x509.h revision 1.20
1/* $OpenBSD: x509.h,v 1.20 2004/04/15 18:39:27 deraadt Exp $ */ 2/* $EOM: x509.h,v 1.11 2000/09/28 12:53:27 niklas Exp $ */ 3 4/* 5 * Copyright (c) 1998, 1999 Niels Provos. All rights reserved. 6 * Copyright (c) 1999 Angelos D. Keromytis. All rights reserved. 7 * Copyright (c) 2000, 2001 Niklas Hallqvist. All rights reserved. 8 * 9 * Redistribution and use in source and binary forms, with or without 10 * modification, are permitted provided that the following conditions 11 * are met: 12 * 1. Redistributions of source code must retain the above copyright 13 * notice, this list of conditions and the following disclaimer. 14 * 2. Redistributions in binary form must reproduce the above copyright 15 * notice, this list of conditions and the following disclaimer in the 16 * documentation and/or other materials provided with the distribution. 17 * 18 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR 19 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES 20 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. 21 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, 22 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 23 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, 24 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY 25 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 26 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF 27 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 28 */ 29 30/* 31 * This code was written under funding by Ericsson Radio Systems. 32 */ 33 34#ifndef _X509_H_ 35#define _X509_H_ 36 37#include "libcrypto.h" 38 39#define X509v3_RFC_NAME 1 40#define X509v3_DNS_NAME 2 41#define X509v3_IP_ADDR 7 42 43struct x509_attribval { 44 char *type; 45 char *val; 46}; 47 48/* 49 * The acceptable certification authority. 50 * XXX We only support two names at the moment, as of ASN this can 51 * be dynamic but we don't care for now. 52 */ 53struct x509_aca { 54 struct x509_attribval name1; 55 struct x509_attribval name2; 56}; 57 58struct X509; 59struct X509_STORE; 60 61/* Functions provided by cert handler. */ 62 63int x509_certreq_validate(u_int8_t *, u_int32_t); 64void *x509_certreq_decode(u_int8_t *, u_int32_t); 65void x509_cert_free(void *); 66void *x509_cert_get(u_int8_t *, u_int32_t); 67int x509_cert_get_key(void *, void *); 68int x509_cert_get_subjects(void *, int *, u_int8_t ***, u_int32_t **); 69int x509_cert_init(void); 70int x509_crl_init(void); 71int x509_cert_obtain(u_int8_t *, size_t, void *, u_int8_t **, u_int32_t *); 72int x509_cert_validate(void *); 73void x509_free_aca(void *); 74void *x509_cert_dup(void *); 75void x509_serialize(void *, u_int8_t **, u_int32_t *); 76char *x509_printable(void *); 77void *x509_from_printable(char *); 78 79/* Misc. X509 certificate functions. */ 80 81char *x509_DN_string(u_int8_t *, size_t); 82int x509_cert_insert(int, void *); 83int x509_cert_subjectaltname(X509 * cert, u_char **, u_int *); 84X509 *x509_from_asn(u_char *, u_int); 85int x509_generate_kn(int, X509 *); 86int x509_read_from_dir(X509_STORE *, char *, int); 87int x509_read_crls_from_dir(X509_STORE *, char *); 88 89#endif /* _X509_H_ */ 90