================================================================
130.\"
131.IX Title "SSL_CTX_set_cert_verify_callback 3"
63.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2).
64.\" Fear. Run. Save yourself. No user-serviceable parts.
65. \" fudge factors for nroff and troff
66.if n \{\
67. ds #H 0
68. ds #V .8m
69. ds #F .3m
70. ds #[ \f1

--- 48 unchanged lines hidden (view full) ---

119. ds Th \o'LP'
120. ds ae ae
121. ds Ae AE
122.\}
123.rm #[ #] #H #V #F C
124.\" ========================================================================
125.\"
126.IX Title "SSL_CTX_set_cert_verify_callback 3"
132.TH SSL_CTX_set_cert_verify_callback 3 "2010-03-24" "0.9.8n" "OpenSSL"
127.TH SSL_CTX_set_cert_verify_callback 3 "2010-11-16" "0.9.8p" "OpenSSL"
128.\" For nroff, turn off justification. Always turn off hyphenation; it makes
129.\" way too many mistakes in technical documents.
130.if n .ad l
131.nh
133.SH "NAME"
134SSL_CTX_set_cert_verify_callback \- set peer certificate verification procedure
135.SH "SYNOPSIS"
136.IX Header "SYNOPSIS"
137.Vb 1
138\& #include <openssl/ssl.h>
132.SH "NAME"
133SSL_CTX_set_cert_verify_callback \- set peer certificate verification procedure
134.SH "SYNOPSIS"
135.IX Header "SYNOPSIS"
136.Vb 1
137\& #include <openssl/ssl.h>
139.Ve
140.PP
141.Vb 1
138\&
142\& void SSL_CTX_set_cert_verify_callback(SSL_CTX *ctx, int (*callback)(X509_STORE_CTX *,void *), void *arg);
143.Ve
144.SH "DESCRIPTION"
145.IX Header "DESCRIPTION"
146\&\fISSL_CTX_set_cert_verify_callback()\fR sets the verification callback function for
147\&\fIctx\fR. \s-1SSL\s0 objects that are created from \fIctx\fR inherit the setting valid at
148the time when \fISSL_new\fR\|(3) is called.
149.SH "NOTES"

--- 10 unchanged lines hidden (view full) ---

160argument \fIarg\fR is specified by the application when setting \fIcallback\fR.
161.PP
162\&\fIcallback\fR should return 1 to indicate verification success and 0 to
163indicate verification failure. If \s-1SSL_VERIFY_PEER\s0 is set and \fIcallback\fR
164returns 0, the handshake will fail. As the verification procedure may
165allow to continue the connection in case of failure (by always returning 1)
166the verification result must be set in any case using the \fBerror\fR
167member of \fIx509_store_ctx\fR so that the calling application will be informed
139\& void SSL_CTX_set_cert_verify_callback(SSL_CTX *ctx, int (*callback)(X509_STORE_CTX *,void *), void *arg);
140.Ve
141.SH "DESCRIPTION"
142.IX Header "DESCRIPTION"
143\&\fISSL_CTX_set_cert_verify_callback()\fR sets the verification callback function for
144\&\fIctx\fR. \s-1SSL\s0 objects that are created from \fIctx\fR inherit the setting valid at
145the time when \fISSL_new\fR\|(3) is called.
146.SH "NOTES"

--- 10 unchanged lines hidden (view full) ---

157argument \fIarg\fR is specified by the application when setting \fIcallback\fR.
158.PP
159\&\fIcallback\fR should return 1 to indicate verification success and 0 to
160indicate verification failure. If \s-1SSL_VERIFY_PEER\s0 is set and \fIcallback\fR
161returns 0, the handshake will fail. As the verification procedure may
162allow to continue the connection in case of failure (by always returning 1)
163the verification result must be set in any case using the \fBerror\fR
164member of \fIx509_store_ctx\fR so that the calling application will be informed
168about the detailed result of the verification procedure!
165about the detailed result of the verification procedure!
169.PP
170Within \fIx509_store_ctx\fR, \fIcallback\fR has access to the \fIverify_callback\fR
171function set using \fISSL_CTX_set_verify\fR\|(3).
172.SH "WARNINGS"
173.IX Header "WARNINGS"
174Do not mix the verification callback described in this function with the
175\&\fBverify_callback\fR function called during the verification process. The
176latter is set using the \fISSL_CTX_set_verify\fR\|(3)

--- 23 unchanged lines hidden ---
166.PP
167Within \fIx509_store_ctx\fR, \fIcallback\fR has access to the \fIverify_callback\fR
168function set using \fISSL_CTX_set_verify\fR\|(3).
169.SH "WARNINGS"
170.IX Header "WARNINGS"
171Do not mix the verification callback described in this function with the
172\&\fBverify_callback\fR function called during the verification process. The
173latter is set using the \fISSL_CTX_set_verify\fR\|(3)

--- 23 unchanged lines hidden ---