Back to home page

EIC code displayed by LXR

 
 

    


File indexing completed on 2026-05-02 08:24:10

0001 /*
0002  * WARNING: do not edit!
0003  * Generated by Makefile from include/openssl/x509.h.in
0004  *
0005  * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
0006  * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved
0007  *
0008  * Licensed under the Apache License 2.0 (the "License").  You may not use
0009  * this file except in compliance with the License.  You can obtain a copy
0010  * in the file LICENSE in the source distribution or at
0011  * https://www.openssl.org/source/license.html
0012  */
0013 
0014 /* clang-format off */
0015 
0016 /* clang-format on */
0017 
0018 #ifndef OPENSSL_X509_H
0019 #define OPENSSL_X509_H
0020 #pragma once
0021 
0022 #include <openssl/macros.h>
0023 #ifndef OPENSSL_NO_DEPRECATED_3_0
0024 #define HEADER_X509_H
0025 #endif
0026 
0027 #include <openssl/e_os2.h>
0028 #include <openssl/types.h>
0029 #include <openssl/symhacks.h>
0030 #include <openssl/buffer.h>
0031 #include <openssl/evp.h>
0032 #include <openssl/bio.h>
0033 #include <openssl/asn1.h>
0034 #include <openssl/safestack.h>
0035 #include <openssl/ec.h>
0036 
0037 #ifndef OPENSSL_NO_DEPRECATED_1_1_0
0038 #include <openssl/rsa.h>
0039 #include <openssl/dsa.h>
0040 #include <openssl/dh.h>
0041 #endif
0042 
0043 #include <openssl/sha.h>
0044 #include <openssl/x509err.h>
0045 #ifndef OPENSSL_NO_STDIO
0046 #include <stdio.h>
0047 #endif
0048 
0049 #ifdef __cplusplus
0050 extern "C" {
0051 #endif
0052 
0053 /* Needed stacks for types defined in other headers */
0054 /* clang-format off */
0055 SKM_DEFINE_STACK_OF_INTERNAL(X509_NAME, X509_NAME, X509_NAME)
0056 #define sk_X509_NAME_num(sk) OPENSSL_sk_num(ossl_check_const_X509_NAME_sk_type(sk))
0057 #define sk_X509_NAME_value(sk, idx) ((X509_NAME *)OPENSSL_sk_value(ossl_check_const_X509_NAME_sk_type(sk), (idx)))
0058 #define sk_X509_NAME_new(cmp) ((STACK_OF(X509_NAME) *)OPENSSL_sk_new(ossl_check_X509_NAME_compfunc_type(cmp)))
0059 #define sk_X509_NAME_new_null() ((STACK_OF(X509_NAME) *)OPENSSL_sk_new_null())
0060 #define sk_X509_NAME_new_reserve(cmp, n) ((STACK_OF(X509_NAME) *)OPENSSL_sk_new_reserve(ossl_check_X509_NAME_compfunc_type(cmp), (n)))
0061 #define sk_X509_NAME_reserve(sk, n) OPENSSL_sk_reserve(ossl_check_X509_NAME_sk_type(sk), (n))
0062 #define sk_X509_NAME_free(sk) OPENSSL_sk_free(ossl_check_X509_NAME_sk_type(sk))
0063 #define sk_X509_NAME_zero(sk) OPENSSL_sk_zero(ossl_check_X509_NAME_sk_type(sk))
0064 #define sk_X509_NAME_delete(sk, i) ((X509_NAME *)OPENSSL_sk_delete(ossl_check_X509_NAME_sk_type(sk), (i)))
0065 #define sk_X509_NAME_delete_ptr(sk, ptr) ((X509_NAME *)OPENSSL_sk_delete_ptr(ossl_check_X509_NAME_sk_type(sk), ossl_check_X509_NAME_type(ptr)))
0066 #define sk_X509_NAME_push(sk, ptr) OPENSSL_sk_push(ossl_check_X509_NAME_sk_type(sk), ossl_check_X509_NAME_type(ptr))
0067 #define sk_X509_NAME_unshift(sk, ptr) OPENSSL_sk_unshift(ossl_check_X509_NAME_sk_type(sk), ossl_check_X509_NAME_type(ptr))
0068 #define sk_X509_NAME_pop(sk) ((X509_NAME *)OPENSSL_sk_pop(ossl_check_X509_NAME_sk_type(sk)))
0069 #define sk_X509_NAME_shift(sk) ((X509_NAME *)OPENSSL_sk_shift(ossl_check_X509_NAME_sk_type(sk)))
0070 #define sk_X509_NAME_pop_free(sk, freefunc) OPENSSL_sk_pop_free(ossl_check_X509_NAME_sk_type(sk), ossl_check_X509_NAME_freefunc_type(freefunc))
0071 #define sk_X509_NAME_insert(sk, ptr, idx) OPENSSL_sk_insert(ossl_check_X509_NAME_sk_type(sk), ossl_check_X509_NAME_type(ptr), (idx))
0072 #define sk_X509_NAME_set(sk, idx, ptr) ((X509_NAME *)OPENSSL_sk_set(ossl_check_X509_NAME_sk_type(sk), (idx), ossl_check_X509_NAME_type(ptr)))
0073 #define sk_X509_NAME_find(sk, ptr) OPENSSL_sk_find(ossl_check_X509_NAME_sk_type(sk), ossl_check_X509_NAME_type(ptr))
0074 #define sk_X509_NAME_find_ex(sk, ptr) OPENSSL_sk_find_ex(ossl_check_X509_NAME_sk_type(sk), ossl_check_X509_NAME_type(ptr))
0075 #define sk_X509_NAME_find_all(sk, ptr, pnum) OPENSSL_sk_find_all(ossl_check_X509_NAME_sk_type(sk), ossl_check_X509_NAME_type(ptr), pnum)
0076 #define sk_X509_NAME_sort(sk) OPENSSL_sk_sort(ossl_check_X509_NAME_sk_type(sk))
0077 #define sk_X509_NAME_is_sorted(sk) OPENSSL_sk_is_sorted(ossl_check_const_X509_NAME_sk_type(sk))
0078 #define sk_X509_NAME_dup(sk) ((STACK_OF(X509_NAME) *)OPENSSL_sk_dup(ossl_check_const_X509_NAME_sk_type(sk)))
0079 #define sk_X509_NAME_deep_copy(sk, copyfunc, freefunc) ((STACK_OF(X509_NAME) *)OPENSSL_sk_deep_copy(ossl_check_const_X509_NAME_sk_type(sk), ossl_check_X509_NAME_copyfunc_type(copyfunc), ossl_check_X509_NAME_freefunc_type(freefunc)))
0080 #define sk_X509_NAME_set_cmp_func(sk, cmp) ((sk_X509_NAME_compfunc)OPENSSL_sk_set_cmp_func(ossl_check_X509_NAME_sk_type(sk), ossl_check_X509_NAME_compfunc_type(cmp)))
0081 SKM_DEFINE_STACK_OF_INTERNAL(X509, X509, X509)
0082 #define sk_X509_num(sk) OPENSSL_sk_num(ossl_check_const_X509_sk_type(sk))
0083 #define sk_X509_value(sk, idx) ((X509 *)OPENSSL_sk_value(ossl_check_const_X509_sk_type(sk), (idx)))
0084 #define sk_X509_new(cmp) ((STACK_OF(X509) *)OPENSSL_sk_new(ossl_check_X509_compfunc_type(cmp)))
0085 #define sk_X509_new_null() ((STACK_OF(X509) *)OPENSSL_sk_new_null())
0086 #define sk_X509_new_reserve(cmp, n) ((STACK_OF(X509) *)OPENSSL_sk_new_reserve(ossl_check_X509_compfunc_type(cmp), (n)))
0087 #define sk_X509_reserve(sk, n) OPENSSL_sk_reserve(ossl_check_X509_sk_type(sk), (n))
0088 #define sk_X509_free(sk) OPENSSL_sk_free(ossl_check_X509_sk_type(sk))
0089 #define sk_X509_zero(sk) OPENSSL_sk_zero(ossl_check_X509_sk_type(sk))
0090 #define sk_X509_delete(sk, i) ((X509 *)OPENSSL_sk_delete(ossl_check_X509_sk_type(sk), (i)))
0091 #define sk_X509_delete_ptr(sk, ptr) ((X509 *)OPENSSL_sk_delete_ptr(ossl_check_X509_sk_type(sk), ossl_check_X509_type(ptr)))
0092 #define sk_X509_push(sk, ptr) OPENSSL_sk_push(ossl_check_X509_sk_type(sk), ossl_check_X509_type(ptr))
0093 #define sk_X509_unshift(sk, ptr) OPENSSL_sk_unshift(ossl_check_X509_sk_type(sk), ossl_check_X509_type(ptr))
0094 #define sk_X509_pop(sk) ((X509 *)OPENSSL_sk_pop(ossl_check_X509_sk_type(sk)))
0095 #define sk_X509_shift(sk) ((X509 *)OPENSSL_sk_shift(ossl_check_X509_sk_type(sk)))
0096 #define sk_X509_pop_free(sk, freefunc) OPENSSL_sk_pop_free(ossl_check_X509_sk_type(sk), ossl_check_X509_freefunc_type(freefunc))
0097 #define sk_X509_insert(sk, ptr, idx) OPENSSL_sk_insert(ossl_check_X509_sk_type(sk), ossl_check_X509_type(ptr), (idx))
0098 #define sk_X509_set(sk, idx, ptr) ((X509 *)OPENSSL_sk_set(ossl_check_X509_sk_type(sk), (idx), ossl_check_X509_type(ptr)))
0099 #define sk_X509_find(sk, ptr) OPENSSL_sk_find(ossl_check_X509_sk_type(sk), ossl_check_X509_type(ptr))
0100 #define sk_X509_find_ex(sk, ptr) OPENSSL_sk_find_ex(ossl_check_X509_sk_type(sk), ossl_check_X509_type(ptr))
0101 #define sk_X509_find_all(sk, ptr, pnum) OPENSSL_sk_find_all(ossl_check_X509_sk_type(sk), ossl_check_X509_type(ptr), pnum)
0102 #define sk_X509_sort(sk) OPENSSL_sk_sort(ossl_check_X509_sk_type(sk))
0103 #define sk_X509_is_sorted(sk) OPENSSL_sk_is_sorted(ossl_check_const_X509_sk_type(sk))
0104 #define sk_X509_dup(sk) ((STACK_OF(X509) *)OPENSSL_sk_dup(ossl_check_const_X509_sk_type(sk)))
0105 #define sk_X509_deep_copy(sk, copyfunc, freefunc) ((STACK_OF(X509) *)OPENSSL_sk_deep_copy(ossl_check_const_X509_sk_type(sk), ossl_check_X509_copyfunc_type(copyfunc), ossl_check_X509_freefunc_type(freefunc)))
0106 #define sk_X509_set_cmp_func(sk, cmp) ((sk_X509_compfunc)OPENSSL_sk_set_cmp_func(ossl_check_X509_sk_type(sk), ossl_check_X509_compfunc_type(cmp)))
0107 SKM_DEFINE_STACK_OF_INTERNAL(X509_REVOKED, X509_REVOKED, X509_REVOKED)
0108 #define sk_X509_REVOKED_num(sk) OPENSSL_sk_num(ossl_check_const_X509_REVOKED_sk_type(sk))
0109 #define sk_X509_REVOKED_value(sk, idx) ((X509_REVOKED *)OPENSSL_sk_value(ossl_check_const_X509_REVOKED_sk_type(sk), (idx)))
0110 #define sk_X509_REVOKED_new(cmp) ((STACK_OF(X509_REVOKED) *)OPENSSL_sk_new(ossl_check_X509_REVOKED_compfunc_type(cmp)))
0111 #define sk_X509_REVOKED_new_null() ((STACK_OF(X509_REVOKED) *)OPENSSL_sk_new_null())
0112 #define sk_X509_REVOKED_new_reserve(cmp, n) ((STACK_OF(X509_REVOKED) *)OPENSSL_sk_new_reserve(ossl_check_X509_REVOKED_compfunc_type(cmp), (n)))
0113 #define sk_X509_REVOKED_reserve(sk, n) OPENSSL_sk_reserve(ossl_check_X509_REVOKED_sk_type(sk), (n))
0114 #define sk_X509_REVOKED_free(sk) OPENSSL_sk_free(ossl_check_X509_REVOKED_sk_type(sk))
0115 #define sk_X509_REVOKED_zero(sk) OPENSSL_sk_zero(ossl_check_X509_REVOKED_sk_type(sk))
0116 #define sk_X509_REVOKED_delete(sk, i) ((X509_REVOKED *)OPENSSL_sk_delete(ossl_check_X509_REVOKED_sk_type(sk), (i)))
0117 #define sk_X509_REVOKED_delete_ptr(sk, ptr) ((X509_REVOKED *)OPENSSL_sk_delete_ptr(ossl_check_X509_REVOKED_sk_type(sk), ossl_check_X509_REVOKED_type(ptr)))
0118 #define sk_X509_REVOKED_push(sk, ptr) OPENSSL_sk_push(ossl_check_X509_REVOKED_sk_type(sk), ossl_check_X509_REVOKED_type(ptr))
0119 #define sk_X509_REVOKED_unshift(sk, ptr) OPENSSL_sk_unshift(ossl_check_X509_REVOKED_sk_type(sk), ossl_check_X509_REVOKED_type(ptr))
0120 #define sk_X509_REVOKED_pop(sk) ((X509_REVOKED *)OPENSSL_sk_pop(ossl_check_X509_REVOKED_sk_type(sk)))
0121 #define sk_X509_REVOKED_shift(sk) ((X509_REVOKED *)OPENSSL_sk_shift(ossl_check_X509_REVOKED_sk_type(sk)))
0122 #define sk_X509_REVOKED_pop_free(sk, freefunc) OPENSSL_sk_pop_free(ossl_check_X509_REVOKED_sk_type(sk), ossl_check_X509_REVOKED_freefunc_type(freefunc))
0123 #define sk_X509_REVOKED_insert(sk, ptr, idx) OPENSSL_sk_insert(ossl_check_X509_REVOKED_sk_type(sk), ossl_check_X509_REVOKED_type(ptr), (idx))
0124 #define sk_X509_REVOKED_set(sk, idx, ptr) ((X509_REVOKED *)OPENSSL_sk_set(ossl_check_X509_REVOKED_sk_type(sk), (idx), ossl_check_X509_REVOKED_type(ptr)))
0125 #define sk_X509_REVOKED_find(sk, ptr) OPENSSL_sk_find(ossl_check_X509_REVOKED_sk_type(sk), ossl_check_X509_REVOKED_type(ptr))
0126 #define sk_X509_REVOKED_find_ex(sk, ptr) OPENSSL_sk_find_ex(ossl_check_X509_REVOKED_sk_type(sk), ossl_check_X509_REVOKED_type(ptr))
0127 #define sk_X509_REVOKED_find_all(sk, ptr, pnum) OPENSSL_sk_find_all(ossl_check_X509_REVOKED_sk_type(sk), ossl_check_X509_REVOKED_type(ptr), pnum)
0128 #define sk_X509_REVOKED_sort(sk) OPENSSL_sk_sort(ossl_check_X509_REVOKED_sk_type(sk))
0129 #define sk_X509_REVOKED_is_sorted(sk) OPENSSL_sk_is_sorted(ossl_check_const_X509_REVOKED_sk_type(sk))
0130 #define sk_X509_REVOKED_dup(sk) ((STACK_OF(X509_REVOKED) *)OPENSSL_sk_dup(ossl_check_const_X509_REVOKED_sk_type(sk)))
0131 #define sk_X509_REVOKED_deep_copy(sk, copyfunc, freefunc) ((STACK_OF(X509_REVOKED) *)OPENSSL_sk_deep_copy(ossl_check_const_X509_REVOKED_sk_type(sk), ossl_check_X509_REVOKED_copyfunc_type(copyfunc), ossl_check_X509_REVOKED_freefunc_type(freefunc)))
0132 #define sk_X509_REVOKED_set_cmp_func(sk, cmp) ((sk_X509_REVOKED_compfunc)OPENSSL_sk_set_cmp_func(ossl_check_X509_REVOKED_sk_type(sk), ossl_check_X509_REVOKED_compfunc_type(cmp)))
0133 SKM_DEFINE_STACK_OF_INTERNAL(X509_CRL, X509_CRL, X509_CRL)
0134 #define sk_X509_CRL_num(sk) OPENSSL_sk_num(ossl_check_const_X509_CRL_sk_type(sk))
0135 #define sk_X509_CRL_value(sk, idx) ((X509_CRL *)OPENSSL_sk_value(ossl_check_const_X509_CRL_sk_type(sk), (idx)))
0136 #define sk_X509_CRL_new(cmp) ((STACK_OF(X509_CRL) *)OPENSSL_sk_new(ossl_check_X509_CRL_compfunc_type(cmp)))
0137 #define sk_X509_CRL_new_null() ((STACK_OF(X509_CRL) *)OPENSSL_sk_new_null())
0138 #define sk_X509_CRL_new_reserve(cmp, n) ((STACK_OF(X509_CRL) *)OPENSSL_sk_new_reserve(ossl_check_X509_CRL_compfunc_type(cmp), (n)))
0139 #define sk_X509_CRL_reserve(sk, n) OPENSSL_sk_reserve(ossl_check_X509_CRL_sk_type(sk), (n))
0140 #define sk_X509_CRL_free(sk) OPENSSL_sk_free(ossl_check_X509_CRL_sk_type(sk))
0141 #define sk_X509_CRL_zero(sk) OPENSSL_sk_zero(ossl_check_X509_CRL_sk_type(sk))
0142 #define sk_X509_CRL_delete(sk, i) ((X509_CRL *)OPENSSL_sk_delete(ossl_check_X509_CRL_sk_type(sk), (i)))
0143 #define sk_X509_CRL_delete_ptr(sk, ptr) ((X509_CRL *)OPENSSL_sk_delete_ptr(ossl_check_X509_CRL_sk_type(sk), ossl_check_X509_CRL_type(ptr)))
0144 #define sk_X509_CRL_push(sk, ptr) OPENSSL_sk_push(ossl_check_X509_CRL_sk_type(sk), ossl_check_X509_CRL_type(ptr))
0145 #define sk_X509_CRL_unshift(sk, ptr) OPENSSL_sk_unshift(ossl_check_X509_CRL_sk_type(sk), ossl_check_X509_CRL_type(ptr))
0146 #define sk_X509_CRL_pop(sk) ((X509_CRL *)OPENSSL_sk_pop(ossl_check_X509_CRL_sk_type(sk)))
0147 #define sk_X509_CRL_shift(sk) ((X509_CRL *)OPENSSL_sk_shift(ossl_check_X509_CRL_sk_type(sk)))
0148 #define sk_X509_CRL_pop_free(sk, freefunc) OPENSSL_sk_pop_free(ossl_check_X509_CRL_sk_type(sk), ossl_check_X509_CRL_freefunc_type(freefunc))
0149 #define sk_X509_CRL_insert(sk, ptr, idx) OPENSSL_sk_insert(ossl_check_X509_CRL_sk_type(sk), ossl_check_X509_CRL_type(ptr), (idx))
0150 #define sk_X509_CRL_set(sk, idx, ptr) ((X509_CRL *)OPENSSL_sk_set(ossl_check_X509_CRL_sk_type(sk), (idx), ossl_check_X509_CRL_type(ptr)))
0151 #define sk_X509_CRL_find(sk, ptr) OPENSSL_sk_find(ossl_check_X509_CRL_sk_type(sk), ossl_check_X509_CRL_type(ptr))
0152 #define sk_X509_CRL_find_ex(sk, ptr) OPENSSL_sk_find_ex(ossl_check_X509_CRL_sk_type(sk), ossl_check_X509_CRL_type(ptr))
0153 #define sk_X509_CRL_find_all(sk, ptr, pnum) OPENSSL_sk_find_all(ossl_check_X509_CRL_sk_type(sk), ossl_check_X509_CRL_type(ptr), pnum)
0154 #define sk_X509_CRL_sort(sk) OPENSSL_sk_sort(ossl_check_X509_CRL_sk_type(sk))
0155 #define sk_X509_CRL_is_sorted(sk) OPENSSL_sk_is_sorted(ossl_check_const_X509_CRL_sk_type(sk))
0156 #define sk_X509_CRL_dup(sk) ((STACK_OF(X509_CRL) *)OPENSSL_sk_dup(ossl_check_const_X509_CRL_sk_type(sk)))
0157 #define sk_X509_CRL_deep_copy(sk, copyfunc, freefunc) ((STACK_OF(X509_CRL) *)OPENSSL_sk_deep_copy(ossl_check_const_X509_CRL_sk_type(sk), ossl_check_X509_CRL_copyfunc_type(copyfunc), ossl_check_X509_CRL_freefunc_type(freefunc)))
0158 #define sk_X509_CRL_set_cmp_func(sk, cmp) ((sk_X509_CRL_compfunc)OPENSSL_sk_set_cmp_func(ossl_check_X509_CRL_sk_type(sk), ossl_check_X509_CRL_compfunc_type(cmp)))
0159 
0160 /* clang-format on */
0161 
0162 /* Flags for X509_get_signature_info() */
0163 /* Signature info is valid */
0164 #define X509_SIG_INFO_VALID 0x1
0165 /* Signature is suitable for TLS use */
0166 #define X509_SIG_INFO_TLS 0x2
0167 
0168 #define X509_FILETYPE_PEM 1
0169 #define X509_FILETYPE_ASN1 2
0170 #define X509_FILETYPE_DEFAULT 3
0171 
0172 /*-
0173  * <https://datatracker.ietf.org/doc/html/rfc5280#section-4.2.1.3>:
0174  * The KeyUsage BITSTRING is treated as a little-endian integer, hence bit `0`
0175  * is 0x80, while bit `7` is 0x01 (the LSB of the integer value), bit `8` is
0176  * then the MSB of the second octet, or 0x8000.
0177  */
0178 #define X509v3_KU_DIGITAL_SIGNATURE 0x0080 /* (0) */
0179 #define X509v3_KU_NON_REPUDIATION 0x0040 /* (1) */
0180 #define X509v3_KU_KEY_ENCIPHERMENT 0x0020 /* (2) */
0181 #define X509v3_KU_DATA_ENCIPHERMENT 0x0010 /* (3) */
0182 #define X509v3_KU_KEY_AGREEMENT 0x0008 /* (4) */
0183 #define X509v3_KU_KEY_CERT_SIGN 0x0004 /* (5) */
0184 #define X509v3_KU_CRL_SIGN 0x0002 /* (6) */
0185 #define X509v3_KU_ENCIPHER_ONLY 0x0001 /* (7) */
0186 #define X509v3_KU_DECIPHER_ONLY 0x8000 /* (8) */
0187 #ifndef OPENSSL_NO_DEPRECATED_3_4
0188 #define X509v3_KU_UNDEF 0xffff /* vestigial, not used */
0189 #endif
0190 
0191 struct X509_algor_st {
0192     ASN1_OBJECT *algorithm;
0193     ASN1_TYPE *parameter;
0194 } /* X509_ALGOR */;
0195 
0196 typedef STACK_OF(X509_ALGOR) X509_ALGORS;
0197 
0198 typedef struct X509_val_st {
0199     ASN1_TIME *notBefore;
0200     ASN1_TIME *notAfter;
0201 } X509_VAL;
0202 
0203 typedef struct X509_sig_st X509_SIG;
0204 
0205 typedef struct X509_name_entry_st X509_NAME_ENTRY;
0206 
0207 /* clang-format off */
0208 SKM_DEFINE_STACK_OF_INTERNAL(X509_NAME_ENTRY, X509_NAME_ENTRY, X509_NAME_ENTRY)
0209 #define sk_X509_NAME_ENTRY_num(sk) OPENSSL_sk_num(ossl_check_const_X509_NAME_ENTRY_sk_type(sk))
0210 #define sk_X509_NAME_ENTRY_value(sk, idx) ((X509_NAME_ENTRY *)OPENSSL_sk_value(ossl_check_const_X509_NAME_ENTRY_sk_type(sk), (idx)))
0211 #define sk_X509_NAME_ENTRY_new(cmp) ((STACK_OF(X509_NAME_ENTRY) *)OPENSSL_sk_new(ossl_check_X509_NAME_ENTRY_compfunc_type(cmp)))
0212 #define sk_X509_NAME_ENTRY_new_null() ((STACK_OF(X509_NAME_ENTRY) *)OPENSSL_sk_new_null())
0213 #define sk_X509_NAME_ENTRY_new_reserve(cmp, n) ((STACK_OF(X509_NAME_ENTRY) *)OPENSSL_sk_new_reserve(ossl_check_X509_NAME_ENTRY_compfunc_type(cmp), (n)))
0214 #define sk_X509_NAME_ENTRY_reserve(sk, n) OPENSSL_sk_reserve(ossl_check_X509_NAME_ENTRY_sk_type(sk), (n))
0215 #define sk_X509_NAME_ENTRY_free(sk) OPENSSL_sk_free(ossl_check_X509_NAME_ENTRY_sk_type(sk))
0216 #define sk_X509_NAME_ENTRY_zero(sk) OPENSSL_sk_zero(ossl_check_X509_NAME_ENTRY_sk_type(sk))
0217 #define sk_X509_NAME_ENTRY_delete(sk, i) ((X509_NAME_ENTRY *)OPENSSL_sk_delete(ossl_check_X509_NAME_ENTRY_sk_type(sk), (i)))
0218 #define sk_X509_NAME_ENTRY_delete_ptr(sk, ptr) ((X509_NAME_ENTRY *)OPENSSL_sk_delete_ptr(ossl_check_X509_NAME_ENTRY_sk_type(sk), ossl_check_X509_NAME_ENTRY_type(ptr)))
0219 #define sk_X509_NAME_ENTRY_push(sk, ptr) OPENSSL_sk_push(ossl_check_X509_NAME_ENTRY_sk_type(sk), ossl_check_X509_NAME_ENTRY_type(ptr))
0220 #define sk_X509_NAME_ENTRY_unshift(sk, ptr) OPENSSL_sk_unshift(ossl_check_X509_NAME_ENTRY_sk_type(sk), ossl_check_X509_NAME_ENTRY_type(ptr))
0221 #define sk_X509_NAME_ENTRY_pop(sk) ((X509_NAME_ENTRY *)OPENSSL_sk_pop(ossl_check_X509_NAME_ENTRY_sk_type(sk)))
0222 #define sk_X509_NAME_ENTRY_shift(sk) ((X509_NAME_ENTRY *)OPENSSL_sk_shift(ossl_check_X509_NAME_ENTRY_sk_type(sk)))
0223 #define sk_X509_NAME_ENTRY_pop_free(sk, freefunc) OPENSSL_sk_pop_free(ossl_check_X509_NAME_ENTRY_sk_type(sk), ossl_check_X509_NAME_ENTRY_freefunc_type(freefunc))
0224 #define sk_X509_NAME_ENTRY_insert(sk, ptr, idx) OPENSSL_sk_insert(ossl_check_X509_NAME_ENTRY_sk_type(sk), ossl_check_X509_NAME_ENTRY_type(ptr), (idx))
0225 #define sk_X509_NAME_ENTRY_set(sk, idx, ptr) ((X509_NAME_ENTRY *)OPENSSL_sk_set(ossl_check_X509_NAME_ENTRY_sk_type(sk), (idx), ossl_check_X509_NAME_ENTRY_type(ptr)))
0226 #define sk_X509_NAME_ENTRY_find(sk, ptr) OPENSSL_sk_find(ossl_check_X509_NAME_ENTRY_sk_type(sk), ossl_check_X509_NAME_ENTRY_type(ptr))
0227 #define sk_X509_NAME_ENTRY_find_ex(sk, ptr) OPENSSL_sk_find_ex(ossl_check_X509_NAME_ENTRY_sk_type(sk), ossl_check_X509_NAME_ENTRY_type(ptr))
0228 #define sk_X509_NAME_ENTRY_find_all(sk, ptr, pnum) OPENSSL_sk_find_all(ossl_check_X509_NAME_ENTRY_sk_type(sk), ossl_check_X509_NAME_ENTRY_type(ptr), pnum)
0229 #define sk_X509_NAME_ENTRY_sort(sk) OPENSSL_sk_sort(ossl_check_X509_NAME_ENTRY_sk_type(sk))
0230 #define sk_X509_NAME_ENTRY_is_sorted(sk) OPENSSL_sk_is_sorted(ossl_check_const_X509_NAME_ENTRY_sk_type(sk))
0231 #define sk_X509_NAME_ENTRY_dup(sk) ((STACK_OF(X509_NAME_ENTRY) *)OPENSSL_sk_dup(ossl_check_const_X509_NAME_ENTRY_sk_type(sk)))
0232 #define sk_X509_NAME_ENTRY_deep_copy(sk, copyfunc, freefunc) ((STACK_OF(X509_NAME_ENTRY) *)OPENSSL_sk_deep_copy(ossl_check_const_X509_NAME_ENTRY_sk_type(sk), ossl_check_X509_NAME_ENTRY_copyfunc_type(copyfunc), ossl_check_X509_NAME_ENTRY_freefunc_type(freefunc)))
0233 #define sk_X509_NAME_ENTRY_set_cmp_func(sk, cmp) ((sk_X509_NAME_ENTRY_compfunc)OPENSSL_sk_set_cmp_func(ossl_check_X509_NAME_ENTRY_sk_type(sk), ossl_check_X509_NAME_ENTRY_compfunc_type(cmp)))
0234 
0235 /* clang-format on */
0236 
0237 #define X509_EX_V_NETSCAPE_HACK 0x8000
0238 #define X509_EX_V_INIT 0x0001
0239 typedef struct X509_extension_st X509_EXTENSION;
0240 /* clang-format off */
0241 SKM_DEFINE_STACK_OF_INTERNAL(X509_EXTENSION, X509_EXTENSION, X509_EXTENSION)
0242 #define sk_X509_EXTENSION_num(sk) OPENSSL_sk_num(ossl_check_const_X509_EXTENSION_sk_type(sk))
0243 #define sk_X509_EXTENSION_value(sk, idx) ((X509_EXTENSION *)OPENSSL_sk_value(ossl_check_const_X509_EXTENSION_sk_type(sk), (idx)))
0244 #define sk_X509_EXTENSION_new(cmp) ((STACK_OF(X509_EXTENSION) *)OPENSSL_sk_new(ossl_check_X509_EXTENSION_compfunc_type(cmp)))
0245 #define sk_X509_EXTENSION_new_null() ((STACK_OF(X509_EXTENSION) *)OPENSSL_sk_new_null())
0246 #define sk_X509_EXTENSION_new_reserve(cmp, n) ((STACK_OF(X509_EXTENSION) *)OPENSSL_sk_new_reserve(ossl_check_X509_EXTENSION_compfunc_type(cmp), (n)))
0247 #define sk_X509_EXTENSION_reserve(sk, n) OPENSSL_sk_reserve(ossl_check_X509_EXTENSION_sk_type(sk), (n))
0248 #define sk_X509_EXTENSION_free(sk) OPENSSL_sk_free(ossl_check_X509_EXTENSION_sk_type(sk))
0249 #define sk_X509_EXTENSION_zero(sk) OPENSSL_sk_zero(ossl_check_X509_EXTENSION_sk_type(sk))
0250 #define sk_X509_EXTENSION_delete(sk, i) ((X509_EXTENSION *)OPENSSL_sk_delete(ossl_check_X509_EXTENSION_sk_type(sk), (i)))
0251 #define sk_X509_EXTENSION_delete_ptr(sk, ptr) ((X509_EXTENSION *)OPENSSL_sk_delete_ptr(ossl_check_X509_EXTENSION_sk_type(sk), ossl_check_X509_EXTENSION_type(ptr)))
0252 #define sk_X509_EXTENSION_push(sk, ptr) OPENSSL_sk_push(ossl_check_X509_EXTENSION_sk_type(sk), ossl_check_X509_EXTENSION_type(ptr))
0253 #define sk_X509_EXTENSION_unshift(sk, ptr) OPENSSL_sk_unshift(ossl_check_X509_EXTENSION_sk_type(sk), ossl_check_X509_EXTENSION_type(ptr))
0254 #define sk_X509_EXTENSION_pop(sk) ((X509_EXTENSION *)OPENSSL_sk_pop(ossl_check_X509_EXTENSION_sk_type(sk)))
0255 #define sk_X509_EXTENSION_shift(sk) ((X509_EXTENSION *)OPENSSL_sk_shift(ossl_check_X509_EXTENSION_sk_type(sk)))
0256 #define sk_X509_EXTENSION_pop_free(sk, freefunc) OPENSSL_sk_pop_free(ossl_check_X509_EXTENSION_sk_type(sk), ossl_check_X509_EXTENSION_freefunc_type(freefunc))
0257 #define sk_X509_EXTENSION_insert(sk, ptr, idx) OPENSSL_sk_insert(ossl_check_X509_EXTENSION_sk_type(sk), ossl_check_X509_EXTENSION_type(ptr), (idx))
0258 #define sk_X509_EXTENSION_set(sk, idx, ptr) ((X509_EXTENSION *)OPENSSL_sk_set(ossl_check_X509_EXTENSION_sk_type(sk), (idx), ossl_check_X509_EXTENSION_type(ptr)))
0259 #define sk_X509_EXTENSION_find(sk, ptr) OPENSSL_sk_find(ossl_check_X509_EXTENSION_sk_type(sk), ossl_check_X509_EXTENSION_type(ptr))
0260 #define sk_X509_EXTENSION_find_ex(sk, ptr) OPENSSL_sk_find_ex(ossl_check_X509_EXTENSION_sk_type(sk), ossl_check_X509_EXTENSION_type(ptr))
0261 #define sk_X509_EXTENSION_find_all(sk, ptr, pnum) OPENSSL_sk_find_all(ossl_check_X509_EXTENSION_sk_type(sk), ossl_check_X509_EXTENSION_type(ptr), pnum)
0262 #define sk_X509_EXTENSION_sort(sk) OPENSSL_sk_sort(ossl_check_X509_EXTENSION_sk_type(sk))
0263 #define sk_X509_EXTENSION_is_sorted(sk) OPENSSL_sk_is_sorted(ossl_check_const_X509_EXTENSION_sk_type(sk))
0264 #define sk_X509_EXTENSION_dup(sk) ((STACK_OF(X509_EXTENSION) *)OPENSSL_sk_dup(ossl_check_const_X509_EXTENSION_sk_type(sk)))
0265 #define sk_X509_EXTENSION_deep_copy(sk, copyfunc, freefunc) ((STACK_OF(X509_EXTENSION) *)OPENSSL_sk_deep_copy(ossl_check_const_X509_EXTENSION_sk_type(sk), ossl_check_X509_EXTENSION_copyfunc_type(copyfunc), ossl_check_X509_EXTENSION_freefunc_type(freefunc)))
0266 #define sk_X509_EXTENSION_set_cmp_func(sk, cmp) ((sk_X509_EXTENSION_compfunc)OPENSSL_sk_set_cmp_func(ossl_check_X509_EXTENSION_sk_type(sk), ossl_check_X509_EXTENSION_compfunc_type(cmp)))
0267 
0268 /* clang-format on */
0269 typedef STACK_OF(X509_EXTENSION) X509_EXTENSIONS;
0270 typedef struct x509_attributes_st X509_ATTRIBUTE;
0271 /* clang-format off */
0272 SKM_DEFINE_STACK_OF_INTERNAL(X509_ATTRIBUTE, X509_ATTRIBUTE, X509_ATTRIBUTE)
0273 #define sk_X509_ATTRIBUTE_num(sk) OPENSSL_sk_num(ossl_check_const_X509_ATTRIBUTE_sk_type(sk))
0274 #define sk_X509_ATTRIBUTE_value(sk, idx) ((X509_ATTRIBUTE *)OPENSSL_sk_value(ossl_check_const_X509_ATTRIBUTE_sk_type(sk), (idx)))
0275 #define sk_X509_ATTRIBUTE_new(cmp) ((STACK_OF(X509_ATTRIBUTE) *)OPENSSL_sk_new(ossl_check_X509_ATTRIBUTE_compfunc_type(cmp)))
0276 #define sk_X509_ATTRIBUTE_new_null() ((STACK_OF(X509_ATTRIBUTE) *)OPENSSL_sk_new_null())
0277 #define sk_X509_ATTRIBUTE_new_reserve(cmp, n) ((STACK_OF(X509_ATTRIBUTE) *)OPENSSL_sk_new_reserve(ossl_check_X509_ATTRIBUTE_compfunc_type(cmp), (n)))
0278 #define sk_X509_ATTRIBUTE_reserve(sk, n) OPENSSL_sk_reserve(ossl_check_X509_ATTRIBUTE_sk_type(sk), (n))
0279 #define sk_X509_ATTRIBUTE_free(sk) OPENSSL_sk_free(ossl_check_X509_ATTRIBUTE_sk_type(sk))
0280 #define sk_X509_ATTRIBUTE_zero(sk) OPENSSL_sk_zero(ossl_check_X509_ATTRIBUTE_sk_type(sk))
0281 #define sk_X509_ATTRIBUTE_delete(sk, i) ((X509_ATTRIBUTE *)OPENSSL_sk_delete(ossl_check_X509_ATTRIBUTE_sk_type(sk), (i)))
0282 #define sk_X509_ATTRIBUTE_delete_ptr(sk, ptr) ((X509_ATTRIBUTE *)OPENSSL_sk_delete_ptr(ossl_check_X509_ATTRIBUTE_sk_type(sk), ossl_check_X509_ATTRIBUTE_type(ptr)))
0283 #define sk_X509_ATTRIBUTE_push(sk, ptr) OPENSSL_sk_push(ossl_check_X509_ATTRIBUTE_sk_type(sk), ossl_check_X509_ATTRIBUTE_type(ptr))
0284 #define sk_X509_ATTRIBUTE_unshift(sk, ptr) OPENSSL_sk_unshift(ossl_check_X509_ATTRIBUTE_sk_type(sk), ossl_check_X509_ATTRIBUTE_type(ptr))
0285 #define sk_X509_ATTRIBUTE_pop(sk) ((X509_ATTRIBUTE *)OPENSSL_sk_pop(ossl_check_X509_ATTRIBUTE_sk_type(sk)))
0286 #define sk_X509_ATTRIBUTE_shift(sk) ((X509_ATTRIBUTE *)OPENSSL_sk_shift(ossl_check_X509_ATTRIBUTE_sk_type(sk)))
0287 #define sk_X509_ATTRIBUTE_pop_free(sk, freefunc) OPENSSL_sk_pop_free(ossl_check_X509_ATTRIBUTE_sk_type(sk), ossl_check_X509_ATTRIBUTE_freefunc_type(freefunc))
0288 #define sk_X509_ATTRIBUTE_insert(sk, ptr, idx) OPENSSL_sk_insert(ossl_check_X509_ATTRIBUTE_sk_type(sk), ossl_check_X509_ATTRIBUTE_type(ptr), (idx))
0289 #define sk_X509_ATTRIBUTE_set(sk, idx, ptr) ((X509_ATTRIBUTE *)OPENSSL_sk_set(ossl_check_X509_ATTRIBUTE_sk_type(sk), (idx), ossl_check_X509_ATTRIBUTE_type(ptr)))
0290 #define sk_X509_ATTRIBUTE_find(sk, ptr) OPENSSL_sk_find(ossl_check_X509_ATTRIBUTE_sk_type(sk), ossl_check_X509_ATTRIBUTE_type(ptr))
0291 #define sk_X509_ATTRIBUTE_find_ex(sk, ptr) OPENSSL_sk_find_ex(ossl_check_X509_ATTRIBUTE_sk_type(sk), ossl_check_X509_ATTRIBUTE_type(ptr))
0292 #define sk_X509_ATTRIBUTE_find_all(sk, ptr, pnum) OPENSSL_sk_find_all(ossl_check_X509_ATTRIBUTE_sk_type(sk), ossl_check_X509_ATTRIBUTE_type(ptr), pnum)
0293 #define sk_X509_ATTRIBUTE_sort(sk) OPENSSL_sk_sort(ossl_check_X509_ATTRIBUTE_sk_type(sk))
0294 #define sk_X509_ATTRIBUTE_is_sorted(sk) OPENSSL_sk_is_sorted(ossl_check_const_X509_ATTRIBUTE_sk_type(sk))
0295 #define sk_X509_ATTRIBUTE_dup(sk) ((STACK_OF(X509_ATTRIBUTE) *)OPENSSL_sk_dup(ossl_check_const_X509_ATTRIBUTE_sk_type(sk)))
0296 #define sk_X509_ATTRIBUTE_deep_copy(sk, copyfunc, freefunc) ((STACK_OF(X509_ATTRIBUTE) *)OPENSSL_sk_deep_copy(ossl_check_const_X509_ATTRIBUTE_sk_type(sk), ossl_check_X509_ATTRIBUTE_copyfunc_type(copyfunc), ossl_check_X509_ATTRIBUTE_freefunc_type(freefunc)))
0297 #define sk_X509_ATTRIBUTE_set_cmp_func(sk, cmp) ((sk_X509_ATTRIBUTE_compfunc)OPENSSL_sk_set_cmp_func(ossl_check_X509_ATTRIBUTE_sk_type(sk), ossl_check_X509_ATTRIBUTE_compfunc_type(cmp)))
0298 
0299 /* clang-format on */
0300 typedef struct X509_req_info_st X509_REQ_INFO;
0301 typedef struct X509_req_st X509_REQ;
0302 typedef struct x509_cert_aux_st X509_CERT_AUX;
0303 typedef struct x509_cinf_st X509_CINF;
0304 
0305 /* Flags for X509_print_ex() */
0306 
0307 #define X509_FLAG_COMPAT 0
0308 #define X509_FLAG_NO_HEADER 1L
0309 #define X509_FLAG_NO_VERSION (1L << 1)
0310 #define X509_FLAG_NO_SERIAL (1L << 2)
0311 #define X509_FLAG_NO_SIGNAME (1L << 3)
0312 #define X509_FLAG_NO_ISSUER (1L << 4)
0313 #define X509_FLAG_NO_VALIDITY (1L << 5)
0314 #define X509_FLAG_NO_SUBJECT (1L << 6)
0315 #define X509_FLAG_NO_PUBKEY (1L << 7)
0316 #define X509_FLAG_NO_EXTENSIONS (1L << 8)
0317 #define X509_FLAG_NO_SIGDUMP (1L << 9)
0318 #define X509_FLAG_NO_AUX (1L << 10)
0319 #define X509_FLAG_NO_ATTRIBUTES (1L << 11)
0320 #define X509_FLAG_NO_IDS (1L << 12)
0321 #define X509_FLAG_EXTENSIONS_ONLY_KID (1L << 13)
0322 
0323 /* Flags specific to X509_NAME_print_ex() */
0324 
0325 /* The field separator information */
0326 
0327 #define XN_FLAG_SEP_MASK (0xf << 16)
0328 
0329 #define XN_FLAG_COMPAT 0 /* Traditional; use old X509_NAME_print */
0330 #define XN_FLAG_SEP_COMMA_PLUS (1 << 16) /* RFC2253 ,+ */
0331 #define XN_FLAG_SEP_CPLUS_SPC (2 << 16) /* ,+ spaced: more readable */
0332 #define XN_FLAG_SEP_SPLUS_SPC (3 << 16) /* ;+ spaced */
0333 #define XN_FLAG_SEP_MULTILINE (4 << 16) /* One line per field */
0334 
0335 #define XN_FLAG_DN_REV (1 << 20) /* Reverse DN order */
0336 
0337 /* How the field name is shown */
0338 
0339 #define XN_FLAG_FN_MASK (0x3 << 21)
0340 
0341 #define XN_FLAG_FN_SN 0 /* Object short name */
0342 #define XN_FLAG_FN_LN (1 << 21) /* Object long name */
0343 #define XN_FLAG_FN_OID (2 << 21) /* Always use OIDs */
0344 #define XN_FLAG_FN_NONE (3 << 21) /* No field names */
0345 
0346 #define XN_FLAG_SPC_EQ (1 << 23) /* Put spaces round '=' */
0347 
0348 /*
0349  * This determines if we dump fields we don't recognise: RFC2253 requires
0350  * this.
0351  */
0352 
0353 #define XN_FLAG_DUMP_UNKNOWN_FIELDS (1 << 24)
0354 
0355 #define XN_FLAG_FN_ALIGN (1 << 25) /* Align field names to 20 \
0356                                     * characters */
0357 
0358 /* Complete set of RFC2253 flags */
0359 
0360 #define XN_FLAG_RFC2253 (ASN1_STRFLGS_RFC2253 | XN_FLAG_SEP_COMMA_PLUS | XN_FLAG_DN_REV | XN_FLAG_FN_SN | XN_FLAG_DUMP_UNKNOWN_FIELDS)
0361 
0362 /* readable oneline form */
0363 
0364 #define XN_FLAG_ONELINE (ASN1_STRFLGS_RFC2253 | ASN1_STRFLGS_ESC_QUOTE | XN_FLAG_SEP_CPLUS_SPC | XN_FLAG_SPC_EQ | XN_FLAG_FN_SN)
0365 
0366 /* readable multiline form */
0367 
0368 #define XN_FLAG_MULTILINE (ASN1_STRFLGS_ESC_CTRL | ASN1_STRFLGS_ESC_MSB | XN_FLAG_SEP_MULTILINE | XN_FLAG_SPC_EQ | XN_FLAG_FN_LN | XN_FLAG_FN_ALIGN)
0369 
0370 typedef struct X509_crl_info_st X509_CRL_INFO;
0371 
0372 typedef struct private_key_st {
0373     int version;
0374     /* The PKCS#8 data types */
0375     X509_ALGOR *enc_algor;
0376     ASN1_OCTET_STRING *enc_pkey; /* encrypted pub key */
0377     /* When decrypted, the following will not be NULL */
0378     EVP_PKEY *dec_pkey;
0379     /* used to encrypt and decrypt */
0380     int key_length;
0381     char *key_data;
0382     int key_free; /* true if we should auto free key_data */
0383     /* expanded version of 'enc_algor' */
0384     EVP_CIPHER_INFO cipher;
0385 } X509_PKEY;
0386 
0387 typedef struct X509_info_st {
0388     X509 *x509;
0389     X509_CRL *crl;
0390     X509_PKEY *x_pkey;
0391     EVP_CIPHER_INFO enc_cipher;
0392     int enc_len;
0393     char *enc_data;
0394 } X509_INFO;
0395 /* clang-format off */
0396 SKM_DEFINE_STACK_OF_INTERNAL(X509_INFO, X509_INFO, X509_INFO)
0397 #define sk_X509_INFO_num(sk) OPENSSL_sk_num(ossl_check_const_X509_INFO_sk_type(sk))
0398 #define sk_X509_INFO_value(sk, idx) ((X509_INFO *)OPENSSL_sk_value(ossl_check_const_X509_INFO_sk_type(sk), (idx)))
0399 #define sk_X509_INFO_new(cmp) ((STACK_OF(X509_INFO) *)OPENSSL_sk_new(ossl_check_X509_INFO_compfunc_type(cmp)))
0400 #define sk_X509_INFO_new_null() ((STACK_OF(X509_INFO) *)OPENSSL_sk_new_null())
0401 #define sk_X509_INFO_new_reserve(cmp, n) ((STACK_OF(X509_INFO) *)OPENSSL_sk_new_reserve(ossl_check_X509_INFO_compfunc_type(cmp), (n)))
0402 #define sk_X509_INFO_reserve(sk, n) OPENSSL_sk_reserve(ossl_check_X509_INFO_sk_type(sk), (n))
0403 #define sk_X509_INFO_free(sk) OPENSSL_sk_free(ossl_check_X509_INFO_sk_type(sk))
0404 #define sk_X509_INFO_zero(sk) OPENSSL_sk_zero(ossl_check_X509_INFO_sk_type(sk))
0405 #define sk_X509_INFO_delete(sk, i) ((X509_INFO *)OPENSSL_sk_delete(ossl_check_X509_INFO_sk_type(sk), (i)))
0406 #define sk_X509_INFO_delete_ptr(sk, ptr) ((X509_INFO *)OPENSSL_sk_delete_ptr(ossl_check_X509_INFO_sk_type(sk), ossl_check_X509_INFO_type(ptr)))
0407 #define sk_X509_INFO_push(sk, ptr) OPENSSL_sk_push(ossl_check_X509_INFO_sk_type(sk), ossl_check_X509_INFO_type(ptr))
0408 #define sk_X509_INFO_unshift(sk, ptr) OPENSSL_sk_unshift(ossl_check_X509_INFO_sk_type(sk), ossl_check_X509_INFO_type(ptr))
0409 #define sk_X509_INFO_pop(sk) ((X509_INFO *)OPENSSL_sk_pop(ossl_check_X509_INFO_sk_type(sk)))
0410 #define sk_X509_INFO_shift(sk) ((X509_INFO *)OPENSSL_sk_shift(ossl_check_X509_INFO_sk_type(sk)))
0411 #define sk_X509_INFO_pop_free(sk, freefunc) OPENSSL_sk_pop_free(ossl_check_X509_INFO_sk_type(sk), ossl_check_X509_INFO_freefunc_type(freefunc))
0412 #define sk_X509_INFO_insert(sk, ptr, idx) OPENSSL_sk_insert(ossl_check_X509_INFO_sk_type(sk), ossl_check_X509_INFO_type(ptr), (idx))
0413 #define sk_X509_INFO_set(sk, idx, ptr) ((X509_INFO *)OPENSSL_sk_set(ossl_check_X509_INFO_sk_type(sk), (idx), ossl_check_X509_INFO_type(ptr)))
0414 #define sk_X509_INFO_find(sk, ptr) OPENSSL_sk_find(ossl_check_X509_INFO_sk_type(sk), ossl_check_X509_INFO_type(ptr))
0415 #define sk_X509_INFO_find_ex(sk, ptr) OPENSSL_sk_find_ex(ossl_check_X509_INFO_sk_type(sk), ossl_check_X509_INFO_type(ptr))
0416 #define sk_X509_INFO_find_all(sk, ptr, pnum) OPENSSL_sk_find_all(ossl_check_X509_INFO_sk_type(sk), ossl_check_X509_INFO_type(ptr), pnum)
0417 #define sk_X509_INFO_sort(sk) OPENSSL_sk_sort(ossl_check_X509_INFO_sk_type(sk))
0418 #define sk_X509_INFO_is_sorted(sk) OPENSSL_sk_is_sorted(ossl_check_const_X509_INFO_sk_type(sk))
0419 #define sk_X509_INFO_dup(sk) ((STACK_OF(X509_INFO) *)OPENSSL_sk_dup(ossl_check_const_X509_INFO_sk_type(sk)))
0420 #define sk_X509_INFO_deep_copy(sk, copyfunc, freefunc) ((STACK_OF(X509_INFO) *)OPENSSL_sk_deep_copy(ossl_check_const_X509_INFO_sk_type(sk), ossl_check_X509_INFO_copyfunc_type(copyfunc), ossl_check_X509_INFO_freefunc_type(freefunc)))
0421 #define sk_X509_INFO_set_cmp_func(sk, cmp) ((sk_X509_INFO_compfunc)OPENSSL_sk_set_cmp_func(ossl_check_X509_INFO_sk_type(sk), ossl_check_X509_INFO_compfunc_type(cmp)))
0422 
0423 /* clang-format on */
0424 
0425 /*
0426  * The next 2 structures and their 8 routines are used to manipulate Netscape's
0427  * spki structures - useful if you are writing a CA web page
0428  */
0429 typedef struct Netscape_spkac_st {
0430     X509_PUBKEY *pubkey;
0431     ASN1_IA5STRING *challenge; /* challenge sent in atlas >= PR2 */
0432 } NETSCAPE_SPKAC;
0433 
0434 typedef struct Netscape_spki_st {
0435     NETSCAPE_SPKAC *spkac; /* signed public key and challenge */
0436     X509_ALGOR sig_algor;
0437     ASN1_BIT_STRING *signature;
0438 } NETSCAPE_SPKI;
0439 
0440 /* Netscape certificate sequence structure */
0441 typedef struct Netscape_certificate_sequence {
0442     ASN1_OBJECT *type;
0443     STACK_OF(X509) *certs;
0444 } NETSCAPE_CERT_SEQUENCE;
0445 
0446 /*- Unused (and iv length is wrong)
0447 typedef struct CBCParameter_st
0448         {
0449         unsigned char iv[8];
0450         } CBC_PARAM;
0451 */
0452 
0453 /* Password based encryption structure */
0454 
0455 typedef struct PBEPARAM_st {
0456     ASN1_OCTET_STRING *salt;
0457     ASN1_INTEGER *iter;
0458 } PBEPARAM;
0459 
0460 /* Password based encryption V2 structures */
0461 
0462 typedef struct PBE2PARAM_st {
0463     X509_ALGOR *keyfunc;
0464     X509_ALGOR *encryption;
0465 } PBE2PARAM;
0466 
0467 typedef struct PBKDF2PARAM_st {
0468     /* Usually OCTET STRING but could be anything */
0469     ASN1_TYPE *salt;
0470     ASN1_INTEGER *iter;
0471     ASN1_INTEGER *keylength;
0472     X509_ALGOR *prf;
0473 } PBKDF2PARAM;
0474 
0475 typedef struct {
0476     X509_ALGOR *keyDerivationFunc;
0477     X509_ALGOR *messageAuthScheme;
0478 } PBMAC1PARAM;
0479 
0480 #ifndef OPENSSL_NO_SCRYPT
0481 typedef struct SCRYPT_PARAMS_st {
0482     ASN1_OCTET_STRING *salt;
0483     ASN1_INTEGER *costParameter;
0484     ASN1_INTEGER *blockSize;
0485     ASN1_INTEGER *parallelizationParameter;
0486     ASN1_INTEGER *keyLength;
0487 } SCRYPT_PARAMS;
0488 #endif
0489 
0490 #ifdef __cplusplus
0491 }
0492 #endif
0493 
0494 #include <openssl/x509_vfy.h>
0495 #include <openssl/pkcs7.h>
0496 
0497 #ifdef __cplusplus
0498 extern "C" {
0499 #endif
0500 
0501 #define X509_EXT_PACK_UNKNOWN 1
0502 #define X509_EXT_PACK_STRING 2
0503 
0504 #define X509_extract_key(x) X509_get_pubkey(x) /*****/
0505 #define X509_REQ_extract_key(a) X509_REQ_get_pubkey(a)
0506 #define X509_name_cmp(a, b) X509_NAME_cmp((a), (b))
0507 
0508 void X509_CRL_set_default_method(const X509_CRL_METHOD *meth);
0509 X509_CRL_METHOD *X509_CRL_METHOD_new(int (*crl_init)(X509_CRL *crl),
0510     int (*crl_free)(X509_CRL *crl),
0511     int (*crl_lookup)(X509_CRL *crl,
0512         X509_REVOKED **ret,
0513         const ASN1_INTEGER *serial,
0514         const X509_NAME *issuer),
0515     int (*crl_verify)(X509_CRL *crl,
0516         EVP_PKEY *pk));
0517 void X509_CRL_METHOD_free(X509_CRL_METHOD *m);
0518 
0519 void X509_CRL_set_meth_data(X509_CRL *crl, void *dat);
0520 void *X509_CRL_get_meth_data(X509_CRL *crl);
0521 
0522 const char *X509_verify_cert_error_string(long n);
0523 
0524 int X509_verify(X509 *a, EVP_PKEY *r);
0525 int X509_self_signed(X509 *cert, int verify_signature);
0526 
0527 int X509_REQ_verify_ex(X509_REQ *a, EVP_PKEY *r, OSSL_LIB_CTX *libctx,
0528     const char *propq);
0529 int X509_REQ_verify(X509_REQ *a, EVP_PKEY *r);
0530 int X509_CRL_verify(X509_CRL *a, EVP_PKEY *r);
0531 int NETSCAPE_SPKI_verify(NETSCAPE_SPKI *a, EVP_PKEY *r);
0532 
0533 NETSCAPE_SPKI *NETSCAPE_SPKI_b64_decode(const char *str, int len);
0534 char *NETSCAPE_SPKI_b64_encode(NETSCAPE_SPKI *x);
0535 EVP_PKEY *NETSCAPE_SPKI_get_pubkey(NETSCAPE_SPKI *x);
0536 int NETSCAPE_SPKI_set_pubkey(NETSCAPE_SPKI *x, EVP_PKEY *pkey);
0537 
0538 int NETSCAPE_SPKI_print(BIO *out, NETSCAPE_SPKI *spki);
0539 
0540 int X509_signature_dump(BIO *bp, const ASN1_STRING *sig, int indent);
0541 int X509_signature_print(BIO *bp, const X509_ALGOR *alg,
0542     const ASN1_STRING *sig);
0543 
0544 int X509_sign(X509 *x, EVP_PKEY *pkey, const EVP_MD *md);
0545 int X509_sign_ctx(X509 *x, EVP_MD_CTX *ctx);
0546 int X509_REQ_sign(X509_REQ *x, EVP_PKEY *pkey, const EVP_MD *md);
0547 int X509_REQ_sign_ctx(X509_REQ *x, EVP_MD_CTX *ctx);
0548 int X509_CRL_sign(X509_CRL *x, EVP_PKEY *pkey, const EVP_MD *md);
0549 int X509_CRL_sign_ctx(X509_CRL *x, EVP_MD_CTX *ctx);
0550 int NETSCAPE_SPKI_sign(NETSCAPE_SPKI *x, EVP_PKEY *pkey, const EVP_MD *md);
0551 
0552 int X509_pubkey_digest(const X509 *data, const EVP_MD *type,
0553     unsigned char *md, unsigned int *len);
0554 int X509_digest(const X509 *data, const EVP_MD *type,
0555     unsigned char *md, unsigned int *len);
0556 ASN1_OCTET_STRING *X509_digest_sig(const X509 *cert,
0557     EVP_MD **md_used, int *md_is_fallback);
0558 int X509_CRL_digest(const X509_CRL *data, const EVP_MD *type,
0559     unsigned char *md, unsigned int *len);
0560 int X509_REQ_digest(const X509_REQ *data, const EVP_MD *type,
0561     unsigned char *md, unsigned int *len);
0562 int X509_NAME_digest(const X509_NAME *data, const EVP_MD *type,
0563     unsigned char *md, unsigned int *len);
0564 
0565 X509 *X509_load_http(const char *url, BIO *bio, BIO *rbio, int timeout);
0566 X509_CRL *X509_CRL_load_http(const char *url, BIO *bio, BIO *rbio, int timeout);
0567 #ifndef OPENSSL_NO_DEPRECATED_3_0
0568 #include <openssl/http.h> /* OSSL_HTTP_REQ_CTX_nbio_d2i */
0569 #define X509_http_nbio(rctx, pcert) \
0570     OSSL_HTTP_REQ_CTX_nbio_d2i(rctx, pcert, ASN1_ITEM_rptr(X509))
0571 #define X509_CRL_http_nbio(rctx, pcrl) \
0572     OSSL_HTTP_REQ_CTX_nbio_d2i(rctx, pcrl, ASN1_ITEM_rptr(X509_CRL))
0573 #endif
0574 
0575 #ifndef OPENSSL_NO_STDIO
0576 X509 *d2i_X509_fp(FILE *fp, X509 **x509);
0577 int i2d_X509_fp(FILE *fp, const X509 *x509);
0578 X509_CRL *d2i_X509_CRL_fp(FILE *fp, X509_CRL **crl);
0579 int i2d_X509_CRL_fp(FILE *fp, const X509_CRL *crl);
0580 X509_REQ *d2i_X509_REQ_fp(FILE *fp, X509_REQ **req);
0581 int i2d_X509_REQ_fp(FILE *fp, const X509_REQ *req);
0582 #ifndef OPENSSL_NO_DEPRECATED_3_0
0583 OSSL_DEPRECATEDIN_3_0 RSA *d2i_RSAPrivateKey_fp(FILE *fp, RSA **rsa);
0584 OSSL_DEPRECATEDIN_3_0 int i2d_RSAPrivateKey_fp(FILE *fp, const RSA *rsa);
0585 OSSL_DEPRECATEDIN_3_0 RSA *d2i_RSAPublicKey_fp(FILE *fp, RSA **rsa);
0586 OSSL_DEPRECATEDIN_3_0 int i2d_RSAPublicKey_fp(FILE *fp, const RSA *rsa);
0587 OSSL_DEPRECATEDIN_3_0 RSA *d2i_RSA_PUBKEY_fp(FILE *fp, RSA **rsa);
0588 OSSL_DEPRECATEDIN_3_0 int i2d_RSA_PUBKEY_fp(FILE *fp, const RSA *rsa);
0589 #endif
0590 #ifndef OPENSSL_NO_DEPRECATED_3_0
0591 #ifndef OPENSSL_NO_DSA
0592 OSSL_DEPRECATEDIN_3_0 DSA *d2i_DSA_PUBKEY_fp(FILE *fp, DSA **dsa);
0593 OSSL_DEPRECATEDIN_3_0 int i2d_DSA_PUBKEY_fp(FILE *fp, const DSA *dsa);
0594 OSSL_DEPRECATEDIN_3_0 DSA *d2i_DSAPrivateKey_fp(FILE *fp, DSA **dsa);
0595 OSSL_DEPRECATEDIN_3_0 int i2d_DSAPrivateKey_fp(FILE *fp, const DSA *dsa);
0596 #endif
0597 #endif
0598 #ifndef OPENSSL_NO_DEPRECATED_3_0
0599 #ifndef OPENSSL_NO_EC
0600 OSSL_DEPRECATEDIN_3_0 EC_KEY *d2i_EC_PUBKEY_fp(FILE *fp, EC_KEY **eckey);
0601 OSSL_DEPRECATEDIN_3_0 int i2d_EC_PUBKEY_fp(FILE *fp, const EC_KEY *eckey);
0602 OSSL_DEPRECATEDIN_3_0 EC_KEY *d2i_ECPrivateKey_fp(FILE *fp, EC_KEY **eckey);
0603 OSSL_DEPRECATEDIN_3_0 int i2d_ECPrivateKey_fp(FILE *fp, const EC_KEY *eckey);
0604 #endif /* OPENSSL_NO_EC */
0605 #endif /* OPENSSL_NO_DEPRECATED_3_0 */
0606 X509_SIG *d2i_PKCS8_fp(FILE *fp, X509_SIG **p8);
0607 int i2d_PKCS8_fp(FILE *fp, const X509_SIG *p8);
0608 X509_PUBKEY *d2i_X509_PUBKEY_fp(FILE *fp, X509_PUBKEY **xpk);
0609 int i2d_X509_PUBKEY_fp(FILE *fp, const X509_PUBKEY *xpk);
0610 PKCS8_PRIV_KEY_INFO *d2i_PKCS8_PRIV_KEY_INFO_fp(FILE *fp,
0611     PKCS8_PRIV_KEY_INFO **p8inf);
0612 int i2d_PKCS8_PRIV_KEY_INFO_fp(FILE *fp, const PKCS8_PRIV_KEY_INFO *p8inf);
0613 int i2d_PKCS8PrivateKeyInfo_fp(FILE *fp, const EVP_PKEY *key);
0614 int i2d_PrivateKey_fp(FILE *fp, const EVP_PKEY *pkey);
0615 EVP_PKEY *d2i_PrivateKey_ex_fp(FILE *fp, EVP_PKEY **a, OSSL_LIB_CTX *libctx,
0616     const char *propq);
0617 EVP_PKEY *d2i_PrivateKey_fp(FILE *fp, EVP_PKEY **a);
0618 int i2d_PUBKEY_fp(FILE *fp, const EVP_PKEY *pkey);
0619 EVP_PKEY *d2i_PUBKEY_ex_fp(FILE *fp, EVP_PKEY **a, OSSL_LIB_CTX *libctx,
0620     const char *propq);
0621 EVP_PKEY *d2i_PUBKEY_fp(FILE *fp, EVP_PKEY **a);
0622 #endif
0623 
0624 X509 *d2i_X509_bio(BIO *bp, X509 **x509);
0625 int i2d_X509_bio(BIO *bp, const X509 *x509);
0626 X509_CRL *d2i_X509_CRL_bio(BIO *bp, X509_CRL **crl);
0627 int i2d_X509_CRL_bio(BIO *bp, const X509_CRL *crl);
0628 X509_REQ *d2i_X509_REQ_bio(BIO *bp, X509_REQ **req);
0629 int i2d_X509_REQ_bio(BIO *bp, const X509_REQ *req);
0630 #ifndef OPENSSL_NO_DEPRECATED_3_0
0631 OSSL_DEPRECATEDIN_3_0 RSA *d2i_RSAPrivateKey_bio(BIO *bp, RSA **rsa);
0632 OSSL_DEPRECATEDIN_3_0 int i2d_RSAPrivateKey_bio(BIO *bp, const RSA *rsa);
0633 OSSL_DEPRECATEDIN_3_0 RSA *d2i_RSAPublicKey_bio(BIO *bp, RSA **rsa);
0634 OSSL_DEPRECATEDIN_3_0 int i2d_RSAPublicKey_bio(BIO *bp, const RSA *rsa);
0635 OSSL_DEPRECATEDIN_3_0 RSA *d2i_RSA_PUBKEY_bio(BIO *bp, RSA **rsa);
0636 OSSL_DEPRECATEDIN_3_0 int i2d_RSA_PUBKEY_bio(BIO *bp, const RSA *rsa);
0637 #endif
0638 #ifndef OPENSSL_NO_DEPRECATED_3_0
0639 #ifndef OPENSSL_NO_DSA
0640 OSSL_DEPRECATEDIN_3_0 DSA *d2i_DSA_PUBKEY_bio(BIO *bp, DSA **dsa);
0641 OSSL_DEPRECATEDIN_3_0 int i2d_DSA_PUBKEY_bio(BIO *bp, const DSA *dsa);
0642 OSSL_DEPRECATEDIN_3_0 DSA *d2i_DSAPrivateKey_bio(BIO *bp, DSA **dsa);
0643 OSSL_DEPRECATEDIN_3_0 int i2d_DSAPrivateKey_bio(BIO *bp, const DSA *dsa);
0644 #endif
0645 #endif
0646 
0647 #ifndef OPENSSL_NO_DEPRECATED_3_0
0648 #ifndef OPENSSL_NO_EC
0649 OSSL_DEPRECATEDIN_3_0 EC_KEY *d2i_EC_PUBKEY_bio(BIO *bp, EC_KEY **eckey);
0650 OSSL_DEPRECATEDIN_3_0 int i2d_EC_PUBKEY_bio(BIO *bp, const EC_KEY *eckey);
0651 OSSL_DEPRECATEDIN_3_0 EC_KEY *d2i_ECPrivateKey_bio(BIO *bp, EC_KEY **eckey);
0652 OSSL_DEPRECATEDIN_3_0 int i2d_ECPrivateKey_bio(BIO *bp, const EC_KEY *eckey);
0653 #endif /* OPENSSL_NO_EC */
0654 #endif /* OPENSSL_NO_DEPRECATED_3_0 */
0655 
0656 X509_SIG *d2i_PKCS8_bio(BIO *bp, X509_SIG **p8);
0657 int i2d_PKCS8_bio(BIO *bp, const X509_SIG *p8);
0658 X509_PUBKEY *d2i_X509_PUBKEY_bio(BIO *bp, X509_PUBKEY **xpk);
0659 int i2d_X509_PUBKEY_bio(BIO *bp, const X509_PUBKEY *xpk);
0660 PKCS8_PRIV_KEY_INFO *d2i_PKCS8_PRIV_KEY_INFO_bio(BIO *bp,
0661     PKCS8_PRIV_KEY_INFO **p8inf);
0662 int i2d_PKCS8_PRIV_KEY_INFO_bio(BIO *bp, const PKCS8_PRIV_KEY_INFO *p8inf);
0663 int i2d_PKCS8PrivateKeyInfo_bio(BIO *bp, const EVP_PKEY *key);
0664 int i2d_PrivateKey_bio(BIO *bp, const EVP_PKEY *pkey);
0665 EVP_PKEY *d2i_PrivateKey_ex_bio(BIO *bp, EVP_PKEY **a, OSSL_LIB_CTX *libctx,
0666     const char *propq);
0667 EVP_PKEY *d2i_PrivateKey_bio(BIO *bp, EVP_PKEY **a);
0668 int i2d_PUBKEY_bio(BIO *bp, const EVP_PKEY *pkey);
0669 EVP_PKEY *d2i_PUBKEY_ex_bio(BIO *bp, EVP_PKEY **a, OSSL_LIB_CTX *libctx,
0670     const char *propq);
0671 EVP_PKEY *d2i_PUBKEY_bio(BIO *bp, EVP_PKEY **a);
0672 
0673 DECLARE_ASN1_DUP_FUNCTION(X509)
0674 DECLARE_ASN1_DUP_FUNCTION(X509_ALGOR)
0675 DECLARE_ASN1_DUP_FUNCTION(X509_ATTRIBUTE)
0676 DECLARE_ASN1_DUP_FUNCTION(X509_CRL)
0677 DECLARE_ASN1_DUP_FUNCTION(X509_EXTENSION)
0678 DECLARE_ASN1_DUP_FUNCTION(X509_PUBKEY)
0679 DECLARE_ASN1_DUP_FUNCTION(X509_REQ)
0680 DECLARE_ASN1_DUP_FUNCTION(X509_REVOKED)
0681 int X509_ALGOR_set0(X509_ALGOR *alg, ASN1_OBJECT *aobj, int ptype,
0682     void *pval);
0683 void X509_ALGOR_get0(const ASN1_OBJECT **paobj, int *pptype,
0684     const void **ppval, const X509_ALGOR *algor);
0685 void X509_ALGOR_set_md(X509_ALGOR *alg, const EVP_MD *md);
0686 int X509_ALGOR_cmp(const X509_ALGOR *a, const X509_ALGOR *b);
0687 int X509_ALGOR_copy(X509_ALGOR *dest, const X509_ALGOR *src);
0688 
0689 DECLARE_ASN1_DUP_FUNCTION(X509_NAME)
0690 DECLARE_ASN1_DUP_FUNCTION(X509_NAME_ENTRY)
0691 
0692 int X509_cmp_time(const ASN1_TIME *s, time_t *t);
0693 int X509_cmp_current_time(const ASN1_TIME *s);
0694 int X509_cmp_timeframe(const X509_VERIFY_PARAM *vpm,
0695     const ASN1_TIME *start, const ASN1_TIME *end);
0696 ASN1_TIME *X509_time_adj(ASN1_TIME *s, long adj, time_t *t);
0697 ASN1_TIME *X509_time_adj_ex(ASN1_TIME *s,
0698     int offset_day, long offset_sec, time_t *t);
0699 ASN1_TIME *X509_gmtime_adj(ASN1_TIME *s, long adj);
0700 
0701 const char *X509_get_default_cert_area(void);
0702 const char *X509_get_default_cert_dir(void);
0703 const char *X509_get_default_cert_file(void);
0704 const char *X509_get_default_cert_dir_env(void);
0705 const char *X509_get_default_cert_file_env(void);
0706 const char *X509_get_default_private_dir(void);
0707 
0708 X509_REQ *X509_to_X509_REQ(X509 *x, EVP_PKEY *pkey, const EVP_MD *md);
0709 X509 *X509_REQ_to_X509(X509_REQ *r, int days, EVP_PKEY *pkey);
0710 
0711 DECLARE_ASN1_FUNCTIONS(X509_ALGOR)
0712 DECLARE_ASN1_ENCODE_FUNCTIONS(X509_ALGORS, X509_ALGORS, X509_ALGORS)
0713 DECLARE_ASN1_FUNCTIONS(X509_VAL)
0714 
0715 DECLARE_ASN1_FUNCTIONS(X509_PUBKEY)
0716 
0717 X509_PUBKEY *X509_PUBKEY_new_ex(OSSL_LIB_CTX *libctx, const char *propq);
0718 int X509_PUBKEY_set(X509_PUBKEY **x, EVP_PKEY *pkey);
0719 EVP_PKEY *X509_PUBKEY_get0(const X509_PUBKEY *key);
0720 EVP_PKEY *X509_PUBKEY_get(const X509_PUBKEY *key);
0721 int X509_get_pubkey_parameters(EVP_PKEY *pkey, STACK_OF(X509) *chain);
0722 long X509_get_pathlen(X509 *x);
0723 DECLARE_ASN1_ENCODE_FUNCTIONS_only(EVP_PKEY, PUBKEY)
0724 EVP_PKEY *d2i_PUBKEY_ex(EVP_PKEY **a, const unsigned char **pp, long length,
0725     OSSL_LIB_CTX *libctx, const char *propq);
0726 #ifndef OPENSSL_NO_DEPRECATED_3_0
0727 DECLARE_ASN1_ENCODE_FUNCTIONS_only_attr(OSSL_DEPRECATEDIN_3_0, RSA, RSA_PUBKEY)
0728 #endif
0729 #ifndef OPENSSL_NO_DEPRECATED_3_0
0730 #ifndef OPENSSL_NO_DSA
0731 DECLARE_ASN1_ENCODE_FUNCTIONS_only_attr(OSSL_DEPRECATEDIN_3_0, DSA, DSA_PUBKEY)
0732 #endif
0733 #endif
0734 #ifndef OPENSSL_NO_DEPRECATED_3_0
0735 #ifndef OPENSSL_NO_EC
0736 DECLARE_ASN1_ENCODE_FUNCTIONS_only_attr(OSSL_DEPRECATEDIN_3_0, EC_KEY, EC_PUBKEY)
0737 #endif
0738 #endif
0739 
0740 DECLARE_ASN1_FUNCTIONS(X509_SIG)
0741 void X509_SIG_get0(const X509_SIG *sig, const X509_ALGOR **palg,
0742     const ASN1_OCTET_STRING **pdigest);
0743 void X509_SIG_getm(X509_SIG *sig, X509_ALGOR **palg,
0744     ASN1_OCTET_STRING **pdigest);
0745 
0746 DECLARE_ASN1_FUNCTIONS(X509_REQ_INFO)
0747 DECLARE_ASN1_FUNCTIONS(X509_REQ)
0748 X509_REQ *X509_REQ_new_ex(OSSL_LIB_CTX *libctx, const char *propq);
0749 
0750 DECLARE_ASN1_FUNCTIONS(X509_ATTRIBUTE)
0751 X509_ATTRIBUTE *X509_ATTRIBUTE_create(int nid, int atrtype, void *value);
0752 
0753 DECLARE_ASN1_FUNCTIONS(X509_EXTENSION)
0754 DECLARE_ASN1_ENCODE_FUNCTIONS(X509_EXTENSIONS, X509_EXTENSIONS, X509_EXTENSIONS)
0755 
0756 DECLARE_ASN1_FUNCTIONS(X509_NAME_ENTRY)
0757 
0758 DECLARE_ASN1_FUNCTIONS(X509_NAME)
0759 
0760 int X509_NAME_set(X509_NAME **xn, const X509_NAME *name);
0761 
0762 DECLARE_ASN1_FUNCTIONS(X509_CINF)
0763 DECLARE_ASN1_FUNCTIONS(X509)
0764 X509 *X509_new_ex(OSSL_LIB_CTX *libctx, const char *propq);
0765 DECLARE_ASN1_FUNCTIONS(X509_CERT_AUX)
0766 
0767 #define X509_get_ex_new_index(l, p, newf, dupf, freef) \
0768     CRYPTO_get_ex_new_index(CRYPTO_EX_INDEX_X509, l, p, newf, dupf, freef)
0769 int X509_set_ex_data(X509 *r, int idx, void *arg);
0770 void *X509_get_ex_data(const X509 *r, int idx);
0771 DECLARE_ASN1_ENCODE_FUNCTIONS_only(X509, X509_AUX)
0772 
0773 int i2d_re_X509_tbs(X509 *x, unsigned char **pp);
0774 
0775 int X509_SIG_INFO_get(const X509_SIG_INFO *siginf, int *mdnid, int *pknid,
0776     int *secbits, uint32_t *flags);
0777 void X509_SIG_INFO_set(X509_SIG_INFO *siginf, int mdnid, int pknid,
0778     int secbits, uint32_t flags);
0779 
0780 int X509_get_signature_info(X509 *x, int *mdnid, int *pknid, int *secbits,
0781     uint32_t *flags);
0782 
0783 void X509_get0_signature(const ASN1_BIT_STRING **psig,
0784     const X509_ALGOR **palg, const X509 *x);
0785 int X509_get_signature_nid(const X509 *x);
0786 
0787 void X509_set0_distinguishing_id(X509 *x, ASN1_OCTET_STRING *d_id);
0788 ASN1_OCTET_STRING *X509_get0_distinguishing_id(X509 *x);
0789 void X509_REQ_set0_distinguishing_id(X509_REQ *x, ASN1_OCTET_STRING *d_id);
0790 ASN1_OCTET_STRING *X509_REQ_get0_distinguishing_id(X509_REQ *x);
0791 
0792 int X509_alias_set1(X509 *x, const unsigned char *name, int len);
0793 int X509_keyid_set1(X509 *x, const unsigned char *id, int len);
0794 unsigned char *X509_alias_get0(X509 *x, int *len);
0795 unsigned char *X509_keyid_get0(X509 *x, int *len);
0796 
0797 DECLARE_ASN1_FUNCTIONS(X509_REVOKED)
0798 DECLARE_ASN1_FUNCTIONS(X509_CRL_INFO)
0799 DECLARE_ASN1_FUNCTIONS(X509_CRL)
0800 X509_CRL *X509_CRL_new_ex(OSSL_LIB_CTX *libctx, const char *propq);
0801 
0802 int X509_CRL_add0_revoked(X509_CRL *crl, X509_REVOKED *rev);
0803 int X509_CRL_get0_by_serial(X509_CRL *crl,
0804     X509_REVOKED **ret, const ASN1_INTEGER *serial);
0805 int X509_CRL_get0_by_cert(X509_CRL *crl, X509_REVOKED **ret, X509 *x);
0806 
0807 X509_PKEY *X509_PKEY_new(void);
0808 void X509_PKEY_free(X509_PKEY *a);
0809 
0810 DECLARE_ASN1_FUNCTIONS(NETSCAPE_SPKI)
0811 DECLARE_ASN1_FUNCTIONS(NETSCAPE_SPKAC)
0812 DECLARE_ASN1_FUNCTIONS(NETSCAPE_CERT_SEQUENCE)
0813 
0814 X509_INFO *X509_INFO_new(void);
0815 void X509_INFO_free(X509_INFO *a);
0816 char *X509_NAME_oneline(const X509_NAME *a, char *buf, int size);
0817 
0818 #ifndef OPENSSL_NO_DEPRECATED_3_0
0819 OSSL_DEPRECATEDIN_3_0
0820 int ASN1_verify(i2d_of_void *i2d, X509_ALGOR *algor1,
0821     ASN1_BIT_STRING *signature, char *data, EVP_PKEY *pkey);
0822 OSSL_DEPRECATEDIN_3_0
0823 int ASN1_digest(i2d_of_void *i2d, const EVP_MD *type, char *data,
0824     unsigned char *md, unsigned int *len);
0825 OSSL_DEPRECATEDIN_3_0
0826 int ASN1_sign(i2d_of_void *i2d, X509_ALGOR *algor1, X509_ALGOR *algor2,
0827     ASN1_BIT_STRING *signature, char *data, EVP_PKEY *pkey,
0828     const EVP_MD *type);
0829 #endif
0830 int ASN1_item_digest(const ASN1_ITEM *it, const EVP_MD *type, void *data,
0831     unsigned char *md, unsigned int *len);
0832 int ASN1_item_verify(const ASN1_ITEM *it, const X509_ALGOR *alg,
0833     const ASN1_BIT_STRING *signature, const void *data,
0834     EVP_PKEY *pkey);
0835 int ASN1_item_verify_ctx(const ASN1_ITEM *it, const X509_ALGOR *alg,
0836     const ASN1_BIT_STRING *signature, const void *data,
0837     EVP_MD_CTX *ctx);
0838 int ASN1_item_sign(const ASN1_ITEM *it, X509_ALGOR *algor1, X509_ALGOR *algor2,
0839     ASN1_BIT_STRING *signature, const void *data,
0840     EVP_PKEY *pkey, const EVP_MD *md);
0841 int ASN1_item_sign_ctx(const ASN1_ITEM *it, X509_ALGOR *algor1,
0842     X509_ALGOR *algor2, ASN1_BIT_STRING *signature,
0843     const void *data, EVP_MD_CTX *ctx);
0844 
0845 #define X509_VERSION_1 0
0846 #define X509_VERSION_2 1
0847 #define X509_VERSION_3 2
0848 
0849 long X509_get_version(const X509 *x);
0850 int X509_set_version(X509 *x, long version);
0851 int X509_set_serialNumber(X509 *x, ASN1_INTEGER *serial);
0852 ASN1_INTEGER *X509_get_serialNumber(X509 *x);
0853 const ASN1_INTEGER *X509_get0_serialNumber(const X509 *x);
0854 int X509_set_issuer_name(X509 *x, const X509_NAME *name);
0855 X509_NAME *X509_get_issuer_name(const X509 *a);
0856 int X509_set_subject_name(X509 *x, const X509_NAME *name);
0857 X509_NAME *X509_get_subject_name(const X509 *a);
0858 const ASN1_TIME *X509_get0_notBefore(const X509 *x);
0859 ASN1_TIME *X509_getm_notBefore(const X509 *x);
0860 int X509_set1_notBefore(X509 *x, const ASN1_TIME *tm);
0861 const ASN1_TIME *X509_get0_notAfter(const X509 *x);
0862 ASN1_TIME *X509_getm_notAfter(const X509 *x);
0863 int X509_set1_notAfter(X509 *x, const ASN1_TIME *tm);
0864 int X509_set_pubkey(X509 *x, EVP_PKEY *pkey);
0865 int X509_up_ref(X509 *x);
0866 int X509_get_signature_type(const X509 *x);
0867 
0868 #ifndef OPENSSL_NO_DEPRECATED_1_1_0
0869 #define X509_get_notBefore X509_getm_notBefore
0870 #define X509_get_notAfter X509_getm_notAfter
0871 #define X509_set_notBefore X509_set1_notBefore
0872 #define X509_set_notAfter X509_set1_notAfter
0873 #endif
0874 
0875 /*
0876  * This one is only used so that a binary form can output, as in
0877  * i2d_X509_PUBKEY(X509_get_X509_PUBKEY(x), &buf)
0878  */
0879 X509_PUBKEY *X509_get_X509_PUBKEY(const X509 *x);
0880 const STACK_OF(X509_EXTENSION) *X509_get0_extensions(const X509 *x);
0881 void X509_get0_uids(const X509 *x, const ASN1_BIT_STRING **piuid,
0882     const ASN1_BIT_STRING **psuid);
0883 const X509_ALGOR *X509_get0_tbs_sigalg(const X509 *x);
0884 
0885 EVP_PKEY *X509_get0_pubkey(const X509 *x);
0886 EVP_PKEY *X509_get_pubkey(X509 *x);
0887 ASN1_BIT_STRING *X509_get0_pubkey_bitstr(const X509 *x);
0888 
0889 #define X509_REQ_VERSION_1 0
0890 
0891 long X509_REQ_get_version(const X509_REQ *req);
0892 int X509_REQ_set_version(X509_REQ *x, long version);
0893 X509_NAME *X509_REQ_get_subject_name(const X509_REQ *req);
0894 int X509_REQ_set_subject_name(X509_REQ *req, const X509_NAME *name);
0895 void X509_REQ_get0_signature(const X509_REQ *req, const ASN1_BIT_STRING **psig,
0896     const X509_ALGOR **palg);
0897 void X509_REQ_set0_signature(X509_REQ *req, ASN1_BIT_STRING *psig);
0898 int X509_REQ_set1_signature_algo(X509_REQ *req, X509_ALGOR *palg);
0899 int X509_REQ_get_signature_nid(const X509_REQ *req);
0900 int i2d_re_X509_REQ_tbs(X509_REQ *req, unsigned char **pp);
0901 int X509_REQ_set_pubkey(X509_REQ *x, EVP_PKEY *pkey);
0902 EVP_PKEY *X509_REQ_get_pubkey(X509_REQ *req);
0903 EVP_PKEY *X509_REQ_get0_pubkey(const X509_REQ *req);
0904 X509_PUBKEY *X509_REQ_get_X509_PUBKEY(X509_REQ *req);
0905 int X509_REQ_extension_nid(int nid);
0906 int *X509_REQ_get_extension_nids(void);
0907 void X509_REQ_set_extension_nids(int *nids);
0908 STACK_OF(X509_EXTENSION) *X509_REQ_get_extensions(OSSL_FUTURE_CONST X509_REQ *req);
0909 int X509_REQ_add_extensions_nid(X509_REQ *req,
0910     const STACK_OF(X509_EXTENSION) *exts, int nid);
0911 int X509_REQ_add_extensions(X509_REQ *req, const STACK_OF(X509_EXTENSION) *ext);
0912 int X509_REQ_get_attr_count(const X509_REQ *req);
0913 int X509_REQ_get_attr_by_NID(const X509_REQ *req, int nid, int lastpos);
0914 int X509_REQ_get_attr_by_OBJ(const X509_REQ *req, const ASN1_OBJECT *obj,
0915     int lastpos);
0916 X509_ATTRIBUTE *X509_REQ_get_attr(const X509_REQ *req, int loc);
0917 X509_ATTRIBUTE *X509_REQ_delete_attr(X509_REQ *req, int loc);
0918 int X509_REQ_add1_attr(X509_REQ *req, X509_ATTRIBUTE *attr);
0919 int X509_REQ_add1_attr_by_OBJ(X509_REQ *req,
0920     const ASN1_OBJECT *obj, int type,
0921     const unsigned char *bytes, int len);
0922 int X509_REQ_add1_attr_by_NID(X509_REQ *req,
0923     int nid, int type,
0924     const unsigned char *bytes, int len);
0925 int X509_REQ_add1_attr_by_txt(X509_REQ *req,
0926     const char *attrname, int type,
0927     const unsigned char *bytes, int len);
0928 
0929 #define X509_CRL_VERSION_1 0
0930 #define X509_CRL_VERSION_2 1
0931 
0932 int X509_CRL_set_version(X509_CRL *x, long version);
0933 int X509_CRL_set_issuer_name(X509_CRL *x, const X509_NAME *name);
0934 int X509_CRL_set1_lastUpdate(X509_CRL *x, const ASN1_TIME *tm);
0935 int X509_CRL_set1_nextUpdate(X509_CRL *x, const ASN1_TIME *tm);
0936 int X509_CRL_sort(X509_CRL *crl);
0937 int X509_CRL_up_ref(X509_CRL *crl);
0938 
0939 #ifndef OPENSSL_NO_DEPRECATED_1_1_0
0940 #define X509_CRL_set_lastUpdate X509_CRL_set1_lastUpdate
0941 #define X509_CRL_set_nextUpdate X509_CRL_set1_nextUpdate
0942 #endif
0943 
0944 long X509_CRL_get_version(const X509_CRL *crl);
0945 const ASN1_TIME *X509_CRL_get0_lastUpdate(const X509_CRL *crl);
0946 const ASN1_TIME *X509_CRL_get0_nextUpdate(const X509_CRL *crl);
0947 #ifndef OPENSSL_NO_DEPRECATED_1_1_0
0948 OSSL_DEPRECATEDIN_1_1_0 ASN1_TIME *X509_CRL_get_lastUpdate(X509_CRL *crl);
0949 OSSL_DEPRECATEDIN_1_1_0 ASN1_TIME *X509_CRL_get_nextUpdate(X509_CRL *crl);
0950 #endif
0951 X509_NAME *X509_CRL_get_issuer(const X509_CRL *crl);
0952 const STACK_OF(X509_EXTENSION) *X509_CRL_get0_extensions(const X509_CRL *crl);
0953 STACK_OF(X509_REVOKED) *X509_CRL_get_REVOKED(X509_CRL *crl);
0954 const X509_ALGOR *X509_CRL_get0_tbs_sigalg(const X509_CRL *crl);
0955 void X509_CRL_get0_signature(const X509_CRL *crl, const ASN1_BIT_STRING **psig,
0956     const X509_ALGOR **palg);
0957 int X509_CRL_get_signature_nid(const X509_CRL *crl);
0958 int i2d_re_X509_CRL_tbs(X509_CRL *req, unsigned char **pp);
0959 
0960 const ASN1_INTEGER *X509_REVOKED_get0_serialNumber(const X509_REVOKED *x);
0961 int X509_REVOKED_set_serialNumber(X509_REVOKED *x, ASN1_INTEGER *serial);
0962 const ASN1_TIME *X509_REVOKED_get0_revocationDate(const X509_REVOKED *x);
0963 int X509_REVOKED_set_revocationDate(X509_REVOKED *r, ASN1_TIME *tm);
0964 const STACK_OF(X509_EXTENSION) *
0965 X509_REVOKED_get0_extensions(const X509_REVOKED *r);
0966 
0967 X509_CRL *X509_CRL_diff(X509_CRL *base, X509_CRL *newer,
0968     EVP_PKEY *skey, const EVP_MD *md, unsigned int flags);
0969 
0970 int X509_REQ_check_private_key(const X509_REQ *req, EVP_PKEY *pkey);
0971 
0972 int X509_check_private_key(const X509 *cert, const EVP_PKEY *pkey);
0973 int X509_chain_check_suiteb(int *perror_depth,
0974     X509 *x, STACK_OF(X509) *chain,
0975     unsigned long flags);
0976 int X509_CRL_check_suiteb(X509_CRL *crl, EVP_PKEY *pk, unsigned long flags);
0977 void OSSL_STACK_OF_X509_free(STACK_OF(X509) *certs);
0978 STACK_OF(X509) *X509_chain_up_ref(STACK_OF(X509) *chain);
0979 
0980 int X509_issuer_and_serial_cmp(const X509 *a, const X509 *b);
0981 unsigned long X509_issuer_and_serial_hash(X509 *a);
0982 
0983 int X509_issuer_name_cmp(const X509 *a, const X509 *b);
0984 unsigned long X509_issuer_name_hash(X509 *a);
0985 
0986 int X509_subject_name_cmp(const X509 *a, const X509 *b);
0987 unsigned long X509_subject_name_hash(X509 *x);
0988 
0989 #ifndef OPENSSL_NO_MD5
0990 unsigned long X509_issuer_name_hash_old(X509 *a);
0991 unsigned long X509_subject_name_hash_old(X509 *x);
0992 #endif
0993 
0994 #define X509_ADD_FLAG_DEFAULT 0
0995 #define X509_ADD_FLAG_UP_REF 0x1
0996 #define X509_ADD_FLAG_PREPEND 0x2
0997 #define X509_ADD_FLAG_NO_DUP 0x4
0998 #define X509_ADD_FLAG_NO_SS 0x8
0999 int X509_add_cert(STACK_OF(X509) *sk, X509 *cert, int flags);
1000 int X509_add_certs(STACK_OF(X509) *sk, STACK_OF(X509) *certs, int flags);
1001 
1002 int X509_cmp(const X509 *a, const X509 *b);
1003 int X509_NAME_cmp(const X509_NAME *a, const X509_NAME *b);
1004 #ifndef OPENSSL_NO_DEPRECATED_3_0
1005 #define X509_NAME_hash(x) X509_NAME_hash_ex(x, NULL, NULL, NULL)
1006 OSSL_DEPRECATEDIN_3_0 int X509_certificate_type(const X509 *x,
1007     const EVP_PKEY *pubkey);
1008 #endif
1009 unsigned long X509_NAME_hash_ex(const X509_NAME *x, OSSL_LIB_CTX *libctx,
1010     const char *propq, int *ok);
1011 unsigned long X509_NAME_hash_old(const X509_NAME *x);
1012 
1013 int X509_CRL_cmp(const X509_CRL *a, const X509_CRL *b);
1014 int X509_CRL_match(const X509_CRL *a, const X509_CRL *b);
1015 int X509_aux_print(BIO *out, X509 *x, int indent);
1016 #ifndef OPENSSL_NO_STDIO
1017 int X509_print_ex_fp(FILE *bp, X509 *x, unsigned long nmflag,
1018     unsigned long cflag);
1019 int X509_print_fp(FILE *bp, X509 *x);
1020 int X509_CRL_print_fp(FILE *bp, X509_CRL *x);
1021 int X509_REQ_print_fp(FILE *bp, X509_REQ *req);
1022 int X509_NAME_print_ex_fp(FILE *fp, const X509_NAME *nm, int indent,
1023     unsigned long flags);
1024 #endif
1025 
1026 int X509_NAME_print(BIO *bp, const X509_NAME *name, int obase);
1027 int X509_NAME_print_ex(BIO *out, const X509_NAME *nm, int indent,
1028     unsigned long flags);
1029 int X509_print_ex(BIO *bp, X509 *x, unsigned long nmflag,
1030     unsigned long cflag);
1031 int X509_print(BIO *bp, X509 *x);
1032 int X509_ocspid_print(BIO *bp, X509 *x);
1033 int X509_CRL_print_ex(BIO *out, X509_CRL *x, unsigned long nmflag);
1034 int X509_CRL_print(BIO *bp, X509_CRL *x);
1035 int X509_REQ_print_ex(BIO *bp, X509_REQ *x, unsigned long nmflag,
1036     unsigned long cflag);
1037 int X509_REQ_print(BIO *bp, X509_REQ *req);
1038 
1039 int X509_NAME_entry_count(const X509_NAME *name);
1040 int X509_NAME_get_text_by_NID(const X509_NAME *name, int nid,
1041     char *buf, int len);
1042 int X509_NAME_get_text_by_OBJ(const X509_NAME *name, const ASN1_OBJECT *obj,
1043     char *buf, int len);
1044 
1045 /*
1046  * NOTE: you should be passing -1, not 0 as lastpos. The functions that use
1047  * lastpos, search after that position on.
1048  */
1049 int X509_NAME_get_index_by_NID(const X509_NAME *name, int nid, int lastpos);
1050 int X509_NAME_get_index_by_OBJ(const X509_NAME *name, const ASN1_OBJECT *obj,
1051     int lastpos);
1052 X509_NAME_ENTRY *X509_NAME_get_entry(const X509_NAME *name, int loc);
1053 X509_NAME_ENTRY *X509_NAME_delete_entry(X509_NAME *name, int loc);
1054 int X509_NAME_add_entry(X509_NAME *name, const X509_NAME_ENTRY *ne,
1055     int loc, int set);
1056 int X509_NAME_add_entry_by_OBJ(X509_NAME *name, const ASN1_OBJECT *obj, int type,
1057     const unsigned char *bytes, int len, int loc,
1058     int set);
1059 int X509_NAME_add_entry_by_NID(X509_NAME *name, int nid, int type,
1060     const unsigned char *bytes, int len, int loc,
1061     int set);
1062 X509_NAME_ENTRY *X509_NAME_ENTRY_create_by_txt(X509_NAME_ENTRY **ne,
1063     const char *field, int type,
1064     const unsigned char *bytes,
1065     int len);
1066 X509_NAME_ENTRY *X509_NAME_ENTRY_create_by_NID(X509_NAME_ENTRY **ne, int nid,
1067     int type,
1068     const unsigned char *bytes,
1069     int len);
1070 int X509_NAME_add_entry_by_txt(X509_NAME *name, const char *field, int type,
1071     const unsigned char *bytes, int len, int loc,
1072     int set);
1073 X509_NAME_ENTRY *X509_NAME_ENTRY_create_by_OBJ(X509_NAME_ENTRY **ne,
1074     const ASN1_OBJECT *obj, int type,
1075     const unsigned char *bytes,
1076     int len);
1077 int X509_NAME_ENTRY_set_object(X509_NAME_ENTRY *ne, const ASN1_OBJECT *obj);
1078 int X509_NAME_ENTRY_set_data(X509_NAME_ENTRY *ne, int type,
1079     const unsigned char *bytes, int len);
1080 ASN1_OBJECT *X509_NAME_ENTRY_get_object(const X509_NAME_ENTRY *ne);
1081 ASN1_STRING *X509_NAME_ENTRY_get_data(const X509_NAME_ENTRY *ne);
1082 int X509_NAME_ENTRY_set(const X509_NAME_ENTRY *ne);
1083 
1084 int X509_NAME_get0_der(const X509_NAME *nm, const unsigned char **pder,
1085     size_t *pderlen);
1086 
1087 int X509v3_get_ext_count(const STACK_OF(X509_EXTENSION) *x);
1088 int X509v3_get_ext_by_NID(const STACK_OF(X509_EXTENSION) *x,
1089     int nid, int lastpos);
1090 int X509v3_get_ext_by_OBJ(const STACK_OF(X509_EXTENSION) *x,
1091     const ASN1_OBJECT *obj, int lastpos);
1092 int X509v3_get_ext_by_critical(const STACK_OF(X509_EXTENSION) *x,
1093     int crit, int lastpos);
1094 X509_EXTENSION *X509v3_get_ext(const STACK_OF(X509_EXTENSION) *x, int loc);
1095 X509_EXTENSION *X509v3_delete_ext(STACK_OF(X509_EXTENSION) *x, int loc);
1096 STACK_OF(X509_EXTENSION) *X509v3_add_ext(STACK_OF(X509_EXTENSION) **x,
1097     X509_EXTENSION *ex, int loc);
1098 STACK_OF(X509_EXTENSION) *X509v3_add_extensions(STACK_OF(X509_EXTENSION) **target,
1099     const STACK_OF(X509_EXTENSION) *exts);
1100 
1101 int X509_get_ext_count(const X509 *x);
1102 int X509_get_ext_by_NID(const X509 *x, int nid, int lastpos);
1103 int X509_get_ext_by_OBJ(const X509 *x, const ASN1_OBJECT *obj, int lastpos);
1104 int X509_get_ext_by_critical(const X509 *x, int crit, int lastpos);
1105 X509_EXTENSION *X509_get_ext(const X509 *x, int loc);
1106 X509_EXTENSION *X509_delete_ext(X509 *x, int loc);
1107 int X509_add_ext(X509 *x, X509_EXTENSION *ex, int loc);
1108 void *X509_get_ext_d2i(const X509 *x, int nid, int *crit, int *idx);
1109 int X509_add1_ext_i2d(X509 *x, int nid, void *value, int crit,
1110     unsigned long flags);
1111 
1112 int X509_CRL_get_ext_count(const X509_CRL *x);
1113 int X509_CRL_get_ext_by_NID(const X509_CRL *x, int nid, int lastpos);
1114 int X509_CRL_get_ext_by_OBJ(const X509_CRL *x, const ASN1_OBJECT *obj,
1115     int lastpos);
1116 int X509_CRL_get_ext_by_critical(const X509_CRL *x, int crit, int lastpos);
1117 X509_EXTENSION *X509_CRL_get_ext(const X509_CRL *x, int loc);
1118 X509_EXTENSION *X509_CRL_delete_ext(X509_CRL *x, int loc);
1119 int X509_CRL_add_ext(X509_CRL *x, X509_EXTENSION *ex, int loc);
1120 void *X509_CRL_get_ext_d2i(const X509_CRL *x, int nid, int *crit, int *idx);
1121 int X509_CRL_add1_ext_i2d(X509_CRL *x, int nid, void *value, int crit,
1122     unsigned long flags);
1123 
1124 int X509_REVOKED_get_ext_count(const X509_REVOKED *x);
1125 int X509_REVOKED_get_ext_by_NID(const X509_REVOKED *x, int nid, int lastpos);
1126 int X509_REVOKED_get_ext_by_OBJ(const X509_REVOKED *x, const ASN1_OBJECT *obj,
1127     int lastpos);
1128 int X509_REVOKED_get_ext_by_critical(const X509_REVOKED *x, int crit,
1129     int lastpos);
1130 X509_EXTENSION *X509_REVOKED_get_ext(const X509_REVOKED *x, int loc);
1131 X509_EXTENSION *X509_REVOKED_delete_ext(X509_REVOKED *x, int loc);
1132 int X509_REVOKED_add_ext(X509_REVOKED *x, X509_EXTENSION *ex, int loc);
1133 void *X509_REVOKED_get_ext_d2i(const X509_REVOKED *x, int nid, int *crit,
1134     int *idx);
1135 int X509_REVOKED_add1_ext_i2d(X509_REVOKED *x, int nid, void *value, int crit,
1136     unsigned long flags);
1137 
1138 X509_EXTENSION *X509_EXTENSION_create_by_NID(X509_EXTENSION **ex,
1139     int nid, int crit,
1140     ASN1_OCTET_STRING *data);
1141 X509_EXTENSION *X509_EXTENSION_create_by_OBJ(X509_EXTENSION **ex,
1142     const ASN1_OBJECT *obj, int crit,
1143     ASN1_OCTET_STRING *data);
1144 int X509_EXTENSION_set_object(X509_EXTENSION *ex, const ASN1_OBJECT *obj);
1145 int X509_EXTENSION_set_critical(X509_EXTENSION *ex, int crit);
1146 int X509_EXTENSION_set_data(X509_EXTENSION *ex, ASN1_OCTET_STRING *data);
1147 ASN1_OBJECT *X509_EXTENSION_get_object(X509_EXTENSION *ex);
1148 ASN1_OCTET_STRING *X509_EXTENSION_get_data(X509_EXTENSION *ne);
1149 int X509_EXTENSION_get_critical(const X509_EXTENSION *ex);
1150 
1151 int X509at_get_attr_count(const STACK_OF(X509_ATTRIBUTE) *x);
1152 int X509at_get_attr_by_NID(const STACK_OF(X509_ATTRIBUTE) *x, int nid,
1153     int lastpos);
1154 int X509at_get_attr_by_OBJ(const STACK_OF(X509_ATTRIBUTE) *sk,
1155     const ASN1_OBJECT *obj, int lastpos);
1156 X509_ATTRIBUTE *X509at_get_attr(const STACK_OF(X509_ATTRIBUTE) *x, int loc);
1157 X509_ATTRIBUTE *X509at_delete_attr(STACK_OF(X509_ATTRIBUTE) *x, int loc);
1158 STACK_OF(X509_ATTRIBUTE) *X509at_add1_attr(STACK_OF(X509_ATTRIBUTE) **x,
1159     X509_ATTRIBUTE *attr);
1160 STACK_OF(X509_ATTRIBUTE) *X509at_add1_attr_by_OBJ(STACK_OF(X509_ATTRIBUTE)
1161                                                       **x,
1162     const ASN1_OBJECT *obj,
1163     int type,
1164     const unsigned char *bytes,
1165     int len);
1166 STACK_OF(X509_ATTRIBUTE) *X509at_add1_attr_by_NID(STACK_OF(X509_ATTRIBUTE)
1167                                                       **x,
1168     int nid, int type,
1169     const unsigned char *bytes,
1170     int len);
1171 STACK_OF(X509_ATTRIBUTE) *X509at_add1_attr_by_txt(STACK_OF(X509_ATTRIBUTE)
1172                                                       **x,
1173     const char *attrname,
1174     int type,
1175     const unsigned char *bytes,
1176     int len);
1177 void *X509at_get0_data_by_OBJ(const STACK_OF(X509_ATTRIBUTE) *x,
1178     const ASN1_OBJECT *obj, int lastpos, int type);
1179 X509_ATTRIBUTE *X509_ATTRIBUTE_create_by_NID(X509_ATTRIBUTE **attr, int nid,
1180     int atrtype, const void *data,
1181     int len);
1182 X509_ATTRIBUTE *X509_ATTRIBUTE_create_by_OBJ(X509_ATTRIBUTE **attr,
1183     const ASN1_OBJECT *obj,
1184     int atrtype, const void *data,
1185     int len);
1186 X509_ATTRIBUTE *X509_ATTRIBUTE_create_by_txt(X509_ATTRIBUTE **attr,
1187     const char *atrname, int type,
1188     const unsigned char *bytes,
1189     int len);
1190 int X509_ATTRIBUTE_set1_object(X509_ATTRIBUTE *attr, const ASN1_OBJECT *obj);
1191 int X509_ATTRIBUTE_set1_data(X509_ATTRIBUTE *attr, int attrtype,
1192     const void *data, int len);
1193 void *X509_ATTRIBUTE_get0_data(X509_ATTRIBUTE *attr, int idx, int atrtype,
1194     void *data);
1195 int X509_ATTRIBUTE_count(const X509_ATTRIBUTE *attr);
1196 ASN1_OBJECT *X509_ATTRIBUTE_get0_object(X509_ATTRIBUTE *attr);
1197 ASN1_TYPE *X509_ATTRIBUTE_get0_type(X509_ATTRIBUTE *attr, int idx);
1198 
1199 int EVP_PKEY_get_attr_count(const EVP_PKEY *key);
1200 int EVP_PKEY_get_attr_by_NID(const EVP_PKEY *key, int nid, int lastpos);
1201 int EVP_PKEY_get_attr_by_OBJ(const EVP_PKEY *key, const ASN1_OBJECT *obj,
1202     int lastpos);
1203 X509_ATTRIBUTE *EVP_PKEY_get_attr(const EVP_PKEY *key, int loc);
1204 X509_ATTRIBUTE *EVP_PKEY_delete_attr(EVP_PKEY *key, int loc);
1205 int EVP_PKEY_add1_attr(EVP_PKEY *key, X509_ATTRIBUTE *attr);
1206 int EVP_PKEY_add1_attr_by_OBJ(EVP_PKEY *key,
1207     const ASN1_OBJECT *obj, int type,
1208     const unsigned char *bytes, int len);
1209 int EVP_PKEY_add1_attr_by_NID(EVP_PKEY *key,
1210     int nid, int type,
1211     const unsigned char *bytes, int len);
1212 int EVP_PKEY_add1_attr_by_txt(EVP_PKEY *key,
1213     const char *attrname, int type,
1214     const unsigned char *bytes, int len);
1215 
1216 /* lookup a cert from a X509 STACK */
1217 X509 *X509_find_by_issuer_and_serial(STACK_OF(X509) *sk, const X509_NAME *name,
1218     const ASN1_INTEGER *serial);
1219 X509 *X509_find_by_subject(STACK_OF(X509) *sk, const X509_NAME *name);
1220 
1221 DECLARE_ASN1_FUNCTIONS(PBEPARAM)
1222 DECLARE_ASN1_FUNCTIONS(PBE2PARAM)
1223 DECLARE_ASN1_FUNCTIONS(PBKDF2PARAM)
1224 DECLARE_ASN1_FUNCTIONS(PBMAC1PARAM)
1225 #ifndef OPENSSL_NO_SCRYPT
1226 DECLARE_ASN1_FUNCTIONS(SCRYPT_PARAMS)
1227 #endif
1228 
1229 int PKCS5_pbe_set0_algor(X509_ALGOR *algor, int alg, int iter,
1230     const unsigned char *salt, int saltlen);
1231 int PKCS5_pbe_set0_algor_ex(X509_ALGOR *algor, int alg, int iter,
1232     const unsigned char *salt, int saltlen,
1233     OSSL_LIB_CTX *libctx);
1234 
1235 X509_ALGOR *PKCS5_pbe_set(int alg, int iter,
1236     const unsigned char *salt, int saltlen);
1237 X509_ALGOR *PKCS5_pbe_set_ex(int alg, int iter,
1238     const unsigned char *salt, int saltlen,
1239     OSSL_LIB_CTX *libctx);
1240 
1241 X509_ALGOR *PKCS5_pbe2_set(const EVP_CIPHER *cipher, int iter,
1242     unsigned char *salt, int saltlen);
1243 X509_ALGOR *PKCS5_pbe2_set_iv(const EVP_CIPHER *cipher, int iter,
1244     unsigned char *salt, int saltlen,
1245     unsigned char *aiv, int prf_nid);
1246 X509_ALGOR *PKCS5_pbe2_set_iv_ex(const EVP_CIPHER *cipher, int iter,
1247     unsigned char *salt, int saltlen,
1248     unsigned char *aiv, int prf_nid,
1249     OSSL_LIB_CTX *libctx);
1250 
1251 #ifndef OPENSSL_NO_SCRYPT
1252 X509_ALGOR *PKCS5_pbe2_set_scrypt(const EVP_CIPHER *cipher,
1253     const unsigned char *salt, int saltlen,
1254     unsigned char *aiv, uint64_t N, uint64_t r,
1255     uint64_t p);
1256 #endif
1257 
1258 X509_ALGOR *PKCS5_pbkdf2_set(int iter, unsigned char *salt, int saltlen,
1259     int prf_nid, int keylen);
1260 X509_ALGOR *PKCS5_pbkdf2_set_ex(int iter, unsigned char *salt, int saltlen,
1261     int prf_nid, int keylen,
1262     OSSL_LIB_CTX *libctx);
1263 
1264 PBKDF2PARAM *PBMAC1_get1_pbkdf2_param(const X509_ALGOR *macalg);
1265 /* PKCS#8 utilities */
1266 
1267 DECLARE_ASN1_FUNCTIONS(PKCS8_PRIV_KEY_INFO)
1268 
1269 EVP_PKEY *EVP_PKCS82PKEY(const PKCS8_PRIV_KEY_INFO *p8);
1270 EVP_PKEY *EVP_PKCS82PKEY_ex(const PKCS8_PRIV_KEY_INFO *p8, OSSL_LIB_CTX *libctx,
1271     const char *propq);
1272 PKCS8_PRIV_KEY_INFO *EVP_PKEY2PKCS8(const EVP_PKEY *pkey);
1273 
1274 int PKCS8_pkey_set0(PKCS8_PRIV_KEY_INFO *priv, ASN1_OBJECT *aobj,
1275     int version, int ptype, void *pval,
1276     unsigned char *penc, int penclen);
1277 int PKCS8_pkey_get0(const ASN1_OBJECT **ppkalg,
1278     const unsigned char **pk, int *ppklen,
1279     const X509_ALGOR **pa, const PKCS8_PRIV_KEY_INFO *p8);
1280 
1281 const STACK_OF(X509_ATTRIBUTE) *
1282 PKCS8_pkey_get0_attrs(const PKCS8_PRIV_KEY_INFO *p8);
1283 int PKCS8_pkey_add1_attr(PKCS8_PRIV_KEY_INFO *p8, X509_ATTRIBUTE *attr);
1284 int PKCS8_pkey_add1_attr_by_NID(PKCS8_PRIV_KEY_INFO *p8, int nid, int type,
1285     const unsigned char *bytes, int len);
1286 int PKCS8_pkey_add1_attr_by_OBJ(PKCS8_PRIV_KEY_INFO *p8, const ASN1_OBJECT *obj,
1287     int type, const unsigned char *bytes, int len);
1288 
1289 void X509_PUBKEY_set0_public_key(X509_PUBKEY *pub,
1290     unsigned char *penc, int penclen);
1291 int X509_PUBKEY_set0_param(X509_PUBKEY *pub, ASN1_OBJECT *aobj,
1292     int ptype, void *pval,
1293     unsigned char *penc, int penclen);
1294 int X509_PUBKEY_get0_param(ASN1_OBJECT **ppkalg,
1295     const unsigned char **pk, int *ppklen,
1296     X509_ALGOR **pa, const X509_PUBKEY *pub);
1297 int X509_PUBKEY_eq(const X509_PUBKEY *a, const X509_PUBKEY *b);
1298 
1299 #ifdef __cplusplus
1300 }
1301 #endif
1302 #endif