Mercurial > repos > rliterman > csp2
comparison CSP2/CSP2_env/env-d9b9114564458d9d-741b3de822f2aaca6c6caa4325c4afce/include/openssl/ocsp.h @ 69:33d812a61356
planemo upload commit 2e9511a184a1ca667c7be0c6321a36dc4e3d116d
author | jpayne |
---|---|
date | Tue, 18 Mar 2025 17:55:14 -0400 |
parents | |
children |
comparison
equal
deleted
inserted
replaced
67:0e9998148a16 | 69:33d812a61356 |
---|---|
1 /* | |
2 * Copyright 2000-2019 The OpenSSL Project Authors. All Rights Reserved. | |
3 * | |
4 * Licensed under the OpenSSL license (the "License"). You may not use | |
5 * this file except in compliance with the License. You can obtain a copy | |
6 * in the file LICENSE in the source distribution or at | |
7 * https://www.openssl.org/source/license.html | |
8 */ | |
9 | |
10 #ifndef HEADER_OCSP_H | |
11 # define HEADER_OCSP_H | |
12 | |
13 #include <openssl/opensslconf.h> | |
14 | |
15 /* | |
16 * These definitions are outside the OPENSSL_NO_OCSP guard because although for | |
17 * historical reasons they have OCSP_* names, they can actually be used | |
18 * independently of OCSP. E.g. see RFC5280 | |
19 */ | |
20 /*- | |
21 * CRLReason ::= ENUMERATED { | |
22 * unspecified (0), | |
23 * keyCompromise (1), | |
24 * cACompromise (2), | |
25 * affiliationChanged (3), | |
26 * superseded (4), | |
27 * cessationOfOperation (5), | |
28 * certificateHold (6), | |
29 * removeFromCRL (8) } | |
30 */ | |
31 # define OCSP_REVOKED_STATUS_NOSTATUS -1 | |
32 # define OCSP_REVOKED_STATUS_UNSPECIFIED 0 | |
33 # define OCSP_REVOKED_STATUS_KEYCOMPROMISE 1 | |
34 # define OCSP_REVOKED_STATUS_CACOMPROMISE 2 | |
35 # define OCSP_REVOKED_STATUS_AFFILIATIONCHANGED 3 | |
36 # define OCSP_REVOKED_STATUS_SUPERSEDED 4 | |
37 # define OCSP_REVOKED_STATUS_CESSATIONOFOPERATION 5 | |
38 # define OCSP_REVOKED_STATUS_CERTIFICATEHOLD 6 | |
39 # define OCSP_REVOKED_STATUS_REMOVEFROMCRL 8 | |
40 | |
41 | |
42 # ifndef OPENSSL_NO_OCSP | |
43 | |
44 # include <openssl/ossl_typ.h> | |
45 # include <openssl/x509.h> | |
46 # include <openssl/x509v3.h> | |
47 # include <openssl/safestack.h> | |
48 # include <openssl/ocsperr.h> | |
49 | |
50 #ifdef __cplusplus | |
51 extern "C" { | |
52 #endif | |
53 | |
54 /* Various flags and values */ | |
55 | |
56 # define OCSP_DEFAULT_NONCE_LENGTH 16 | |
57 | |
58 # define OCSP_NOCERTS 0x1 | |
59 # define OCSP_NOINTERN 0x2 | |
60 # define OCSP_NOSIGS 0x4 | |
61 # define OCSP_NOCHAIN 0x8 | |
62 # define OCSP_NOVERIFY 0x10 | |
63 # define OCSP_NOEXPLICIT 0x20 | |
64 # define OCSP_NOCASIGN 0x40 | |
65 # define OCSP_NODELEGATED 0x80 | |
66 # define OCSP_NOCHECKS 0x100 | |
67 # define OCSP_TRUSTOTHER 0x200 | |
68 # define OCSP_RESPID_KEY 0x400 | |
69 # define OCSP_NOTIME 0x800 | |
70 | |
71 typedef struct ocsp_cert_id_st OCSP_CERTID; | |
72 | |
73 DEFINE_STACK_OF(OCSP_CERTID) | |
74 | |
75 typedef struct ocsp_one_request_st OCSP_ONEREQ; | |
76 | |
77 DEFINE_STACK_OF(OCSP_ONEREQ) | |
78 | |
79 typedef struct ocsp_req_info_st OCSP_REQINFO; | |
80 typedef struct ocsp_signature_st OCSP_SIGNATURE; | |
81 typedef struct ocsp_request_st OCSP_REQUEST; | |
82 | |
83 # define OCSP_RESPONSE_STATUS_SUCCESSFUL 0 | |
84 # define OCSP_RESPONSE_STATUS_MALFORMEDREQUEST 1 | |
85 # define OCSP_RESPONSE_STATUS_INTERNALERROR 2 | |
86 # define OCSP_RESPONSE_STATUS_TRYLATER 3 | |
87 # define OCSP_RESPONSE_STATUS_SIGREQUIRED 5 | |
88 # define OCSP_RESPONSE_STATUS_UNAUTHORIZED 6 | |
89 | |
90 typedef struct ocsp_resp_bytes_st OCSP_RESPBYTES; | |
91 | |
92 # define V_OCSP_RESPID_NAME 0 | |
93 # define V_OCSP_RESPID_KEY 1 | |
94 | |
95 DEFINE_STACK_OF(OCSP_RESPID) | |
96 | |
97 typedef struct ocsp_revoked_info_st OCSP_REVOKEDINFO; | |
98 | |
99 # define V_OCSP_CERTSTATUS_GOOD 0 | |
100 # define V_OCSP_CERTSTATUS_REVOKED 1 | |
101 # define V_OCSP_CERTSTATUS_UNKNOWN 2 | |
102 | |
103 typedef struct ocsp_cert_status_st OCSP_CERTSTATUS; | |
104 typedef struct ocsp_single_response_st OCSP_SINGLERESP; | |
105 | |
106 DEFINE_STACK_OF(OCSP_SINGLERESP) | |
107 | |
108 typedef struct ocsp_response_data_st OCSP_RESPDATA; | |
109 | |
110 typedef struct ocsp_basic_response_st OCSP_BASICRESP; | |
111 | |
112 typedef struct ocsp_crl_id_st OCSP_CRLID; | |
113 typedef struct ocsp_service_locator_st OCSP_SERVICELOC; | |
114 | |
115 # define PEM_STRING_OCSP_REQUEST "OCSP REQUEST" | |
116 # define PEM_STRING_OCSP_RESPONSE "OCSP RESPONSE" | |
117 | |
118 # define d2i_OCSP_REQUEST_bio(bp,p) ASN1_d2i_bio_of(OCSP_REQUEST,OCSP_REQUEST_new,d2i_OCSP_REQUEST,bp,p) | |
119 | |
120 # define d2i_OCSP_RESPONSE_bio(bp,p) ASN1_d2i_bio_of(OCSP_RESPONSE,OCSP_RESPONSE_new,d2i_OCSP_RESPONSE,bp,p) | |
121 | |
122 # define PEM_read_bio_OCSP_REQUEST(bp,x,cb) (OCSP_REQUEST *)PEM_ASN1_read_bio( \ | |
123 (char *(*)())d2i_OCSP_REQUEST,PEM_STRING_OCSP_REQUEST, \ | |
124 bp,(char **)(x),cb,NULL) | |
125 | |
126 # define PEM_read_bio_OCSP_RESPONSE(bp,x,cb) (OCSP_RESPONSE *)PEM_ASN1_read_bio(\ | |
127 (char *(*)())d2i_OCSP_RESPONSE,PEM_STRING_OCSP_RESPONSE, \ | |
128 bp,(char **)(x),cb,NULL) | |
129 | |
130 # define PEM_write_bio_OCSP_REQUEST(bp,o) \ | |
131 PEM_ASN1_write_bio((int (*)())i2d_OCSP_REQUEST,PEM_STRING_OCSP_REQUEST,\ | |
132 bp,(char *)(o), NULL,NULL,0,NULL,NULL) | |
133 | |
134 # define PEM_write_bio_OCSP_RESPONSE(bp,o) \ | |
135 PEM_ASN1_write_bio((int (*)())i2d_OCSP_RESPONSE,PEM_STRING_OCSP_RESPONSE,\ | |
136 bp,(char *)(o), NULL,NULL,0,NULL,NULL) | |
137 | |
138 # define i2d_OCSP_RESPONSE_bio(bp,o) ASN1_i2d_bio_of(OCSP_RESPONSE,i2d_OCSP_RESPONSE,bp,o) | |
139 | |
140 # define i2d_OCSP_REQUEST_bio(bp,o) ASN1_i2d_bio_of(OCSP_REQUEST,i2d_OCSP_REQUEST,bp,o) | |
141 | |
142 # define ASN1_BIT_STRING_digest(data,type,md,len) \ | |
143 ASN1_item_digest(ASN1_ITEM_rptr(ASN1_BIT_STRING),type,data,md,len) | |
144 | |
145 # define OCSP_CERTSTATUS_dup(cs)\ | |
146 (OCSP_CERTSTATUS*)ASN1_dup((int(*)())i2d_OCSP_CERTSTATUS,\ | |
147 (char *(*)())d2i_OCSP_CERTSTATUS,(char *)(cs)) | |
148 | |
149 OCSP_CERTID *OCSP_CERTID_dup(OCSP_CERTID *id); | |
150 | |
151 OCSP_RESPONSE *OCSP_sendreq_bio(BIO *b, const char *path, OCSP_REQUEST *req); | |
152 OCSP_REQ_CTX *OCSP_sendreq_new(BIO *io, const char *path, OCSP_REQUEST *req, | |
153 int maxline); | |
154 int OCSP_REQ_CTX_nbio(OCSP_REQ_CTX *rctx); | |
155 int OCSP_sendreq_nbio(OCSP_RESPONSE **presp, OCSP_REQ_CTX *rctx); | |
156 OCSP_REQ_CTX *OCSP_REQ_CTX_new(BIO *io, int maxline); | |
157 void OCSP_REQ_CTX_free(OCSP_REQ_CTX *rctx); | |
158 void OCSP_set_max_response_length(OCSP_REQ_CTX *rctx, unsigned long len); | |
159 int OCSP_REQ_CTX_i2d(OCSP_REQ_CTX *rctx, const ASN1_ITEM *it, | |
160 ASN1_VALUE *val); | |
161 int OCSP_REQ_CTX_nbio_d2i(OCSP_REQ_CTX *rctx, ASN1_VALUE **pval, | |
162 const ASN1_ITEM *it); | |
163 BIO *OCSP_REQ_CTX_get0_mem_bio(OCSP_REQ_CTX *rctx); | |
164 int OCSP_REQ_CTX_http(OCSP_REQ_CTX *rctx, const char *op, const char *path); | |
165 int OCSP_REQ_CTX_set1_req(OCSP_REQ_CTX *rctx, OCSP_REQUEST *req); | |
166 int OCSP_REQ_CTX_add1_header(OCSP_REQ_CTX *rctx, | |
167 const char *name, const char *value); | |
168 | |
169 OCSP_CERTID *OCSP_cert_to_id(const EVP_MD *dgst, const X509 *subject, | |
170 const X509 *issuer); | |
171 | |
172 OCSP_CERTID *OCSP_cert_id_new(const EVP_MD *dgst, | |
173 const X509_NAME *issuerName, | |
174 const ASN1_BIT_STRING *issuerKey, | |
175 const ASN1_INTEGER *serialNumber); | |
176 | |
177 OCSP_ONEREQ *OCSP_request_add0_id(OCSP_REQUEST *req, OCSP_CERTID *cid); | |
178 | |
179 int OCSP_request_add1_nonce(OCSP_REQUEST *req, unsigned char *val, int len); | |
180 int OCSP_basic_add1_nonce(OCSP_BASICRESP *resp, unsigned char *val, int len); | |
181 int OCSP_check_nonce(OCSP_REQUEST *req, OCSP_BASICRESP *bs); | |
182 int OCSP_copy_nonce(OCSP_BASICRESP *resp, OCSP_REQUEST *req); | |
183 | |
184 int OCSP_request_set1_name(OCSP_REQUEST *req, X509_NAME *nm); | |
185 int OCSP_request_add1_cert(OCSP_REQUEST *req, X509 *cert); | |
186 | |
187 int OCSP_request_sign(OCSP_REQUEST *req, | |
188 X509 *signer, | |
189 EVP_PKEY *key, | |
190 const EVP_MD *dgst, | |
191 STACK_OF(X509) *certs, unsigned long flags); | |
192 | |
193 int OCSP_response_status(OCSP_RESPONSE *resp); | |
194 OCSP_BASICRESP *OCSP_response_get1_basic(OCSP_RESPONSE *resp); | |
195 | |
196 const ASN1_OCTET_STRING *OCSP_resp_get0_signature(const OCSP_BASICRESP *bs); | |
197 const X509_ALGOR *OCSP_resp_get0_tbs_sigalg(const OCSP_BASICRESP *bs); | |
198 const OCSP_RESPDATA *OCSP_resp_get0_respdata(const OCSP_BASICRESP *bs); | |
199 int OCSP_resp_get0_signer(OCSP_BASICRESP *bs, X509 **signer, | |
200 STACK_OF(X509) *extra_certs); | |
201 | |
202 int OCSP_resp_count(OCSP_BASICRESP *bs); | |
203 OCSP_SINGLERESP *OCSP_resp_get0(OCSP_BASICRESP *bs, int idx); | |
204 const ASN1_GENERALIZEDTIME *OCSP_resp_get0_produced_at(const OCSP_BASICRESP* bs); | |
205 const STACK_OF(X509) *OCSP_resp_get0_certs(const OCSP_BASICRESP *bs); | |
206 int OCSP_resp_get0_id(const OCSP_BASICRESP *bs, | |
207 const ASN1_OCTET_STRING **pid, | |
208 const X509_NAME **pname); | |
209 int OCSP_resp_get1_id(const OCSP_BASICRESP *bs, | |
210 ASN1_OCTET_STRING **pid, | |
211 X509_NAME **pname); | |
212 | |
213 int OCSP_resp_find(OCSP_BASICRESP *bs, OCSP_CERTID *id, int last); | |
214 int OCSP_single_get0_status(OCSP_SINGLERESP *single, int *reason, | |
215 ASN1_GENERALIZEDTIME **revtime, | |
216 ASN1_GENERALIZEDTIME **thisupd, | |
217 ASN1_GENERALIZEDTIME **nextupd); | |
218 int OCSP_resp_find_status(OCSP_BASICRESP *bs, OCSP_CERTID *id, int *status, | |
219 int *reason, | |
220 ASN1_GENERALIZEDTIME **revtime, | |
221 ASN1_GENERALIZEDTIME **thisupd, | |
222 ASN1_GENERALIZEDTIME **nextupd); | |
223 int OCSP_check_validity(ASN1_GENERALIZEDTIME *thisupd, | |
224 ASN1_GENERALIZEDTIME *nextupd, long sec, long maxsec); | |
225 | |
226 int OCSP_request_verify(OCSP_REQUEST *req, STACK_OF(X509) *certs, | |
227 X509_STORE *store, unsigned long flags); | |
228 | |
229 int OCSP_parse_url(const char *url, char **phost, char **pport, char **ppath, | |
230 int *pssl); | |
231 | |
232 int OCSP_id_issuer_cmp(const OCSP_CERTID *a, const OCSP_CERTID *b); | |
233 int OCSP_id_cmp(const OCSP_CERTID *a, const OCSP_CERTID *b); | |
234 | |
235 int OCSP_request_onereq_count(OCSP_REQUEST *req); | |
236 OCSP_ONEREQ *OCSP_request_onereq_get0(OCSP_REQUEST *req, int i); | |
237 OCSP_CERTID *OCSP_onereq_get0_id(OCSP_ONEREQ *one); | |
238 int OCSP_id_get0_info(ASN1_OCTET_STRING **piNameHash, ASN1_OBJECT **pmd, | |
239 ASN1_OCTET_STRING **pikeyHash, | |
240 ASN1_INTEGER **pserial, OCSP_CERTID *cid); | |
241 int OCSP_request_is_signed(OCSP_REQUEST *req); | |
242 OCSP_RESPONSE *OCSP_response_create(int status, OCSP_BASICRESP *bs); | |
243 OCSP_SINGLERESP *OCSP_basic_add1_status(OCSP_BASICRESP *rsp, | |
244 OCSP_CERTID *cid, | |
245 int status, int reason, | |
246 ASN1_TIME *revtime, | |
247 ASN1_TIME *thisupd, | |
248 ASN1_TIME *nextupd); | |
249 int OCSP_basic_add1_cert(OCSP_BASICRESP *resp, X509 *cert); | |
250 int OCSP_basic_sign(OCSP_BASICRESP *brsp, | |
251 X509 *signer, EVP_PKEY *key, const EVP_MD *dgst, | |
252 STACK_OF(X509) *certs, unsigned long flags); | |
253 int OCSP_basic_sign_ctx(OCSP_BASICRESP *brsp, | |
254 X509 *signer, EVP_MD_CTX *ctx, | |
255 STACK_OF(X509) *certs, unsigned long flags); | |
256 int OCSP_RESPID_set_by_name(OCSP_RESPID *respid, X509 *cert); | |
257 int OCSP_RESPID_set_by_key(OCSP_RESPID *respid, X509 *cert); | |
258 int OCSP_RESPID_match(OCSP_RESPID *respid, X509 *cert); | |
259 | |
260 X509_EXTENSION *OCSP_crlID_new(const char *url, long *n, char *tim); | |
261 | |
262 X509_EXTENSION *OCSP_accept_responses_new(char **oids); | |
263 | |
264 X509_EXTENSION *OCSP_archive_cutoff_new(char *tim); | |
265 | |
266 X509_EXTENSION *OCSP_url_svcloc_new(X509_NAME *issuer, const char **urls); | |
267 | |
268 int OCSP_REQUEST_get_ext_count(OCSP_REQUEST *x); | |
269 int OCSP_REQUEST_get_ext_by_NID(OCSP_REQUEST *x, int nid, int lastpos); | |
270 int OCSP_REQUEST_get_ext_by_OBJ(OCSP_REQUEST *x, const ASN1_OBJECT *obj, | |
271 int lastpos); | |
272 int OCSP_REQUEST_get_ext_by_critical(OCSP_REQUEST *x, int crit, int lastpos); | |
273 X509_EXTENSION *OCSP_REQUEST_get_ext(OCSP_REQUEST *x, int loc); | |
274 X509_EXTENSION *OCSP_REQUEST_delete_ext(OCSP_REQUEST *x, int loc); | |
275 void *OCSP_REQUEST_get1_ext_d2i(OCSP_REQUEST *x, int nid, int *crit, | |
276 int *idx); | |
277 int OCSP_REQUEST_add1_ext_i2d(OCSP_REQUEST *x, int nid, void *value, int crit, | |
278 unsigned long flags); | |
279 int OCSP_REQUEST_add_ext(OCSP_REQUEST *x, X509_EXTENSION *ex, int loc); | |
280 | |
281 int OCSP_ONEREQ_get_ext_count(OCSP_ONEREQ *x); | |
282 int OCSP_ONEREQ_get_ext_by_NID(OCSP_ONEREQ *x, int nid, int lastpos); | |
283 int OCSP_ONEREQ_get_ext_by_OBJ(OCSP_ONEREQ *x, const ASN1_OBJECT *obj, int lastpos); | |
284 int OCSP_ONEREQ_get_ext_by_critical(OCSP_ONEREQ *x, int crit, int lastpos); | |
285 X509_EXTENSION *OCSP_ONEREQ_get_ext(OCSP_ONEREQ *x, int loc); | |
286 X509_EXTENSION *OCSP_ONEREQ_delete_ext(OCSP_ONEREQ *x, int loc); | |
287 void *OCSP_ONEREQ_get1_ext_d2i(OCSP_ONEREQ *x, int nid, int *crit, int *idx); | |
288 int OCSP_ONEREQ_add1_ext_i2d(OCSP_ONEREQ *x, int nid, void *value, int crit, | |
289 unsigned long flags); | |
290 int OCSP_ONEREQ_add_ext(OCSP_ONEREQ *x, X509_EXTENSION *ex, int loc); | |
291 | |
292 int OCSP_BASICRESP_get_ext_count(OCSP_BASICRESP *x); | |
293 int OCSP_BASICRESP_get_ext_by_NID(OCSP_BASICRESP *x, int nid, int lastpos); | |
294 int OCSP_BASICRESP_get_ext_by_OBJ(OCSP_BASICRESP *x, const ASN1_OBJECT *obj, | |
295 int lastpos); | |
296 int OCSP_BASICRESP_get_ext_by_critical(OCSP_BASICRESP *x, int crit, | |
297 int lastpos); | |
298 X509_EXTENSION *OCSP_BASICRESP_get_ext(OCSP_BASICRESP *x, int loc); | |
299 X509_EXTENSION *OCSP_BASICRESP_delete_ext(OCSP_BASICRESP *x, int loc); | |
300 void *OCSP_BASICRESP_get1_ext_d2i(OCSP_BASICRESP *x, int nid, int *crit, | |
301 int *idx); | |
302 int OCSP_BASICRESP_add1_ext_i2d(OCSP_BASICRESP *x, int nid, void *value, | |
303 int crit, unsigned long flags); | |
304 int OCSP_BASICRESP_add_ext(OCSP_BASICRESP *x, X509_EXTENSION *ex, int loc); | |
305 | |
306 int OCSP_SINGLERESP_get_ext_count(OCSP_SINGLERESP *x); | |
307 int OCSP_SINGLERESP_get_ext_by_NID(OCSP_SINGLERESP *x, int nid, int lastpos); | |
308 int OCSP_SINGLERESP_get_ext_by_OBJ(OCSP_SINGLERESP *x, const ASN1_OBJECT *obj, | |
309 int lastpos); | |
310 int OCSP_SINGLERESP_get_ext_by_critical(OCSP_SINGLERESP *x, int crit, | |
311 int lastpos); | |
312 X509_EXTENSION *OCSP_SINGLERESP_get_ext(OCSP_SINGLERESP *x, int loc); | |
313 X509_EXTENSION *OCSP_SINGLERESP_delete_ext(OCSP_SINGLERESP *x, int loc); | |
314 void *OCSP_SINGLERESP_get1_ext_d2i(OCSP_SINGLERESP *x, int nid, int *crit, | |
315 int *idx); | |
316 int OCSP_SINGLERESP_add1_ext_i2d(OCSP_SINGLERESP *x, int nid, void *value, | |
317 int crit, unsigned long flags); | |
318 int OCSP_SINGLERESP_add_ext(OCSP_SINGLERESP *x, X509_EXTENSION *ex, int loc); | |
319 const OCSP_CERTID *OCSP_SINGLERESP_get0_id(const OCSP_SINGLERESP *x); | |
320 | |
321 DECLARE_ASN1_FUNCTIONS(OCSP_SINGLERESP) | |
322 DECLARE_ASN1_FUNCTIONS(OCSP_CERTSTATUS) | |
323 DECLARE_ASN1_FUNCTIONS(OCSP_REVOKEDINFO) | |
324 DECLARE_ASN1_FUNCTIONS(OCSP_BASICRESP) | |
325 DECLARE_ASN1_FUNCTIONS(OCSP_RESPDATA) | |
326 DECLARE_ASN1_FUNCTIONS(OCSP_RESPID) | |
327 DECLARE_ASN1_FUNCTIONS(OCSP_RESPONSE) | |
328 DECLARE_ASN1_FUNCTIONS(OCSP_RESPBYTES) | |
329 DECLARE_ASN1_FUNCTIONS(OCSP_ONEREQ) | |
330 DECLARE_ASN1_FUNCTIONS(OCSP_CERTID) | |
331 DECLARE_ASN1_FUNCTIONS(OCSP_REQUEST) | |
332 DECLARE_ASN1_FUNCTIONS(OCSP_SIGNATURE) | |
333 DECLARE_ASN1_FUNCTIONS(OCSP_REQINFO) | |
334 DECLARE_ASN1_FUNCTIONS(OCSP_CRLID) | |
335 DECLARE_ASN1_FUNCTIONS(OCSP_SERVICELOC) | |
336 | |
337 const char *OCSP_response_status_str(long s); | |
338 const char *OCSP_cert_status_str(long s); | |
339 const char *OCSP_crl_reason_str(long s); | |
340 | |
341 int OCSP_REQUEST_print(BIO *bp, OCSP_REQUEST *a, unsigned long flags); | |
342 int OCSP_RESPONSE_print(BIO *bp, OCSP_RESPONSE *o, unsigned long flags); | |
343 | |
344 int OCSP_basic_verify(OCSP_BASICRESP *bs, STACK_OF(X509) *certs, | |
345 X509_STORE *st, unsigned long flags); | |
346 | |
347 | |
348 # ifdef __cplusplus | |
349 } | |
350 # endif | |
351 # endif | |
352 #endif |