xref: /openbsd/sbin/isakmpd/x509.h (revision 3d8817e4)
1 /* $OpenBSD: x509.h,v 1.22 2007/08/05 09:43:09 tom Exp $	 */
2 /* $EOM: x509.h,v 1.11 2000/09/28 12:53:27 niklas Exp $	 */
3 
4 /*
5  * Copyright (c) 1998, 1999 Niels Provos.  All rights reserved.
6  * Copyright (c) 1999 Angelos D. Keromytis.  All rights reserved.
7  * Copyright (c) 2000, 2001 Niklas Hallqvist.  All rights reserved.
8  *
9  * Redistribution and use in source and binary forms, with or without
10  * modification, are permitted provided that the following conditions
11  * are met:
12  * 1. Redistributions of source code must retain the above copyright
13  *    notice, this list of conditions and the following disclaimer.
14  * 2. Redistributions in binary form must reproduce the above copyright
15  *    notice, this list of conditions and the following disclaimer in the
16  *    documentation and/or other materials provided with the distribution.
17  *
18  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
19  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
20  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
21  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
22  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
23  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
24  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
25  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
26  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
27  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
28  */
29 
30 /*
31  * This code was written under funding by Ericsson Radio Systems.
32  */
33 
34 #ifndef _X509_H_
35 #define _X509_H_
36 
37 #include "libcrypto.h"
38 
39 #define X509v3_RFC_NAME		1
40 #define X509v3_DNS_NAME		2
41 #define X509v3_IP_ADDR		7
42 
43 struct x509_attribval {
44 	char           *type;
45 	char           *val;
46 };
47 
48 /*
49  * The acceptable certification authority.
50  * XXX We only support two names at the moment, as of ASN this can
51  * be dynamic but we don't care for now.
52  */
53 struct x509_aca {
54 	struct x509_attribval name1;
55 	struct x509_attribval name2;
56 };
57 
58 struct X509;
59 struct X509_STORE;
60 
61 /* Functions provided by cert handler.  */
62 
63 int             x509_certreq_validate(u_int8_t *, u_int32_t);
64 int             x509_certreq_decode(void **, u_int8_t *, u_int32_t);
65 void            x509_cert_free(void *);
66 void           *x509_cert_get(u_int8_t *, u_int32_t);
67 int             x509_cert_get_key(void *, void *);
68 int             x509_cert_get_subjects(void *, int *, u_int8_t ***, u_int32_t **);
69 int             x509_cert_init(void);
70 int             x509_crl_init(void);
71 int             x509_cert_obtain(u_int8_t *, size_t, void *, u_int8_t **,
72 		    u_int32_t *);
73 int             x509_cert_validate(void *);
74 void            x509_free_aca(void *);
75 void           *x509_cert_dup(void *);
76 void            x509_serialize(void *, u_int8_t **, u_int32_t *);
77 char           *x509_printable(void *);
78 void           *x509_from_printable(char *);
79 int		x509_ca_count(void);
80 
81 /* Misc. X509 certificate functions.  */
82 
83 char           *x509_DN_string(u_int8_t *, size_t);
84 int             x509_cert_insert(int, void *);
85 int             x509_cert_subjectaltname(X509 * cert, u_char **, u_int *);
86 X509           *x509_from_asn(u_char *, u_int);
87 int             x509_generate_kn(int, X509 *);
88 int             x509_read_from_dir(X509_STORE *, char *, int, int *);
89 int             x509_read_crls_from_dir(X509_STORE *, char *);
90 
91 #endif				/* _X509_H_ */
92