xref: /reactos/sdk/include/psdk/wincrypt.h (revision c2c66aff)
1 /*
2  * Copyright (C) 2002 Travis Michielsen
3  * Copyright (C) 2004-2005 Juan Lang
4  * Copyright (C) 2007 Vijay Kiran Kamuju
5  *
6  * This library is free software; you can redistribute it and/or
7  * modify it under the terms of the GNU Lesser General Public
8  * License as published by the Free Software Foundation; either
9  * version 2.1 of the License, or (at your option) any later version.
10  *
11  * This library is distributed in the hope that it will be useful,
12  * but WITHOUT ANY WARRANTY; without even the implied warranty of
13  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
14  * Lesser General Public License for more details.
15  *
16  * You should have received a copy of the GNU Lesser General Public
17  * License along with this library; if not, write to the Free Software
18  * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
19  */
20 
21 #ifndef __WINE_WINCRYPT_H
22 #define __WINE_WINCRYPT_H
23 
24 #include <specstrings.h>
25 
26 #ifdef __cplusplus
27 extern "C" {
28 #endif
29 
30 #ifdef _MSC_VER
31 #pragma warning(push)
32 #pragma warning(disable:4201)
33 #endif
34 
35 #include <bcrypt.h>
36 /* FIXME: #include <ncrypt.h> */
37 
38 #ifdef _ADVAPI32_
39 # define WINADVAPI
40 #else
41 # define WINADVAPI DECLSPEC_IMPORT
42 #endif
43 
44 /* some typedefs for function parameters */
45 typedef unsigned int ALG_ID;
46 typedef ULONG_PTR HCRYPTPROV;
47 typedef ULONG_PTR HCRYPTPROV_OR_NCRYPT_KEY_HANDLE;
48 typedef ULONG_PTR HCRYPTPROV_LEGACY;
49 typedef ULONG_PTR HCRYPTKEY;
50 typedef ULONG_PTR HCRYPTHASH;
51 typedef void *HCERTSTORE;
52 typedef void *HCRYPTMSG;
53 typedef void *HCERTSTOREPROV;
54 typedef void *HCRYPTOIDFUNCSET;
55 typedef void *HCRYPTOIDFUNCADDR;
56 typedef void *HCRYPTDEFAULTCONTEXT;
57 
58 /* CSP Structs */
59 
60 typedef struct _PROV_ENUMALGS {
61   ALG_ID aiAlgid;
62   DWORD  dwBitLen;
63   DWORD  dwNameLen;
64   CHAR   szName[20];
65 } PROV_ENUMALGS;
66 
67 typedef struct _PROV_ENUMALGS_EX {
68   ALG_ID aiAlgid;
69   DWORD  dwDefaultLen;
70   DWORD  dwMinLen;
71   DWORD  dwMaxLen;
72   DWORD  dwProtocols;
73   DWORD  dwNameLen;
74   CHAR   szName[20];
75   DWORD  dwLongNameLen;
76   CHAR   szLongName[40];
77 } PROV_ENUMALGS_EX;
78 
79 #define SCHANNEL_MAC_KEY 0
80 #define SCHANNEL_ENC_KEY 1
81 
82 typedef struct _SCHANNEL_ALG {
83   DWORD  dwUse;
84   ALG_ID Algid;
85   DWORD  cBits;
86   DWORD  dwFlags;
87   DWORD  dwReserved;
88 } SCHANNEL_ALG, *PSCHANNEL_ALG;
89 
90 
91 #define CRYPT_IPSEC_HMAC_KEY 0x0100
92 
93 typedef struct _HMAC_INFO {
94   ALG_ID HashAlgid;
95   BYTE*  pbInnerString;
96   DWORD  cbInnerString;
97   BYTE*  pbOuterString;
98   DWORD  cbOuterString;
99 } HMAC_INFO, *PHMAC_INFO;
100 
101 typedef struct _CRYPTOAPI_BLOB {
102   DWORD    cbData;
103   BYTE*    pbData;
104 } CRYPT_INTEGER_BLOB,  *PCRYPT_INTEGER_BLOB,
105   CRYPT_UINT_BLOB,     *PCRYPT_UINT_BLOB,
106   CRYPT_OBJID_BLOB,    *PCRYPT_OBJID_BLOB,
107   CERT_NAME_BLOB,      *PCERT_NAME_BLOB,
108   CERT_RDN_VALUE_BLOB, *PCERT_RDN_VALUE_BLOB,
109   CERT_BLOB,           *PCERT_BLOB,
110   CRL_BLOB,            *PCRL_BLOB,
111   DATA_BLOB,           *PDATA_BLOB,
112   CRYPT_DATA_BLOB,     *PCRYPT_DATA_BLOB,
113   CRYPT_HASH_BLOB,     *PCRYPT_HASH_BLOB,
114   CRYPT_DIGEST_BLOB,   *PCRYPT_DIGEST_BLOB,
115   CRYPT_DER_BLOB,      *PCRYPT_DER_BLOB,
116   CRYPT_ATTR_BLOB,     *PCRYPT_ATTR_BLOB;
117 
118 typedef struct _CRYPTPROTECT_PROMPTSTRUCT{
119   DWORD   cbSize;
120   DWORD   dwPromptFlags;
121   HWND    hwndApp;
122   LPCWSTR szPrompt;
123 } CRYPTPROTECT_PROMPTSTRUCT, *PCRYPTPROTECT_PROMPTSTRUCT;
124 
125 typedef struct _CRYPT_ALGORITHM_IDENTIFIER {
126   LPSTR            pszObjId;
127   CRYPT_OBJID_BLOB Parameters;
128 } CRYPT_ALGORITHM_IDENTIFIER, *PCRYPT_ALGORITHM_IDENTIFIER;
129 
130 typedef struct _CRYPT_ATTRIBUTE_TYPE_VALUE {
131   LPSTR               pszObjId;
132   CRYPT_OBJID_BLOB    Value;
133 } CRYPT_ATTRIBUTE_TYPE_VALUE, *PCRYPT_ATTRIBUTE_TYPE_VALUE;
134 
135 typedef struct _PUBLICKEYSTRUC {
136     BYTE   bType;
137     BYTE   bVersion;
138     WORD   reserved;
139     ALG_ID aiKeyAlg;
140 } BLOBHEADER, PUBLICKEYSTRUC;
141 
142 typedef struct _RSAPUBKEY {
143     DWORD   magic;
144     DWORD   bitlen;
145     DWORD   pubexp;
146 } RSAPUBKEY;
147 
148 typedef struct _PUBKEY {
149     DWORD   magic;
150     DWORD   bitlen;
151 } DHPUBKEY, DSSPUBKEY, KEAPUBKEY, TEKPUBKEY;
152 
153 typedef struct _DSSSEED {
154     DWORD   counter;
155     BYTE    seed[20];
156 } DSSSEED;
157 
158 typedef struct _PUBKEYVER3 {
159     DWORD   magic;
160     DWORD   bitlenP;
161     DWORD   bitlenQ;
162     DWORD   bitlenJ;
163     DSSSEED DSSSeed;
164 } DHPUBKEY_VER3, DSSPUBKEY_VER3;
165 
166 typedef struct _PRIVKEYVER3 {
167     DWORD   magic;
168     DWORD   bitlenP;
169     DWORD   bitlenQ;
170     DWORD   bitlenJ;
171     DWORD   bitlenX;
172     DSSSEED DSSSeed;
173 } DHPRIVKEY_VER3, DSSPRIVKEY_VER3;
174 
175 typedef struct _KEY_TYPE_SUBTYPE {
176     DWORD   dwKeySpec;
177     GUID    Type;
178     GUID    SubType;
179 } KEY_TYPE_SUBTYPE, *PKEY_TYPE_SUBTYPE;
180 
181 typedef struct _CERT_FORTEZZA_DATA_PROP {
182     unsigned char   SerialNumber[8];
183     int             CertIndex;
184     unsigned char   CertLabel[36];
185 } CERT_FORTEZZA_DATA_PROP;
186 
187 typedef struct _CMS_DH_KEY_INFO {
188     DWORD             dwVersion;
189     ALG_ID            Algid;
190     LPSTR             pszContentEncObjId;
191     CRYPT_DATA_BLOB   PubInfo;
192     void              *pReserved;
193 } CMS_DH_KEY_INFO, *PCMS_DH_KEY_INFO;
194 
195 typedef struct _CRYPT_BIT_BLOB {
196     DWORD cbData;
197     BYTE  *pbData;
198     DWORD cUnusedBits;
199 } CRYPT_BIT_BLOB, *PCRYPT_BIT_BLOB;
200 
201 typedef struct _CRYPT_KEY_PROV_PARAM {
202     DWORD dwParam;
203     BYTE *pbData;
204     DWORD cbData;
205     DWORD dwFlags;
206 } CRYPT_KEY_PROV_PARAM, *PCRYPT_KEY_PROV_PARAM;
207 
208 typedef struct _CRYPT_KEY_PROV_INFO {
209     LPWSTR                pwszContainerName;
210     LPWSTR                pwszProvName;
211     DWORD                 dwProvType;
212     DWORD                 dwFlags;
213     DWORD                 cProvParam;
214     PCRYPT_KEY_PROV_PARAM rgProvParam;
215     DWORD                 dwKeySpec;
216 } CRYPT_KEY_PROV_INFO, *PCRYPT_KEY_PROV_INFO;
217 
218 typedef struct _CERT_KEY_CONTEXT {
219     DWORD      cbSize;
220     HCRYPTPROV hCryptProv;
221     DWORD      dwKeySpec;
222 } CERT_KEY_CONTEXT, *PCERT_KEY_CONTEXT;
223 
224 typedef struct _CERT_PUBLIC_KEY_INFO {
225     CRYPT_ALGORITHM_IDENTIFIER Algorithm;
226     CRYPT_BIT_BLOB             PublicKey;
227 } CERT_PUBLIC_KEY_INFO, *PCERT_PUBLIC_KEY_INFO;
228 
229 typedef struct _CERT_EXTENSION {
230     LPSTR               pszObjId;
231     BOOL                fCritical;
232     CRYPT_OBJID_BLOB    Value;
233 } CERT_EXTENSION, *PCERT_EXTENSION;
234 
235 typedef struct _CERT_EXTENSIONS {
236     DWORD           cExtension;
237     PCERT_EXTENSION rgExtension;
238 } CERT_EXTENSIONS, *PCERT_EXTENSIONS;
239 
240 typedef struct _CERT_INFO {
241     DWORD                      dwVersion;
242     CRYPT_INTEGER_BLOB         SerialNumber;
243     CRYPT_ALGORITHM_IDENTIFIER SignatureAlgorithm;
244     CERT_NAME_BLOB             Issuer;
245     FILETIME                   NotBefore;
246     FILETIME                   NotAfter;
247     CERT_NAME_BLOB             Subject;
248     CERT_PUBLIC_KEY_INFO       SubjectPublicKeyInfo;
249     CRYPT_BIT_BLOB             IssuerUniqueId;
250     CRYPT_BIT_BLOB             SubjectUniqueId;
251     DWORD                      cExtension;
252     PCERT_EXTENSION            rgExtension;
253 } CERT_INFO, *PCERT_INFO;
254 
255 typedef struct _CERT_RDN_ATTR {
256     LPSTR               pszObjId;
257     DWORD               dwValueType;
258     CERT_RDN_VALUE_BLOB Value;
259 } CERT_RDN_ATTR, *PCERT_RDN_ATTR;
260 
261 typedef struct _CERT_RDN {
262     DWORD          cRDNAttr;
263     PCERT_RDN_ATTR rgRDNAttr;
264 } CERT_RDN, *PCERT_RDN;
265 
266 typedef struct _CERT_NAME_INFO {
267     DWORD     cRDN;
268     PCERT_RDN rgRDN;
269 } CERT_NAME_INFO, *PCERT_NAME_INFO;
270 
271 typedef struct _CERT_NAME_VALUE {
272     DWORD               dwValueType;
273     CERT_RDN_VALUE_BLOB Value;
274 } CERT_NAME_VALUE, *PCERT_NAME_VALUE;
275 
276 typedef struct _CERT_ENCRYPTED_PRIVATE_KEY_INFO {
277     CRYPT_ALGORITHM_IDENTIFIER EncryptionAlgorithm;
278     CRYPT_DATA_BLOB            EncryptedPrivateKey;
279 } CERT_ENCRYPTED_PRIVATE_KEY_INFO, *PCERT_ENCRYPTED_PRIVATE_KEY_INFO;
280 
281 typedef struct _CERT_AUTHORITY_KEY_ID_INFO {
282     CRYPT_DATA_BLOB    KeyId;
283     CERT_NAME_BLOB     CertIssuer;
284     CRYPT_INTEGER_BLOB CertSerialNumber;
285 } CERT_AUTHORITY_KEY_ID_INFO, *PCERT_AUTHORITY_KEY_ID_INFO;
286 
287 typedef struct _CERT_PRIVATE_KEY_VALIDITY {
288     FILETIME NotBefore;
289     FILETIME NotAfter;
290 } CERT_PRIVATE_KEY_VALIDITY, *PCERT_PRIVATE_KEY_VALIDITY;
291 
292 typedef struct _CERT_KEY_ATTRIBUTES_INFO {
293     CRYPT_DATA_BLOB            KeyId;
294     CRYPT_BIT_BLOB             IntendedKeyUsage;
295     PCERT_PRIVATE_KEY_VALIDITY pPrivateKeyUsagePeriod;
296 } CERT_KEY_ATTRIBUTES_INFO, *PCERT_KEY_ATTRIBUTES_INFO;
297 
298 /* byte 0 */
299 #define CERT_DIGITAL_SIGNATURE_KEY_USAGE 0x80
300 #define CERT_NON_REPUDIATION_KEY_USAGE   0x40
301 #define CERT_KEY_ENCIPHERMENT_KEY_USAGE  0x20
302 #define CERT_DATA_ENCIPHERMENT_KEY_USAGE 0x10
303 #define CERT_KEY_AGREEMENT_KEY_USAGE     0x08
304 #define CERT_KEY_CERT_SIGN_KEY_USAGE     0x04
305 #define CERT_OFFLINE_CRL_SIGN_KEY_USAGE  0x02
306 #define CERT_CRL_SIGN_KEY_USAGE          0x02
307 #define CERT_ENCIPHER_ONLY_KEY_USAGE     0x01
308 /* byte 1 */
309 #define CERT_DECIPHER_ONLY_KEY_USAGE     0x80
310 
311 typedef struct _CERT_POLICY_ID {
312     DWORD  cCertPolicyElementId;
313     LPSTR *rgbszCertPolicyElementId;
314 } CERT_POLICY_ID, *PCERT_POLICY_ID;
315 
316 typedef struct _CERT_KEY_USAGE_RESTRICTION_INFO {
317     DWORD           cCertPolicyId;
318     PCERT_POLICY_ID rgCertPolicyId;
319     CRYPT_BIT_BLOB  RestrictedKeyUsage;
320 } CERT_KEY_USAGE_RESTRICTION_INFO, *PCERT_KEY_USAGE_RESTRICTION_INFO;
321 
322 typedef struct _CERT_OTHER_NAME {
323     LPSTR            pszObjId;
324     CRYPT_OBJID_BLOB Value;
325 } CERT_OTHER_NAME, *PCERT_OTHER_NAME;
326 
327 typedef struct _CERT_ALT_NAME_ENTRY {
328     DWORD dwAltNameChoice;
329     union {
330         PCERT_OTHER_NAME pOtherName;
331         LPWSTR           pwszRfc822Name;
332         LPWSTR           pwszDNSName;
333         CERT_NAME_BLOB   DirectoryName;
334         LPWSTR           pwszURL;
335         CRYPT_DATA_BLOB  IPAddress;
336         LPSTR            pszRegisteredID;
337     } DUMMYUNIONNAME;
338 } CERT_ALT_NAME_ENTRY, *PCERT_ALT_NAME_ENTRY;
339 
340 #define CERT_ALT_NAME_OTHER_NAME     1
341 #define CERT_ALT_NAME_RFC822_NAME    2
342 #define CERT_ALT_NAME_DNS_NAME       3
343 #define CERT_ALT_NAME_X400_ADDRESS   4
344 #define CERT_ALT_NAME_DIRECTORY_NAME 5
345 #define CERT_ALT_NAME_EDI_PARTY_NAME 6
346 #define CERT_ALT_NAME_URL            7
347 #define CERT_ALT_NAME_IP_ADDRESS     8
348 #define CERT_ALT_NAME_REGISTERED_ID  9
349 
350 typedef struct _CERT_ALT_NAME_INFO {
351     DWORD                cAltEntry;
352     PCERT_ALT_NAME_ENTRY rgAltEntry;
353 } CERT_ALT_NAME_INFO, *PCERT_ALT_NAME_INFO;
354 
355 #define CERT_ALT_NAME_ENTRY_ERR_INDEX_MASK  0xff
356 #define CERT_ALT_NAME_ENTRY_ERR_INDEX_SHIFT 16
357 #define CERT_ALT_NAME_VALUE_ERR_INDEX_MASK  0x0000ffff
358 #define CERT_ALT_NAME_VALUE_ERR_INDEX_SHIFT 0
359 #define GET_CERT_ALT_NAME_ENTRY_ERR_INDEX(x) \
360  (((x) >> CERT_ALT_NAME_ENTRY_ERR_INDEX_SHIFT) & \
361   CERT_ALT_NAME_ENTRY_ERR_INDEX_MASK)
362 #define GET_CERT_ALT_NAME_VALUE_ERR_INDEX(x) \
363  ((x) & CERT_ALT_NAME_VALUE_ERR_INDEX_MASK)
364 
365 typedef struct _CERT_BASIC_CONSTRAINTS_INFO {
366     CRYPT_BIT_BLOB  SubjectType;
367     BOOL            fPathLenConstraint;
368     DWORD           dwPathLenConstraint;
369     DWORD           cSubtreesConstraint;
370     CERT_NAME_BLOB *rgSubtreesConstraint;
371 } CERT_BASIC_CONSTRAINTS_INFO, *PCERT_BASIC_CONSTRAINTS_INFO;
372 
373 #define CERT_CA_SUBJECT_FLAG         0x80
374 #define CERT_END_ENTITY_SUBJECT_FLAG 0x40
375 
376 typedef struct _CERT_BASIC_CONSTRAINTS2_INFO {
377     BOOL  fCA;
378     BOOL  fPathLenConstraint;
379     DWORD dwPathLenConstraint;
380 } CERT_BASIC_CONSTRAINTS2_INFO, *PCERT_BASIC_CONSTRAINTS2_INFO;
381 
382 typedef struct _CERT_POLICY_QUALIFIER_INFO {
383     LPSTR            pszPolicyQualifierId;
384     CRYPT_OBJID_BLOB Qualifier;
385 } CERT_POLICY_QUALIFIER_INFO, *PCERT_POLICY_QUALIFIER_INFO;
386 
387 typedef struct _CERT_POLICY_INFO {
388     LPSTR                       pszPolicyIdentifier;
389     DWORD                       cPolicyQualifier;
390     CERT_POLICY_QUALIFIER_INFO *rgPolicyQualifier;
391 } CERT_POLICY_INFO, *PCERT_POLICY_INFO;
392 
393 typedef struct _CERT_POLICIES_INFO {
394     DWORD             cPolicyInfo;
395     CERT_POLICY_INFO *rgPolicyInfo;
396 } CERT_POLICIES_INFO, *PCERT_POLICIES_INFO;
397 
398 typedef struct _CERT_POLICY_QUALIFIER_NOTICE_REFERENCE {
399     LPSTR pszOrganization;
400     DWORD cNoticeNumbers;
401     int  *rgNoticeNumbers;
402 } CERT_POLICY_QUALIFIER_NOTICE_REFERENCE,
403  *PCERT_POLICY_QUALIFIER_NOTICE_REFERENCE;
404 
405 typedef struct _CERT_POLICY_QUALIFIER_USER_NOTICE {
406     CERT_POLICY_QUALIFIER_NOTICE_REFERENCE *pNoticeReference;
407     LPWSTR                                  pszDisplayText;
408 } CERT_POLICY_QUALIFIER_USER_NOTICE, *PCERT_POLICY_QUALIFIER_USER_NOTICE;
409 
410 typedef struct _CPS_URLS {
411     LPWSTR                      pszURL;
412     CRYPT_ALGORITHM_IDENTIFIER *pAlgorithm;
413     CRYPT_DATA_BLOB            *pDigest;
414 } CPS_URLS, *PCPS_URLS;
415 
416 typedef struct _CERT_POLICY95_QUALIFIER1 {
417     LPWSTR    pszPracticesReference;
418     LPSTR     pszNoticeIdentifier;
419     LPSTR     pszNSINoticeIdentifier;
420     DWORD     cCPSURLs;
421     CPS_URLS *rgCPSURLs;
422 } CERT_POLICY95_QUALIFIER1, *PCERT_POLICY95_QUALIFIER1;
423 
424 typedef struct _CERT_POLICY_MAPPING {
425     LPSTR pszIssuerDomainPolicy;
426     LPSTR pszSubjectDomainPolicy;
427 } CERT_POLICY_MAPPING, *PCERT_POLICY_MAPPING;
428 
429 typedef struct _CERT_POLICY_MAPPINGS_INFO {
430     DWORD                cPolicyMapping;
431     PCERT_POLICY_MAPPING rgPolicyMapping;
432 } CERT_POLICY_MAPPINGS_INFO, *PCERT_POLICY_MAPPINGS_INFO;
433 
434 typedef struct _CERT_POLICY_CONSTRAINTS_INFO {
435     BOOL  fRequireExplicitPolicy;
436     DWORD dwRequireExplicitPolicySkipCerts;
437     BOOL  fInhibitPolicyMapping;
438     DWORD dwInhibitPolicyMappingSkipCerts;
439 } CERT_POLICY_CONSTRAINTS_INFO, *PCERT_POLICY_CONSTRAINTS_INFO;
440 
441 typedef struct _CRYPT_CONTENT_INFO_SEQUENCE_OF_ANY {
442     LPSTR           pszObjId;
443     DWORD           cValue;
444     PCRYPT_DER_BLOB rgValue;
445 } CRYPT_CONTENT_INFO_SEQUENCE_OF_ANY, *PCRYPT_CONTENT_INFO_SEQUENCE_OF_ANY;
446 
447 typedef struct _CRYPT_CONTENT_INFO {
448     LPSTR          pszObjId;
449     CRYPT_DER_BLOB Content;
450 } CRYPT_CONTENT_INFO, *PCRYPT_CONTENT_INFO;
451 
452 typedef struct _CRYPT_SEQUENCE_OF_ANY {
453     DWORD           cValue;
454     PCRYPT_DER_BLOB rgValue;
455 } CRYPT_SEQUENCE_OF_ANY, *PCRYPT_SEQUENCE_OF_ANY;
456 
457 typedef struct _CERT_AUTHORITY_KEY_ID2_INFO {
458     CRYPT_DATA_BLOB    KeyId;
459     CERT_ALT_NAME_INFO AuthorityCertIssuer;
460     CRYPT_INTEGER_BLOB AuthorityCertSerialNumber;
461 } CERT_AUTHORITY_KEY_ID2_INFO, *PCERT_AUTHORITY_KEY_ID2_INFO;
462 
463 typedef struct _CERT_ACCESS_DESCRIPTION {
464     LPSTR               pszAccessMethod;
465     CERT_ALT_NAME_ENTRY AccessLocation;
466 } CERT_ACCESS_DESCRIPTION, *PCERT_ACCESS_DESCRIPTION;
467 
468 typedef struct _CERT_AUTHORITY_INFO_ACCESS {
469     DWORD                    cAccDescr;
470     PCERT_ACCESS_DESCRIPTION rgAccDescr;
471 } CERT_AUTHORITY_INFO_ACCESS, *PCERT_AUTHORITY_INFO_ACCESS;
472 
473 typedef struct _CERT_CONTEXT {
474     DWORD      dwCertEncodingType;
475     BYTE       *pbCertEncoded;
476     DWORD      cbCertEncoded;
477     PCERT_INFO pCertInfo;
478     HCERTSTORE hCertStore;
479 } CERT_CONTEXT, *PCERT_CONTEXT;
480 typedef const CERT_CONTEXT *PCCERT_CONTEXT;
481 
482 typedef struct _CRL_ENTRY {
483     CRYPT_INTEGER_BLOB SerialNumber;
484     FILETIME           RevocationDate;
485     DWORD              cExtension;
486     PCERT_EXTENSION    rgExtension;
487 } CRL_ENTRY, *PCRL_ENTRY;
488 
489 typedef struct _CRL_INFO {
490     DWORD           dwVersion;
491     CRYPT_ALGORITHM_IDENTIFIER SignatureAlgorithm;
492     CERT_NAME_BLOB  Issuer;
493     FILETIME        ThisUpdate;
494     FILETIME        NextUpdate;
495     DWORD           cCRLEntry;
496     PCRL_ENTRY      rgCRLEntry;
497     DWORD           cExtension;
498     PCERT_EXTENSION rgExtension;
499 } CRL_INFO, *PCRL_INFO;
500 
501 typedef struct _CRL_DIST_POINT_NAME {
502     DWORD dwDistPointNameChoice;
503     union {
504         CERT_ALT_NAME_INFO FullName;
505     } DUMMYUNIONNAME;
506 } CRL_DIST_POINT_NAME, *PCRL_DIST_POINT_NAME;
507 
508 #define CRL_DIST_POINT_NO_NAME         0
509 #define CRL_DIST_POINT_FULL_NAME       1
510 #define CRL_DIST_POINT_ISSUER_RDN_NAME 2
511 
512 typedef struct _CRL_DIST_POINT {
513     CRL_DIST_POINT_NAME DistPointName;
514     CRYPT_BIT_BLOB      ReasonFlags;
515     CERT_ALT_NAME_INFO  CRLIssuer;
516 } CRL_DIST_POINT, *PCRL_DIST_POINT;
517 
518 #define CRL_REASON_UNUSED_FLAG                 0x80
519 #define CRL_REASON_KEY_COMPROMISE_FLAG         0x40
520 #define CRL_REASON_CA_COMPROMISE_FLAG          0x20
521 #define CRL_REASON_AFFILIATION_CHANGED_FLAG    0x10
522 #define CRL_REASON_SUPERSEDED_FLAG             0x08
523 #define CRL_REASON_CESSATION_OF_OPERATION_FLAG 0x04
524 #define CRL_REASON_CERTIFICATE_HOLD_FLAG       0x02
525 
526 typedef struct _CRL_DIST_POINTS_INFO {
527     DWORD           cDistPoint;
528     PCRL_DIST_POINT rgDistPoint;
529 } CRL_DIST_POINTS_INFO, *PCRL_DIST_POINTS_INFO;
530 
531 #define CRL_DIST_POINT_ERR_INDEX_MASK  0x7f
532 #define CRL_DIST_POINT_ERR_INDEX_SHIFT 24
533 #define GET_CRL_DIST_POINT_ERR_INDEX(x) \
534  (((x) >> CRL_DIST_POINT_ERR_INDEX_SHIFT) & CRL_DIST_POINT_ERR_INDEX_MASK)
535 
536 #define CRL_DIST_POINT_ERR_CRL_ISSUER_BIT 0x80000000L
537 #define IS_CRL_DIST_POINT_ERR_CRL_ISSUER(x) \
538  ((x) & CRL_DIST_POINT_ERR_CRL_ISSUER_BIT)
539 
540 typedef struct _CROSS_CERT_DIST_POINTS_INFO {
541     DWORD               dwSyncDeltaTime;
542     DWORD               cDistPoint;
543     PCERT_ALT_NAME_INFO rgDistPoint;
544 } CROSS_CERT_DIST_POINTS_INFO, *PCROSS_CERT_DIST_POINTS_INFO;
545 
546 #define CROSS_CERT_DIST_POINT_ERR_INDEX_MASK  0xff
547 #define CROSS_CERT_DIST_POINT_ERR_INDEX_SHIFT 24
548 #define GET_CROSS_CERT_DIST_POINT_ERR_INDEX(x) \
549  (((x) >> CROSS_CERT_DIST_POINT_ERR_INDEX_SHIFT) & \
550  CROSS_CERT_DIST_POINT_ERR_INDEX_MASK)
551 
552 typedef struct _CERT_PAIR {
553     CERT_BLOB Forward;
554     CERT_BLOB Reverse;
555 } CERT_PAIR, *PCERT_PAIR;
556 
557 typedef struct _CRL_ISSUING_DIST_POINT {
558     CRL_DIST_POINT_NAME DistPointName;
559     BOOL                fOnlyContainsUserCerts;
560     BOOL                fOnlyContainsCACerts;
561     CRYPT_BIT_BLOB      OnlySomeReasonFlags;
562     BOOL                fIndirectCRL;
563 } CRL_ISSUING_DIST_POINT, *PCRL_ISSUING_DIST_POINT;
564 
565 typedef struct _CERT_GENERAL_SUBTREE {
566     CERT_ALT_NAME_ENTRY Base;
567     DWORD               dwMinimum;
568     BOOL                fMaximum;
569     DWORD               dwMaximum;
570 } CERT_GENERAL_SUBTREE, *PCERT_GENERAL_SUBTREE;
571 
572 typedef struct _CERT_NAME_CONSTRAINTS_INFO {
573     DWORD                 cPermittedSubtree;
574     PCERT_GENERAL_SUBTREE rgPermittedSubtree;
575     DWORD                 cExcludedSubtree;
576     PCERT_GENERAL_SUBTREE rgExcludedSubtree;
577 } CERT_NAME_CONSTRAINTS_INFO, *PCERT_NAME_CONSTRAINTS_INFO;
578 
579 #define CERT_EXCLUDED_SUBTREE_BIT 0x80000000L
580 #define IS_CERT_EXCLUDED_SUBTREE(x) ((x) & CERT_EXCLUDED_SUBTREE_BIT)
581 
582 typedef struct _CRYPT_ATTRIBUTE {
583     LPSTR            pszObjId;
584     DWORD            cValue;
585     PCRYPT_DATA_BLOB rgValue;
586 } CRYPT_ATTRIBUTE, *PCRYPT_ATTRIBUTE;
587 
588 typedef struct _CRYPT_ATTRIBUTES {
589     DWORD            cAttr;
590     PCRYPT_ATTRIBUTE rgAttr;
591 } CRYPT_ATTRIBUTES, *PCRYPT_ATTRIBUTES;
592 
593 typedef struct _CERT_REQUEST_INFO {
594     DWORD                dwVersion;
595     CERT_NAME_BLOB       Subject;
596     CERT_PUBLIC_KEY_INFO SubjectPublicKeyInfo;
597     DWORD                cAttribute;
598     PCRYPT_ATTRIBUTE     rgAttribute;
599 } CERT_REQUEST_INFO, *PCERT_REQUEST_INFO;
600 
601 typedef struct _CERT_KEYGEN_REQUEST_INFO {
602     DWORD                dwVersion;
603     CERT_PUBLIC_KEY_INFO SubjectPublicKeyInfo;
604     LPWSTR               pwszChallengeString;
605 } CERT_KEYGEN_REQUEST_INFO, *PCERT_KEYGEN_REQUEST_INFO;
606 
607 typedef struct _CERT_SIGNED_CONTENT_INFO {
608     CRYPT_DER_BLOB             ToBeSigned;
609     CRYPT_ALGORITHM_IDENTIFIER SignatureAlgorithm;
610     CRYPT_BIT_BLOB             Signature;
611 } CERT_SIGNED_CONTENT_INFO, *PCERT_SIGNED_CONTENT_INFO;
612 
613 typedef struct _CRL_CONTEXT {
614     DWORD      dwCertEncodingType;
615     BYTE      *pbCrlEncoded;
616     DWORD      cbCrlEncoded;
617     PCRL_INFO  pCrlInfo;
618     HCERTSTORE hCertStore;
619 } CRL_CONTEXT, *PCRL_CONTEXT;
620 typedef const CRL_CONTEXT *PCCRL_CONTEXT;
621 
622 #define SORTED_CTL_EXT_FLAGS_OFFSET                (0*4)
623 #define SORTED_CTL_EXT_COUNT_OFFSET                (1*4)
624 #define SORTED_CTL_EXT_MAX_COLLISION_OFFSET        (2*4)
625 #define SORTED_CTL_EXT_HASH_BUCKET_OFFSET          (3*4)
626 
627 #define SORTED_CTL_EXT_HASHED_SUBJECT_IDENTIFIER_FLAG    0x1
628 
629 typedef struct _CERT_DSS_PARAMETERS {
630     CRYPT_UINT_BLOB    p;
631     CRYPT_UINT_BLOB    q;
632     CRYPT_UINT_BLOB    g;
633 } CERT_DSS_PARAMETERS, *PCERT_DSS_PARAMETERS;
634 
635 #define CERT_DSS_R_LEN            20
636 #define CERT_DSS_S_LEN            20
637 #define CERT_DSS_SIGNATURE_LEN    (CERT_DSS_R_LEN + CERT_DSS_S_LEN)
638 
639 #define CERT_MAX_ENCODED_DSS_SIGNATURE_LEN    (2 + 2*(2 + 20 +1))
640 
641 typedef struct _CERT_DH_PARAMETERS {
642     CRYPT_UINT_BLOB    p;
643     CRYPT_UINT_BLOB    g;
644 } CERT_DH_PARAMETERS, *PCERT_DH_PARAMETERS;
645 
646 typedef struct _CERT_X942_DH_VALIDATION_PARAMS {
647     CRYPT_BIT_BLOB     seed;
648     DWORD              pgenCounter;
649 } CERT_X942_DH_VALIDATION_PARAMS, *PCERT_X942_DH_VALIDATION_PARAMS;
650 
651 typedef struct _CERT_X942_DH_PARAMETERS {
652     CRYPT_UINT_BLOB                    p;
653     CRYPT_UINT_BLOB                    g;
654     CRYPT_UINT_BLOB                    q;
655     CRYPT_UINT_BLOB                    j;
656     PCERT_X942_DH_VALIDATION_PARAMS    pValidationParams;
657 } CERT_X942_DH_PARAMETERS, *PCERT_X942_DH_PARAMETERS;
658 
659 #define CRYPT_X942_COUNTER_BYTE_LENGTH        4
660 #define CRYPT_X942_KEY_LENGTH_BYTE_LENGTH     4
661 #define CRYPT_X942_PUB_INFO_BYTE_LENGTH       (512/8)
662 
663 typedef struct _CRYPT_X942_OTHER_INFO {
664     LPSTR              pszContentEncryptionObjId;
665     BYTE               rgbCounter[CRYPT_X942_COUNTER_BYTE_LENGTH];
666     BYTE               rgbKeyLength[CRYPT_X942_KEY_LENGTH_BYTE_LENGTH];
667     CRYPT_DATA_BLOB    PubInfo;
668 } CRYPT_X942_OTHER_INFO, *PCRYPT_X942_OTHER_INFO;
669 
670 typedef struct _CRYPT_RC2_CBC_PARAMETERS {
671     DWORD    dwVersion;
672     BOOL     fIV;
673     BYTE     rgbIV[4];
674 } CRYPT_RC2_CBC_PARAMETERS, *PCRYPT_RC2_CBC_PARAMETERS;
675 
676 #define CRYPT_RC2_40BIT_VERSION    160
677 #define CRYPT_RC2_56BIT_VERSION    52
678 #define CRYPT_RC2_64BIT_VERSION    120
679 #define CRYPT_RC2_128BIT_VERSION   58
680 
681 typedef struct _CRYPT_SMIME_CAPABILITY {
682     LPSTR               pszObjId;
683     CRYPT_OBJID_BLOB    Parameters;
684 } CRYPT_SMIME_CAPABILITY, *PCRYPT_SMIME_CAPABILITY;
685 
686 typedef struct _CRYPT_SMIME_CAPABILITIES {
687     DWORD                   cCapability;
688     PCRYPT_SMIME_CAPABILITY rgCapability;
689 } CRYPT_SMIME_CAPABILITIES, *PCRYPT_SMIME_CAPABILITIES;
690 
691 typedef struct _VTableProvStruc {
692     DWORD    Version;
693 #ifdef WINE_STRICT_PROTOTYPES
694     BOOL     (WINAPI *FuncVerifyImage)(LPCSTR,BYTE*);
695     void     (WINAPI *FuncReturnhWnd)(HWND*);
696 #else
697     FARPROC  FuncVerifyImage;
698     FARPROC  FuncReturnhWnd;
699 #endif
700     DWORD    dwProvType;
701     BYTE    *pbContextInfo;
702     DWORD    cbContextInfo;
703     LPSTR    pszProvName;
704 } VTableProvStruc, *PVTableProvStruc;
705 
706 typedef struct _CERT_PRIVATE_KEY_INFO {
707     DWORD                      Version;
708     CRYPT_ALGORITHM_IDENTIFIER Algorithm;
709     CRYPT_DER_BLOB             PrivateKey;
710     PCRYPT_ATTRIBUTES          pAttributes;
711 } CERT_PRIVATE_KEY_INFO, *PCERT_PRIVATE_KEY_INFO;
712 
713 typedef struct _CTL_USAGE {
714     DWORD  cUsageIdentifier;
715     LPSTR *rgpszUsageIdentifier;
716 } CTL_USAGE, *PCTL_USAGE, CERT_ENHKEY_USAGE, *PCERT_ENHKEY_USAGE;
717 
718 typedef struct _CTL_ENTRY {
719     CRYPT_DATA_BLOB  SubjectIdentifier;
720     DWORD            cAttribute;
721     PCRYPT_ATTRIBUTE rgAttribute;
722 } CTL_ENTRY, *PCTL_ENTRY;
723 
724 typedef struct _CTL_INFO {
725     DWORD                      dwVersion;
726     CTL_USAGE                  SubjectUsage;
727     CRYPT_DATA_BLOB            ListIdentifier;
728     CRYPT_INTEGER_BLOB         SequenceNumber;
729     FILETIME                   ThisUpdate;
730     FILETIME                   NextUpdate;
731     CRYPT_ALGORITHM_IDENTIFIER SubjectAlgorithm;
732     DWORD                      cCTLEntry;
733     PCTL_ENTRY                 rgCTLEntry;
734     DWORD                      cExtension;
735     PCERT_EXTENSION            rgExtension;
736 } CTL_INFO, *PCTL_INFO;
737 
738 typedef struct _CTL_CONTEXT {
739     DWORD      dwMsgAndCertEncodingType;
740     BYTE      *pbCtlEncoded;
741     DWORD      cbCtlEncoded;
742     PCTL_INFO  pCtlInfo;
743     HCERTSTORE hCertStore;
744     HCRYPTMSG  hCryptMsg;
745     BYTE      *pbCtlContext;
746     DWORD      cbCtlContext;
747 } CTL_CONTEXT, *PCTL_CONTEXT;
748 typedef const CTL_CONTEXT *PCCTL_CONTEXT;
749 
750 typedef struct _CRYPT_TIME_STAMP_REQUEST_INFO {
751     LPSTR            pszTimeStampAlgorithm;
752     LPSTR            pszContentType;
753     CRYPT_OBJID_BLOB Content;
754     DWORD            cAttribute;
755     PCRYPT_ATTRIBUTE rgAttribute;
756 } CRYPT_TIME_STAMP_REQUEST_INFO, *PCRYPT_TIME_STAMP_REQUEST_INFO;
757 
758 typedef struct _CRYPT_ENROLLMENT_NAME_VALUE_PAIR {
759     LPWSTR pwszName;
760     LPWSTR pwszValue;
761 } CRYPT_ENROLLMENT_NAME_VALUE_PAIR, *PCRYPT_ENROLLMENT_NAME_VALUE_PAIR;
762 
763 typedef struct _CMSG_SIGNER_INFO {
764     DWORD                      dwVersion;
765     CERT_NAME_BLOB             Issuer;
766     CRYPT_INTEGER_BLOB         SerialNumber;
767     CRYPT_ALGORITHM_IDENTIFIER HashAlgorithm;
768     CRYPT_ALGORITHM_IDENTIFIER HashEncryptionAlgorithm;
769     CRYPT_DATA_BLOB            EncryptedHash;
770     CRYPT_ATTRIBUTES           AuthAttrs;
771     CRYPT_ATTRIBUTES           UnauthAttrs;
772 } CMSG_SIGNER_INFO, *PCMSG_SIGNER_INFO;
773 
774 #define CMSG_VERIFY_SIGNER_PUBKEY 1
775 #define CMSG_VERIFY_SIGNER_CERT   2
776 #define CMSG_VERIFY_SIGNER_CHAIN  3
777 #define CMSG_VERIFY_SIGNER_NULL   4
778 
779 typedef struct _CERT_REVOCATION_CRL_INFO {
780     DWORD         cbSize;
781     PCCRL_CONTEXT pBaseCrlContext;
782     PCCRL_CONTEXT pDeltaCrlContext;
783     PCRL_ENTRY    pCrlEntry;
784     BOOL          fDeltaCrlEntry;
785 } CERT_REVOCATION_CRL_INFO, *PCERT_REVOCATION_CRL_INFO;
786 
787 typedef struct _CERT_REVOCATION_INFO {
788     DWORD                     cbSize;
789     DWORD                     dwRevocationResult;
790     LPCSTR                    pszRevocationOid;
791     LPVOID                    pvOidSpecificInfo;
792     BOOL                      fHasFreshnessTime;
793     DWORD                     dwFreshnessTime;
794     PCERT_REVOCATION_CRL_INFO pCrlInfo;
795 } CERT_REVOCATION_INFO, *PCERT_REVOCATION_INFO;
796 
797 typedef struct _CERT_REVOCATION_PARA {
798     DWORD                     cbSize;
799     PCCERT_CONTEXT            pIssuerCert;
800     DWORD                     cCertStore;
801     HCERTSTORE               *rgCertStore;
802     HCERTSTORE                hCrlStore;
803     LPFILETIME                pftTimeToUse;
804 #ifdef CERT_REVOCATION_PARA_HAS_EXTRA_FIELDS
805     DWORD                     dwUrlRetrievalTimeout;
806     BOOL                      fCheckFreshnessTime;
807     DWORD                     dwFreshnessTime;
808     LPFILETIME                pftCurrentTime;
809     PCERT_REVOCATION_CRL_INFO pCrlInfo;
810 #endif
811 } CERT_REVOCATION_PARA, *PCERT_REVOCATION_PARA;
812 
813 #define CERT_CONTEXT_REVOCATION_TYPE 1
814 #define CERT_VERIFY_REV_CHAIN_FLAG                0x00000001
815 #define CERT_VERIFY_CACHE_ONLY_BASED_REVOCATION   0x00000002
816 #define CERT_VERIFY_REV_ACCUMULATIVE_TIMEOUT_FLAG 0x00000004
817 
818 typedef struct _CTL_VERIFY_USAGE_PARA {
819     DWORD           cbSize;
820     CRYPT_DATA_BLOB ListIdentifier;
821     DWORD           cCtlStore;
822     HCERTSTORE     *rghCtlStore;
823     DWORD           cSignerStore;
824     HCERTSTORE     *rghSignerStore;
825 } CTL_VERIFY_USAGE_PARA, *PCTL_VERIFY_USAGE_PARA;
826 
827 typedef struct _CTL_VERIFY_USAGE_STATUS {
828     DWORD           cbSize;
829     DWORD           dwError;
830     DWORD           dwFlags;
831     PCCTL_CONTEXT  *ppCtl;
832     DWORD           dwCtlEntryIndex;
833     PCCERT_CONTEXT *ppSigner;
834     DWORD           dwSignerIndex;
835 } CTL_VERIFY_USAGE_STATUS, *PCTL_VERIFY_USAGE_STATUS;
836 
837 #define CERT_VERIFY_INHIBIT_CTL_UPDATE_FLAG 0x1
838 #define CERT_VERIFY_TRUSTED_SIGNERS_FLAG    0x2
839 #define CERT_VERIFY_NO_TIME_CHECK_FLAG      0x4
840 #define CERT_VERIFY_ALLOW_MORE_USAGE_FLAG   0x8
841 #define CERT_VERIFY_UPDATED_CTL_FLAG        0x1
842 
843 typedef struct _CERT_CHAIN {
844     DWORD               cCerts;
845     PCERT_BLOB          certs;
846     CRYPT_KEY_PROV_INFO keyLocatorInfo;
847 } CERT_CHAIN, *PCERT_CHAIN;
848 
849 typedef struct _CERT_REVOCATION_STATUS {
850     DWORD cbSize;
851     DWORD dwIndex;
852     DWORD dwError;
853     DWORD dwReason;
854     BOOL  fHasFreshnessTime;
855     DWORD dwFreshnessTime;
856 } CERT_REVOCATION_STATUS, *PCERT_REVOCATION_STATUS;
857 
858 typedef struct _CERT_TRUST_LIST_INFO {
859     DWORD         cbSize;
860     PCTL_ENTRY    pCtlEntry;
861     PCCTL_CONTEXT pCtlContext;
862 } CERT_TRUST_LIST_INFO, *PCERT_TRUST_LIST_INFO;
863 
864 #define CERT_TRUST_NO_ERROR                          0x00000000
865 #define CERT_TRUST_IS_NOT_TIME_VALID                 0x00000001
866 #define CERT_TRUST_IS_NOT_TIME_NESTED                0x00000002
867 #define CERT_TRUST_IS_REVOKED                        0x00000004
868 #define CERT_TRUST_IS_NOT_SIGNATURE_VALID            0x00000008
869 #define CERT_TRUST_IS_NOT_VALID_FOR_USAGE            0x00000010
870 #define CERT_TRUST_IS_UNTRUSTED_ROOT                 0x00000020
871 #define CERT_TRUST_REVOCATION_STATUS_UNKNOWN         0x00000040
872 #define CERT_TRUST_IS_CYCLIC                         0x00000080
873 #define CERT_TRUST_INVALID_EXTENSION                 0x00000100
874 #define CERT_TRUST_INVALID_POLICY_CONSTRAINTS        0x00000200
875 #define CERT_TRUST_INVALID_BASIC_CONSTRAINTS         0x00000400
876 #define CERT_TRUST_INVALID_NAME_CONSTRAINTS          0x00000800
877 #define CERT_TRUST_HAS_NOT_SUPPORTED_NAME_CONSTRAINT 0x00001000
878 #define CERT_TRUST_HAS_NOT_DEFINED_NAME_CONSTRAINT   0x00002000
879 #define CERT_TRUST_HAS_NOT_PERMITTED_NAME_CONSTRAINT 0x00004000
880 #define CERT_TRUST_HAS_EXCLUDED_NAME_CONSTRAINT      0x00008000
881 #define CERT_TRUST_IS_OFFLINE_REVOCATION             0x01000000
882 #define CERT_TRUST_NO_ISSUANCE_CHAIN_POLICY          0x02000000
883 #define CERT_TRUST_IS_EXPLICIT_DISTRUST              0x04000000
884 #define CERT_TRUST_HAS_NOT_SUPPORTED_CRITICAL_EXT    0x08000000
885 
886 #define CERT_TRUST_IS_PARTIAL_CHAIN                  0x00010000
887 #define CERT_TRUST_CTL_IS_NOT_TIME_VALID             0x00020000
888 #define CERT_TRUST_CTL_IS_NOT_SIGNATURE_VALID        0x00040000
889 #define CERT_TRUST_CTL_IS_NOT_VALID_FOR_USAGE        0x00080000
890 
891 #define CERT_TRUST_HAS_EXACT_MATCH_ISSUER            0x00000001
892 #define CERT_TRUST_HAS_KEY_MATCH_ISSUER              0x00000002
893 #define CERT_TRUST_HAS_NAME_MATCH_ISSUER             0x00000004
894 #define CERT_TRUST_IS_SELF_SIGNED                    0x00000008
895 
896 #define CERT_TRUST_HAS_PREFERRED_ISSUER              0x00000100
897 #define CERT_TRUST_HAS_ISSUANCE_CHAIN_POLICY         0x00000200
898 #define CERT_TRUST_HAS_VALID_NAME_CONSTRAINTS        0x00000400
899 #define CERT_TRUST_IS_PEER_TRUSTED                   0x00000800
900 #define CERT_TRUST_HAS_CRL_VALIDITY_EXTENDED         0x00001000
901 
902 #define CERT_TRUST_IS_COMPLEX_CHAIN                  0x00010000
903 
904 typedef struct _CERT_TRUST_STATUS {
905     DWORD dwErrorStatus;
906     DWORD dwInfoStatus;
907 } CERT_TRUST_STATUS, *PCERT_TRUST_STATUS;
908 
909 typedef struct _CERT_CHAIN_ELEMENT {
910     DWORD                 cbSize;
911     PCCERT_CONTEXT        pCertContext;
912     CERT_TRUST_STATUS     TrustStatus;
913     PCERT_REVOCATION_INFO pRevocationInfo;
914     PCERT_ENHKEY_USAGE    pIssuanceUsage;
915     PCERT_ENHKEY_USAGE    pApplicationUsage;
916     LPCWSTR               pwszExtendedErrorInfo;
917 } CERT_CHAIN_ELEMENT, *PCERT_CHAIN_ELEMENT;
918 
919 typedef struct _CERT_SIMPLE_CHAIN {
920     DWORD                 cbSize;
921     CERT_TRUST_STATUS     TrustStatus;
922     DWORD                 cElement;
923     PCERT_CHAIN_ELEMENT  *rgpElement;
924     PCERT_TRUST_LIST_INFO pTrustListInfo;
925     BOOL                  fHasRevocationFreshnessTime;
926     DWORD                 dwRevocationFreshnessTime;
927 } CERT_SIMPLE_CHAIN, *PCERT_SIMPLE_CHAIN;
928 
929 typedef struct _CERT_CHAIN_CONTEXT CERT_CHAIN_CONTEXT, *PCERT_CHAIN_CONTEXT;
930 typedef const CERT_CHAIN_CONTEXT *PCCERT_CHAIN_CONTEXT;
931 
932 struct _CERT_CHAIN_CONTEXT {
933     DWORD                 cbSize;
934     CERT_TRUST_STATUS     TrustStatus;
935     DWORD                 cChain;
936     PCERT_SIMPLE_CHAIN   *rgpChain;
937     DWORD                 cLowerQualityChainContext;
938     PCCERT_CHAIN_CONTEXT *rgpLowerQualityChainContext;
939     BOOL                  fHasRevocationFreshnessTime;
940     DWORD                 dwRevocationFreshnessTime;
941 };
942 
943 typedef struct _CERT_CHAIN_POLICY_PARA {
944     DWORD cbSize;
945     DWORD dwFlags;
946     void *pvExtraPolicyPara;
947 } CERT_CHAIN_POLICY_PARA, *PCERT_CHAIN_POLICY_PARA;
948 
949 typedef struct _CERT_CHAIN_POLICY_STATUS {
950     DWORD cbSize;
951     DWORD dwError;
952     LONG  lChainIndex;
953     LONG  lElementIndex;
954     void *pvExtraPolicyStatus;
955 } CERT_CHAIN_POLICY_STATUS, *PCERT_CHAIN_POLICY_STATUS;
956 
957 #define CERT_CHAIN_POLICY_BASE              ((LPCSTR)1)
958 #define CERT_CHAIN_POLICY_AUTHENTICODE      ((LPCSTR)2)
959 #define CERT_CHAIN_POLICY_AUTHENTICODE_TS   ((LPCSTR)3)
960 #define CERT_CHAIN_POLICY_SSL               ((LPCSTR)4)
961 #define CERT_CHAIN_POLICY_BASIC_CONSTRAINTS ((LPCSTR)5)
962 #define CERT_CHAIN_POLICY_NT_AUTH           ((LPCSTR)6)
963 #define CERT_CHAIN_POLICY_MICROSOFT_ROOT    ((LPCSTR)7)
964 
965 #define CERT_CHAIN_POLICY_IGNORE_NOT_TIME_VALID_FLAG            0x00000001
966 #define CERT_CHAIN_POLICY_IGNORE_CTL_NOT_TIME_VALID_FLAG        0x00000002
967 #define CERT_CHAIN_POLICY_IGNORE_NOT_TIME_NESTED_FLAG           0x00000004
968 #define CERT_CHAIN_POLICY_IGNORE_INVALID_BASIC_CONSTRAINTS_FLAG 0x00000008
969 
970 #define CERT_CHAIN_POLICY_IGNORE_ALL_NOT_TIME_VALID_FLAGS ( \
971  CERT_CHAIN_POLICY_IGNORE_NOT_TIME_VALID_FLAG \
972  CERT_CHAIN_POLICY_IGNORE_CTL_NOT_TIME_VALID_FLAG \
973  CERT_CHAIN_POLICY_IGNORE_NOT_TIME_NESTED_FLAG )
974 
975 #define CERT_CHAIN_POLICY_ALLOW_UNKNOWN_CA_FLAG                 0x00000010
976 #define CERT_CHAIN_POLICY_IGNORE_WRONG_USAGE_FLAG               0x00000020
977 #define CERT_CHAIN_POLICY_IGNORE_INVALID_NAME_FLAG              0x00000040
978 #define CERT_CHAIN_POLICY_IGNORE_INVALID_POLICY_FLAG            0x00000080
979 
980 #define CERT_CHAIN_POLICY_IGNORE_END_REV_UNKNOWN_FLAG           0x00000100
981 #define CERT_CHAIN_POLICY_IGNORE_CTL_SIGNER_REV_UNKNOWN_FLAG    0x00000200
982 #define CERT_CHAIN_POLICY_IGNORE_CA_REV_UNKNOWN_FLAG            0x00000400
983 #define CERT_CHAIN_POLICY_IGNORE_ROOT_REV_UNKNOWN_FLAG          0x00000800
984 
985 #define CERT_CHAIN_POLICY_IGNORE_ALL_REV_UNKNOWN_FLAGS ( \
986  CERT_CHAIN_POLICY_IGNORE_END_REV_UNKNOWN_FLAG \
987  CERT_CHAIN_POLICY_IGNORE_CTL_SIGNER_REV_UNKNOWN_FLAG \
988  CERT_CHAIN_POLICY_IGNORE_CA_REV_UNKNOWN_FLAG \
989  CERT_CHAIN_POLICY_IGNORE_ROOT_REV_UNKNOWN_FLAG )
990 
991 #define CERT_CHAIN_POLICY_IGNORE_PEER_TRUST_FLAG                 0x00001000
992 #define CERT_CHAIN_POLICY_IGNORE_NOT_SUPPORTED_CRITICAL_EXT_FLAG 0x00002000
993 #define CERT_CHAIN_POLICY_TRUST_TESTROOT_FLAG                    0x00004000
994 #define CERT_CHAIN_POLICY_ALLOW_TESTROOT_FLAG                    0x00008000
995 #define MICROSOFT_ROOT_CERT_CHAIN_POLICY_ENABLE_TEST_ROOT_FLAG   0x00010000
996 
997 typedef struct _AUTHENTICODE_EXTRA_CERT_CHAIN_POLICY_PARA {
998     DWORD             cbSize;
999     DWORD             dwRegPolicySettings;
1000     PCMSG_SIGNER_INFO pSignerInfo;
1001 } AUTHENTICODE_EXTRA_CERT_CHAIN_POLICY_PARA,
1002  *PAUTHENTICODE_EXTRA_CERT_CHAIN_POLICY_PARA;
1003 
1004 typedef struct _AUTHENTICODE_EXTRA_CERT_CHAIN_POLICY_STATUS {
1005     DWORD cbSize;
1006     BOOL  fCommercial;
1007 } AUTHENTICODE_EXTRA_CERT_CHAIN_POLICY_STATUS,
1008  *PAUTHENTICODE_EXTRA_CERT_CHAIN_POLICY_STATUS;
1009 
1010 typedef struct _AUTHENTICODE_TS_EXTRA_CERT_CHAIN_POLICY_PARA {
1011     DWORD cbSize;
1012     DWORD dwRegPolicySettings;
1013     BOOL  fCommercial;
1014 } AUTHENTICODE_TS_EXTRA_CERT_CHAIN_POLICY_PARA,
1015  *PAUTHENTICODE_TS_EXTRA_CERT_CHAIN_POLICY_PARA;
1016 
1017 typedef struct _HTTPSPolicyCallbackData {
1018     union {
1019         DWORD cbStruct;
1020         DWORD cbSize;
1021     } DUMMYUNIONNAME;
1022     DWORD  dwAuthType;
1023     DWORD  fdwChecks;
1024     WCHAR *pwszServerName;
1025 } HTTPSPolicyCallbackData, *PHTTPSPolicyCallbackData,
1026  SSL_EXTRA_CERT_CHAIN_POLICY_PARA, *PSSL_EXTRA_CERT_CHAIN_POLICY_PARA;
1027 
1028 /* Values for HTTPSPolicyCallbackData's dwAuthType */
1029 #define AUTHTYPE_CLIENT 1
1030 #define AUTHTYPE_SERVER 2
1031 /* Values for HTTPSPolicyCallbackData's fdwChecks are defined in wininet.h */
1032 
1033 #define BASIC_CONSTRAINTS_CERT_CHAIN_POLICY_CA_FLAG         0x80000000
1034 #define BASIC_CONSTRAINTS_CERT_CHAIN_POLICY_END_ENTITY_FLAG 0x40000000
1035 
1036 #define MICROSOFT_ROOT_CERT_CHAIN_POLICY_ENABLE_TEST_ROOT_FLAG 0x00010000
1037 
1038 #define USAGE_MATCH_TYPE_AND 0x00000000
1039 #define USAGE_MATCH_TYPE_OR  0x00000001
1040 
1041 typedef struct _CERT_USAGE_MATCH {
1042     DWORD             dwType;
1043     CERT_ENHKEY_USAGE Usage;
1044 } CERT_USAGE_MATCH, *PCERT_USAGE_MATCH;
1045 
1046 typedef struct _CTL_USAGE_MATCH {
1047     DWORD     dwType;
1048     CTL_USAGE Usage;
1049 } CTL_USAGE_MATCH, *PCTL_USAGE_MATCH;
1050 
1051 #define CERT_CHAIN_REVOCATION_CHECK_END_CERT           0x10000000
1052 #define CERT_CHAIN_REVOCATION_CHECK_CHAIN              0x20000000
1053 #define CERT_CHAIN_REVOCATION_CHECK_CHAIN_EXCLUDE_ROOT 0x40000000
1054 #define CERT_CHAIN_REVOCATION_CHECK_CACHE_ONLY         0x80000000
1055 
1056 #define CERT_CHAIN_REVOCATION_ACCUMULATIVE_TIMEOUT     0x08000000
1057 
1058 #define CERT_CHAIN_DISABLE_PASS1_QUALITY_FILTERING     0x00000040
1059 #define CERT_CHAIN_RETURN_LOWER_QUALITY_CONTEXTS       0x00000080
1060 #define CERT_CHAIN_DISABLE_AUTH_ROOT_AUTO_UPDATE       0x00000100
1061 #define CERT_CHAIN_TIMESTAMP_TIME                      0x00000200
1062 
1063 typedef struct _CERT_CHAIN_PARA {
1064     DWORD            cbSize;
1065     CERT_USAGE_MATCH RequestedUsage;
1066 #ifdef CERT_CHAIN_PARA_HAS_EXTRA_FIELDS
1067     CERT_USAGE_MATCH RequestedIssuancePolicy;
1068     DWORD            dwUrlRetrievalTimeout;
1069     BOOL             fCheckRevocationFreshnessTime;
1070     DWORD            dwRevocationFreshnessTime;
1071     LPFILETIME       pftCacheResync;
1072 #endif
1073 } CERT_CHAIN_PARA, *PCERT_CHAIN_PARA;
1074 
1075 typedef struct _CERT_SYSTEM_STORE_INFO {
1076     DWORD cbSize;
1077 } CERT_SYSTEM_STORE_INFO, *PCERT_SYSTEM_STORE_INFO;
1078 
1079 typedef struct _CERT_PHYSICAL_STORE_INFO {
1080     DWORD           cbSize;
1081     LPSTR           pszOpenStoreProvider;
1082     DWORD           dwOpenEncodingType;
1083     DWORD           dwOpenFlags;
1084     CRYPT_DATA_BLOB OpenParameters;
1085     DWORD           dwFlags;
1086     DWORD           dwPriority;
1087 } CERT_PHYSICAL_STORE_INFO, *PCERT_PHYSICAL_STORE_INFO;
1088 
1089 typedef struct _CERT_SYSTEM_STORE_RELOCATE_PARA {
1090     union {
1091         HKEY  hKeyBase;
1092         VOID *pvBase;
1093     } DUMMYUNIONNAME;
1094     union {
1095         void   *pvSystemStore;
1096         LPCSTR  pszSystemStore;
1097         LPCWSTR pwszSystemStore;
1098     } DUMMYUNIONNAME2;
1099 } CERT_SYSTEM_STORE_RELOCATE_PARA, *PCERT_SYSTEM_STORE_RELOCATE_PARA;
1100 
1101 typedef BOOL
1102 (WINAPI *PFN_CERT_ENUM_SYSTEM_STORE_LOCATION)(
1103   _In_ LPCWSTR pwszStoreLocation,
1104   _In_ DWORD dwFlags,
1105   _Reserved_ void *pvReserved,
1106   _Inout_opt_ void *pvArg);
1107 
1108 typedef BOOL
1109 (WINAPI *PFN_CERT_ENUM_SYSTEM_STORE)(
1110   _In_ const void *pvSystemStore,
1111   _In_ DWORD dwFlags,
1112   _In_ PCERT_SYSTEM_STORE_INFO pStoreInfo,
1113   _Reserved_ void *pvReserved,
1114   _Inout_opt_ void *pvArg);
1115 
1116 typedef BOOL
1117 (WINAPI *PFN_CERT_ENUM_PHYSICAL_STORE)(
1118   _In_ const void *pvSystemStore,
1119   _In_ DWORD dwFlags,
1120   _In_ LPCWSTR pwszStoreName,
1121   _In_ PCERT_PHYSICAL_STORE_INFO pStoreInfo,
1122   _Reserved_ void *pvReserved,
1123   _Inout_opt_ void *pvArg);
1124 
1125 /* Encode/decode object */
1126 typedef LPVOID (__WINE_ALLOC_SIZE(1) WINAPI *PFN_CRYPT_ALLOC)(_In_ size_t cbsize);
1127 typedef VOID(WINAPI *PFN_CRYPT_FREE)(_In_ LPVOID pv);
1128 
1129 typedef struct _CRYPT_ENCODE_PARA {
1130     DWORD           cbSize;
1131     PFN_CRYPT_ALLOC pfnAlloc;
1132     PFN_CRYPT_FREE  pfnFree;
1133 } CRYPT_ENCODE_PARA, *PCRYPT_ENCODE_PARA;
1134 
1135 typedef struct _CRYPT_DECODE_PARA {
1136     DWORD           cbSize;
1137     PFN_CRYPT_ALLOC pfnAlloc;
1138     PFN_CRYPT_FREE  pfnFree;
1139 } CRYPT_DECODE_PARA, *PCRYPT_DECODE_PARA;
1140 
1141 typedef struct _CERT_STORE_PROV_INFO {
1142     DWORD             cbSize;
1143     DWORD             cStoreProvFunc;
1144     void            **rgpvStoreProvFunc;
1145     HCERTSTOREPROV    hStoreProv;
1146     DWORD             dwStoreProvFlags;
1147     HCRYPTOIDFUNCADDR hStoreProvFuncAddr2;
1148 } CERT_STORE_PROV_INFO, *PCERT_STORE_PROV_INFO;
1149 
1150 typedef BOOL
1151 (WINAPI *PFN_CERT_DLL_OPEN_STORE_PROV_FUNC)(
1152   _In_ LPCSTR lpszStoreProvider,
1153   _In_ DWORD dwEncodingType,
1154   _In_opt_ HCRYPTPROV_LEGACY hCryptProv,
1155   _In_ DWORD dwFlags,
1156   _In_opt_ const void *pvPara,
1157   _In_ HCERTSTORE hCertStore,
1158   _Inout_ PCERT_STORE_PROV_INFO pStoreProvInfo);
1159 
1160 typedef void
1161 (WINAPI *PFN_CERT_STORE_PROV_CLOSE)(
1162   _Inout_opt_ HCERTSTOREPROV hStoreProv,
1163   _In_ DWORD dwFlags);
1164 
1165 typedef
1166 _Success_(return != 0)
1167 BOOL
1168 (WINAPI *PFN_CERT_STORE_PROV_READ_CERT)(
1169   _Inout_ HCERTSTOREPROV hStoreProv,
1170   _In_ PCCERT_CONTEXT pStoreCertContext,
1171   _In_ DWORD dwFlags,
1172   _Outptr_ PCCERT_CONTEXT *ppProvCertContext);
1173 
1174 typedef BOOL
1175 (WINAPI *PFN_CERT_STORE_PROV_WRITE_CERT)(
1176   _Inout_ HCERTSTOREPROV hStoreProv,
1177   _In_ PCCERT_CONTEXT pCertContext,
1178   _In_ DWORD dwFlags);
1179 
1180 typedef BOOL
1181 (WINAPI *PFN_CERT_STORE_PROV_DELETE_CERT)(
1182   _Inout_ HCERTSTOREPROV hStoreProv,
1183   _In_ PCCERT_CONTEXT pCertContext,
1184   _In_ DWORD dwFlags);
1185 
1186 typedef BOOL
1187 (WINAPI *PFN_CERT_STORE_PROV_SET_CERT_PROPERTY)(
1188   _Inout_ HCERTSTOREPROV hStoreProv,
1189   _In_ PCCERT_CONTEXT pCertContext,
1190   _In_ DWORD dwPropId,
1191   _In_ DWORD dwFlags,
1192   _In_opt_ const void *pvData);
1193 
1194 typedef
1195 _Success_(return != 0)
1196 BOOL
1197 (WINAPI *PFN_CERT_STORE_PROV_READ_CRL)(
1198   _Inout_ HCERTSTOREPROV hStoreProv,
1199   _In_ PCCRL_CONTEXT pStoreCrlContext,
1200   _In_ DWORD dwFlags,
1201   _Outptr_ PCCRL_CONTEXT *ppProvCrlContext);
1202 
1203 typedef BOOL
1204 (WINAPI *PFN_CERT_STORE_PROV_WRITE_CRL)(
1205   _Inout_ HCERTSTOREPROV hStoreProv,
1206   _In_ PCCRL_CONTEXT pCrlContext,
1207   _In_ DWORD dwFlags);
1208 
1209 typedef BOOL
1210 (WINAPI *PFN_CERT_STORE_PROV_DELETE_CRL)(
1211   _Inout_ HCERTSTOREPROV hStoreProv,
1212   _In_ PCCRL_CONTEXT pCrlContext,
1213   _In_ DWORD dwFlags);
1214 
1215 typedef BOOL
1216 (WINAPI *PFN_CERT_STORE_PROV_SET_CRL_PROPERTY)(
1217   _Inout_ HCERTSTOREPROV hStoreProv,
1218   _In_ PCCRL_CONTEXT pCrlContext,
1219   _In_ DWORD dwPropId,
1220   _In_ DWORD dwFlags,
1221   _In_opt_ const void *pvData);
1222 
1223 typedef
1224 _Success_(return != 0)
1225 BOOL
1226 (WINAPI *PFN_CERT_STORE_PROV_READ_CTL)(
1227   _Inout_ HCERTSTOREPROV hStoreProv,
1228   _In_ PCCTL_CONTEXT pStoreCtlContext,
1229   _In_ DWORD dwFlags,
1230   _Outptr_ PCCTL_CONTEXT *ppProvCtlContext);
1231 
1232 typedef BOOL
1233 (WINAPI *PFN_CERT_STORE_PROV_WRITE_CTL)(
1234   _Inout_ HCERTSTOREPROV hStoreProv,
1235   _In_ PCCTL_CONTEXT pCtlContext,
1236   _In_ DWORD dwFlags);
1237 
1238 typedef BOOL
1239 (WINAPI *PFN_CERT_STORE_PROV_DELETE_CTL)(
1240   _Inout_ HCERTSTOREPROV hStoreProv,
1241   _In_ PCCTL_CONTEXT pCtlContext,
1242   _In_ DWORD dwFlags);
1243 
1244 typedef BOOL
1245 (WINAPI *PFN_CERT_STORE_PROV_SET_CTL_PROPERTY)(
1246   _Inout_ HCERTSTOREPROV hStoreProv,
1247   _In_ PCCTL_CONTEXT pCtlContext,
1248   _In_ DWORD dwPropId,
1249   _In_ DWORD dwFlags,
1250   _In_opt_ const void *pvData);
1251 
1252 typedef BOOL
1253 (WINAPI *PFN_CERT_STORE_PROV_CONTROL)(
1254   _Inout_ HCERTSTOREPROV hStoreProv,
1255   _In_ DWORD dwFlags,
1256   _In_ DWORD dwCtrlType,
1257   _In_opt_ void const *pvCtrlPara);
1258 
1259 typedef struct _CERT_STORE_PROV_FIND_INFO {
1260     DWORD       cbSize;
1261     DWORD       dwMsgAndCertEncodingType;
1262     DWORD       dwFindFlags;
1263     DWORD       dwFindType;
1264     const void *pvFindPara;
1265 } CERT_STORE_PROV_FIND_INFO, *PCERT_STORE_PROV_FIND_INFO;
1266 typedef const CERT_STORE_PROV_FIND_INFO CCERT_STORE_PROV_FIND_INFO,
1267  *PCCERT_STORE_PROV_FIND_INFO;
1268 
1269 typedef
1270 _Success_(return != 0)
1271 BOOL
1272 (WINAPI *PFN_CERT_STORE_PROV_FIND_CERT)(
1273   _Inout_ HCERTSTOREPROV hStoreProv,
1274   _In_ PCCERT_STORE_PROV_FIND_INFO pFindInfo,
1275   _In_ PCCERT_CONTEXT pPrevCertContext,
1276   _In_ DWORD dwFlags,
1277   _Inout_ void **ppvStoreProvFindInfo,
1278   _Outptr_ PCCERT_CONTEXT *ppProvCertContext);
1279 
1280 typedef BOOL
1281 (WINAPI *PFN_CERT_STORE_PROV_FREE_FIND_CERT)(
1282   _Inout_ HCERTSTOREPROV hStoreProv,
1283   _In_ PCCERT_CONTEXT pCertContext,
1284   _In_ void *pvStoreProvFindInfo,
1285   _In_ DWORD dwFlags);
1286 
1287 typedef BOOL
1288 (WINAPI *PFN_CERT_STORE_PROV_GET_CERT_PROPERTY)(
1289   _Inout_ HCERTSTOREPROV hStoreProv,
1290   _In_ PCCERT_CONTEXT pCertContext,
1291   _In_ DWORD dwPropId,
1292   _In_ DWORD dwFlags,
1293   _Out_writes_bytes_to_opt_(*pcbData, *pcbData) void *pvData,
1294   _Inout_ DWORD *pcbData);
1295 
1296 typedef
1297 _Success_(return != 0)
1298 BOOL
1299 (WINAPI *PFN_CERT_STORE_PROV_FIND_CRL)(
1300   _Inout_ HCERTSTOREPROV hStoreProv,
1301   _In_ PCCERT_STORE_PROV_FIND_INFO pFindInfo,
1302   _In_ PCCRL_CONTEXT pPrevCrlContext,
1303   _In_ DWORD dwFlags,
1304   _Inout_ void **ppvStoreProvFindInfo,
1305   _Outptr_ PCCRL_CONTEXT *ppProvCrlContext);
1306 
1307 typedef BOOL
1308 (WINAPI *PFN_CERT_STORE_PROV_FREE_FIND_CRL)(
1309   _Inout_ HCERTSTOREPROV hStoreProv,
1310   _In_ PCCRL_CONTEXT pCrlContext,
1311   _In_ void *pvStoreProvFindInfo,
1312   _In_ DWORD dwFlags);
1313 
1314 typedef BOOL
1315 (WINAPI *PFN_CERT_STORE_PROV_GET_CRL_PROPERTY)(
1316   _Inout_ HCERTSTOREPROV hStoreProv,
1317   _In_ PCCRL_CONTEXT pCrlContext,
1318   _In_ DWORD dwPropId,
1319   _In_ DWORD dwFlags,
1320   _Out_writes_bytes_to_opt_(*pcbData, *pcbData) void *pvData,
1321   _Inout_ DWORD *pcbData);
1322 
1323 typedef
1324 _Success_(return != 0)
1325 BOOL
1326 (WINAPI *PFN_CERT_STORE_PROV_FIND_CTL)(
1327   _In_ HCERTSTOREPROV hStoreProv,
1328   _In_ PCCERT_STORE_PROV_FIND_INFO pFindInfo,
1329   _In_ PCCTL_CONTEXT pPrevCtlContext,
1330   _In_ DWORD dwFlags,
1331   _Inout_ void **ppvStoreProvFindInfo,
1332   _Outptr_ PCCTL_CONTEXT *ppProvCtlContext);
1333 
1334 typedef BOOL
1335 (WINAPI *PFN_CERT_STORE_PROV_GET_CTL_PROPERTY)(
1336   _Inout_ HCERTSTOREPROV hStoreProv,
1337   _In_ PCCTL_CONTEXT pCtlContext,
1338   _In_ DWORD dwPropId,
1339   _In_ DWORD dwFlags,
1340   _Out_writes_bytes_to_opt_(*pcbData, *pcbData) void *pvData,
1341   _Inout_ DWORD *pcbData);
1342 
1343 typedef struct _CERT_CREATE_CONTEXT_PARA {
1344     DWORD          cbSize;
1345     PFN_CRYPT_FREE pfnFree;
1346     void          *pvFree;
1347 } CERT_CREATE_CONTEXT_PARA, *PCERT_CREATE_CONTEXT_PARA;
1348 
1349 typedef struct _CRYPT_OID_FUNC_ENTRY {
1350     LPCSTR pszOID;
1351     void  *pvFuncAddr;
1352 } CRYPT_OID_FUNC_ENTRY, *PCRYPT_OID_FUNC_ENTRY;
1353 
1354 typedef BOOL
1355 (WINAPI *PFN_CRYPT_ENUM_OID_FUNC)(
1356   _In_ DWORD dwEncodingType,
1357   _In_ LPCSTR pszFuncName,
1358   _In_ LPCSTR pszOID,
1359   _In_ DWORD cValue,
1360   _In_reads_(cValue) const DWORD rgdwValueType[],
1361   _In_reads_(cValue) LPCWSTR const rgpwszValueName[],
1362   _In_reads_(cValue) const BYTE * const rgpbValueData[],
1363   _In_reads_(cValue) const DWORD rgcbValueData[],
1364   _Inout_opt_ void *pvArg);
1365 
1366 #define CRYPT_MATCH_ANY_ENCODING_TYPE 0xffffffff
1367 
1368 typedef struct _CRYPT_OID_INFO {
1369     DWORD   cbSize;
1370     LPCSTR  pszOID;
1371     LPCWSTR pwszName;
1372     DWORD   dwGroupId;
1373     union {
1374         DWORD  dwValue;
1375         ALG_ID Algid;
1376         DWORD  dwLength;
1377     } DUMMYUNIONNAME;
1378     CRYPT_DATA_BLOB ExtraInfo;
1379 } CRYPT_OID_INFO, *PCRYPT_OID_INFO;
1380 typedef const CRYPT_OID_INFO CCRYPT_OID_INFO, *PCCRYPT_OID_INFO;
1381 
1382 typedef BOOL
1383 (WINAPI *PFN_CRYPT_ENUM_OID_INFO)(
1384   _In_ PCCRYPT_OID_INFO pInfo,
1385   _Inout_opt_ void *pvArg);
1386 
1387 typedef struct _CRYPT_SIGN_MESSAGE_PARA {
1388     DWORD                      cbSize;
1389     DWORD                      dwMsgEncodingType;
1390     PCCERT_CONTEXT             pSigningCert;
1391     CRYPT_ALGORITHM_IDENTIFIER HashAlgorithm;
1392     void *                     pvHashAuxInfo;
1393     DWORD                      cMsgCert;
1394     PCCERT_CONTEXT            *rgpMsgCert;
1395     DWORD                      cMsgCrl;
1396     PCCRL_CONTEXT             *rgpMsgCrl;
1397     DWORD                      cAuthAttr;
1398     PCRYPT_ATTRIBUTE           rgAuthAttr;
1399     DWORD                      cUnauthAttr;
1400     PCRYPT_ATTRIBUTE           rgUnauthAttr;
1401     DWORD                      dwFlags;
1402     DWORD                      dwInnerContentType;
1403 #ifdef CRYPT_SIGN_MESSAGE_PARA_HAS_CMS_FIELDS
1404     CRYPT_ALGORITHM_IDENTIFIER HashEncryptionAlgorithm;
1405     void *                     pvHashEncryptionAuxInfo;
1406 #endif
1407 } CRYPT_SIGN_MESSAGE_PARA, *PCRYPT_SIGN_MESSAGE_PARA;
1408 
1409 #define CRYPT_MESSAGE_BARE_CONTENT_OUT_FLAG         0x00000001
1410 #define CRYPT_MESSAGE_ENCAPSULATED_CONTENT_OUT_FLAG 0x00000002
1411 #define CRYPT_MESSAGE_KEYID_SIGNER_FLAG             0x00000004
1412 #define CRYPT_MESSAGE_SILENT_KEYSET_FLAG            0x00000008
1413 
1414 typedef PCCERT_CONTEXT
1415 (WINAPI *PFN_CRYPT_GET_SIGNER_CERTIFICATE)(
1416   _Inout_opt_ void *pvGetArg,
1417   _In_ DWORD dwCertEncodingType,
1418   _In_ PCERT_INFO pSignerId,
1419   _In_ HCERTSTORE hMsgCertStore);
1420 
1421 typedef struct _CRYPT_VERIFY_MESSAGE_PARA {
1422     DWORD                            cbSize;
1423     DWORD                            dwMsgAndCertEncodingType;
1424     HCRYPTPROV_LEGACY                hCryptProv;
1425     PFN_CRYPT_GET_SIGNER_CERTIFICATE pfnGetSignerCertificate;
1426     void *                           pvGetArg;
1427 } CRYPT_VERIFY_MESSAGE_PARA, *PCRYPT_VERIFY_MESSAGE_PARA;
1428 
1429 typedef struct _CRYPT_ENCRYPT_MESSAGE_PARA {
1430     DWORD                      cbSize;
1431     DWORD                      dwMsgEncodingType;
1432     HCRYPTPROV_LEGACY          hCryptProv;
1433     CRYPT_ALGORITHM_IDENTIFIER ContentEncryptionAlgorithm;
1434     void *                     pvEncryptionAuxInfo;
1435     DWORD                      dwFlags;
1436     DWORD                      dwInnerContentType;
1437 } CRYPT_ENCRYPT_MESSAGE_PARA, *PCRYPT_ENCRYPT_MESSAGE_PARA;
1438 
1439 #define CRYPT_MESSAGE_KEYID_RECIPIENT_FLAG 0x00000004
1440 
1441 typedef struct _CRYPT_DECRYPT_MESSAGE_PARA {
1442     DWORD       cbSize;
1443     DWORD       dwMsgAndCertEncodingType;
1444     DWORD       cCertStore;
1445     HCERTSTORE *rghCertStore;
1446 #ifdef CRYPT_DECRYPT_MESSAGE_PARA_HAS_EXTRA_FIELDS
1447     DWORD       dwFlags;
1448 #endif
1449 } CRYPT_DECRYPT_MESSAGE_PARA, *PCRYPT_DECRYPT_MESSAGE_PARA;
1450 
1451 typedef struct _CRYPT_HASH_MESSAGE_PARA {
1452     DWORD                      cbSize;
1453     DWORD                      dwMsgEncodingType;
1454     HCRYPTPROV_LEGACY          hCryptProv;
1455     CRYPT_ALGORITHM_IDENTIFIER HashAlgorithm;
1456     void *                     pvHashAuxInfo;
1457 } CRYPT_HASH_MESSAGE_PARA, *PCRYPT_HASH_MESSAGE_PARA;
1458 
1459 typedef struct _CRYPT_KEY_SIGN_MESSAGE_PARA {
1460     DWORD                      cbSize;
1461     DWORD                      dwMsgAndCertEncodingType;
1462     HCRYPTPROV                 hCryptProv;
1463     DWORD                      dwKeySpec;
1464     CRYPT_ALGORITHM_IDENTIFIER HashAlgorithm;
1465     void *                     pvHashAuxInfo;
1466 } CRYPT_KEY_SIGN_MESSAGE_PARA, *PCRYPT_KEY_SIGN_MESSAGE_PARA;
1467 
1468 typedef struct _CRYPT_KEY_VERIFY_MESSAGE_PARA {
1469     DWORD      cbSize;
1470     DWORD      dwMsgEncodingType;
1471     HCRYPTPROV_LEGACY hCryptProv;
1472 } CRYPT_KEY_VERIFY_MESSAGE_PARA, *PCRYPT_KEY_VERIFY_MESSAGE_PARA;
1473 
1474 typedef struct _CRYPT_URL_ARRAY {
1475     DWORD   cUrl;
1476     LPWSTR *rgwszUrl;
1477 } CRYPT_URL_ARRAY, *PCRYPT_URL_ARRAY;
1478 
1479 typedef struct _CRYPT_URL_INFO {
1480     DWORD  cbSize;
1481     DWORD  dwSyncDeltaTime;
1482     DWORD  cGroup;
1483     DWORD *rgcGroupEntry;
1484 } CRYPT_URL_INFO, *PCRYPT_URL_INFO;
1485 
1486 #define URL_OID_CERTIFICATE_ISSUER                  ((LPCSTR)1)
1487 #define URL_OID_CERTIFICATE_CRL_DIST_POINT          ((LPCSTR)2)
1488 #define URL_OID_CTL_ISSUER                          ((LPCSTR)3)
1489 #define URL_OID_CTL_NEXT_UPDATE                     ((LPCSTR)4)
1490 #define URL_OID_CRL_ISSUER                          ((LPCSTR)5)
1491 #define URL_OID_CERTIFICATE_FRESHEST_CRL            ((LPCSTR)6)
1492 #define URL_OID_CRL_FRESHEST_CRL                    ((LPCSTR)7)
1493 #define URL_OID_CROSS_CERT_DIST_POINT               ((LPCSTR)8)
1494 #define URL_OID_CERTIFICATE_OCSP                    ((LPCSTR)9)
1495 #define URL_OID_CERTIFICATE_OCSP_AND_CRL_DIST_POINT ((LPCSTR)10)
1496 #define URL_OID_CERTIFICATE_CRL_DIST_POINT_AND_OCSP ((LPCSTR)11)
1497 #define URL_OID_CROSS_CERT_SUBJECT_INFO_ACCESS      ((LPCSTR)12)
1498 
1499 #define URL_OID_GET_OBJECT_URL_FUNC "UrlDllGetObjectUrl"
1500 
1501 typedef HANDLE HCRYPTASYNC, *PHCRYPTASYNC;
1502 
1503 typedef void
1504 (WINAPI *PFN_CRYPT_ASYNC_PARAM_FREE_FUNC)(
1505   _In_ LPSTR pszParamOid,
1506   _In_ LPVOID pvParam);
1507 
1508 #define CRYPT_PARAM_ASYNC_RETRIEVAL_COMPLETION ((LPCSTR)1)
1509 #define CRYPT_PARAM_CANCEL_ASYNC_RETRIEVAL     ((LPCSTR)2)
1510 
1511 typedef void
1512 (WINAPI *PFN_CRYPT_ASYNC_RETRIEVAL_COMPLETION_FUNC)(
1513   _Inout_opt_ void *pvCompletion,
1514   _In_ DWORD dwCompletionCode,
1515   _In_ LPCSTR pszURL,
1516   _In_opt_ LPSTR pszObjectOid,
1517   _In_ void *pvObject);
1518 
1519 typedef struct _CRYPT_ASYNC_RETRIEVAL_COMPLETION {
1520   __callback PFN_CRYPT_ASYNC_RETRIEVAL_COMPLETION_FUNC pfnCompletion;
1521   _Inout_opt_ void *pvCompletion;
1522 } CRYPT_ASYNC_RETRIEVAL_COMPLETION, *PCRYPT_ASYNC_RETRIEVAL_COMPLETION;
1523 
1524 typedef BOOL
1525 (WINAPI *PFN_CANCEL_ASYNC_RETRIEVAL_FUNC)(
1526   _In_opt_ HCRYPTASYNC hAsyncRetrieve);
1527 
1528 typedef struct _CRYPT_BLOB_ARRAY
1529 {
1530     DWORD            cBlob;
1531     PCRYPT_DATA_BLOB rgBlob;
1532 } CRYPT_BLOB_ARRAY, *PCRYPT_BLOB_ARRAY;
1533 
1534 typedef struct _CRYPT_CREDENTIALS {
1535     DWORD  cbSize;
1536     LPCSTR pszCredentialsOid;
1537     LPVOID pvCredentials;
1538 } CRYPT_CREDENTIALS, *PCRYPT_CREDENTIALS;
1539 
1540 #define CREDENTIAL_OID_PASSWORD_CREDENTIALS_A ((LPCSTR)1)
1541 #define CREDENTIAL_OID_PASSWORD_CREDENTIALS_W ((LPCSTR)2)
1542 #define CREDENTIAL_OID_PASSWORD_CREDENTIALS \
1543  WINELIB_NAME_AW(CREDENTIAL_OID_PASSWORD_CREDENTIALS_)
1544 
1545 typedef struct _CRYPT_PASSWORD_CREDENTIALSA {
1546     DWORD cbSize;
1547     LPSTR pszUsername;
1548     LPSTR pszPassword;
1549 } CRYPT_PASSWORD_CREDENTIALSA, *PCRYPT_PASSWORD_CREDENTIALSA;
1550 
1551 typedef struct _CRYPT_PASSWORD_CREDENTIALSW {
1552     DWORD  cbSize;
1553     LPWSTR pszUsername;
1554     LPWSTR pszPassword;
1555 } CRYPT_PASSWORD_CREDENTIALSW, *PCRYPT_PASSWORD_CREDENTIALSW;
1556 #define CRYPT_PASSWORD_CREDENTIALS WINELIB_NAME_AW(CRYPT_PASSWORD_CREDENTIALS)
1557 #define PCRYPT_PASSWORD_CREDENTIALS WINELIB_NAME_AW(PCRYPT_PASSWORD_CREDENTIALS)
1558 
1559 typedef struct _CRYPT_RETRIEVE_AUX_INFO {
1560     DWORD     cbSize;
1561     FILETIME *pLastSyncTime;
1562     DWORD     dwMaxUrlRetrievalByteCount;
1563 } CRYPT_RETRIEVE_AUX_INFO, *PCRYPT_RETRIEVE_AUX_INFO;
1564 
1565 typedef void
1566 (WINAPI *PFN_FREE_ENCODED_OBJECT_FUNC)(
1567   _In_opt_ LPCSTR pszObjectOid,
1568   _Inout_ PCRYPT_BLOB_ARRAY pObject,
1569   _Inout_opt_ void *pvFreeContext);
1570 
1571 #define SCHEME_OID_RETRIEVE_ENCODED_OBJECT_FUNC \
1572  "SchemeDllRetrieveEncodedObject"
1573 #define SCHEME_OID_RETRIEVE_ENCODED_OBJECTW_FUNC \
1574  "SchemeDllRetrieveEncodedObjectW"
1575 /* The signature of SchemeDllRetrieveEncodedObjectW is:
1576 BOOL WINAPI SchemeDllRetrieveEncodedObjectW(LPCWSTR pwszUrl,
1577  LPCSTR pszObjectOid, DWORD dwRetrievalFlags, DWORD dwTimeout,
1578  PCRYPT_BLOB_ARRAY pObject, PFN_FREE_ENCODED_OBJECT_FUNC *ppfnFreeObject,
1579  void **ppvFreeContext, HCRYPTASYNC hAsyncRetrieve,
1580  PCRYPT_CREDENTIALS pCredentials, PCRYPT_RETRIEVE_AUX_INFO pAuxInfo);
1581  */
1582 
1583 #define CONTEXT_OID_CREATE_OBJECT_CONTEXT_FUNC "ContextDllCreateObjectContext"
1584 /* The signature of ContextDllCreateObjectContext is:
1585 BOOL WINAPI ContextDllCreateObjectContext(LPCSTR pszObjectOid,
1586  DWORD dwRetrievalFlags, PCRYPT_BLOB_ARRAY pObject, void **ppvContxt);
1587  */
1588 
1589 #define CONTEXT_OID_CERTIFICATE ((LPCSTR)1)
1590 #define CONTEXT_OID_CRL         ((LPCSTR)2)
1591 #define CONTEXT_OID_CTL         ((LPCSTR)3)
1592 #define CONTEXT_OID_PKCS7       ((LPCSTR)4)
1593 #define CONTEXT_OID_CAPI2_ANY   ((LPCSTR)5)
1594 
1595 #define CRYPT_RETRIEVE_MULTIPLE_OBJECTS      0x00000001
1596 #define CRYPT_CACHE_ONLY_RETRIEVAL           0x00000002
1597 #define CRYPT_WIRE_ONLY_RETRIEVAL            0x00000004
1598 #define CRYPT_DONT_CACHE_RESULT              0x00000008
1599 #define CRYPT_ASYNC_RETRIEVAL                0x00000010
1600 #define CRYPT_STICKY_CACHE_RETRIEVAL         0x00001000
1601 #define CRYPT_LDAP_SCOPE_BASE_ONLY_RETRIEVAL 0x00002000
1602 #define CRYPT_OFFLINE_CHECK_RETRIEVAL        0x00004000
1603 #define CRYPT_LDAP_INSERT_ENTRY_ATTRIBUTE    0x00008000
1604 #define CRYPT_LDAP_SIGN_RETRIEVAL            0x00010000
1605 #define CRYPT_NO_AUTH_RETRIEVAL              0x00020000
1606 #define CRYPT_LDAP_AREC_EXCLUSIVE_RETRIEVAL  0x00040000
1607 #define CRYPT_AIA_RETRIEVAL                  0x00080000
1608 
1609 #define CRYPT_VERIFY_CONTEXT_SIGNATURE      0x00000020
1610 #define CRYPT_VERIFY_DATA_HASH              0x00000040
1611 #define CRYPT_KEEP_TIME_VALID               0x00000080
1612 #define CRYPT_DONT_VERIFY_SIGNATURE         0x00000100
1613 #define CRYPT_DONT_CHECK_TIME_VALIDITY      0x00000200
1614 #define CRYPT_CHECK_FRESHNESS_TIME_VALIDITY 0x00000400
1615 #define CRYPT_ACCUMULATIVE_TIMEOUT          0x00000800
1616 
1617 typedef BOOL
1618 (WINAPI *PFN_CRYPT_CANCEL_RETRIEVAL)(
1619   _In_ DWORD dwFlags,
1620   _Inout_opt_ void *pvArg);
1621 
1622 typedef struct _CERT_CRL_CONTEXT_PAIR
1623 {
1624     PCCERT_CONTEXT pCertContext;
1625     PCCRL_CONTEXT  pCrlContext;
1626 } CERT_CRL_CONTEXT_PAIR, *PCERT_CRL_CONTEXT_PAIR;
1627 typedef const CERT_CRL_CONTEXT_PAIR *PCCERT_CRL_CONTEXT_PAIR;
1628 
1629 #define TIME_VALID_OID_GET_OBJECT_FUNC   "TimeValidDllGetObject"
1630 
1631 #define TIME_VALID_OID_GET_CTL                    ((LPCSTR)1)
1632 #define TIME_VALID_OID_GET_CRL                    ((LPCSTR)2)
1633 #define TIME_VALID_OID_GET_CRL_FROM_CERT          ((LPCSTR)3)
1634 #define TIME_VALID_OID_GET_FRESHEST_CRL_FROM_CERT ((LPCSTR)4)
1635 #define TIME_VALID_OID_GET_FRESHEST_CRL_FROM_CRL  ((LPCSTR)5)
1636 
1637 #define TIME_VALID_OID_FLUSH_OBJECT_FUNC "TimeValidDllFlushObject"
1638 
1639 #define TIME_VALID_OID_FLUSH_CTL                    ((LPCSTR)1)
1640 #define TIME_VALID_OID_FLUSH_CRL                    ((LPCSTR)2)
1641 #define TIME_VALID_OID_FLUSH_CRL_FROM_CERT          ((LPCSTR)3)
1642 #define TIME_VALID_OID_FLUSH_FRESHEST_CRL_FROM_CERT ((LPCSTR)4)
1643 #define TIME_VALID_OID_FLUSH_FRESHEST_CRL_FROM_CRL  ((LPCSTR)5)
1644 
1645 /* OID group IDs */
1646 #define CRYPT_HASH_ALG_OID_GROUP_ID     1
1647 #define CRYPT_ENCRYPT_ALG_OID_GROUP_ID  2
1648 #define CRYPT_PUBKEY_ALG_OID_GROUP_ID   3
1649 #define CRYPT_SIGN_ALG_OID_GROUP_ID     4
1650 #define CRYPT_RDN_ATTR_OID_GROUP_ID     5
1651 #define CRYPT_EXT_OR_ATTR_OID_GROUP_ID  6
1652 #define CRYPT_ENHKEY_USAGE_OID_GROUP_ID 7
1653 #define CRYPT_POLICY_OID_GROUP_ID       8
1654 #define CRYPT_TEMPLATE_OID_GROUP_ID     9
1655 #define CRYPT_LAST_OID_GROUP_ID         9
1656 
1657 #define CRYPT_FIRST_ALG_OID_GROUP_ID CRYPT_HASH_ALG_OID_GROUP_ID
1658 #define CRYPT_LAST_ALG_OID_GROUP_ID  CRYPT_SIGN_ALG_OID_GROUP_ID
1659 
1660 #define CRYPT_OID_INHIBIT_SIGNATURE_FORMAT_FLAG  0x1
1661 #define CRYPT_OID_USE_PUBKEY_PARA_FOR_PKCS7_FLAG 0x2
1662 #define CRYPT_OID_NO_NULL_ALGORITHM_PARA_FLAG    0x4
1663 
1664 #define CRYPT_OID_INFO_OID_KEY   1
1665 #define CRYPT_OID_INFO_NAME_KEY  2
1666 #define CRYPT_OID_INFO_ALGID_KEY 3
1667 #define CRYPT_OID_INFO_SIGN_KEY  4
1668 
1669 /* Algorithm IDs */
1670 
1671 #define GET_ALG_CLASS(x)                (x & (7 << 13))
1672 #define GET_ALG_TYPE(x)                 (x & (15 << 9))
1673 #define GET_ALG_SID(x)                  (x & (511))
1674 
1675 /* Algorithm Classes */
1676 #define ALG_CLASS_ANY                   (0)
1677 #define ALG_CLASS_SIGNATURE             (1 << 13)
1678 #define ALG_CLASS_MSG_ENCRYPT           (2 << 13)
1679 #define ALG_CLASS_DATA_ENCRYPT          (3 << 13)
1680 #define ALG_CLASS_HASH                  (4 << 13)
1681 #define ALG_CLASS_KEY_EXCHANGE          (5 << 13)
1682 #define ALG_CLASS_ALL                   (7 << 13)
1683 /* Algorithm types */
1684 #define ALG_TYPE_ANY                    (0)
1685 #define ALG_TYPE_DSS                    (1 << 9)
1686 #define ALG_TYPE_RSA                    (2 << 9)
1687 #define ALG_TYPE_BLOCK                  (3 << 9)
1688 #define ALG_TYPE_STREAM                 (4 << 9)
1689 #define ALG_TYPE_DH                     (5 << 9)
1690 #define ALG_TYPE_SECURECHANNEL          (6 << 9)
1691 #define ALG_TYPE_DH_EPHEM               (7 << 9) /* FIXME: find the real TYPE name */
1692 
1693 /* SIDs */
1694 #define ALG_SID_ANY                     (0)
1695 /* RSA SIDs */
1696 #define ALG_SID_RSA_ANY                 0
1697 #define ALG_SID_RSA_PKCS                1
1698 #define ALG_SID_RSA_MSATWORK            2
1699 #define ALG_SID_RSA_ENTRUST             3
1700 #define ALG_SID_RSA_PGP                 4
1701 /* DSS SIDs */
1702 #define ALG_SID_DSS_ANY                 0
1703 #define ALG_SID_DSS_PKCS                1
1704 #define ALG_SID_DSS_DMS                 2
1705 #define ALG_SID_ECDSA                   3
1706 
1707 /* DES SIDs */
1708 #define ALG_SID_DES                     1
1709 #define ALG_SID_3DES                    3
1710 #define ALG_SID_DESX                    4
1711 #define ALG_SID_IDEA                    5
1712 #define ALG_SID_CAST                    6
1713 #define ALG_SID_SAFERSK64               7
1714 #define ALG_SID_SAFERSK128              8
1715 #define ALG_SID_3DES_112                9
1716 #define ALG_SID_CYLINK_MEK             12
1717 #define ALG_SID_RC5                    13
1718 #define ALG_SID_AES_128                14
1719 #define ALG_SID_AES_192                15
1720 #define ALG_SID_AES_256                16
1721 #define ALG_SID_AES                    17
1722 /* Fortezza */
1723 #define ALG_SID_SKIPJACK               10
1724 #define ALG_SID_TEK                    11
1725 /* Diffie-Hellman SIDs */
1726 #define ALG_SID_DH_SANDF                1
1727 #define ALG_SID_DH_EPHEM                2
1728 #define ALG_SID_AGREED_KEY_ANY          3
1729 #define ALG_SID_KEA                     4
1730 #define ALG_SID_ECDH                    5
1731 #define ALG_SID_ECDH_EPHEM              6 /* FIXME: find the real SID name */
1732 /* RC2 SIDs */
1733 #define ALG_SID_RC4                     1
1734 #define ALG_SID_RC2                     2
1735 #define ALG_SID_SEAL                    2
1736 /* Hash SIDs */
1737 #define ALG_SID_MD2                     1
1738 #define ALG_SID_MD4                     2
1739 #define ALG_SID_MD5                     3
1740 #define ALG_SID_SHA                     4
1741 #define ALG_SID_SHA1                    ALG_SID_SHA
1742 #define ALG_SID_MAC                     5
1743 #define ALG_SID_RIPEMD                  6
1744 #define ALG_SID_RIPEMD160               7
1745 #define ALG_SID_SSL3SHAMD5              8
1746 #define ALG_SID_HMAC                    9
1747 #define ALG_SID_TLS1PRF                10
1748 #define ALG_SID_HASH_REPLACE_OWF       11
1749 #define ALG_SID_SHA_256                12
1750 #define ALG_SID_SHA_384                13
1751 #define ALG_SID_SHA_512                14
1752 /* SCHANNEL SIDs */
1753 #define ALG_SID_SSL3_MASTER             1
1754 #define ALG_SID_SCHANNEL_MASTER_HASH    2
1755 #define ALG_SID_SCHANNEL_MAC_KEY        3
1756 #define ALG_SID_PCT1_MASTER             4
1757 #define ALG_SID_SSL2_MASTER             5
1758 #define ALG_SID_TLS1_MASTER             6
1759 #define ALG_SID_SCHANNEL_ENC_KEY        7
1760 #define ALG_SID_EXAMPLE                80
1761 
1762 #define ALG_SID_ECMQV                   1
1763 
1764 /* Algorithm Definitions */
1765 #define CALG_MD2                  (ALG_CLASS_HASH         | ALG_TYPE_ANY           | ALG_SID_MD2)
1766 #define CALG_MD4                  (ALG_CLASS_HASH         | ALG_TYPE_ANY           | ALG_SID_MD4)
1767 #define CALG_MD5                  (ALG_CLASS_HASH         | ALG_TYPE_ANY           | ALG_SID_MD5)
1768 #define CALG_SHA                  (ALG_CLASS_HASH         | ALG_TYPE_ANY           | ALG_SID_SHA)
1769 #define CALG_SHA1 CALG_SHA
1770 #define CALG_MAC                  (ALG_CLASS_HASH         | ALG_TYPE_ANY           | ALG_SID_MAC)
1771 #define CALG_SSL3_SHAMD5          (ALG_CLASS_HASH         | ALG_TYPE_ANY           | ALG_SID_SSL3SHAMD5)
1772 #define CALG_HMAC                 (ALG_CLASS_HASH         | ALG_TYPE_ANY           | ALG_SID_HMAC)
1773 #define CALG_TLS1PRF              (ALG_CLASS_HASH         | ALG_TYPE_ANY           | ALG_SID_TLS1PRF)
1774 #define CALG_HASH_REPLACE_OWF     (ALG_CLASS_HASH         | ALG_TYPE_ANY           | ALG_SID_HASH_REPLACE_OWF)
1775 #define CALG_SHA_256              (ALG_CLASS_HASH         | ALG_TYPE_ANY           | ALG_SID_SHA_256)
1776 #define CALG_SHA_384              (ALG_CLASS_HASH         | ALG_TYPE_ANY           | ALG_SID_SHA_384)
1777 #define CALG_SHA_512              (ALG_CLASS_HASH         | ALG_TYPE_ANY           | ALG_SID_SHA_512)
1778 #define CALG_RSA_SIGN             (ALG_CLASS_SIGNATURE    | ALG_TYPE_RSA           | ALG_SID_RSA_ANY)
1779 #define CALG_DSS_SIGN             (ALG_CLASS_SIGNATURE    | ALG_TYPE_DSS           | ALG_SID_DSS_ANY)
1780 #define CALG_NO_SIGN              (ALG_CLASS_SIGNATURE    | ALG_TYPE_ANY           | ALG_SID_ANY)
1781 #define CALG_DH_SF                (ALG_CLASS_KEY_EXCHANGE | ALG_TYPE_DH            | ALG_SID_DH_SANDF)
1782 #define CALG_DH_EPHEM             (ALG_CLASS_KEY_EXCHANGE | ALG_TYPE_DH            | ALG_SID_DH_EPHEM)
1783 #define CALG_AGREEDKEY_ANY        (ALG_CLASS_KEY_EXCHANGE | ALG_TYPE_DH            | ALG_SID_AGREED_KEY_ANY)
1784 #define CALG_KEA_KEYX             (ALG_CLASS_KEY_EXCHANGE | ALG_TYPE_DH            | ALG_SID_KEA)
1785 #define CALG_HUGHES_MD5           (ALG_CLASS_KEY_EXCHANGE | ALG_TYPE_ANY           | ALG_SID_MD5)
1786 #define CALG_RSA_KEYX             (ALG_CLASS_KEY_EXCHANGE | ALG_TYPE_RSA           | ALG_SID_RSA_ANY)
1787 #define CALG_ECDH                 (ALG_CLASS_KEY_EXCHANGE | ALG_TYPE_DH            | ALG_SID_ECDH)
1788 #define CALG_ECDH_EPHEM           (ALG_CLASS_KEY_EXCHANGE | ALG_TYPE_DH_EPHEM      | ALG_SID_ECDH_EPHEM) /* FIXME: find the original TYPE and SID names */
1789 #define CALG_ECMQV                (ALG_CLASS_KEY_EXCHANGE | ALG_TYPE_ANY           | ALG_SID_ECMQV)
1790 #define CALG_DES                  (ALG_CLASS_DATA_ENCRYPT | ALG_TYPE_BLOCK         | ALG_SID_DES)
1791 #define CALG_RC2                  (ALG_CLASS_DATA_ENCRYPT | ALG_TYPE_BLOCK         | ALG_SID_RC2)
1792 #define CALG_3DES                 (ALG_CLASS_DATA_ENCRYPT | ALG_TYPE_BLOCK         | ALG_SID_3DES)
1793 #define CALG_3DES_112             (ALG_CLASS_DATA_ENCRYPT | ALG_TYPE_BLOCK         | ALG_SID_3DES_112)
1794 #define CALG_DESX                 (ALG_CLASS_DATA_ENCRYPT | ALG_TYPE_BLOCK         | ALG_SID_DESX)
1795 #define CALG_AES_128              (ALG_CLASS_DATA_ENCRYPT | ALG_TYPE_BLOCK         | ALG_SID_AES_128)
1796 #define CALG_AES_192              (ALG_CLASS_DATA_ENCRYPT | ALG_TYPE_BLOCK         | ALG_SID_AES_192)
1797 #define CALG_AES_256              (ALG_CLASS_DATA_ENCRYPT | ALG_TYPE_BLOCK         | ALG_SID_AES_256)
1798 #define CALG_AES                  (ALG_CLASS_DATA_ENCRYPT | ALG_TYPE_BLOCK         | ALG_SID_AES)
1799 #define CALG_RC4                  (ALG_CLASS_DATA_ENCRYPT | ALG_TYPE_STREAM        | ALG_SID_RC4)
1800 #define CALG_SEAL                 (ALG_CLASS_DATA_ENCRYPT | ALG_TYPE_STREAM        | ALG_SID_SEAL)
1801 #define CALG_RC5                  (ALG_CLASS_DATA_ENCRYPT | ALG_TYPE_STREAM        | ALG_SID_RC5)
1802 #define CALG_SKIPJACK             (ALG_CLASS_DATA_ENCRYPT | ALG_TYPE_BLOCK         | ALG_SID_SKIPJACK)
1803 #define CALG_TEK                  (ALG_CLASS_DATA_ENCRYPT | ALG_TYPE_BLOCK         | ALG_SID_TEK)
1804 #define CALG_CYLINK_MEK           (ALG_CLASS_DATA_ENCRYPT | ALG_TYPE_BLOCK         | ALG_SID_CYLINK_MEK)
1805 #define CALG_SSL3_MASTER          (ALG_CLASS_MSG_ENCRYPT  | ALG_TYPE_SECURECHANNEL | ALG_SID_SSL3_MASTER)
1806 #define CALG_SCHANNEL_MASTER_HASH (ALG_CLASS_MSG_ENCRYPT  | ALG_TYPE_SECURECHANNEL | ALG_SID_SCHANNEL_MASTER_HASH)
1807 #define CALG_SCHANNEL_MAC_KEY     (ALG_CLASS_MSG_ENCRYPT  | ALG_TYPE_SECURECHANNEL | ALG_SID_SCHANNEL_MAC_KEY)
1808 #define CALG_SCHANNEL_ENC_KEY     (ALG_CLASS_MSG_ENCRYPT  | ALG_TYPE_SECURECHANNEL | ALG_SID_SCHANNEL_ENC_KEY)
1809 #define CALG_PCT1_MASTER          (ALG_CLASS_MSG_ENCRYPT  | ALG_TYPE_SECURECHANNEL | ALG_SID_PCT1_MASTER)
1810 #define CALG_SSL2_MASTER          (ALG_CLASS_MSG_ENCRYPT  | ALG_TYPE_SECURECHANNEL | ALG_SID_SSL2_MASTER)
1811 #define CALG_TLS1_MASTER          (ALG_CLASS_MSG_ENCRYPT  | ALG_TYPE_SECURECHANNEL | ALG_SID_TLS1_MASTER)
1812 #define CALG_ECDSA                (ALG_CLASS_SIGNATURE    | ALG_TYPE_DSS           | ALG_SID_ECDSA)
1813 /* Protocol Flags */
1814 #define CRYPT_FLAG_PCT1    0x0001
1815 #define CRYPT_FLAG_SSL2    0x0002
1816 #define CRYPT_FLAG_SSL3    0x0004
1817 #define CRYPT_FLAG_TLS1    0x0008
1818 #define CRYPT_FLAG_IPSEC   0x0010
1819 #define CRYPT_FLAG_SIGNING 0x0020
1820 
1821 /* Provider names */
1822 #define MS_DEF_PROV_A                            "Microsoft Base Cryptographic Provider v1.0"
1823 #if defined(__GNUC__)
1824 # define MS_DEF_PROV_W (const WCHAR []){ 'M','i','c','r','o','s','o','f','t',' ', \
1825 	'B','a','s','e',' ','C','r','y','p','t','o','g','r','a','p','h','i','c',' ', \
1826 	'P','r','o','v','i','d','e','r',' ','v','1','.','0',0 }
1827 #elif defined(_MSC_VER)
1828 # define MS_DEF_PROV_W      L"Microsoft Base Cryptographic Provider v1.0"
1829 #else
1830 static const WCHAR MS_DEF_PROV_W[] =             { 'M','i','c','r','o','s','o','f','t',' ',
1831 	'B','a','s','e',' ','C','r','y','p','t','o','g','r','a','p','h','i','c',' ',
1832 	'P','r','o','v','i','d','e','r',' ','v','1','.','0',0 };
1833 #endif
1834 #define MS_DEF_PROV                              WINELIB_NAME_AW(MS_DEF_PROV_)
1835 
1836 #define MS_ENHANCED_PROV_A                       "Microsoft Enhanced Cryptographic Provider v1.0"
1837 #if defined(__GNUC__)
1838 # define MS_ENHANCED_PROV_W (const WCHAR []){ 'M','i','c','r','o','s','o','f','t',' ', \
1839 	'E','n','h','a','n','c','e','d',' ','C','r','y','p','t','o','g','r','a','p','h','i','c',' ', \
1840 	'P','r','o','v','i','d','e','r',' ','v','1','.','0',0 }
1841 #elif defined(_MSC_VER)
1842 # define MS_ENHANCED_PROV_W     L"Microsoft Enhanced Cryptographic Provider v1.0"
1843 #else
1844 static const WCHAR MS_ENHANCED_PROV_W[] =        { 'M','i','c','r','o','s','o','f','t',' ',
1845 	'E','n','h','a','n','c','e','d',' ','C','r','y','p','t','o','g','r','a','p','h','i','c',' ',
1846 	'P','r','o','v','i','d','e','r',' ','v','1','.','0',0 };
1847 #endif
1848 #define MS_ENHANCED_PROV                         WINELIB_NAME_AW(MS_ENHANCED_PROV_)
1849 
1850 #define MS_STRONG_PROV_A                         "Microsoft Strong Cryptographic Provider"
1851 #if defined(__GNUC__)
1852 # define MS_STRONG_PROV_W (const WCHAR []){ 'M','i','c','r','o','s','o','f','t',' ', \
1853 	'S','t','r','o','n','g',' ','C','r','y','p','t','o','g','r','a','p','h','i','c',' ', \
1854 	'P','r','o','v','i','d','e','r',0 }
1855 #elif defined(_MSC_VER)
1856 # define MS_STRONG_PROV_W     L"Microsoft Strong Cryptographic Provider"
1857 #else
1858 static const WCHAR MS_STRONG_PROV_W[] =          { 'M','i','c','r','o','s','o','f','t',' ',
1859 	'S','t','r','o','n','g',' ','C','r','y','p','t','o','g','r','a','p','h','i','c',' ',
1860 	'P','r','o','v','i','d','e','r',0 };
1861 #endif
1862 #define MS_STRONG_PROV                           WINELIB_NAME_AW(MS_STRONG_PROV_)
1863 
1864 #define MS_DEF_RSA_SIG_PROV_A                    "Microsoft RSA Signature Cryptographic Provider"
1865 #if defined(__GNUC__)
1866 # define MS_DEF_RSA_SIG_PROV_W (const WCHAR []){ 'M','i','c','r','o','s','o','f','t',' ', \
1867 	'R','S','A',' ','S','i','g','n','a','t','u','r','e',' ', \
1868 	'C','r','y','p','t','o','g','r','a','p','h','i','c',' ','P','r','o','v','i','d','e','r',0 }
1869 #elif defined(_MSC_VER)
1870 # define MS_DEF_RSA_SIG_PROV_W      L"Microsoft RSA Signature Cryptographic Provider"
1871 #else
1872 static const WCHAR MS_DEF_RSA_SIG_PROV_W[] =     { 'M','i','c','r','o','s','o','f','t',' ',
1873 	'R','S','A',' ','S','i','g','n','a','t','u','r','e',' ',
1874 	'C','r','y','p','t','o','g','r','a','p','h','i','c',' ','P','r','o','v','i','d','e','r',0 };
1875 #endif
1876 #define MS_DEF_RSA_SIG_PROV                      WINELIB_NAME_AW(MS_DEF_RSA_SIG_PROV_)
1877 
1878 #define MS_DEF_RSA_SCHANNEL_PROV_A               "Microsoft RSA SChannel Cryptographic Provider"
1879 #if defined(__GNUC__)
1880 # define MS_DEF_RSA_SCHANNEL_PROV_W (const WCHAR []){ 'M','i','c','r','o','s','o','f','t',' ', \
1881 	'R','S','A',' ','S','C','h','a','n','n','e','l',' ', \
1882 	'C','r','y','p','t','o','g','r','a','p','h','i','c',' ','P','r','o','v','i','d','e','r',0 }
1883 #elif defined(_MSC_VER)
1884 # define MS_DEF_RSA_SCHANNEL_PROV_W     L"Microsoft RSA SChannel Cryptographic Provider"
1885 #else
1886 static const WCHAR MS_DEF_RSA_SCHANNEL_PROV_W[] = { 'M','i','c','r','o','s','o','f','t',' ',
1887 	'R','S','A',' ','S','C','h','a','n','n','e','l',' ',
1888 	'C','r','y','p','t','o','g','r','a','p','h','i','c',' ','P','r','o','v','i','d','e','r',0 };
1889 #endif
1890 #define MS_DEF_RSA_SCHANNEL_PROV                 WINELIB_NAME_AW(MS_DEF_RSA_SCHANNEL_PROV_)
1891 
1892 #define MS_DEF_DSS_PROV_A                        "Microsoft Base DSS Cryptographic Provider"
1893 #if defined(__GNUC__)
1894 # define MS_DEF_DSS_PROV_W (const WCHAR []){ 'M','i','c','r','o','s','o','f','t',' ', \
1895 	'B','a','s','e',' ','D','S','S',' ', \
1896 	'C','r','y','p','t','o','g','r','a','p','h','i','c',' ','P','r','o','v','i','d','e','r',0 }
1897 #elif defined(_MSC_VER)
1898 # define MS_DEF_DSS_PROV_W     L"Microsoft Base DSS Cryptographic Provider"
1899 #else
1900 static const WCHAR MS_DEF_DSS_PROV_W[] =         { 'M','i','c','r','o','s','o','f','t',' ',
1901 	'B','a','s','e',' ','D','S','S',' ',
1902 	'C','r','y','p','t','o','g','r','a','p','h','i','c',' ','P','r','o','v','i','d','e','r',0 };
1903 #endif
1904 #define MS_DEF_DSS_PROV                          WINELIB_NAME_AW(MS_DEF_DSS_PROV_)
1905 
1906 #define MS_DEF_DSS_DH_PROV_A                     "Microsoft Base DSS and Diffie-Hellman Cryptographic Provider"
1907 #if defined(__GNUC__)
1908 # define MS_DEF_DSS_DH_PROV_W (const WCHAR []){ 'M','i','c','r','o','s','o','f','t',' ', \
1909 	'B','a','s','e',' ','D','S','S',' ','a','n','d',' ', \
1910 	'D','i','f','f','i','e','-','H','e','l','l','m','a','n',' ', \
1911 	'C','r','y','p','t','o','g','r','a','p','h','i','c',' ','P','r','o','v','i','d','e','r',0 }
1912 #elif defined(_MSC_VER)
1913 # define MS_DEF_DSS_DH_PROV_W     L"Microsoft Base DSS and Diffie-Hellman Cryptographic Provider"
1914 #else
1915 static const WCHAR MS_DEF_DSS_DH_PROV_W[] =      { 'M','i','c','r','o','s','o','f','t',' ',
1916 	'B','a','s','e',' ','D','S','S',' ','a','n','d',' ',
1917 	'D','i','f','f','i','e','-','H','e','l','l','m','a','n',' ',
1918 	'C','r','y','p','t','o','g','r','a','p','h','i','c',' ','P','r','o','v','i','d','e','r',0 };
1919 #endif
1920 #define MS_DEF_DSS_DH_PROV                       WINELIB_NAME_AW(MS_DEF_DSS_DH_PROV_)
1921 
1922 #define MS_ENH_DSS_DH_PROV_A                     "Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider"
1923 #if defined(__GNUC__)
1924 # define MS_ENH_DSS_DH_PROV_W (const WCHAR []){ 'M','i','c','r','o','s','o','f','t',' ', \
1925 	'E','n','h','a','n','c','e','d',' ','D','S','S',' ','a','n','d',' ', \
1926 	'D','i','f','f','i','e','-','H','e','l','l','m','a','n',' ', \
1927 	'C','r','y','p','t','o','g','r','a','p','h','i','c',' ','P','r','o','v','i','d','e','r',0 }
1928 #elif defined(_MSC_VER)
1929 # define MS_ENH_DSS_DH_PROV_W     L"Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider"
1930 #else
1931 static const WCHAR MS_ENH_DSS_DH_PROV_W[] =      { 'M','i','c','r','o','s','o','f','t',' ',
1932 	'E','n','h','a','n','c','e','d',' ','D','S','S',' ','a','n','d',' ',
1933 	'D','i','f','f','i','e','-','H','e','l','l','m','a','n',' ',
1934 	'C','r','y','p','t','o','g','r','a','p','h','i','c',' ','P','r','o','v','i','d','e','r',0 };
1935 #endif
1936 #define MS_ENH_DSS_DH_PROV                       WINELIB_NAME_AW(MS_ENH_DSS_DH_PROV_)
1937 
1938 #define MS_DEF_DH_SCHANNEL_PROV_A                "Microsoft DH SChannel Cryptographic Provider"
1939 #if defined(__GNUC__)
1940 # define MS_DEF_DH_SCHANNEL_PROV_W (const WCHAR []){ 'M','i','c','r','o','s','o','f','t',' ', \
1941 	'D','H',' ','S','C','h','a','n','n','e','l',' ', \
1942 	'C','r','y','p','t','o','g','r','a','p','h','i','c',' ','P','r','o','v','i','d','e','r',0 }
1943 #elif defined(_MSC_VER)
1944 # define MS_DEF_DH_SCHANNEL_PROV_W     L"Microsoft DH SChannel Cryptographic Provider"
1945 #else
1946 static const WCHAR MS_DEF_DH_SCHANNEL_PROV_W[] = { 'M','i','c','r','o','s','o','f','t',' ',
1947 	'D','H',' ','S','C','h','a','n','n','e','l',' ',
1948 	'C','r','y','p','t','o','g','r','a','p','h','i','c',' ','P','r','o','v','i','d','e','r',0 };
1949 #endif
1950 #define MS_DEF_DH_SCHANNEL_PROV                  WINELIB_NAME_AW(MS_DEF_DH_SCHANNEL_PROV_)
1951 
1952 #define MS_SCARD_PROV_A                          "Microsoft Base Smart Card Cryptographic Provider"
1953 #if defined(__GNUC__)
1954 # define MS_SCARD_PROV_W (const WCHAR []){ 'M','i','c','r','o','s','o','f','t',' ', \
1955 	'B','a','s','e',' ','S','m','a','r','t',' ','C','a','r','d',' ', \
1956 	'C','r','y','p','t','o','g','r','a','p','h','i','c',' ','P','r','o','v','i','d','e','r',0 }
1957 #elif defined(_MSC_VER)
1958 # define MS_SCARD_PROV_W     L"Microsoft Base Smart Card Cryptographic Provider"
1959 #else
1960 static const WCHAR MS_SCARD_PROV_W[] =           { 'M','i','c','r','o','s','o','f','t',' ',
1961 	'B','a','s','e',' ','S','m','a','r','t',' ','C','a','r','d',' ',
1962 	'C','r','y','p','t','o','g','r','a','p','h','i','c',' ','P','r','o','v','i','d','e','r',0 };
1963 #endif
1964 #define MS_SCARD_PROV                            WINELIB_NAME_AW(MS_SCARD_PROV_)
1965 
1966 #define MS_ENH_RSA_AES_PROV_A                          "Microsoft Enhanced RSA and AES Cryptographic Provider"
1967 #if defined(__GNUC__)
1968 # define MS_ENH_RSA_AES_PROV_W (const WCHAR []){ 'M','i','c','r','o','s','o','f','t',' ', \
1969 	'E','n','h','a','n','c','e','d',' ','R','S','A',' ','a','n','d',' ','A','E','S',' ',\
1970 	'C','r','y','p','t','o','g','r','a','p','h','i','c',' ','P','r','o','v','i','d','e','r',0 }
1971 #elif defined(_MSC_VER)
1972 # define MS_ENH_RSA_AES_PROV_W     L"Microsoft Enhanced RSA and AES Cryptographic Provider"
1973 #else
1974 static const WCHAR MS_ENH_RSA_AES_PROV_W[] =           { 'M','i','c','r','o','s','o','f','t',' ',
1975 	'E','n','h','a','n','c','e','d',' ','R','S','A',' ','a','n','d',' ','A','E','S',' ',
1976 	'C','r','y','p','t','o','g','r','a','p','h','i','c',' ','P','r','o','v','i','d','e','r',0 };
1977 #endif
1978 #define MS_ENH_RSA_AES_PROV                            WINELIB_NAME_AW(MS_ENH_RSA_AES_PROV_)
1979 
1980 #define MS_ENH_RSA_AES_PROV_XP_A    "Microsoft Enhanced RSA and AES Cryptographic Provider (Prototype)"
1981 #if defined(__GNUC__)
1982 # define MS_ENH_RSA_AES_PROV_XP_W (const WCHAR []){ 'M','i','c','r','o','s','o','f','t',' ', \
1983         'E','n','h','a','n','c','e','d',' ','R','S','A',' ','a','n','d',' ','A','E','S',' ',\
1984         'C','r','y','p','t','o','g','r','a','p','h','i','c',' ','P','r','o','v','i','d','e','r',' ',\
1985         '(','P','r','o','t','o','t','y','p','e',')',0 }
1986 #elif defined(_MSC_VER)
1987 # define MS_ENH_RSA_AES_PROV_XP_W   L"Microsoft Enhanced RSA and AES Cryptographic Provider (Prototype)"
1988 #else
1989 static const WCHAR MS_ENH_RSA_AES_PROV_XP_W[] = { 'M','i','c','r','o','s','o','f','t',' ',
1990         'E','n','h','a','n','c','e','d',' ','R','S','A',' ','a','n','d',' ','A','E','S',' ',
1991         'C','r','y','p','t','o','g','r','a','p','h','i','c',' ','P','r','o','v','i','d','e','r',' ',
1992         '(','P','r','o','t','o','t','y','p','e',')',0 };
1993 #endif
1994 #define MS_ENH_RSA_AES_PROV_XP                   WINELIB_NAME_AW(MS_ENH_RSA_AES_PROV_XP_)
1995 
1996 /* Key Specs*/
1997 #define AT_KEYEXCHANGE          1
1998 #define AT_SIGNATURE            2
1999 
2000 /* Provider Types */
2001 #define PROV_RSA_FULL             1
2002 #define PROV_RSA_SIG              2
2003 #define PROV_DSS                  3
2004 #define PROV_FORTEZZA             4
2005 #define PROV_MS_EXCHANGE          5
2006 #define PROV_SSL                  6
2007 #define PROV_RSA_SCHANNEL         12
2008 #define PROV_DSS_DH               13
2009 #define PROV_EC_ECDSA_SIG         14
2010 #define PROV_EC_ECNRA_SIG         15
2011 #define PROV_EC_ECDSA_FULL        16
2012 #define PROV_EC_ECNRA_FULL        17
2013 #define PROV_DH_SCHANNEL          18
2014 #define PROV_SPYRUS_LYNKS         20
2015 #define PROV_RNG                  21
2016 #define PROV_INTEL_SEC            22
2017 #define PROV_REPLACE_OWF          23
2018 #define PROV_RSA_AES              24
2019 
2020 /* FLAGS Section */
2021 
2022 #define CRYPT_FIRST             1
2023 #define CRYPT_NEXT              2
2024 
2025 #define CRYPT_IMPL_HARDWARE     1
2026 #define CRYPT_IMPL_SOFTWARE     2
2027 #define CRYPT_IMPL_MIXED        3
2028 #define CRYPT_IMPL_UNKNOWN      4
2029 
2030 /* CryptAcquireContext */
2031 #define CRYPT_VERIFYCONTEXT       0xF0000000
2032 #define CRYPT_NEWKEYSET           0x00000008
2033 #define CRYPT_DELETEKEYSET        0x00000010
2034 #define CRYPT_MACHINE_KEYSET      0x00000020
2035 #define CRYPT_SILENT              0x00000040
2036 
2037 /* Crypt{Get|Set}Provider */
2038 #define CRYPT_MACHINE_DEFAULT     0x00000001
2039 #define CRYPT_USER_DEFAULT        0x00000002
2040 #define CRYPT_DELETE_DEFAULT      0x00000004
2041 
2042 /* Crypt{Get/Set}ProvParam */
2043 #define PP_CLIENT_HWND          1
2044 #define PP_ENUMALGS             1
2045 #define PP_ENUMCONTAINERS       2
2046 #define PP_IMPTYPE              3
2047 #define PP_NAME                 4
2048 #define PP_VERSION              5
2049 #define PP_CONTAINER            6
2050 #define PP_CHANGE_PASSWORD      7
2051 #define PP_KEYSET_SEC_DESCR     8
2052 #define PP_KEY_TYPE_SUBTYPE     10
2053 #define PP_CONTEXT_INFO         11
2054 #define PP_KEYEXCHANGE_KEYSIZE  12
2055 #define PP_SIGNATURE_KEYSIZE    13
2056 #define PP_KEYEXCHANGE_ALG      14
2057 #define PP_SIGNATURE_ALG        15
2058 #define PP_PROVTYPE             16
2059 #define PP_KEYSTORAGE           17
2060 #define PP_SYM_KEYSIZE          19
2061 #define PP_SESSION_KEYSIZE      20
2062 #define PP_UI_PROMPT            21
2063 #define PP_ENUMALGS_EX          22
2064 #define PP_DELETEKEY            24
2065 #define PP_ENUMMANDROOTS        25
2066 #define PP_ENUMELECTROOTS       26
2067 #define PP_KEYSET_TYPE          27
2068 #define PP_ADMIN_PIN            31
2069 #define PP_KEYEXCHANGE_PIN      32
2070 #define PP_SIGNATURE_PIN        33
2071 #define PP_SIG_KEYSIZE_INC      34
2072 #define PP_KEYX_KEYSIZE_INC     35
2073 #define PP_UNIQUE_CONTAINER     36
2074 #define PP_SGC_INFO             37
2075 #define PP_USE_HARDWARE_RNG     38
2076 #define PP_KEYSPEC              39
2077 #define PP_ENUMEX_SIGNING_PROT  40
2078 #define PP_CRYPT_COUNT_KEY_USE  41
2079 #define PP_USER_CERTSTORE       42
2080 #define PP_SMARTCARD_READER     43
2081 #define PP_SMARTCARD_GUID       45
2082 #define PP_ROOT_CERTSTORE       46
2083 
2084 /* Values returned by CryptGetProvParam of PP_KEYSTORAGE */
2085 #define CRYPT_SEC_DESCR         0x00000001
2086 #define CRYPT_PSTORE            0x00000002
2087 #define CRYPT_UI_PROMPT         0x00000004
2088 
2089 /* Crypt{Get/Set}KeyParam */
2090 #define KP_IV                   1
2091 #define KP_SALT                 2
2092 #define KP_PADDING              3
2093 #define KP_MODE                 4
2094 #define KP_MODE_BITS            5
2095 #define KP_PERMISSIONS          6
2096 #define KP_ALGID                7
2097 #define KP_BLOCKLEN             8
2098 #define KP_KEYLEN               9
2099 #define KP_SALT_EX              10
2100 #define KP_P                    11
2101 #define KP_G                    12
2102 #define KP_Q                    13
2103 #define KP_X                    14
2104 #define KP_Y                    15
2105 #define KP_RA                   16
2106 #define KP_RB                   17
2107 #define KP_INFO                 18
2108 #define KP_EFFECTIVE_KEYLEN     19
2109 #define KP_SCHANNEL_ALG         20
2110 #define KP_CLIENT_RANDOM        21
2111 #define KP_SERVER_RANDOM        22
2112 #define KP_RP                   23
2113 #define KP_PRECOMP_MD5          24
2114 #define KP_PRECOMP_SHA          25
2115 #define KP_CERTIFICATE          26
2116 #define KP_CLEAR_KEY            27
2117 #define KP_PUB_EX_LEN           28
2118 #define KP_PUB_EX_VAL           29
2119 #define KP_KEYVAL               30
2120 #define KP_ADMIN_PIN            31
2121 #define KP_KEYEXCHANGE_PIN      32
2122 #define KP_SIGNATURE_PIN        33
2123 #define KP_PREHASH              34
2124 #define KP_ROUNDS               35
2125 #define KP_OAEP_PARAMS          36
2126 #define KP_CMS_KEY_INFO         37
2127 #define KP_CMS_DH_KEY_INFO      38
2128 #define KP_PUB_PARAMS           39
2129 #define KP_VERIFY_PARAMS        40
2130 #define KP_HIGHEST_VERSION      41
2131 #define KP_GET_USE_COUNT        42
2132 
2133 /* Values for KP_PADDING */
2134 #define PKCS5_PADDING  1
2135 #define RANDOM_PADDING 2
2136 #define ZERO_PADDING   3
2137 
2138 /* CryptSignHash/CryptVerifySignature */
2139 #define CRYPT_NOHASHOID         0x00000001
2140 #define CRYPT_TYPE2_FORMAT      0x00000002
2141 #define CRYPT_X931_FORMAT       0x00000004
2142 
2143 /* Crypt{Get,Set}HashParam */
2144 #define HP_ALGID                0x0001
2145 #define HP_HASHVAL              0x0002
2146 #define HP_HASHSIZE             0x0004
2147 #define HP_HMAC_INFO            0x0005
2148 #define HP_TLS1PRF_LABEL        0x0006
2149 #define HP_TLS1PRF_SEED         0x0007
2150 
2151 /* Crypt{Get,Set}KeyParam */
2152 #define CRYPT_MODE_CBC          1
2153 #define CRYPT_MODE_ECB          2
2154 #define CRYPT_MODE_OFB          3
2155 #define CRYPT_MODE_CFB          4
2156 
2157 #define CRYPT_ENCRYPT           0x0001
2158 #define CRYPT_DECRYPT           0x0002
2159 #define CRYPT_EXPORT            0x0004
2160 #define CRYPT_READ              0x0008
2161 #define CRYPT_WRITE             0x0010
2162 #define CRYPT_MAC               0x0020
2163 #define CRYPT_EXPORT_KEY        0x0040
2164 #define CRYPT_IMPORT_KEY        0x0080
2165 #define CRYPT_ARCHIVE           0x0100
2166 
2167 /* Crypt*Key */
2168 #define CRYPT_EXPORTABLE        0x00000001
2169 #define CRYPT_USER_PROTECTED    0x00000002
2170 #define CRYPT_CREATE_SALT       0x00000004
2171 #define CRYPT_UPDATE_KEY        0x00000008
2172 #define CRYPT_NO_SALT           0x00000010
2173 #define CRYPT_PREGEN            0x00000040
2174 #define CRYPT_SERVER            0x00000400
2175 #define CRYPT_ARCHIVABLE        0x00004000
2176 
2177 /* CryptExportKey */
2178 #define CRYPT_SSL2_FALLBACK     0x00000002
2179 #define CRYPT_DESTROYKEY        0x00000004
2180 #define CRYPT_OAEP              0x00000040
2181 
2182 /* CryptHashSessionKey */
2183 #define CRYPT_LITTLE_ENDIAN     0x00000001
2184 
2185 /* Crypt{Protect,Unprotect}Data PROMPTSTRUCT flags */
2186 #define CRYPTPROTECT_PROMPT_ON_PROTECT    0x0001
2187 #define CRYPTPROTECT_PROMPT_ON_UNPROTECT  0x0002
2188 /* Crypt{Protect,Unprotect}Data flags */
2189 #define CRYPTPROTECT_UI_FORBIDDEN       0x0001
2190 #define CRYPTPROTECT_LOCAL_MACHINE      0x0004
2191 #define CRYPTPROTECT_AUDIT              0x0010
2192 #define CRYPTPROTECT_VERIFY_PROTECTION  0x0040
2193 
2194 /* Blob Types */
2195 #define SIMPLEBLOB              0x1
2196 #define PUBLICKEYBLOB           0x6
2197 #define PRIVATEKEYBLOB          0x7
2198 #define PLAINTEXTKEYBLOB        0x8
2199 #define OPAQUEKEYBLOB           0x9
2200 #define PUBLICKEYBLOBEX         0xA
2201 #define SYMMETRICWRAPKEYBLOB    0xB
2202 
2203 #define CUR_BLOB_VERSION        2
2204 
2205 /* cert store provider types */
2206 #define CERT_STORE_PROV_MSG                  ((LPCSTR)1)
2207 #define CERT_STORE_PROV_MEMORY               ((LPCSTR)2)
2208 #define CERT_STORE_PROV_FILE                 ((LPCSTR)3)
2209 #define CERT_STORE_PROV_REG                  ((LPCSTR)4)
2210 #define CERT_STORE_PROV_PKCS7                ((LPCSTR)5)
2211 #define CERT_STORE_PROV_SERIALIZED           ((LPCSTR)6)
2212 #define CERT_STORE_PROV_FILENAME_A           ((LPCSTR)7)
2213 #define CERT_STORE_PROV_FILENAME_W           ((LPCSTR)8)
2214 #define CERT_STORE_PROV_SYSTEM_A             ((LPCSTR)9)
2215 #define CERT_STORE_PROV_SYSTEM_W             ((LPCSTR)10)
2216 #define CERT_STORE_PROV_SYSTEM               CERT_STORE_PROV_SYSTEM_W
2217 #define CERT_STORE_PROV_COLLECTION           ((LPCSTR)11)
2218 #define CERT_STORE_PROV_SYSTEM_REGISTRY_A    ((LPCSTR)12)
2219 #define CERT_STORE_PROV_SYSTEM_REGISTRY_W    ((LPCSTR)13)
2220 #define CERT_STORE_PROV_SYSTEM_REGISTRY      CERT_STORE_PROV_SYSTEM_REGISTRY_W
2221 #define CERT_STORE_PROV_PHYSICAL_W           ((LPCSTR)14)
2222 #define CERT_STORE_PROV_PHYSICAL             CERT_STORE_PROV_PHYSICAL_W
2223 #define CERT_STORE_PROV_SMART_CARD_W         ((LPCSTR)15)
2224 #define CERT_STORE_PROV_SMART_CARD           CERT_STORE_PROV_SMART_CARD_W
2225 #define CERT_STORE_PROV_LDAP_W               ((LPCSTR)16)
2226 #define CERT_STORE_PROV_LDAP                 CERT_STORE_PROV_LDAP_W
2227 
2228 #define sz_CERT_STORE_PROV_MEMORY            "Memory"
2229 #define sz_CERT_STORE_PROV_FILENAME_W        "File"
2230 #define sz_CERT_STORE_PROV_FILENAME          sz_CERT_STORE_PROV_FILENAME_W
2231 #define sz_CERT_STORE_PROV_SYSTEM_W          "System"
2232 #define sz_CERT_STORE_PROV_SYSTEM            sz_CERT_STORE_PROV_SYSTEM_W
2233 #define sz_CERT_STORE_PROV_PKCS7             "PKCS7"
2234 #define sz_CERT_STORE_PROV_SERIALIZED        "Serialized"
2235 #define sz_CERT_STORE_PROV_COLLECTION        "Collection"
2236 #define sz_CERT_STORE_PROV_SYSTEM_REGISTRY_W "SystemRegistry"
2237 #define sz_CERT_STORE_PROV_SYSTEM_REGISTRY   sz_CERT_STORE_PROV_SYSTEM_REGISTRY_W
2238 #define sz_CERT_STORE_PROV_PHYSICAL_W        "Physical"
2239 #define sz_CERT_STORE_PROV_PHYSICAL          sz_CERT_STORE_PROV_PHYSICAL_W
2240 #define sz_CERT_STORE_PROV_SMART_CARD_W      "SmartCard"
2241 #define sz_CERT_STORE_PROV_SMART_CARD        sz_CERT_STORE_PROV_SMART_CARD_W
2242 #define sz_CERT_STORE_PROV_LDAP_W            "Ldap"
2243 #define sz_CERT_STORE_PROV_LDAP              sz_CERT_STORE_PROV_LDAP_W
2244 
2245 /* types for CertOpenStore dwEncodingType */
2246 #define CERT_ENCODING_TYPE_MASK 0x0000ffff
2247 #define CMSG_ENCODING_TYPE_MASK 0xffff0000
2248 #define GET_CERT_ENCODING_TYPE(x) ((x) & CERT_ENCODING_TYPE_MASK)
2249 #define GET_CMSG_ENCODING_TYPE(x) ((x) & CMSG_ENCODING_TYPE_MASK)
2250 
2251 #define CRYPT_ASN_ENCODING  0x00000001
2252 #define CRYPT_NDR_ENCODING  0x00000002
2253 #define X509_ASN_ENCODING   0x00000001
2254 #define X509_NDR_ENCODING   0x00000002
2255 #define PKCS_7_ASN_ENCODING 0x00010000
2256 #define PKCS_7_NDR_ENCODING 0x00020000
2257 
2258 /* system store locations */
2259 #define CERT_SYSTEM_STORE_LOCATION_MASK  0x00ff0000
2260 #define CERT_SYSTEM_STORE_LOCATION_SHIFT 16
2261 
2262 /* system store location ids */
2263 /* hkcu */
2264 #define CERT_SYSTEM_STORE_CURRENT_USER_ID               1
2265 /* hklm */
2266 #define CERT_SYSTEM_STORE_LOCAL_MACHINE_ID              2
2267 /* hklm\Software\Microsoft\Cryptography\Services */
2268 #define CERT_SYSTEM_STORE_CURRENT_SERVICE_ID            4
2269 #define CERT_SYSTEM_STORE_SERVICES_ID                   5
2270 /* HKEY_USERS */
2271 #define CERT_SYSTEM_STORE_USERS_ID                      6
2272 /* hkcu\Software\Policies\Microsoft\SystemCertificates */
2273 #define CERT_SYSTEM_STORE_CURRENT_USER_GROUP_POLICY_ID  7
2274 /* hklm\Software\Policies\Microsoft\SystemCertificates */
2275 #define CERT_SYSTEM_STORE_LOCAL_MACHINE_GROUP_POLICY_ID 8
2276 /* hklm\Software\Microsoft\EnterpriseCertificates */
2277 #define CERT_SYSTEM_STORE_LOCAL_MACHINE_ENTERPRISE_ID   9
2278 
2279 /* system store location values */
2280 #define CERT_SYSTEM_STORE_CURRENT_USER \
2281  (CERT_SYSTEM_STORE_CURRENT_USER_ID << CERT_SYSTEM_STORE_LOCATION_SHIFT)
2282 #define CERT_SYSTEM_STORE_LOCAL_MACHINE \
2283  (CERT_SYSTEM_STORE_LOCAL_MACHINE_ID << CERT_SYSTEM_STORE_LOCATION_SHIFT)
2284 #define CERT_SYSTEM_STORE_CURRENT_SERVICE \
2285  (CERT_SYSTEM_STORE_CURRENT_SERVICE_ID << CERT_SYSTEM_STORE_LOCATION_SHIFT)
2286 #define CERT_SYSTEM_STORE_SERVICES \
2287  (CERT_SYSTEM_STORE_SERVICES_ID << CERT_SYSTEM_STORE_LOCATION_SHIFT)
2288 #define CERT_SYSTEM_STORE_USERS \
2289  (CERT_SYSTEM_STORE_USERS_ID << CERT_SYSTEM_STORE_LOCATION_SHIFT)
2290 #define CERT_SYSTEM_STORE_CURRENT_USER_GROUP_POLICY \
2291  (CERT_SYSTEM_STORE_CURRENT_USER_GROUP_POLICY_ID << CERT_SYSTEM_STORE_LOCATION_SHIFT)
2292 #define CERT_SYSTEM_STORE_LOCAL_MACHINE_GROUP_POLICY \
2293  (CERT_SYSTEM_STORE_LOCAL_MACHINE_GROUP_POLICY_ID << CERT_SYSTEM_STORE_LOCATION_SHIFT)
2294 #define CERT_SYSTEM_STORE_LOCAL_MACHINE_ENTERPRISE \
2295  (CERT_SYSTEM_STORE_LOCAL_MACHINE_ENTERPRISE_ID << CERT_SYSTEM_STORE_LOCATION_SHIFT)
2296 
2297 #if defined(__GNUC__)
2298 #define CERT_LOCAL_MACHINE_SYSTEM_STORE_REGPATH (const WCHAR[])\
2299  {'S','o','f','t','w','a','r','e','\\','M','i','c','r','o','s','o','f','t',\
2300   '\\','S','y','s','t','e','m','C','e','r','t','i','f','i','c','a','t','e','s',\
2301   0 }
2302 #define CERT_GROUP_POLICY_SYSTEM_STORE_REGPATH (const WCHAR[])\
2303  {'S','o','f','t','w','a','r','e','\\','P','o','l','i','c','i','e','s','\\',\
2304   'M','i','c','r','o','s','o','f','t','\\','S','y','s','t','e','m','C','e','r',\
2305   't','i','f','i','c','a','t','e','s',0 }
2306 #elif defined(_MSC_VER)
2307 #define CERT_LOCAL_MACHINE_SYSTEM_STORE_REGPATH \
2308  L"Software\\Microsoft\\SystemCertificates"
2309 #define CERT_GROUP_POLICY_SYSTEM_STORE_REGPATH \
2310  L"Software\\Policies\\Microsoft\\SystemCertificates"
2311 #else
2312 static const WCHAR CERT_LOCAL_MACHINE_SYSTEM_STORE_REGPATH[] =
2313  {'S','o','f','t','w','a','r','e','\\','M','i','c','r','o','s','o','f','t','\\',
2314   'S','y','s','t','e','m','C','e','r','t','i','f','i','c','a','t','e','s',0 };
2315 static const WCHAR CERT_GROUP_POLICY_SYSTEM_STORE_REGPATH[] =
2316  {'S','o','f','t','w','a','r','e','\\','P','o','l','i','c','i','e','s','\\',
2317   'M','i','c','r','o','s','o','f','t','\\','S','y','s','t','e','m','C','e','r',
2318   't','i','f','i','c','a','t','e','s',0 };
2319 #endif
2320 
2321 #if defined(__GNUC__)
2322 #define CERT_EFSBLOB_REGPATH (const WCHAR[])\
2323 {'S','o','f','t','w','a','r','e','\\','P','o','l','i','c','i','e','s','\\',\
2324  'M','i','c','r','o','s','o','f','t','\\','S','y','s','t','e','m','C','e','r',\
2325  't','i','f','i','c','a','t','e','s','\\','E','F','S',0 }
2326 #define CERT_EFSBLOB_VALUE_NAME (const WCHAR[]) {'E','F','S','B','l','o','b',0 }
2327 #elif defined(_MSC_VER)
2328 #define CERT_EFSBLOB_REGPATH CERT_GROUP_POLICY_SYSTEM_STORE_REGPATH L"\\EFS"
2329 #define CERT_EFSBLOB_VALUE_NAME L"EFSBlob"
2330 #else
2331 static const WCHAR CERT_EFSBLOB_REGPATH[] =
2332  {'S','o','f','t','w','a','r','e','\\','P','o','l','i','c','i','e','s','\\',
2333   'M','i','c','r','o','s','o','f','t','\\','S','y','s','t','e','m','C','e','r',
2334   't','i','f','i','c','a','t','e','s','\\','E','F','S',0 };
2335 static const CERT_EFSBLOB_VALUE_NAME[] = { 'E','F','S','B','l','o','b',0 };
2336 #endif
2337 
2338 #if defined(__GNUC__)
2339 #define CERT_PROT_ROOT_FLAGS_REGPATH (const WCHAR[])\
2340 {'\\','R','o','o','t','\\','P','r','o','t','e','c','t','e','d','R','o','o','t',\
2341  's',0 }
2342 #define CERT_PROT_ROOT_FLAGS_VALUE_NAME (const WCHAR[])\
2343 {'F','l','a','g','s',0 }
2344 #elif defined(_MSC_VER)
2345 #define CERT_PROT_ROOT_FLAGS_REGPATH L"\\Root\\ProtectedRoots"
2346 #define CERT_PROT_ROOT_FLAGS_VALUE_NAME L"Flags"
2347 #else
2348 static const WCHAR CERT_PROT_ROOT_FLAGS_REGPATH[] =
2349  { '\\','R','o','o','t','\\','P','r','o','t','e','c','t','e','d','R','o','o',
2350    't','s',0 };
2351 static const WCHAR CERT_PROT_ROOT_FLAGS_VALUE_NAME[] = {'F','l','a','g','s',0 };
2352 #endif
2353 
2354 #define CERT_PROT_ROOT_DISABLE_CURRENT_USER_FLAG                0x01
2355 #define CERT_PROT_ROOT_INHIBIT_ADD_AT_INIT_FLAG                 0x02
2356 #define CERT_PROT_ROOT_INHIBIT_PURGE_LM_FLAG                    0x04
2357 #define CERT_PROT_ROOT_DISABLE_LM_AUTH_FLAG                     0x08
2358 #define CERT_PROT_ROOT_DISABLE_NT_AUTH_REQUIRED_FLAG            0x10
2359 #define CERT_PROT_ROOT_DISABLE_NOT_DEFINED_NAME_CONSTRAINT_FLAG 0x20
2360 
2361 #if defined(__GNUC__)
2362 #define CERT_TRUST_PUB_SAFER_GROUP_POLICY_REGPATH (const WCHAR[])\
2363 {'S','o','f','t','w','a','r','e','\\','P','o','l','i','c','i','e','s','\\',\
2364  'M','i','c','r','o','s','o','f','t','\\','S','y','s','t','e','m','C','e','r',\
2365  't','i','f','i','c','a','t','e','s','\\','T','r','u','s','t','e','d',\
2366  'P','u','b','l','i','s','h','e','r','\\','S','a','f','e','r',0 }
2367 #elif defined(_MSC_VER)
2368 #define CERT_TRUST_PUB_SAFER_GROUP_POLICY_REGPATH \
2369  CERT_GROUP_POLICY_SYSTEM_STORE_REGPATH L"\\TrustedPublisher\\Safer"
2370 #else
2371 static const WCHAR CERT_TRUST_PUB_SAFER_GROUP_POLICY_REGPATH[] =
2372  {'S','o','f','t','w','a','r','e','\\','P','o','l','i','c','i','e','s','\\',
2373   'M','i','c','r','o','s','o','f','t','\\','S','y','s','t','e','m','C','e','r',
2374   't','i','f','i','c','a','t','e','s','\\','T','r','u','s','t','e','d',
2375   'P','u','b','l','i','s','h','e','r','\\','S','a','f','e','r',0 };
2376 #endif
2377 
2378 #if defined(__GNUC__)
2379 #define CERT_TRUST_PUB_SAFER_LOCAL_MACHINE_REGPATH (const WCHAR[])\
2380 {'S','o','f','t','w','a','r','e','\\','M','i','c','r','o','s','o','f','t','\\',\
2381  'S','y','s','t','e','m','C','e','r','t','i','f','i','c','a','t','e','s','\\',\
2382  'T','r','u','s','t','e','d','P','u','b','l','i','s','h','e','r','\\',\
2383  'S','a','f','e','r',0 }
2384 #define CERT_TRUST_PUB_AUTHENTICODE_FLAGS_VALUE_NAME (const WCHAR[])\
2385 {'A','u','t','h','e','n','t','i','c','o','d','e','F','l','a','g','s',0 };
2386 #elif defined(_MSC_VER)
2387 #define CERT_TRUST_PUB_SAFER_LOCAL_MACHINE_REGPATH \
2388  CERT_LOCAL_MACHINE_SYSTEM_STORE_REGPATH L"\\TrustedPublisher\\Safer"
2389 #define CERT_TRUST_PUB_AUTHENTICODE_FLAGS_VALUE_NAME L"AuthenticodeFlags"
2390 #else
2391 static const WCHAR CERT_TRUST_PUB_SAFER_LOCAL_MACHINE_REGPATH[] =
2392  {'S','o','f','t','w','a','r','e','\\','M','i','c','r','o','s','o','f','t','\\',
2393   'S','y','s','t','e','m','C','e','r','t','i','f','i','c','a','t','e','s','\\',
2394   'T','r','u','s','t','e','d','P','u','b','l','i','s','h','e','r','\\',
2395   'S','a','f','e','r',0 };
2396 static const WCHAR CERT_TRUST_PUB_AUTHENTICODE_FLAGS_VALUE_NAME[] =
2397  { 'A','u','t','h','e','n','t','i','c','o','d','e','F','l','a','g','s',0 };
2398 #endif
2399 
2400 #define CERT_TRUST_PUB_ALLOW_END_USER_TRUST         0x00000000
2401 #define CERT_TRUST_PUB_ALLOW_MACHINE_ADMIN_TRUST    0x00000001
2402 #define CERT_TRUST_PUB_ALLOW_ENTERPRISE_ADMIN_TRUST 0x00000002
2403 #define CERT_TRUST_PUB_ALLOW_TRUST_MASK             0x00000003
2404 #define CERT_TRUST_PUB_CHECK_PUBLISHER_REV_FLAG     0x00000100
2405 #define CERT_TRUST_PUB_CHECK_TIMESTAMP_REV_FLAG     0x00000200
2406 
2407 /* flags for CertOpenStore dwFlags */
2408 #define CERT_STORE_NO_CRYPT_RELEASE_FLAG            0x00000001
2409 #define CERT_STORE_SET_LOCALIZED_NAME_FLAG          0x00000002
2410 #define CERT_STORE_DEFER_CLOSE_UNTIL_LAST_FREE_FLAG 0x00000004
2411 #define CERT_STORE_DELETE_FLAG                      0x00000010
2412 #define CERT_STORE_UNSAFE_PHYSICAL_FLAG             0x00000020
2413 #define CERT_STORE_SHARE_STORE_FLAG                 0x00000040
2414 #define CERT_STORE_SHARE_CONTEXT_FLAG               0x00000080
2415 #define CERT_STORE_MANIFOLD_FLAG                    0x00000100
2416 #define CERT_STORE_ENUM_ARCHIVED_FLAG               0x00000200
2417 #define CERT_STORE_UPDATE_KEYID_FLAG                0x00000400
2418 #define CERT_STORE_BACKUP_RESTORE_FLAG              0x00000800
2419 #define CERT_STORE_MAXIMUM_ALLOWED_FLAG             0x00001000
2420 #define CERT_STORE_CREATE_NEW_FLAG                  0x00002000
2421 #define CERT_STORE_OPEN_EXISTING_FLAG               0x00004000
2422 #define CERT_STORE_READONLY_FLAG                    0x00008000
2423 
2424 #define CERT_REGISTRY_STORE_REMOTE_FLAG      0x00010000
2425 #define CERT_REGISTRY_STORE_SERIALIZED_FLAG  0x00020000
2426 #define CERT_REGISTRY_STORE_ROAMING_FLAG     0x00040000
2427 #define CERT_REGISTRY_STORE_MY_IE_DIRTY_FLAG 0x00080000
2428 #define CERT_REGISTRY_STORE_LM_GPT_FLAG      0x01000000
2429 #define CERT_REGISTRY_STORE_CLIENT_GPT_FLAG  0x80000000
2430 
2431 #define CERT_FILE_STORE_COMMIT_ENABLE_FLAG 0x00010000
2432 
2433 /* CertCloseStore dwFlags */
2434 #define CERT_CLOSE_STORE_FORCE_FLAG 0x00000001
2435 #define CERT_CLOSE_STORE_CHECK_FLAG 0x00000002
2436 
2437 /* dwAddDisposition */
2438 #define CERT_STORE_ADD_NEW                                 1
2439 #define CERT_STORE_ADD_USE_EXISTING                        2
2440 #define CERT_STORE_ADD_REPLACE_EXISTING                    3
2441 #define CERT_STORE_ADD_ALWAYS                              4
2442 #define CERT_STORE_ADD_REPLACE_EXISTING_INHERIT_PROPERTIES 5
2443 #define CERT_STORE_ADD_NEWER                               6
2444 #define CERT_STORE_ADD_NEWER_INHERIT_PROPERTIES            7
2445 
2446 /* Installable OID function defs */
2447 #define CRYPT_OID_OPEN_STORE_PROV_FUNC     "CertDllOpenStoreProv"
2448 #define CRYPT_OID_ENCODE_OBJECT_FUNC       "CryptDllEncodeObject"
2449 #define CRYPT_OID_DECODE_OBJECT_FUNC       "CryptDllDecodeObject"
2450 #define CRYPT_OID_ENCODE_OBJECT_EX_FUNC    "CryptDllEncodeObjectEx"
2451 #define CRYPT_OID_DECODE_OBJECT_EX_FUNC    "CryptDllDecodeObjectEx"
2452 #define CRYPT_OID_CREATE_COM_OBJECT_FUNC   "CryptDllCreateComObject"
2453 #define CRYPT_OID_VERIFY_REVOCATION_FUNC   "CertDllVerifyRevocation"
2454 #define CRYPT_OID_VERIFY_CTL_USAGE_FUNC    "CertDllVerifyCTLUsage"
2455 #define CRYPT_OID_FORMAT_OBJECT_FUNC       "CryptDllFormatObject"
2456 #define CRYPT_OID_FIND_OID_INFO_FUNC       "CryptDllFindOIDInfo"
2457 #define CRYPT_OID_FIND_LOCALIZED_NAME_FUNC "CryptDllFindLocalizedName"
2458 #define CRYPT_OID_EXPORT_PUBLIC_KEY_INFO_FUNC  "CryptDllExportPublicKeyInfoEx"
2459 #define CRYPT_OID_IMPORT_PUBLIC_KEY_INFO_FUNC  "CryptDllImportPublicKeyInfoEx"
2460 #define CRYPT_OID_EXPORT_PRIVATE_KEY_INFO_FUNC "CryptDllExportPrivateKeyInfoEx"
2461 #define CRYPT_OID_IMPORT_PRIVATE_KEY_INFO_FUNC "CryptDllImportPrivateKeyInfoEx"
2462 #define CRYPT_OID_VERIFY_CERTIFICATE_CHAIN_POLICY_FUNC \
2463  "CertDllVerifyCertificateChainPolicy"
2464 #define URL_OID_GET_OBJECT_URL_FUNC    "UrlDllGetObjectUrl"
2465 #define TIME_VALID_OID_GET_OBJECT_FUNC "TimeValidDllGetObject"
2466 #define CMSG_OID_GEN_CONTENT_ENCRYPT_KEY_FUNC "CryptMsgDllGenContentEncryptKey"
2467 #define CMSG_OID_EXPORT_KEY_TRANS_FUNC        "CryptMsgDllExportKeyTrans"
2468 #define CMSG_OID_IMPORT_KEY_TRANS_FUNC        "CryptMsgDllImportKeyTrans"
2469 
2470 #define CRYPT_OID_REGPATH "Software\\Microsoft\\Cryptography\\OID"
2471 #define CRYPT_OID_REG_ENCODING_TYPE_PREFIX "EncodingType "
2472 #if defined(__GNUC__)
2473 # define CRYPT_OID_REG_DLL_VALUE_NAME (const WCHAR []){ 'D','l','l',0 }
2474 # define CRYPT_OID_REG_FUNC_NAME_VALUE_NAME \
2475  (const WCHAR []){ 'F','u','n','c','N','a','m','e',0 }
2476 # define CRYPT_OID_REG_FLAGS_VALUE_NAME \
2477  (const WCHAR []){ 'C','r','y','p','t','F','l','a','g','s',0 }
2478 #elif defined(_MSC_VER)
2479 # define CRYPT_OID_REG_DLL_VALUE_NAME       L"Dll"
2480 # define CRYPT_OID_REG_FUNC_NAME_VALUE_NAME L"FuncName"
2481 # define CRYPT_OID_REG_FLAGS_VALUE_NAME     L"CryptFlags"
2482 #else
2483 static const WCHAR CRYPT_OID_REG_DLL_VALUE_NAME[] = { 'D','l','l',0 };
2484 static const WCHAR CRYPT_OID_REG_FUNC_NAME_VALUE_NAME[] =
2485  { 'F','u','n','c','N','a','m','e',0 };
2486 static const WCHAR CRYPT_OID_REG_FLAGS_VALUE_NAME[] =
2487  { 'C','r','y','p','t','F','l','a','g','s',0 };
2488 #endif
2489 #define CRYPT_OID_REG_FUNC_NAME_VALUE_NAME_A "FuncName"
2490 #define CRYPT_DEFAULT_OID                    "DEFAULT"
2491 
2492 #define CRYPT_INSTALL_OID_FUNC_BEFORE_FLAG 1
2493 
2494 #define CRYPT_GET_INSTALLED_OID_FUNC_FLAG  0x1
2495 
2496 #define CRYPT_REGISTER_FIRST_INDEX 0
2497 #define CRYPT_REGISTER_LAST_INDEX  0xffffffff
2498 
2499 /* values for CERT_STORE_PROV_INFO's dwStoreProvFlags */
2500 #define CERT_STORE_PROV_EXTERNAL_FLAG        0x1
2501 #define CERT_STORE_PROV_DELETED_FLAG         0x2
2502 #define CERT_STORE_PROV_NO_PERSIST_FLAG      0x4
2503 #define CERT_STORE_PROV_SYSTEM_STORE_FLAG    0x8
2504 #define CERT_STORE_PROV_LM_SYSTEM_STORE_FLAG 0x10
2505 
2506 /* function indices */
2507 #define CERT_STORE_PROV_CLOSE_FUNC             0
2508 #define CERT_STORE_PROV_READ_CERT_FUNC         1
2509 #define CERT_STORE_PROV_WRITE_CERT_FUNC        2
2510 #define CERT_STORE_PROV_DELETE_CERT_FUNC       3
2511 #define CERT_STORE_PROV_SET_CERT_PROPERTY_FUNC 4
2512 #define CERT_STORE_PROV_READ_CRL_FUNC          5
2513 #define CERT_STORE_PROV_WRITE_CRL_FUNC         6
2514 #define CERT_STORE_PROV_DELETE_CRL_FUNC        7
2515 #define CERT_STORE_PROV_SET_CRL_PROPERTY_FUNC  8
2516 #define CERT_STORE_PROV_READ_CTL_FUNC          9
2517 #define CERT_STORE_PROV_WRITE_CTL_FUNC         10
2518 #define CERT_STORE_PROV_DELETE_CTL_FUNC        11
2519 #define CERT_STORE_PROV_SET_CTL_PROPERTY_FUNC  12
2520 #define CERT_STORE_PROV_CONTROL_FUNC           13
2521 #define CERT_STORE_PROV_FIND_CERT_FUNC         14
2522 #define CERT_STORE_PROV_FREE_FIND_CERT_FUNC    15
2523 #define CERT_STORE_PROV_GET_CERT_PROPERTY_FUNC 16
2524 #define CERT_STORE_PROV_FIND_CRL_FUNC          17
2525 #define CERT_STORE_PROV_FREE_FIND_CRL_FUNC     18
2526 #define CERT_STORE_PROV_GET_CRL_PROPERTY_FUNC  19
2527 #define CERT_STORE_PROV_FIND_CTL_FUNC          20
2528 #define CERT_STORE_PROV_FREE_FIND_CTL_FUNC     21
2529 #define CERT_STORE_PROV_GET_CTL_PROPERTY_FUNC  22
2530 
2531 /* physical store dwFlags, also used by CertAddStoreToCollection as
2532  * dwUpdateFlags
2533  */
2534 #define CERT_PHYSICAL_STORE_ADD_ENABLE_FLAG                  0x1
2535 #define CERT_PHYSICAL_STORE_OPEN_DISABLE_FLAG                0x2
2536 #define CERT_PHYSICAL_STORE_REMOVE_OPEN_DISABLE_FLAG         0x4
2537 #define CERT_PHYSICAL_STORE_INSERT_COMPUTER_NAME_ENABLE_FLAG 0x8
2538 
2539 /* dwFlag values for CertEnumPhysicalStore callback */
2540 #define CERT_PHYSICAL_STORE_PREDEFINED_ENUM_FLAG 0x1
2541 
2542 /* predefined store names */
2543 #if defined(__GNUC__)
2544 # define CERT_PHYSICAL_STORE_DEFAULT_NAME (const WCHAR[])\
2545  {'.','D','e','f','a','u','l','t','0'}
2546 # define CERT_PHYSICAL_STORE_GROUP_POLICY_NAME (const WCHAR[])\
2547  {'.','G','r','o','u','p','P','o','l','i','c','y',0}
2548 # define CERT_PHYSICAL_STORE_LOCAL_MACHINE_NAME (const WCHAR[])\
2549  {'.','L','o','c','a','l','M','a','c','h','i','n','e',0}
2550 # define CERT_PHYSICAL_STORE_DS_USER_CERTIFICATE_NAME (const WCHAR[])\
2551  {'.','U','s','e','r','C','e','r','t','i','f','i','c','a','t','e',0}
2552 # define CERT_PHYSICAL_STORE_LOCAL_MACHINE_GROUP_POLICY_NAME (const WCHAR[])\
2553  {'.','L','o','c','a','l','M','a','c','h','i','n','e','G','r','o','u','p',\
2554  'P','o','l','i','c','y',0}
2555 # define CERT_PHYSICAL_STORE_ENTERPRISE_NAME (const WCHAR[])\
2556  {'.','E','n','t','e','r','p','r','i','s','e',0}
2557 # define CERT_PHYSICAL_STORE_AUTH_ROOT_NAME (const WCHAR[])\
2558  {'.','A','u','t','h','R','o','o','t',0}
2559 #elif defined(_MSC_VER)
2560 # define CERT_PHYSICAL_STORE_DEFAULT_NAME \
2561  L".Default"
2562 # define CERT_PHYSICAL_STORE_GROUP_POLICY_NAME \
2563  L".GroupPolicy"
2564 # define CERT_PHYSICAL_STORE_LOCAL_MACHINE_NAME \
2565  L".LocalMachine"
2566 # define CERT_PHYSICAL_STORE_DS_USER_CERTIFICATE_NAME \
2567  L".UserCertificate"
2568 # define CERT_PHYSICAL_STORE_LOCAL_MACHINE_GROUP_POLICY_NAME \
2569  L".LocalMachineGroupPolicy"
2570 # define CERT_PHYSICAL_STORE_ENTERPRISE_NAME \
2571  L".Enterprise"
2572 # define CERT_PHYSICAL_STORE_AUTH_ROOT_NAME \
2573  L".AuthRoot"
2574 #else
2575 static const WCHAR CERT_PHYSICAL_STORE_DEFAULT_NAME[] =
2576  {'.','D','e','f','a','u','l','t','0'};
2577 static const WCHAR CERT_PHYSICAL_STORE_GROUP_POLICY_NAME[] =
2578  {'.','G','r','o','u','p','P','o','l','i','c','y',0};
2579 static const WCHAR CERT_PHYSICAL_STORE_LOCAL_MACHINE_NAME[] =
2580  {'.','L','o','c','a','l','M','a','c','h','i','n','e',0};
2581 static const WCHAR CERT_PHYSICAL_STORE_DS_USER_CERTIFICATE_NAME[] =
2582  {'.','U','s','e','r','C','e','r','t','i','f','i','c','a','t','e',0};
2583 static const WCHAR CERT_PHYSICAL_STORE_LOCAL_MACHINE_GROUP_POLICY_NAME[] =
2584  {'.','L','o','c','a','l','M','a','c','h','i','n','e','G','r','o','u','p',
2585  'P','o','l','i','c','y',0};
2586 static const WCHAR CERT_PHYSICAL_STORE_ENTERPRISE_NAME[] =
2587  {'.','E','n','t','e','r','p','r','i','s','e',0};
2588 static const WCHAR CERT_PHYSICAL_STORE_AUTH_ROOT_NAME[] =
2589  {'.','A','u','t','h','R','o','o','t',0};
2590 #endif
2591 
2592 /* cert system store flags */
2593 #define CERT_SYSTEM_STORE_MASK 0xffff0000
2594 #define CERT_SYSTEM_STORE_RELOCATE_FLAG 0x80000000
2595 
2596 /* CertFindChainInStore dwFindType types */
2597 #define CERT_CHAIN_FIND_BY_ISSUER 1
2598 
2599 /* CertSaveStore dwSaveAs values */
2600 #define CERT_STORE_SAVE_AS_STORE 1
2601 #define CERT_STORE_SAVE_AS_PKCS7 2
2602 /* CertSaveStore dwSaveTo values */
2603 #define CERT_STORE_SAVE_TO_FILE       1
2604 #define CERT_STORE_SAVE_TO_MEMORY     2
2605 #define CERT_STORE_SAVE_TO_FILENAME_A 3
2606 #define CERT_STORE_SAVE_TO_FILENAME_W 4
2607 #define CERT_STORE_SAVE_TO_FILENAME   CERT_STORE_SAVE_TO_FILENAME_W
2608 
2609 /* CERT_INFO versions/flags */
2610 #define CERT_V1 0
2611 #define CERT_V2 1
2612 #define CERT_V3 2
2613 #define CERT_INFO_VERSION_FLAG                 1
2614 #define CERT_INFO_SERIAL_NUMBER_FLAG           2
2615 #define CERT_INFO_SIGNATURE_ALGORITHM_FLAG     3
2616 #define CERT_INFO_ISSUER_FLAG                  4
2617 #define CERT_INFO_NOT_BEFORE_FLAG              5
2618 #define CERT_INFO_NOT_AFTER_FLAG               6
2619 #define CERT_INFO_SUBJECT_FLAG                 7
2620 #define CERT_INFO_SUBJECT_PUBLIC_KEY_INFO_FLAG 8
2621 #define CERT_INFO_ISSUER_UNIQUE_ID_FLAG        9
2622 #define CERT_INFO_SUBJECT_UNIQUE_ID_FLAG       10
2623 #define CERT_INFO_EXTENSION_FLAG               11
2624 
2625 /* CERT_REQUEST_INFO versions */
2626 #define CERT_REQUEST_V1 0
2627 
2628 /* CERT_KEYGEN_REQUEST_INFO versions */
2629 #define CERT_KEYGEN_REQUEST_V1 0
2630 
2631 /* CRL versions */
2632 #define CRL_V1 0
2633 #define CRL_V2 1
2634 
2635 /* CTL versions */
2636 #define CTL_V1 0
2637 
2638 /* Certificate, CRL, CTL property IDs */
2639 #define CERT_KEY_PROV_HANDLE_PROP_ID               1
2640 #define CERT_KEY_PROV_INFO_PROP_ID                 2
2641 #define CERT_SHA1_HASH_PROP_ID                     3
2642 #define CERT_HASH_PROP_ID                          CERT_SHA1_HASH_PROP_ID
2643 #define CERT_MD5_HASH_PROP_ID                      4
2644 #define CERT_KEY_CONTEXT_PROP_ID                   5
2645 #define CERT_KEY_SPEC_PROP_ID                      6
2646 #define CERT_IE30_RESERVED_PROP_ID                 7
2647 #define CERT_PUBKEY_HASH_RESERVED_PROP_ID          8
2648 #define CERT_ENHKEY_USAGE_PROP_ID                  9
2649 #define CERT_CTL_USAGE_PROP_ID                     CERT_ENHKEY_USAGE_PROP_ID
2650 #define CERT_NEXT_UPDATE_LOCATION_PROP_ID          10
2651 #define CERT_FRIENDLY_NAME_PROP_ID                 11
2652 #define CERT_PVK_FILE_PROP_ID                      12
2653 #define CERT_DESCRIPTION_PROP_ID                   13
2654 #define CERT_ACCESS_STATE_PROP_ID                  14
2655 #define CERT_SIGNATURE_HASH_PROP_ID                15
2656 #define CERT_SMART_CARD_DATA_PROP_ID               16
2657 #define CERT_EFS_PROP_ID                           17
2658 #define CERT_FORTEZZA_DATA_PROP                    18
2659 #define CERT_ARCHIVED_PROP_ID                      19
2660 #define CERT_KEY_IDENTIFIER_PROP_ID                20
2661 #define CERT_AUTO_ENROLL_PROP_ID                   21
2662 #define CERT_PUBKEY_ALG_PARA_PROP_ID               22
2663 #define CERT_CROSS_CERT_DIST_POINTS_PROP_ID        23
2664 #define CERT_ISSUER_PUBLIC_KEY_MD5_HASH_PROP_ID    24
2665 #define CERT_SUBJECT_PUBLIC_KEY_MD5_HASH_PROP_ID   25
2666 #define CERT_ENROLLMENT_PROP_ID                    26
2667 #define CERT_DATE_STAMP_PROP_ID                    27
2668 #define CERT_ISSUER_SERIAL_NUMBER_MD5_HASH_PROP_ID 28
2669 #define CERT_SUBJECT_NAME_MD5_HASH_PROP_ID         29
2670 #define CERT_EXTENDED_ERROR_INFO_PROP_ID           30
2671 /* 31    -- unused?
2672    32    -- cert prop id
2673    33    -- CRL prop id
2674    34    -- CTL prop id
2675    35    -- KeyId prop id
2676    36-63 -- reserved
2677  */
2678 #define CERT_RENEWAL_PROP_ID                       64
2679 #define CERT_ARCHIVED_KEY_HASH_PROP_ID             65
2680 #define CERT_AUTO_ENROLL_RETRY_PROP_ID             66
2681 #define CERT_AIA_URL_RETRIEVED_PROP_ID             67
2682 #define CERT_AUTHORITY_INFO_ACCESS_PROP_ID         68
2683 #define CERT_BACKED_UP_PROP_ID                     69
2684 #define CERT_OCSP_RESPONSE_PROP_ID                 70
2685 #define CERT_REQUEST_ORIGINATOR_PROP_ID            71
2686 #define CERT_SOURCE_LOCATION_PROP_ID               72
2687 #define CERT_SOURCE_URL_PROP_ID                    73
2688 #define CERT_NEW_KEY_PROP_ID                       74
2689 #define CERT_OCSP_CACHE_PREFIX_PROP_ID             75
2690 #define CERT_SMART_CARD_ROOT_INFO_PROP_ID          76
2691 #define CERT_NO_AUTO_EXPIRE_CHECK_PROP_ID          77
2692 #define CERT_NCRYPT_KEY_HANDLE_PROP_ID             78
2693 #define CERT_HCRYPTPROV_OR_NCRYPT_KEY_HANDLE_PROP_ID 79
2694 #define CERT_SUBJECT_INFO_ACCESS_PROP_ID           80
2695 #define CERT_CA_OCSP_AUTHORITY_INFO_ACCESS_PROP_ID 81
2696 #define CERT_CA_DISABLE_CRL_PROP_ID                82
2697 #define CERT_ROOT_PROGRAM_CERT_POLICIES_PROP_ID    83
2698 #define CERT_ROOT_PROGRAM_NAME_CONSTRAINTS_PROP_ID 84
2699 
2700 #define CERT_FIRST_RESERVED_PROP_ID                85
2701 #define CERT_LAST_RESERVED_PROP_ID                 0x00007fff
2702 #define CERT_FIRST_USER_PROP_ID                    0x00008000
2703 #define CERT_LAST_USER_PROP_ID                     0x0000ffff
2704 
2705 #define IS_CERT_HASH_PROP_ID(x) \
2706  ((x) == CERT_SHA1_HASH_PROP_ID || (x) == CERT_MD5_HASH_PROP_ID || \
2707   (x) == CERT_SIGNATURE_HASH_PROP_ID)
2708 
2709 #define IS_PUBKEY_HASH_PROP_ID(x) \
2710  ((x) == CERT_ISSUER_PUBLIC_KEY_MD5_HASH_PROP_ID || \
2711   (x) == CERT_SUBJECT_PUBLIC_KEY_MD5_HASH_PROP_ID)
2712 
2713 #define IS_CHAIN_HASH_PROP_ID(x) \
2714  ((x) == CERT_ISSUER_PUBLIC_KEY_MD5_HASH_PROP_ID || \
2715   (x) == CERT_SUBJECT_PUBLIC_KEY_MD5_HASH_PROP_ID || \
2716   (x) == CERT_ISSUER_SERIAL_NUMBER_MD5_HASH_PROP_ID || \
2717   (x) == CERT_SUBJECT_NAME_MD5_HASH_PROP_ID)
2718 
2719 /* access state flags */
2720 #define CERT_ACCESS_STATE_WRITE_PERSIST_FLAG   0x1
2721 #define CERT_ACCESS_STATE_SYSTEM_STORE_FLAG    0x2
2722 #define CERT_ACCESS_STATE_LM_SYSTEM_STORE_FLAG 0x4
2723 
2724 /* CertSetCertificateContextProperty flags */
2725 #define CERT_SET_PROPERTY_INHIBIT_PERSIST_FLAG      0x40000000
2726 #define CERT_SET_PROPERTY_IGNORE_PERSIST_ERROR_FLAG 0x80000000
2727 
2728 /* CERT_RDN attribute dwValueType types */
2729 #define CERT_RDN_TYPE_MASK 0x000000ff
2730 #define CERT_RDN_ANY_TYPE         0
2731 #define CERT_RDN_ENCODED_BLOB     1
2732 #define CERT_RDN_OCTET_STRING     2
2733 #define CERT_RDN_NUMERIC_STRING   3
2734 #define CERT_RDN_PRINTABLE_STRING 4
2735 #define CERT_RDN_TELETEX_STRING   5
2736 #define CERT_RDN_T61_STRING       5
2737 #define CERT_RDN_VIDEOTEX_STRING  6
2738 #define CERT_RDN_IA5_STRING       7
2739 #define CERT_RDN_GRAPHIC_STRING   8
2740 #define CERT_RDN_VISIBLE_STRING   9
2741 #define CERT_RDN_ISO646_STRING    9
2742 #define CERT_RDN_GENERAL_STRING   10
2743 #define CERT_RDN_UNIVERSAL_STRING 11
2744 #define CERT_RDN_INT4_STRING      11
2745 #define CERT_RDN_BMP_STRING       12
2746 #define CERT_RDN_UNICODE_STRING   12
2747 #define CERT_RDN_UTF8_STRING      13
2748 
2749 /* CERT_RDN attribute dwValueType flags */
2750 #define CERT_RDN_FLAGS_MASK 0xff000000
2751 #define CERT_RDN_ENABLE_T61_UNICODE_FLAG  0x80000000
2752 #define CERT_RDN_DISABLE_CHECK_TYPE_FLAG  0x4000000
2753 #define CERT_RDN_ENABLE_UTF8_UNICODE_FLAG 0x2000000
2754 #define CERT_RDN_DISABLE_IE4_UTF8_FLAG    0x0100000
2755 
2756 #define IS_CERT_RDN_CHAR_STRING(x) \
2757  (((x) & CERT_RDN_TYPE_MASK) >= CERT_RDN_NUMERIC_STRING)
2758 
2759 /* CertIsRDNAttrsInCertificateName flags */
2760 #define CERT_UNICODE_IS_RDN_ATTRS_FLAG          0x1
2761 #define CERT_CASE_INSENSITIVE_IS_RDN_ATTRS_FLAG 0x2
2762 
2763 /* CRL reason codes */
2764 #define CRL_REASON_UNSPECIFIED            0
2765 #define CRL_REASON_KEY_COMPROMISE         1
2766 #define CRL_REASON_CA_COMPROMISE          2
2767 #define CRL_REASON_AFFILIATION_CHANGED    3
2768 #define CRL_REASON_SUPERSEDED             4
2769 #define CRL_REASON_CESSATION_OF_OPERATION 5
2770 #define CRL_REASON_CERTIFICATE_HOLD       6
2771 #define CRL_REASON_REMOVE_FROM_CRL        8
2772 
2773 /* CertControlStore control types */
2774 #define CERT_STORE_CTRL_RESYNC        1
2775 #define CERT_STORE_CTRL_NOTIFY_CHANGE 2
2776 #define CERT_STORE_CTRL_COMMIT        3
2777 #define CERT_STORE_CTRL_AUTO_RESYNC   4
2778 #define CERT_STORE_CTRL_CANCEL_NOTIFY 5
2779 
2780 #define CERT_STORE_CTRL_COMMIT_FORCE_FLAG 0x1
2781 #define CERT_STORE_CTRL_COMMIT_CLEAR_FLAG 0x2
2782 
2783 /* cert store properties */
2784 #define CERT_STORE_LOCALIZED_NAME_PROP_ID 0x1000
2785 
2786 /* CertCreateContext flags */
2787 #define CERT_CREATE_CONTEXT_NOCOPY_FLAG       0x1
2788 #define CERT_CREATE_CONTEXT_SORTED_FLAG       0x2
2789 #define CERT_CREATE_CONTEXT_NO_HCRYPTMSG_FLAG 0x4
2790 #define CERT_CREATE_CONTEXT_NO_ENTRY_FLAG     0x8
2791 
2792 #define CERT_COMPARE_MASK                   0xffff
2793 #define CERT_COMPARE_SHIFT                  16
2794 #define CERT_COMPARE_ANY                    0
2795 #define CERT_COMPARE_SHA1_HASH              1
2796 #define CERT_COMPARE_HASH                   CERT_COMPARE_SHA1_HASH
2797 #define CERT_COMPARE_NAME                   2
2798 #define CERT_COMPARE_ATTR                   3
2799 #define CERT_COMPARE_MD5_HASH               4
2800 #define CERT_COMPARE_PROPERTY               5
2801 #define CERT_COMPARE_PUBLIC_KEY             6
2802 #define CERT_COMPARE_NAME_STR_A             7
2803 #define CERT_COMPARE_NAME_STR_W             8
2804 #define CERT_COMPARE_KEY_SPEC               9
2805 #define CERT_COMPARE_ENHKEY_USAGE           10
2806 #define CERT_COMPARE_CTL_USAGE              CERT_COMPARE_ENHKEY_USAGE
2807 #define CERT_COMPARE_SUBJECT_CERT           11
2808 #define CERT_COMPARE_ISSUER_OF              12
2809 #define CERT_COMPARE_EXISTING               13
2810 #define CERT_COMPARE_SIGNATURE_HASH         14
2811 #define CERT_COMPARE_KEY_IDENTIFIER         15
2812 #define CERT_COMPARE_CERT_ID                16
2813 #define CERT_COMPARE_CROSS_CERT_DIST_POINTS 17
2814 #define CERT_COMPARE_PUBKEY_MD5_HASH        18
2815 
2816 /* values of dwFindType for CertFind*InStore */
2817 #define CERT_FIND_ANY \
2818  (CERT_COMPARE_ANY << CERT_COMPARE_SHIFT)
2819 #define CERT_FIND_SHA1_HASH \
2820  (CERT_COMPARE_SHA1_HASH << CERT_COMPARE_SHIFT)
2821 #define CERT_FIND_MD5_HASH \
2822  (CERT_COMPARE_MD5_HASH << CERT_COMPARE_SHIFT)
2823 #define CERT_FIND_SIGNATURE_HASH \
2824  (CERT_COMPARE_SIGNATURE_HASH << CERT_COMPARE_SHIFT)
2825 #define CERT_FIND_KEY_IDENTIFIER \
2826  (CERT_COMPARE_KEY_IDENTIFIER << CERT_COMPARE_SHIFT)
2827 #define CERT_FIND_HASH CERT_FIND_SHA1_HASH
2828 #define CERT_FIND_PROPERTY \
2829  (CERT_COMPARE_PROPERTY << CERT_COMPARE_SHIFT)
2830 #define CERT_FIND_PUBLIC_KEY \
2831  (CERT_COMPARE_PUBLIC_KEY << CERT_COMPARE_SHIFT)
2832 #define CERT_FIND_SUBJECT_NAME \
2833  (CERT_COMPARE_NAME << CERT_COMPARE_SHIFT | CERT_INFO_SUBJECT_FLAG)
2834 #define CERT_FIND_SUBJECT_ATTR \
2835  (CERT_COMPARE_ATTR << CERT_COMPARE_SHIFT | CERT_INFO_SUBJECT_FLAG)
2836 #define CERT_FIND_ISSUER_NAME \
2837  (CERT_COMPARE_NAME << CERT_COMPARE_SHIFT | CERT_INFO_ISSUER_FLAG)
2838 #define CERT_FIND_ISSUER_ATTR \
2839  (CERT_COMPARE_ATTR << CERT_COMPARE_SHIFT | CERT_INFO_ISSUER_FLAG)
2840 #define CERT_FIND_SUBJECT_STR_A \
2841  (CERT_COMPARE_NAME_STR_A << CERT_COMPARE_SHIFT | CERT_INFO_SUBJECT_FLAG)
2842 #define CERT_FIND_SUBJECT_STR_W \
2843  (CERT_COMPARE_NAME_STR_W << CERT_COMPARE_SHIFT | CERT_INFO_SUBJECT_FLAG)
2844 #define CERT_FIND_SUBJECT_STR CERT_FIND_SUBJECT_STR_W
2845 #define CERT_FIND_ISSUER_STR_A \
2846  (CERT_COMPARE_NAME_STR_A << CERT_COMPARE_SHIFT | CERT_INFO_ISSUER_FLAG)
2847 #define CERT_FIND_ISSUER_STR_W \
2848  (CERT_COMPARE_NAME_STR_W << CERT_COMPARE_SHIFT | CERT_INFO_ISSUER_FLAG)
2849 #define CERT_FIND_ISSUER_STR CERT_FIND_ISSUER_STR_W
2850 #define CERT_FIND_KEY_SPEC \
2851  (CERT_COMPARE_KEY_SPEC << CERT_COMPARE_SHIFT)
2852 #define CERT_FIND_ENHKEY_USAGE \
2853  (CERT_COMPARE_ENHKEY_USAGE << CERT_COMPARE_SHIFT)
2854 #define CERT_FIND_CTL_USAGE CERT_FIND_ENHKEY_USAGE
2855 #define CERT_FIND_SUBJECT_CERT \
2856  (CERT_COMPARE_SUBJECT_CERT << CERT_COMPARE_SHIFT)
2857 #define CERT_FIND_ISSUER_OF \
2858  (CERT_COMPARE_ISSUER_OF << CERT_COMPARE_SHIFT)
2859 #define CERT_FIND_EXISTING \
2860  (CERT_COMPARE_EXISTING << CERT_COMPARE_SHIFT)
2861 #define CERT_FIND_CERT_ID \
2862  (CERT_COMPARE_CERT_ID << CERT_COMPARE_SHIFT)
2863 #define CERT_FIND_CROSS_CERT_DIST_POINTS \
2864  (CERT_COMPARE_CROSS_CERT_DIST_POINTS << CERT_COMPARE_SHIFT)
2865 #define CERT_FIND_PUBKEY_MD5_HASH \
2866  (CERT_COMPARE_PUBKEY_MD5_HASH << CERT_COMPARE_SHIFT)
2867 
2868 #define CERT_FIND_OPTIONAL_ENHKEY_USAGE_FLAG  0x1
2869 #define CERT_FIND_OPTIONAL_CTL_USAGE_FLAG     0x1
2870 #define CERT_FIND_EXT_ONLY_ENHKEY_USAGE_FLAG  0x2
2871 #define CERT_FIND_EXT_ONLY_CTL_USAGE_FLAG     0x2
2872 #define CERT_FIND_PROP_ONLY_ENHKEY_USAGE_FLAG 0x4
2873 #define CERT_FIND_PROP_ONLY_CTL_USAGE_FLAG    0x4
2874 #define CERT_FIND_NO_ENHKEY_USAGE_FLAG        0x8
2875 #define CERT_FIND_NO_CTL_USAGE_FLAG           0x8
2876 #define CERT_FIND_OR_ENHKEY_USAGE_FLAG        0x10
2877 #define CERT_FIND_OR_CTL_USAGE_FLAG           0x10
2878 #define CERT_FIND_VALID_ENHKEY_USAGE_FLAG     0x20
2879 #define CERT_FIND_VALID_CTL_USAGE_FLAG        0x20
2880 
2881 #define CRL_FIND_ANY        0
2882 #define CRL_FIND_ISSUED_BY  1
2883 #define CRL_FIND_EXISTING   2
2884 #define CRL_FIND_ISSUED_FOR 3
2885 
2886 #define CRL_FIND_ISSUED_BY_AKI_FLAG       0x1
2887 #define CRL_FIND_ISSUED_BY_SIGNATURE_FLAG 0x2
2888 #define CRL_FIND_ISSUED_BY_DELTA_FLAG     0x4
2889 #define CRL_FIND_ISSUED_BY_BASE_FLAG      0x8
2890 
2891 typedef struct _CRL_FIND_ISSUED_FOR_PARA
2892 {
2893     PCCERT_CONTEXT pSubjectCert;
2894     PCCERT_CONTEXT pIssuerCert;
2895 } CRL_FIND_ISSUED_FOR_PARA, *PCRL_FIND_ISSUED_FOR_PARA;
2896 
2897 #define CTL_FIND_ANY       0
2898 #define CTL_FIND_SHA1_HASH 1
2899 #define CTL_FIND_MD5_HASH  2
2900 #define CTL_FIND_USAGE     3
2901 #define CTL_FIND_SUBJECT   4
2902 #define CTL_FIND_EXISTING  5
2903 
2904 typedef struct _CTL_FIND_USAGE_PARA
2905 {
2906     DWORD           cbSize;
2907     CTL_USAGE       SubjectUsage;
2908     CRYPT_DATA_BLOB ListIdentifier;
2909     PCERT_INFO      pSigner;
2910 } CTL_FIND_USAGE_PARA, *PCTL_FIND_USAGE_PARA;
2911 
2912 #define CTL_FIND_NO_LIST_ID_CBDATA 0xffffffff
2913 #define CTL_FIND_NO_SIGNER_PTR     ((PCERT_INFO)-1)
2914 #define CTL_FIND_SAME_USAGE_FLAG   0x00000001
2915 
2916 typedef struct _CTL_FIND_SUBJECT_PARA
2917 {
2918     DWORD                cbSize;
2919     PCTL_FIND_USAGE_PARA pUsagePara;
2920     DWORD                dwSubjectType;
2921     void                *pvSubject;
2922 } CTL_FIND_SUBJECT_PARA, *PCTL_FIND_SUBJECT_PARA;
2923 
2924 /* PFN_CERT_STORE_PROV_WRITE_CERT dwFlags values */
2925 #define CERT_STORE_PROV_WRITE_ADD_FLAG 0x1
2926 
2927 /* CertAddSerializedElementToStore context types */
2928 #define CERT_STORE_CERTIFICATE_CONTEXT 1
2929 #define CERT_STORE_CRL_CONTEXT         2
2930 #define CERT_STORE_CTL_CONTEXT         3
2931 #define CERT_STORE_ALL_CONTEXT_FLAG    ~0U
2932 #define CERT_STORE_CERTIFICATE_CONTEXT_FLAG \
2933                                     (1 << CERT_STORE_CERTIFICATE_CONTEXT)
2934 #define CERT_STORE_CRL_CONTEXT_FLAG (1 << CERT_STORE_CRL_CONTEXT)
2935 #define CERT_STORE_CTL_CONTEXT_FLAG (1 << CERT_STORE_CTL_CONTEXT)
2936 
2937 /* CryptBinaryToString/CryptStringToBinary flags */
2938 #define CRYPT_STRING_BASE64HEADER        0x00000000
2939 #define CRYPT_STRING_BASE64              0x00000001
2940 #define CRYPT_STRING_BINARY              0x00000002
2941 #define CRYPT_STRING_BASE64REQUESTHEADER 0x00000003
2942 #define CRYPT_STRING_HEX                 0x00000004
2943 #define CRYPT_STRING_HEXASCII            0x00000005
2944 #define CRYPT_STRING_BASE64_ANY          0x00000006
2945 #define CRYPT_STRING_ANY                 0x00000007
2946 #define CRYPT_STRING_HEX_ANY             0x00000008
2947 #define CRYPT_STRING_BASE64X509CRLHEADER 0x00000009
2948 #define CRYPT_STRING_HEXADDR             0x0000000a
2949 #define CRYPT_STRING_HEXASCIIADDR        0x0000000b
2950 #define CRYPT_STRING_NOCRLF              0x40000000
2951 #define CRYPT_STRING_NOCR                0x80000000
2952 
2953 /* OIDs */
2954 #define szOID_RSA                           "1.2.840.113549"
2955 #define szOID_PKCS                          "1.2.840.113549.1"
2956 #define szOID_RSA_HASH                      "1.2.840.113549.2"
2957 #define szOID_RSA_ENCRYPT                   "1.2.840.113549.3"
2958 #define szOID_PKCS_1                        "1.2.840.113549.1.1"
2959 #define szOID_PKCS_2                        "1.2.840.113549.1.2"
2960 #define szOID_PKCS_3                        "1.2.840.113549.1.3"
2961 #define szOID_PKCS_4                        "1.2.840.113549.1.4"
2962 #define szOID_PKCS_5                        "1.2.840.113549.1.5"
2963 #define szOID_PKCS_6                        "1.2.840.113549.1.6"
2964 #define szOID_PKCS_7                        "1.2.840.113549.1.7"
2965 #define szOID_PKCS_8                        "1.2.840.113549.1.8"
2966 #define szOID_PKCS_9                        "1.2.840.113549.1.9"
2967 #define szOID_PKCS_10                       "1.2.840.113549.1.10"
2968 #define szOID_PKCS_11                       "1.2.840.113549.1.12"
2969 #define szOID_RSA_RSA                       "1.2.840.113549.1.1.1"
2970 #define CERT_RSA_PUBLIC_KEY_OBJID           szOID_RSA_RSA
2971 #define CERT_DEFAULT_OID_PUBLIC_KEY_SIGN    szOID_RSA_RSA
2972 #define CERT_DEFAULT_OID_PUBLIC_KEY_XCHG    szOID_RSA_RSA
2973 #define szOID_RSA_MD2RSA                    "1.2.840.113549.1.1.2"
2974 #define szOID_RSA_MD4RSA                    "1.2.840.113549.1.1.3"
2975 #define szOID_RSA_MD5RSA                    "1.2.840.113549.1.1.4"
2976 #define szOID_RSA_SHA1RSA                   "1.2.840.113549.1.1.5"
2977 #define szOID_RSA_SET0AEP_RSA               "1.2.840.113549.1.1.6"
2978 #define szOID_RSA_SHA256RSA                 "1.2.840.113549.1.1.11"
2979 #define szOID_RSA_SHA384RSA                 "1.2.840.113549.1.1.12"
2980 #define szOID_RSA_SHA512RSA                 "1.2.840.113549.1.1.13"
2981 #define szOID_RSA_DH                        "1.2.840.113549.1.3.1"
2982 #define szOID_RSA_data                      "1.2.840.113549.1.7.1"
2983 #define szOID_RSA_signedData                "1.2.840.113549.1.7.2"
2984 #define szOID_RSA_envelopedData             "1.2.840.113549.1.7.3"
2985 #define szOID_RSA_signEnvData               "1.2.840.113549.1.7.4"
2986 #define szOID_RSA_digestedData              "1.2.840.113549.1.7.5"
2987 #define szOID_RSA_hashedData                "1.2.840.113549.1.7.5"
2988 #define szOID_RSA_encryptedData             "1.2.840.113549.1.7.6"
2989 #define szOID_RSA_emailAddr                 "1.2.840.113549.1.9.1"
2990 #define szOID_RSA_unstructName              "1.2.840.113549.1.9.2"
2991 #define szOID_RSA_contentType               "1.2.840.113549.1.9.3"
2992 #define szOID_RSA_messageDigest             "1.2.840.113549.1.9.4"
2993 #define szOID_RSA_signingTime               "1.2.840.113549.1.9.5"
2994 #define szOID_RSA_counterSign               "1.2.840.113549.1.9.6"
2995 #define szOID_RSA_challengePwd              "1.2.840.113549.1.9.7"
2996 #define szOID_RSA_unstructAddr              "1.2.840.113549.1.9.9"
2997 #define szOID_RSA_extCertAttrs              "1.2.840.113549.1.9.9"
2998 #define szOID_RSA_certExtensions            "1.2.840.113549.1.9.14"
2999 #define szOID_RSA_SMIMECapabilities         "1.2.840.113549.1.9.15"
3000 #define szOID_RSA_preferSignedData          "1.2.840.113549.1.9.15.1"
3001 #define szOID_RSA_SMIMEalg                  "1.2.840.113549.1.9.16.3"
3002 #define szOID_RSA_SMIMEalgESDH              "1.2.840.113549.1.9.16.3.5"
3003 #define szOID_RSA_SMIMEalgCMS3DESwrap       "1.2.840.113549.1.9.16.3.6"
3004 #define szOID_RSA_SMIMEalgCMSRC2wrap        "1.2.840.113549.1.9.16.3.7"
3005 #define szOID_RSA_MD2                       "1.2.840.113549.2.2"
3006 #define szOID_RSA_MD4                       "1.2.840.113549.2.4"
3007 #define szOID_RSA_MD5                       "1.2.840.113549.2.5"
3008 #define szOID_RSA_RC2CBC                    "1.2.840.113549.3.2"
3009 #define szOID_RSA_RC4                       "1.2.840.113549.3.4"
3010 #define szOID_RSA_DES_EDE3_CBC              "1.2.840.113549.3.7"
3011 #define szOID_RSA_RC5_CBCPad                "1.2.840.113549.3.9"
3012 #define szOID_ANSI_X942                     "1.2.840.10046"
3013 #define szOID_ANSI_X942_DH                  "1.2.840.10046.2.1"
3014 #define szOID_X957                          "1.2.840.10040"
3015 #define szOID_X957_DSA                      "1.2.840.10040.4.1"
3016 #define szOID_X957_SHA1DSA                  "1.2.840.10040.4.3"
3017 #define szOID_DS                            "2.5"
3018 #define szOID_DSALG                         "2.5.8"
3019 #define szOID_DSALG_CRPT                    "2.5.8.1"
3020 #define szOID_DSALG_HASH                    "2.5.8.2"
3021 #define szOID_DSALG_SIGN                    "2.5.8.3"
3022 #define szOID_DSALG_RSA                     "2.5.8.1.1"
3023 #define szOID_OIW                           "1.3.14"
3024 #define szOID_OIWSEC                        "1.3.14.3.2"
3025 #define szOID_OIWSEC_md4RSA                 "1.3.14.3.2.2"
3026 #define szOID_OIWSEC_md5RSA                 "1.3.14.3.2.3"
3027 #define szOID_OIWSEC_md4RSA2                "1.3.14.3.2.4"
3028 #define szOID_OIWSEC_desECB                 "1.3.14.3.2.6"
3029 #define szOID_OIWSEC_desCBC                 "1.3.14.3.2.7"
3030 #define szOID_OIWSEC_desOFB                 "1.3.14.3.2.8"
3031 #define szOID_OIWSEC_desCFB                 "1.3.14.3.2.9"
3032 #define szOID_OIWSEC_desMAC                 "1.3.14.3.2.10"
3033 #define szOID_OIWSEC_rsaSign                "1.3.14.3.2.11"
3034 #define szOID_OIWSEC_dsa                    "1.3.14.3.2.12"
3035 #define szOID_OIWSEC_shaDSA                 "1.3.14.3.2.13"
3036 #define szOID_OIWSEC_mdc2RSA                "1.3.14.3.2.14"
3037 #define szOID_OIWSEC_shaRSA                 "1.3.14.3.2.15"
3038 #define szOID_OIWSEC_dhCommMod              "1.3.14.3.2.16"
3039 #define szOID_OIWSEC_desEDE                 "1.3.14.3.2.17"
3040 #define szOID_OIWSEC_sha                    "1.3.14.3.2.18"
3041 #define szOID_OIWSEC_mdc2                   "1.3.14.3.2.19"
3042 #define szOID_OIWSEC_dsaComm                "1.3.14.3.2.20"
3043 #define szOID_OIWSEC_dsaCommSHA             "1.3.14.3.2.21"
3044 #define szOID_OIWSEC_rsaXchg                "1.3.14.3.2.22"
3045 #define szOID_OIWSEC_keyHashSeal            "1.3.14.3.2.23"
3046 #define szOID_OIWSEC_md2RSASign             "1.3.14.3.2.24"
3047 #define szOID_OIWSEC_md5RSASign             "1.3.14.3.2.25"
3048 #define szOID_OIWSEC_sha1                   "1.3.14.3.2.26"
3049 #define szOID_OIWSEC_dsaSHA1                "1.3.14.3.2.27"
3050 #define szOID_OIWSEC_dsaCommSHA1            "1.3.14.3.2.28"
3051 #define szOID_OIWSEC_sha1RSASign            "1.3.14.3.2.29"
3052 #define szOID_OIWDIR                        "1.3.14.7.2"
3053 #define szOID_OIWDIR_CRPT                   "1.3.14.7.2.1"
3054 #define szOID_OIWDIR_HASH                   "1.3.14.7.2.2"
3055 #define szOID_OIWDIR_SIGN                   "1.3.14.7.2.3"
3056 #define szOID_OIWDIR_md2                    "1.3.14.7.2.2.1"
3057 #define szOID_OIWDIR_md2RSA                 "1.3.14.7.2.3.1"
3058 #define szOID_INFOSEC                       "2.16.840.1.101.2.1"
3059 #define szOID_INFOSEC_sdnsSignature         "2.16.840.1.101.2.1.1.1"
3060 #define szOID_INFOSEC_mosaicSignature       "2.16.840.1.101.2.1.1.2"
3061 #define szOID_INFOSEC_sdnsConfidentiality   "2.16.840.1.101.2.1.1.3"
3062 #define szOID_INFOSEC_mosaicConfidentiality "2.16.840.1.101.2.1.1.4"
3063 #define szOID_INFOSEC_sdnsIntegrity         "2.16.840.1.101.2.1.1.5"
3064 #define szOID_INFOSEC_mosaicIntegrity       "2.16.840.1.101.2.1.1.6"
3065 #define szOID_INFOSEC_sdnsTokenProtection   "2.16.840.1.101.2.1.1.7"
3066 #define szOID_INFOSEC_mosaicTokenProtection "2.16.840.1.101.2.1.1.8"
3067 #define szOID_INFOSEC_sdnsKeyManagement     "2.16.840.1.101.2.1.1.9"
3068 #define szOID_INFOSEC_mosaicKeyManagement   "2.16.840.1.101.2.1.1.10"
3069 #define szOID_INFOSEC_sdnsKMandSig          "2.16.840.1.101.2.1.1.11"
3070 #define szOID_INFOSEC_mosaicKMandSig        "2.16.840.1.101.2.1.1.12"
3071 #define szOID_INFOSEC_SuiteASignature       "2.16.840.1.101.2.1.1.13"
3072 #define szOID_INFOSEC_SuiteAConfidentiality "2.16.840.1.101.2.1.1.14"
3073 #define szOID_INFOSEC_SuiteAIntegrity       "2.16.840.1.101.2.1.1.15"
3074 #define szOID_INFOSEC_SuiteATokenProtection "2.16.840.1.101.2.1.1.16"
3075 #define szOID_INFOSEC_SuiteAKeyManagement   "2.16.840.1.101.2.1.1.17"
3076 #define szOID_INFOSEC_SuiteAKMandSig        "2.16.840.1.101.2.1.1.18"
3077 #define szOID_INFOSEC_mosaicUpdatedSig      "2.16.840.1.101.2.1.1.19"
3078 #define szOID_INFOSEC_mosaicKMandUpdSig     "2.16.840.1.101.2.1.1.20"
3079 #define szOID_INFOSEC_mosaicUpdateInteg     "2.16.840.1.101.2.1.1.21"
3080 #define szOID_COMMON_NAME                   "2.5.4.3"
3081 #define szOID_SUR_NAME                      "2.5.4.4"
3082 #define szOID_DEVICE_SERIAL_NUMBER          "2.5.4.5"
3083 #define szOID_COUNTRY_NAME                  "2.5.4.6"
3084 #define szOID_LOCALITY_NAME                 "2.5.4.7"
3085 #define szOID_STATE_OR_PROVINCE_NAME        "2.5.4.8"
3086 #define szOID_STREET_ADDRESS                "2.5.4.9"
3087 #define szOID_ORGANIZATION_NAME             "2.5.4.10"
3088 #define szOID_ORGANIZATIONAL_UNIT_NAME      "2.5.4.11"
3089 #define szOID_TITLE                         "2.5.4.12"
3090 #define szOID_DESCRIPTION                   "2.5.4.13"
3091 #define szOID_SEARCH_GUIDE                  "2.5.4.14"
3092 #define szOID_BUSINESS_CATEGORY             "2.5.4.15"
3093 #define szOID_POSTAL_ADDRESS                "2.5.4.16"
3094 #define szOID_POSTAL_CODE                   "2.5.4.17"
3095 #define szOID_POST_OFFICE_BOX               "2.5.4.18"
3096 #define szOID_PHYSICAL_DELIVERY_OFFICE_NAME "2.5.4.19"
3097 #define szOID_TELEPHONE_NUMBER              "2.5.4.20"
3098 #define szOID_TELEX_NUMBER                  "2.5.4.21"
3099 #define szOID_TELETEXT_TERMINAL_IDENTIFIER  "2.5.4.22"
3100 #define szOID_FACSIMILE_TELEPHONE_NUMBER    "2.5.4.23"
3101 #define szOID_X21_ADDRESS                   "2.5.4.24"
3102 #define szOID_INTERNATIONAL_ISDN_NUMBER     "2.5.4.25"
3103 #define szOID_REGISTERED_ADDRESS            "2.5.4.26"
3104 #define szOID_DESTINATION_INDICATOR         "2.5.4.27"
3105 #define szOID_PREFERRED_DELIVERY_METHOD     "2.5.4.28"
3106 #define szOID_PRESENTATION_ADDRESS          "2.5.4.29"
3107 #define szOID_SUPPORTED_APPLICATION_CONTEXT "2.5.4.30"
3108 #define szOID_MEMBER                        "2.5.4.31"
3109 #define szOID_OWNER                         "2.5.4.32"
3110 #define szOID_ROLE_OCCUPANT                 "2.5.4.33"
3111 #define szOID_SEE_ALSO                      "2.5.4.34"
3112 #define szOID_USER_PASSWORD                 "2.5.4.35"
3113 #define szOID_USER_CERTIFICATE              "2.5.4.36"
3114 #define szOID_CA_CERTIFICATE                "2.5.4.37"
3115 #define szOID_AUTHORITY_REVOCATION_LIST     "2.5.4.38"
3116 #define szOID_CERTIFICATE_REVOCATION_LIST   "2.5.4.39"
3117 #define szOID_CROSS_CERTIFICATE_PAIR        "2.5.4.40"
3118 #define szOID_GIVEN_NAME                    "2.5.4.42"
3119 #define szOID_INITIALS                      "2.5.4.43"
3120 #define szOID_DN_QUALIFIER                  "2.5.4.46"
3121 #define szOID_AUTHORITY_KEY_IDENTIFIER      "2.5.29.1"
3122 #define szOID_KEY_ATTRIBUTES                "2.5.29.2"
3123 #define szOID_CERT_POLICIES_95              "2.5.29.3"
3124 #define szOID_KEY_USAGE_RESTRICTION         "2.5.29.4"
3125 #define szOID_LEGACY_POLICY_MAPPINGS        "2.5.29.5"
3126 #define szOID_SUBJECT_ALT_NAME              "2.5.29.7"
3127 #define szOID_ISSUER_ALT_NAME               "2.5.29.8"
3128 #define szOID_SUBJECT_DIR_ATTRS             "2.5.29.9"
3129 #define szOID_BASIC_CONSTRAINTS             "2.5.29.10"
3130 #define szOID_SUBJECT_KEY_IDENTIFIER        "2.5.29.14"
3131 #define szOID_KEY_USAGE                     "2.5.29.15"
3132 #define szOID_PRIVATEKEY_USAGE_PERIOD       "2.5.29.16"
3133 #define szOID_SUBJECT_ALT_NAME2             "2.5.29.17"
3134 #define szOID_ISSUER_ALT_NAME2              "2.5.29.18"
3135 #define szOID_BASIC_CONSTRAINTS2            "2.5.29.19"
3136 #define szOID_CRL_NUMBER                    "2.5.29.20"
3137 #define szOID_CRL_REASON_CODE               "2.5.29.21"
3138 #define szOID_REASON_CODE_HOLD              "2.5.29.23"
3139 #define szOID_DELTA_CRL_INDICATOR           "2.5.29.27"
3140 #define szOID_ISSUING_DIST_POINT            "2.5.29.28"
3141 #define szOID_NAME_CONSTRAINTS              "2.5.29.30"
3142 #define szOID_CRL_DIST_POINTS               "2.5.29.31"
3143 #define szOID_CERT_POLICIES                 "2.5.29.32"
3144 #define szOID_ANY_CERT_POLICY               "2.5.29.32.0"
3145 #define szOID_POLICY_MAPPINGS               "2.5.29.33"
3146 #define szOID_AUTHORITY_KEY_IDENTIFIER2     "2.5.29.35"
3147 #define szOID_POLICY_CONSTRAINTS            "2.5.29.36"
3148 #define szOID_ENHANCED_KEY_USAGE            "2.5.29.37"
3149 #define szOID_FRESHEST_CRL                  "2.5.29.46"
3150 #define szOID_INHIBIT_ANY_POLICY            "2.5.29.54"
3151 #define szOID_DOMAIN_COMPONENT              "0.9.2342.19200300.100.1.25"
3152 #define szOID_PKCS_12_FRIENDLY_NAME_ATTR     "1.2.840.113549.1.9.20"
3153 #define szOID_PKCS_12_LOCAL_KEY_ID           "1.2.840.113549.1.9.21"
3154 #define szOID_CERT_EXTENSIONS                "1.3.6.1.4.1.311.2.1.14"
3155 #define szOID_NEXT_UPDATE_LOCATION           "1.3.6.1.4.1.311.10.2"
3156 #define szOID_KP_CTL_USAGE_SIGNING           "1.3.6.1.4.1.311.10.3.1"
3157 #define szOID_KP_TIME_STAMP_SIGNING          "1.3.6.1.4.1.311.10.3.2"
3158 #ifndef szOID_SERVER_GATED_CRYPTO
3159 #define szOID_SERVER_GATED_CRYPTO            "1.3.6.1.4.1.311.10.3.3"
3160 #endif
3161 #ifndef szOID_SGC_NETSCAPE
3162 #define szOID_SGC_NETSCAPE                   "2.16.840.1.113730.4.1"
3163 #endif
3164 #define szOID_KP_EFS                         "1.3.6.1.4.1.311.10.3.4"
3165 #define szOID_EFS_RECOVERY                   "1.3.6.1.4.1.311.10.3.4.1"
3166 #define szOID_WHQL_CRYPTO                    "1.3.6.1.4.1.311.10.3.5"
3167 #define szOID_NT5_CRYPTO                     "1.3.6.1.4.1.311.10.3.6"
3168 #define szOID_OEM_WHQL_CRYPTO                "1.3.6.1.4.1.311.10.3.7"
3169 #define szOID_EMBEDDED_NT_CRYPTO             "1.3.6.1.4.1.311.10.3.8"
3170 #define szOID_ROOT_LIST_SIGNER               "1.3.6.1.4.1.311.10.3.9"
3171 #define szOID_KP_QUALIFIED_SUBORDINATION     "1.3.6.1.4.1.311.10.3.10"
3172 #define szOID_KP_KEY_RECOVERY                "1.3.6.1.4.1.311.10.3.11"
3173 #define szOID_KP_DOCUMENT_SIGNING            "1.3.6.1.4.1.311.10.3.12"
3174 #define szOID_KP_LIFETIME_SIGNING            "1.3.6.1.4.1.311.10.3.13"
3175 #define szOID_KP_MOBILE_DEVICE_SOFTWARE      "1.3.6.1.4.1.311.10.3.14"
3176 #define szOID_YESNO_TRUST_ATTR               "1.3.6.1.4.1.311.10.4.1"
3177 #ifndef szOID_DRM
3178 #define szOID_DRM                            "1.3.6.1.4.1.311.10.5.1"
3179 #endif
3180 #ifndef szOID_DRM_INDIVIDUALIZATION
3181 #define szOID_DRM_INDIVIDUALIZATION          "1.3.6.1.4.1.311.10.5.2"
3182 #endif
3183 #ifndef szOID_LICENSES
3184 #define szOID_LICENSES                       "1.3.6.1.4.1.311.10.6.1"
3185 #endif
3186 #ifndef szOID_LICENSE_SERVER
3187 #define szOID_LICENSE_SERVER                 "1.3.6.1.4.1.311.10.6.2"
3188 #endif
3189 #define szOID_REMOVE_CERTIFICATE             "1.3.6.1.4.1.311.10.8.1"
3190 #define szOID_CROSS_CERT_DIST_POINTS         "1.3.6.1.4.1.311.10.9.1"
3191 #define szOID_CTL                            "1.3.6.1.4.1.311.10.1"
3192 #define szOID_SORTED_CTL                     "1.3.6.1.4.1.311.10.1.1"
3193 #define szOID_ANY_APPLICATION_POLICY         "1.3.6.1.4.1.311.10.12.1"
3194 #define szOID_RENEWAL_CERTIFICATE            "1.3.6.1.4.1.311.13.1"
3195 #define szOID_ENROLLMENT_NAME_VALUE_PAIR     "1.3.6.1.4.1.311.13.2.1"
3196 #define szOID_ENROLLMENT_CSP_PROVIDER        "1.3.6.1.4.1.311.13.2.2"
3197 #define szOID_OS_VERSION                     "1.3.6.1.4.1.311.13.2.3"
3198 #define szOID_PKCS_12_KEY_PROVIDER_NAME_ATTR "1.3.6.1.4.1.311.17.1"
3199 #define szOID_LOCAL_MACHINE_KEYSET           "1.3.6.1.4.1.311.17.2"
3200 #define szOID_AUTO_ENROLL_CTL_USAGE          "1.3.6.1.4.1.311.20.1"
3201 #define szOID_ENROLL_CERTTYPE_EXTENSION      "1.3.6.1.4.1.311.20.2"
3202 #define szOID_ENROLLMENT_AGENT               "1.3.6.1.4.1.311.20.2.1"
3203 #ifndef szOID_KP_SMARTCARD_LOGON
3204 #define szOID_KP_SMARTCARD_LOGON             "1.3.6.1.4.1.311.20.2.2"
3205 #endif
3206 #ifndef szOID_NT_PRINCIPAL_NAME
3207 #define szOID_NT_PRINCIPAL_NAME              "1.3.6.1.4.1.311.20.2.3"
3208 #endif
3209 #define szOID_CERT_MANIFOLD                  "1.3.6.1.4.1.311.20.3"
3210 #ifndef szOID_CERTSRV_CA_VERSION
3211 #define szOID_CERTSRV_CA_VERSION             "1.3.6.1.4.1.311.21.1"
3212 #endif
3213 #define szOID_CERTSRV_PREVIOUS_CERT_HASH     "1.3.6.1.4.1.311.21.2"
3214 #define szOID_CRL_VIRTUAL_BASE               "1.3.6.1.4.1.311.21.3"
3215 #define szOID_CRL_NEXT_PUBLISH               "1.3.6.1.4.1.311.21.4"
3216 #define szOID_KP_CA_EXCHANGE                 "1.3.6.1.4.1.311.21.5"
3217 #define szOID_KP_KEY_RECOVERY_AGENT          "1.3.6.1.4.1.311.21.6"
3218 #define szOID_CERTIFICATE_TEMPLATE           "1.3.6.1.4.1.311.21.7"
3219 #define szOID_ENTERPRISE_OID_ROOT            "1.3.6.1.4.1.311.21.8"
3220 #define szOID_RDN_DUMMY_SIGNER               "1.3.6.1.4.1.311.21.9"
3221 #define szOID_APPLICATION_CERT_POLICIES      "1.3.6.1.4.1.311.21.10"
3222 #define szOID_APPLICATION_POLICY_MAPPINGS    "1.3.6.1.4.1.311.21.11"
3223 #define szOID_APPLICATION_POLICY_CONSTRAINTS "1.3.6.1.4.1.311.21.12"
3224 #define szOID_ARCHIVED_KEY_ATTR              "1.3.6.1.4.1.311.21.13"
3225 #define szOID_CRL_SELF_CDP                   "1.3.6.1.4.1.311.21.14"
3226 #define szOID_REQUIRE_CERT_CHAIN_POLICY      "1.3.6.1.4.1.311.21.15"
3227 #define szOID_ARCHIVED_KEY_CERT_HASH         "1.3.6.1.4.1.311.21.16"
3228 #define szOID_ISSUED_CERT_HASH               "1.3.6.1.4.1.311.21.17"
3229 #define szOID_DS_EMAIL_REPLICATION           "1.3.6.1.4.1.311.21.19"
3230 #define szOID_REQUEST_CLIENT_INFO            "1.3.6.1.4.1.311.21.20"
3231 #define szOID_ENCRYPTED_KEY_HASH             "1.3.6.1.4.1.311.21.21"
3232 #define szOID_CERTSRV_CROSSCA_VERSION        "1.3.6.1.4.1.311.21.22"
3233 #define szOID_KEYID_RDN                      "1.3.6.1.4.1.311.10.7.1"
3234 #define szOID_PKIX                           "1.3.6.1.5.5.7"
3235 #define szOID_PKIX_PE                        "1.3.6.1.5.5.7.1"
3236 #define szOID_AUTHORITY_INFO_ACCESS          "1.3.6.1.5.5.7.1.1"
3237 #define szOID_PKIX_POLICY_QUALIFIER_CPS      "1.3.6.1.5.5.7.2.1"
3238 #define szOID_PKIX_POLICY_QUALIFIER_USERNOTICE "1.3.6.1.5.5.7.2.2"
3239 #define szOID_PKIX_KP                        "1.3.6.1.5.5.7.3"
3240 #define szOID_PKIX_KP_SERVER_AUTH            "1.3.6.1.5.5.7.3.1"
3241 #define szOID_PKIX_KP_CLIENT_AUTH            "1.3.6.1.5.5.7.3.2"
3242 #define szOID_PKIX_KP_CODE_SIGNING           "1.3.6.1.5.5.7.3.3"
3243 #define szOID_PKIX_KP_EMAIL_PROTECTION       "1.3.6.1.5.5.7.3.4"
3244 #define szOID_PKIX_KP_IPSEC_END_SYSTEM       "1.3.6.1.5.5.7.3.5"
3245 #define szOID_PKIX_KP_IPSEC_TUNNEL           "1.3.6.1.5.5.7.3.6"
3246 #define szOID_PKIX_KP_IPSEC_USER             "1.3.6.1.5.5.7.3.7"
3247 #define szOID_PKIX_KP_TIMESTAMP_SIGNING      "1.3.6.1.5.5.7.3.8"
3248 #define szOID_PKIX_NO_SIGNATURE              "1.3.6.1.5.5.7.6.2"
3249 #define szOID_CMC                            "1.3.6.1.5.5.7.7"
3250 #define szOID_CMC_STATUS_INFO                "1.3.6.1.5.5.7.7.1"
3251 #define szOID_CMC_IDENTIFICATION             "1.3.6.1.5.5.7.7.2"
3252 #define szOID_CMC_IDENTITY_PROOF             "1.3.6.1.5.5.7.7.3"
3253 #define szOID_CMC_DATA_RETURN                "1.3.6.1.5.5.7.7.4"
3254 #define szOID_CMC_TRANSACTION_ID             "1.3.6.1.5.5.7.7.5"
3255 #define szOID_CMC_SENDER_NONCE               "1.3.6.1.5.5.7.7.6"
3256 #define szOID_CMC_RECIPIENT_NONCE            "1.3.6.1.5.5.7.7.7"
3257 #define szOID_CMC_ADD_EXTENSIONS             "1.3.6.1.5.5.7.7.8"
3258 #define szOID_CMC_ENCRYPTED_POP              "1.3.6.1.5.5.7.7.9"
3259 #define szOID_CMC_DECRYPTED_POP              "1.3.6.1.5.5.7.7.10"
3260 #define szOID_CMC_LRA_POP_WITNESS            "1.3.6.1.5.5.7.7.11"
3261 #define szOID_CMC_GET_CERT                   "1.3.6.1.5.5.7.7.15"
3262 #define szOID_CMC_GET_CRL                    "1.3.6.1.5.5.7.7.16"
3263 #define szOID_CMC_REVOKE_REQUEST             "1.3.6.1.5.5.7.7.17"
3264 #define szOID_CMC_REG_INFO                   "1.3.6.1.5.5.7.7.18"
3265 #define szOID_CMC_RESPONSE_INFO              "1.3.6.1.5.5.7.7.19"
3266 #define szOID_CMC_QUERY_PENDING              "1.3.6.1.5.5.7.7.21"
3267 #define szOID_CMC_ID_POP_LINK_RANDOM         "1.3.6.1.5.5.7.7.22"
3268 #define szOID_CMC_ID_POP_LINK_WITNESS        "1.3.6.1.5.5.7.7.23"
3269 #define szOID_CT_PKI_DATA                    "1.3.6.1.5.5.7.12.2"
3270 #define szOID_CT_PKI_RESPONSE                "1.3.6.1.5.5.7.12.3"
3271 #define szOID_PKIX_ACC_DESCR                 "1.3.6.1.5.5.7.48"
3272 #define szOID_PKIX_OCSP                      "1.3.6.1.5.5.7.48.1"
3273 #define szOID_PKIX_CA_ISSUERS                "1.3.6.1.5.5.7.48.2"
3274 #define szOID_IPSEC_KP_IKE_INTERMEDIATE      "1.3.6.1.5.5.8.2.2"
3275 
3276 #ifndef szOID_SERIALIZED
3277 #define szOID_SERIALIZED                     "1.3.6.1.4.1.311.10.3.3.1"
3278 #endif
3279 
3280 #ifndef szOID_PRODUCT_UPDATE
3281 #define szOID_PRODUCT_UPDATE                 "1.3.6.1.4.1.311.31.1"
3282 #endif
3283 
3284 #define szOID_NETSCAPE                       "2.16.840.1.113730"
3285 #define szOID_NETSCAPE_CERT_EXTENSION        "2.16.840.1.113730.1"
3286 #define szOID_NETSCAPE_CERT_TYPE             "2.16.840.1.113730.1.1"
3287 #define szOID_NETSCAPE_BASE_URL              "2.16.840.1.113730.1.2"
3288 #define szOID_NETSCAPE_REVOCATION_URL        "2.16.840.1.113730.1.3"
3289 #define szOID_NETSCAPE_CA_REVOCATION_URL     "2.16.840.1.113730.1.4"
3290 #define szOID_NETSCAPE_CERT_RENEWAL_URL      "2.16.840.1.113730.1.7"
3291 #define szOID_NETSCAPE_CA_POLICY_URL         "2.16.840.1.113730.1.8"
3292 #define szOID_NETSCAPE_SSL_SERVER_NAME       "2.16.840.1.113730.1.12"
3293 #define szOID_NETSCAPE_COMMENT               "2.16.840.1.113730.1.13"
3294 #define szOID_NETSCAPE_DATA_TYPE             "2.16.840.1.113730.2"
3295 #define szOID_NETSCAPE_CERT_SEQUENCE         "2.16.840.1.113730.2.5"
3296 
3297 #define szOID_NIST_sha256                    "2.16.840.1.101.3.4.2.1"
3298 #define szOID_NIST_sha384                    "2.16.840.1.101.3.4.2.2"
3299 #define szOID_NIST_sha512                    "2.16.840.1.101.3.4.2.3"
3300 
3301 /* Bits for szOID_NETSCAPE_CERT_TYPE */
3302 #define NETSCAPE_SSL_CLIENT_AUTH_CERT_TYPE 0x80
3303 #define NETSCAPE_SSL_SERVER_AUTH_CERT_TYPE 0x40
3304 #define NETSCAPE_SMIME_CERT_TYPE           0x20
3305 #define NETSCAPE_SIGN_CERT_TYPE            0x10
3306 #define NETSCAPE_SSL_CA_CERT_TYPE          0x04
3307 #define NETSCAPE_SMIME_CA_CERT_TYPE        0x02
3308 #define NETSCAPE_SIGN_CA_CERT_TYPE         0x01
3309 
3310 #define CRYPT_ENCODE_DECODE_NONE             0
3311 #define X509_CERT                            ((LPCSTR)1)
3312 #define X509_CERT_TO_BE_SIGNED               ((LPCSTR)2)
3313 #define X509_CERT_CRL_TO_BE_SIGNED           ((LPCSTR)3)
3314 #define X509_CERT_REQUEST_TO_BE_SIGNED       ((LPCSTR)4)
3315 #define X509_EXTENSIONS                      ((LPCSTR)5)
3316 #define X509_NAME_VALUE                      ((LPCSTR)6)
3317 #define X509_ANY_STRING                      X509_NAME_VALUE
3318 #define X509_NAME                            ((LPCSTR)7)
3319 #define X509_PUBLIC_KEY_INFO                 ((LPCSTR)8)
3320 #define X509_AUTHORITY_KEY_ID                ((LPCSTR)9)
3321 #define X509_KEY_ATTRIBUTES                  ((LPCSTR)10)
3322 #define X509_KEY_USAGE_RESTRICTION           ((LPCSTR)11)
3323 #define X509_ALTERNATE_NAME                  ((LPCSTR)12)
3324 #define X509_BASIC_CONSTRAINTS               ((LPCSTR)13)
3325 #define X509_KEY_USAGE                       ((LPCSTR)14)
3326 #define X509_BASIC_CONSTRAINTS2              ((LPCSTR)15)
3327 #define X509_CERT_POLICIES                   ((LPCSTR)16)
3328 #define PKCS_UTC_TIME                        ((LPCSTR)17)
3329 #define PKCS_TIME_REQUEST                    ((LPCSTR)18)
3330 #define RSA_CSP_PUBLICKEYBLOB                ((LPCSTR)19)
3331 #define X509_UNICODE_NAME                    ((LPCSTR)20)
3332 #define X509_KEYGEN_REQUEST_TO_BE_SIGNED     ((LPCSTR)21)
3333 #define PKCS_ATTRIBUTE                       ((LPCSTR)22)
3334 #define PKCS_CONTENT_INFO_SEQUENCE_OF_ANY    ((LPCSTR)23)
3335 #define X509_UNICODE_NAME_VALUE              ((LPCSTR)24)
3336 #define X509_UNICODE_ANY_STRING              X509_UNICODE_NAME_VALUE
3337 #define X509_OCTET_STRING                    ((LPCSTR)25)
3338 #define X509_BITS                            ((LPCSTR)26)
3339 #define X509_INTEGER                         ((LPCSTR)27)
3340 #define X509_MULTI_BYTE_INTEGER              ((LPCSTR)28)
3341 #define X509_ENUMERATED                      ((LPCSTR)29)
3342 #define X509_CRL_REASON_CODE                 X509_ENUMERATED
3343 #define X509_CHOICE_OF_TIME                  ((LPCSTR)30)
3344 #define X509_AUTHORITY_KEY_ID2               ((LPCSTR)31)
3345 #define X509_AUTHORITY_INFO_ACCESS           ((LPCSTR)32)
3346 #define PKCS_CONTENT_INFO                    ((LPCSTR)33)
3347 #define X509_SEQUENCE_OF_ANY                 ((LPCSTR)34)
3348 #define X509_CRL_DIST_POINTS                 ((LPCSTR)35)
3349 #define X509_ENHANCED_KEY_USAGE              ((LPCSTR)36)
3350 #define PKCS_CTL                             ((LPCSTR)37)
3351 #define X509_MULTI_BYTE_UINT                 ((LPCSTR)38)
3352 #define X509_DSS_PUBLICKEY                   X509_MULTI_BYTE_UINT
3353 #define X509_DSS_PARAMETERS                  ((LPCSTR)39)
3354 #define X509_DSS_SIGNATURE                   ((LPCSTR)40)
3355 #define PKCS_RC2_CBC_PARAMETERS              ((LPCSTR)41)
3356 #define PKCS_SMIME_CAPABILITIES              ((LPCSTR)42)
3357 #define PKCS_RSA_PRIVATE_KEY                 ((LPCSTR)43)
3358 #define PKCS_PRIVATE_KEY_INFO                ((LPCSTR)44)
3359 #define PKCS_ENCRYPTED_PRIVATE_KEY_INFO      ((LPCSTR)45)
3360 #define X509_PKIX_POLICY_QUALIFIER_USERNOTICE ((LPCSTR)46)
3361 #define X509_DH_PUBLICKEY                    X509_MULTI_BYTE_UINT
3362 #define X509_DH_PARAMETERS                   ((LPCSTR)47)
3363 #define PKCS_ATTRIBUTES                      ((LPCSTR)48)
3364 #define PKCS_SORTED_CTL                      ((LPCSTR)49)
3365 #define X942_DH_PARAMETERS                   ((LPCSTR)50)
3366 #define X509_BITS_WITHOUT_TRAILING_ZEROES    ((LPCSTR)51)
3367 #define X942_OTHER_INFO                      ((LPCSTR)52)
3368 #define X509_CERT_PAIR                       ((LPCSTR)53)
3369 #define X509_ISSUING_DIST_POINT              ((LPCSTR)54)
3370 #define X509_NAME_CONSTRAINTS                ((LPCSTR)55)
3371 #define X509_POLICY_MAPPINGS                 ((LPCSTR)56)
3372 #define X509_POLICY_CONSTRAINTS              ((LPCSTR)57)
3373 #define X509_CROSS_CERT_DIST_POINTS          ((LPCSTR)58)
3374 #define CMC_DATA                             ((LPCSTR)59)
3375 #define CMC_RESPONSE                         ((LPCSTR)60)
3376 #define CMC_STATUS                           ((LPCSTR)61)
3377 #define CMC_ADD_EXTENSIONS                   ((LPCSTR)62)
3378 #define CMC_ADD_ATTRIBUTES                   ((LPCSTR)63)
3379 #define X509_CERTIFICATE_TEMPLATE            ((LPCSTR)64)
3380 #define PKCS7_SIGNER_INFO                    ((LPCSTR)500)
3381 #define CMS_SIGNER_INFO                      ((LPCSTR)501)
3382 
3383 /* encode/decode flags */
3384 #define CRYPT_ENCODE_NO_SIGNATURE_BYTE_REVERSAL_FLAG           0x00008
3385 #define CRYPT_ENCODE_ALLOC_FLAG                                0x08000
3386 #define CRYPT_SORTED_CTL_ENCODE_HASHED_SUBJECT_IDENTIFIER_FLAG 0x10000
3387 #define CRYPT_UNICODE_NAME_ENCODE_ENABLE_T61_UNICODE_FLAG \
3388  CERT_RDN_ENABLE_T61_UNICODE_FLAG
3389 #define CRYPT_UNICODE_NAME_ENCODE_ENABLE_UTF8_UNICODE_FLAG \
3390  CERT_RDN_ENABLE_UTF8_UNICODE_FLAG
3391 #define CRYPT_UNICODE_NAME_ENCODE_DISABLE_CHECK_TYPE_FLAG \
3392  CERT_RDN_DISABLE_CHECK_TYPE_FLAG
3393 
3394 #define CRYPT_DECODE_NOCOPY_FLAG                               0x00001
3395 #define CRYPT_DECODE_TO_BE_SIGNED_FLAG                         0x00002
3396 #define CRYPT_DECODE_SHARE_OID_STRING_FLAG                     0x00004
3397 #define CRYPT_DECODE_NO_SIGNATURE_BYTE_REVERSAL_FLAG           0x00008
3398 #define CRYPT_DECODE_ALLOC_FLAG                                0x08000
3399 #define CRYPT_UNICODE_NAME_DECODE_DISABLE_IE4_UTF8_FLAG \
3400  CERT_RDN_DISABLE_IE4_UTF8_FLAG
3401 
3402 #define CERT_STORE_SIGNATURE_FLAG     0x00000001
3403 #define CERT_STORE_TIME_VALIDITY_FLAG 0x00000002
3404 #define CERT_STORE_REVOCATION_FLAG    0x00000004
3405 #define CERT_STORE_NO_CRL_FLAG        0x00010000
3406 #define CERT_STORE_NO_ISSUER_FLAG     0x00020000
3407 
3408 #define CERT_STORE_BASE_CRL_FLAG  0x00000100
3409 #define CERT_STORE_DELTA_CRL_FLAG 0x00000200
3410 
3411 /* subject types for CryptVerifyCertificateSignatureEx */
3412 #define CRYPT_VERIFY_CERT_SIGN_SUBJECT_BLOB 1
3413 #define CRYPT_VERIFY_CERT_SIGN_SUBJECT_CERT 2
3414 #define CRYPT_VERIFY_CERT_SIGN_SUBJECT_CRL  3
3415 
3416 /* issuer types for CryptVerifyCertificateSignatureEx */
3417 #define CRYPT_VERIFY_CERT_SIGN_ISSUER_PUBKEY 1
3418 #define CRYPT_VERIFY_CERT_SIGN_ISSUER_CERT   2
3419 #define CRYPT_VERIFY_CERT_SIGN_ISSUER_CHAIN  3
3420 #define CRYPT_VERIFY_CERT_SIGN_ISSUER_NULL   4
3421 
3422 #define CRYPT_GET_URL_FROM_PROPERTY         0x00000001
3423 #define CRYPT_GET_URL_FROM_EXTENSION        0x00000002
3424 #define CRYPT_GET_URL_FROM_UNAUTH_ATTRIBUTE 0x00000004
3425 #define CRYPT_GET_URL_FROM_AUTH_ATTRIBUTE   0x00000008
3426 
3427 /* Certificate name string types and flags */
3428 #define CERT_SIMPLE_NAME_STR 1
3429 #define CERT_OID_NAME_STR    2
3430 #define CERT_X500_NAME_STR   3
3431 #define CERT_NAME_STR_SEMICOLON_FLAG           0x40000000
3432 #define CERT_NAME_STR_NO_PLUS_FLAG             0x20000000
3433 #define CERT_NAME_STR_NO_QUOTING_FLAG          0x10000000
3434 #define CERT_NAME_STR_CRLF_FLAG                0x08000000
3435 #define CERT_NAME_STR_COMMA_FLAG               0x04000000
3436 #define CERT_NAME_STR_REVERSE_FLAG             0x02000000
3437 #define CERT_NAME_STR_ENABLE_UTF8_UNICODE_FLAG 0x00040000
3438 #define CERT_NAME_STR_ENABLE_T61_UNICODE_FLAG  0x00020000
3439 #define CERT_NAME_STR_DISABLE_IE4_UTF8_FLAG    0x00010000
3440 
3441 #define CERT_NAME_EMAIL_TYPE            1
3442 #define CERT_NAME_RDN_TYPE              2
3443 #define CERT_NAME_ATTR_TYPE             3
3444 #define CERT_NAME_SIMPLE_DISPLAY_TYPE   4
3445 #define CERT_NAME_FRIENDLY_DISPLAY_TYPE 5
3446 #define CERT_NAME_DNS_TYPE              6
3447 #define CERT_NAME_URL_TYPE              7
3448 #define CERT_NAME_UPN_TYPE              8
3449 
3450 #define CERT_NAME_ISSUER_FLAG           0x00000001
3451 #define CERT_NAME_DISABLE_IE4_UTF8_FLAG 0x00010000
3452 
3453 /* CryptFormatObject flags */
3454 #define CRYPT_FORMAT_STR_MULTI_LINE 0x0001
3455 #define CRYPT_FORMAT_STR_NO_HEX     0x0010
3456 
3457 #define CRYPT_FORMAT_SIMPLE        0x0001
3458 #define CRYPT_FORMAT_X509          0x0002
3459 #define CRYPT_FORMAT_OID           0x0004
3460 #define CRYPT_FORMAT_RDN_SEMICOLON 0x0100
3461 #define CRYPT_FORMAT_RDN_CRLF      0x0200
3462 #define CRYPT_FORMAT_RDN_UNQUOTE   0x0400
3463 #define CRYPT_FORMAT_RDN_REVERSE   0x0800
3464 
3465 #define CRYPT_FORMAT_COMMA     0x1000
3466 #define CRYPT_FORMAT_SEMICOLON CRYPT_FORMAT_RDN_SEMICOLON
3467 #define CRYPT_FORMAT_CRLF      CRYPT_FORMAT_RDN_CRLF
3468 
3469 /* CryptQueryObject types and flags */
3470 #define CERT_QUERY_OBJECT_FILE 1
3471 #define CERT_QUERY_OBJECT_BLOB 2
3472 
3473 #define CERT_QUERY_CONTENT_CERT               1
3474 #define CERT_QUERY_CONTENT_CTL                2
3475 #define CERT_QUERY_CONTENT_CRL                3
3476 #define CERT_QUERY_CONTENT_SERIALIZED_STORE   4
3477 #define CERT_QUERY_CONTENT_SERIALIZED_CERT    5
3478 #define CERT_QUERY_CONTENT_SERIALIZED_CTL     6
3479 #define CERT_QUERY_CONTENT_SERIALIZED_CRL     7
3480 #define CERT_QUERY_CONTENT_PKCS7_SIGNED       8
3481 #define CERT_QUERY_CONTENT_PKCS7_UNSIGNED     9
3482 #define CERT_QUERY_CONTENT_PKCS7_SIGNED_EMBED 10
3483 #define CERT_QUERY_CONTENT_PKCS10             11
3484 #define CERT_QUERY_CONTENT_PFX                12
3485 #define CERT_QUERY_CONTENT_CERT_PAIR          13
3486 
3487 #define CERT_QUERY_CONTENT_FLAG_CERT      (1 << CERT_QUERY_CONTENT_CERT)
3488 #define CERT_QUERY_CONTENT_FLAG_CTL       (1 << CERT_QUERY_CONTENT_CTL)
3489 #define CERT_QUERY_CONTENT_FLAG_CRL       (1 << CERT_QUERY_CONTENT_CRL)
3490 #define CERT_QUERY_CONTENT_FLAG_SERIALIZED_STORE \
3491  (1 << CERT_QUERY_CONTENT_SERIALIZED_STORE)
3492 #define CERT_QUERY_CONTENT_FLAG_SERIALIZED_CERT \
3493  (1 << CERT_QUERY_CONTENT_SERIALIZED_CERT)
3494 #define CERT_QUERY_CONTENT_FLAG_SERIALIZED_CTL \
3495  (1 << CERT_QUERY_CONTENT_SERIALIZED_CTL)
3496 #define CERT_QUERY_CONTENT_FLAG_SERIALIZED_CRL \
3497  (1 << CERT_QUERY_CONTENT_SERIALIZED_CRL)
3498 #define CERT_QUERY_CONTENT_FLAG_PKCS7_SIGNED \
3499  (1 << CERT_QUERY_CONTENT_PKCS7_SIGNED)
3500 #define CERT_QUERY_CONTENT_FLAG_PKCS7_UNSIGNED \
3501  (1 << CERT_QUERY_CONTENT_PKCS7_UNSIGNED)
3502 #define CERT_QUERY_CONTENT_FLAG_PKCS7_SIGNED_EMBED \
3503  (1 << CERT_QUERY_CONTENT_PKCS7_SIGNED_EMBED)
3504 #define CERT_QUERY_CONTENT_FLAG_PKCS10    (1 << CERT_QUERY_CONTENT_PKCS10)
3505 #define CERT_QUERY_CONTENT_FLAG_PFX       (1 << CERT_QUERY_CONTENT_PFX)
3506 #define CERT_QUERY_CONTENT_FLAG_CERT_PAIR (1 << CERT_QUERY_CONTENT_CERT_PAIR)
3507 
3508 #define CERT_QUERY_CONTENT_FLAG_ALL \
3509  CERT_QUERY_CONTENT_FLAG_CERT | \
3510  CERT_QUERY_CONTENT_FLAG_CTL | \
3511  CERT_QUERY_CONTENT_FLAG_CRL | \
3512  CERT_QUERY_CONTENT_FLAG_SERIALIZED_STORE | \
3513  CERT_QUERY_CONTENT_FLAG_SERIALIZED_CERT | \
3514  CERT_QUERY_CONTENT_FLAG_SERIALIZED_CTL | \
3515  CERT_QUERY_CONTENT_FLAG_SERIALIZED_CRL | \
3516  CERT_QUERY_CONTENT_FLAG_PKCS7_SIGNED | \
3517  CERT_QUERY_CONTENT_FLAG_PKCS7_UNSIGNED | \
3518  CERT_QUERY_CONTENT_FLAG_PKCS7_SIGNED_EMBED | \
3519  CERT_QUERY_CONTENT_FLAG_PKCS10 | \
3520  CERT_QUERY_CONTENT_FLAG_PFX | \
3521  CERT_QUERY_CONTENT_FLAG_CERT_PAIR
3522 
3523 #define CERT_QUERY_FORMAT_BINARY                1
3524 #define CERT_QUERY_FORMAT_BASE64_ENCODED        2
3525 #define CERT_QUERY_FORMAT_ASN_ASCII_HEX_ENCODED 3
3526 
3527 #define CERT_QUERY_FORMAT_FLAG_BINARY (1 << CERT_QUERY_FORMAT_BINARY)
3528 #define CERT_QUERY_FORMAT_FLAG_BASE64_ENCODED \
3529  (1 << CERT_QUERY_FORMAT_BASE64_ENCODED)
3530 #define CERT_QUERY_FORMAT_FLAG_ASN_ASCII_HEX_ENCODED \
3531  (1 << CERT_QUERY_FORMAT_ASN_ASCII_HEX_ENCODED)
3532 
3533 #define CERT_QUERY_FORMAT_FLAG_ALL \
3534  CERT_QUERY_FORMAT_FLAG_BINARY | \
3535  CERT_QUERY_FORMAT_FLAG_BASE64_ENCODED | \
3536  CERT_QUERY_FORMAT_FLAG_ASN_ASCII_HEX_ENCODED \
3537 
3538 #define CERT_SET_KEY_PROV_HANDLE_PROP_ID 0x00000001
3539 #define CERT_SET_KEY_CONTEXT_PROP_ID     0x00000001
3540 
3541 #define CERT_CREATE_SELFSIGN_NO_SIGN     1
3542 #define CERT_CREATE_SELFSIGN_NO_KEY_INFO 2
3543 
3544 /* flags for CryptAcquireCertificatePrivateKey */
3545 #define CRYPT_ACQUIRE_CACHE_FLAG         0x00000001
3546 #define CRYPT_ACQUIRE_USE_PROV_INFO_FLAG 0x00000002
3547 #define CRYPT_ACQUIRE_COMPARE_KEY_FLAG   0x00000004
3548 #define CRYPT_ACQUIRE_SILENT_FLAG        0x00000040
3549 
3550 /* flags for CryptFindCertificateKeyProvInfo */
3551 #define CRYPT_FIND_USER_KEYSET_FLAG    0x00000001
3552 #define CRYPT_FIND_MACHINE_KEYSET_FLAG 0x00000002
3553 #define CRYPT_FIND_SILENT_KEYSET_FLAG  0x00000040
3554 
3555 /* Chain engines and chains */
3556 typedef HANDLE HCERTCHAINENGINE;
3557 #define HCCE_CURRENT_USER  ((HCERTCHAINENGINE)NULL)
3558 #define HCCE_LOCAL_MACHINE ((HCERTCHAINENGINE)1)
3559 
3560 #define CERT_CHAIN_CACHE_END_CERT           0x00000001
3561 #define CERT_CHAIN_THREAD_STORE_SYNC        0x00000002
3562 #define CERT_CHAIN_CACHE_ONLY_URL_RETRIEVAL 0x00000004
3563 #define CERT_CHAIN_USE_LOCAL_MACHINE_STORE  0x00000008
3564 #define CERT_CHAIN_ENABLE_CACHE_AUTO_UPDATE 0x00000010
3565 #define CERT_CHAIN_ENABLE_SHARE_STORE       0x00000020
3566 
3567 typedef struct _CERT_CHAIN_ENGINE_CONFIG
3568 {
3569     DWORD       cbSize;
3570     HCERTSTORE  hRestrictedRoot;
3571     HCERTSTORE  hRestrictedTrust;
3572     HCERTSTORE  hRestrictedOther;
3573     DWORD       cAdditionalStore;
3574     HCERTSTORE *rghAdditionalStore;
3575     DWORD       dwFlags;
3576     DWORD       dwUrlRetrievalTimeout;
3577     DWORD       MaximumCachedCertificates;
3578     DWORD       CycleDetectionModulus;
3579     HCERTSTORE  hExclusiveRoot;
3580     HCERTSTORE  hExclusiveRootTrustedPeople;
3581 } CERT_CHAIN_ENGINE_CONFIG, *PCERT_CHAIN_ENGINE_CONFIG;
3582 
3583 /* message-related definitions */
3584 
3585 typedef BOOL
3586 (WINAPI *PFN_CMSG_STREAM_OUTPUT)(
3587   _In_opt_ const void *pvArg,
3588   _In_reads_bytes_opt_(cbData) BYTE *pbData,
3589   _In_ DWORD cbData,
3590   _In_ BOOL fFinal);
3591 
3592 #define CMSG_INDEFINITE_LENGTH 0xffffffff
3593 
3594 typedef struct _CMSG_STREAM_INFO
3595 {
3596     DWORD cbContent;
3597     PFN_CMSG_STREAM_OUTPUT pfnStreamOutput;
3598     void *pvArg;
3599 } CMSG_STREAM_INFO, *PCMSG_STREAM_INFO;
3600 
3601 typedef struct _CERT_ISSUER_SERIAL_NUMBER
3602 {
3603     CERT_NAME_BLOB     Issuer;
3604     CRYPT_INTEGER_BLOB SerialNumber;
3605 } CERT_ISSUER_SERIAL_NUMBER, *PCERT_ISSUER_SERIAL_NUMBER;
3606 
3607 typedef struct _CERT_ID
3608 {
3609     DWORD dwIdChoice;
3610     union {
3611         CERT_ISSUER_SERIAL_NUMBER IssuerSerialNumber;
3612         CRYPT_HASH_BLOB           KeyId;
3613         CRYPT_HASH_BLOB           HashId;
3614     } DUMMYUNIONNAME;
3615 } CERT_ID, *PCERT_ID;
3616 
3617 #define CERT_ID_ISSUER_SERIAL_NUMBER 1
3618 #define CERT_ID_KEY_IDENTIFIER       2
3619 #define CERT_ID_SHA1_HASH            3
3620 
3621 #ifndef USE_WC_PREFIX
3622 #undef CMSG_DATA /* may be defined by sys/socket.h */
3623 #define CMSG_DATA                 1
3624 #define CMSG_SIGNED               2
3625 #define CMSG_ENVELOPED            3
3626 #define CMSG_SIGNED_AND_ENVELOPED 4
3627 #define CMSG_HASHED               5
3628 #define CMSG_ENCRYPTED            6
3629 
3630 #define CMSG_ALL_FLAGS                 ~0U
3631 #define CMSG_DATA_FLAG                 (1 << CMSG_DATA)
3632 #define CMSG_SIGNED_FLAG               (1 << CMSG_SIGNED)
3633 #define CMSG_ENVELOPED_FLAG            (1 << CMSG_ENVELOPED)
3634 #define CMSG_SIGNED_AND_ENVELOPED_FLAG (1 << CMSG_SIGNED_AND_ENVELOPED)
3635 #define CMSG_ENCRYPTED_FLAG            (1 << CMSG_ENCRYPTED)
3636 #else
3637 #define WC_CMSG_DATA                 1
3638 #define WC_CMSG_SIGNED               2
3639 #define WC_CMSG_ENVELOPED            3
3640 #define WC_CMSG_SIGNED_AND_ENVELOPED 4
3641 #define WC_CMSG_HASHED               5
3642 #define WC_CMSG_ENCRYPTED            6
3643 
3644 #define WC_CMSG_ALL_FLAGS                 ~0U
3645 #define WC_CMSG_DATA_FLAG                 (1 << WC_CMSG_DATA)
3646 #define WC_CMSG_SIGNED_FLAG               (1 << WC_CMSG_SIGNED)
3647 #define WC_CMSG_ENVELOPED_FLAG            (1 << WC_CMSG_ENVELOPED)
3648 #define WC_CMSG_SIGNED_AND_ENVELOPED_FLAG (1 << WC_CMSG_SIGNED_AND_ENVELOPED)
3649 #define WC_CMSG_ENCRYPTED_FLAG            (1 << WC_CMSG_ENCRYPTED)
3650 #endif
3651 
3652 typedef struct _CMSG_SIGNER_ENCODE_INFO
3653 {
3654     DWORD                      cbSize;
3655     PCERT_INFO                 pCertInfo;
3656     HCRYPTPROV                 hCryptProv;
3657     DWORD                      dwKeySpec;
3658     CRYPT_ALGORITHM_IDENTIFIER HashAlgorithm;
3659     void                      *pvHashAuxInfo;
3660     DWORD                      cAuthAttr;
3661     PCRYPT_ATTRIBUTE           rgAuthAttr;
3662     DWORD                      cUnauthAttr;
3663     PCRYPT_ATTRIBUTE           rgUnauthAttr;
3664 #ifdef CMSG_SIGNER_ENCODE_INFO_HAS_CMS_FIELDS
3665     CERT_ID                    SignerId;
3666     CRYPT_ALGORITHM_IDENTIFIER HashEncryptionAlgorithm;
3667     void                      *pvHashEncryptionAuxInfo;
3668 #endif
3669 } CMSG_SIGNER_ENCODE_INFO, *PCMSG_SIGNER_ENCODE_INFO;
3670 
3671 typedef struct _CMSG_SIGNED_ENCODE_INFO
3672 {
3673     DWORD                    cbSize;
3674     DWORD                    cSigners;
3675     PCMSG_SIGNER_ENCODE_INFO rgSigners;
3676     DWORD                    cCertEncoded;
3677     PCERT_BLOB               rgCertEncoded;
3678     DWORD                    cCrlEncoded;
3679     PCRL_BLOB                rgCrlEncoded;
3680 #ifdef CMSG_SIGNED_ENCODE_INFO_HAS_CMS_FIELDS
3681     DWORD                    cAttrCertEncoded;
3682     PCERT_BLOB               rgAttrCertEncoded;
3683 #endif
3684 } CMSG_SIGNED_ENCODE_INFO, *PCMSG_SIGNED_ENCODE_INFO;
3685 
3686 typedef struct _CMSG_KEY_TRANS_RECIPIENT_ENCODE_INFO
3687 {
3688     DWORD                      cbSize;
3689     CRYPT_ALGORITHM_IDENTIFIER KeyEncryptionAlgorithm;
3690     void                      *pvKeyEncryptionAuxInfo;
3691     HCRYPTPROV_LEGACY          hCryptProv;
3692     CRYPT_BIT_BLOB             RecipientPublicKey;
3693     CERT_ID                    RecipientId;
3694 } CMSG_KEY_TRANS_RECIPIENT_ENCODE_INFO, *PCMSG_KEY_TRANS_RECIPIENT_ENCODE_INFO;
3695 
3696 typedef struct _CMSG_RECIPIENT_ENCRYPTED_KEY_ENCODE_INFO
3697 {
3698     DWORD                       cbSize;
3699     CRYPT_BIT_BLOB              RecipientPublicKey;
3700     CERT_ID                     RecipientId;
3701     FILETIME                    Date;
3702     PCRYPT_ATTRIBUTE_TYPE_VALUE pOtherAttr;
3703 } CMSG_RECIPIENT_ENCRYPTED_KEY_ENCODE_INFO,
3704  *PCMSG_RECIPIENT_ENCRYPTED_KEY_ENCODE_INFO;
3705 
3706 typedef struct _CMSG_KEY_AGREE_RECIPIENT_ENCODE_INFO
3707 {
3708     DWORD                      cbSize;
3709     CRYPT_ALGORITHM_IDENTIFIER KeyEncryptionAlgorithm;
3710     void                      *pvKeyEncryptionAuxInfo;
3711     CRYPT_ALGORITHM_IDENTIFIER KeyWrapAlgorithm;
3712     void                      *pvKeyWrapAuxInfo;
3713     HCRYPTPROV_LEGACY          hCryptProv;
3714     DWORD                      dwKeySpec;
3715     DWORD                      dwKeyChoice;
3716     union {
3717         PCRYPT_ALGORITHM_IDENTIFIER pEphemeralAlgorithm;
3718         PCERT_ID                    pSenderId;
3719     } DUMMYUNIONNAME;
3720     CRYPT_DATA_BLOB            UserKeyingMaterial;
3721     DWORD                      cRecipientEncryptedKeys;
3722     PCMSG_RECIPIENT_ENCRYPTED_KEY_ENCODE_INFO *rgpRecipientEncryptedKeys;
3723 } CMSG_KEY_AGREE_RECIPIENT_ENCODE_INFO, *PCMSG_KEY_AGREE_RECIPIENT_ENCODE_INFO;
3724 
3725 #define CMSG_KEY_AGREE_EPHEMERAL_KEY_CHOICE 1
3726 #define CMSG_KEY_AGREE_STATIC_KEY_CHOICE    2
3727 
3728 typedef struct _CMSG_MAIL_LIST_RECIPIENT_ENCODE_INFO
3729 {
3730     DWORD                       cbSize;
3731     CRYPT_ALGORITHM_IDENTIFIER  KeyEncryptionAlgorithm;
3732     void                       *pvKeyEncryptionAuxInfo;
3733     HCRYPTPROV                  hCryptProv;
3734     DWORD                       dwKeyChoice;
3735     union {
3736         HCRYPTKEY hKeyEncryptionKey;
3737         void     *pvKeyEncryptionKey;
3738     } DUMMYUNIONNAME;
3739     CRYPT_DATA_BLOB             KeyId;
3740     FILETIME                    Date;
3741     PCRYPT_ATTRIBUTE_TYPE_VALUE pOtherAttr;
3742 } CMSG_MAIL_LIST_RECIPIENT_ENCODE_INFO, *PCMSG_MAIL_LIST_RECIPIENT_ENCODE_INFO;
3743 
3744 #define CMSG_MAIL_LIST_HANDLE_KEY_CHOICE 1
3745 
3746 typedef struct _CMSG_RECIPIENT_ENCODE_INFO
3747 {
3748     DWORD dwRecipientChoice;
3749     union {
3750         PCMSG_KEY_TRANS_RECIPIENT_ENCODE_INFO pKeyTrans;
3751         PCMSG_KEY_AGREE_RECIPIENT_ENCODE_INFO pKeyAgree;
3752         PCMSG_MAIL_LIST_RECIPIENT_ENCODE_INFO pMailList;
3753     } DUMMYUNIONNAME;
3754 } CMSG_RECIPIENT_ENCODE_INFO, *PCMSG_RECIPIENT_ENCODE_INFO;
3755 
3756 #define CMSG_KEY_TRANS_RECIPIENT 1
3757 #define CMSG_KEY_AGREE_RECIPIENT 2
3758 #define CMSG_MAIL_LIST_RECIPIENT 3
3759 
3760 typedef struct _CMSG_ENVELOPED_ENCODE_INFO
3761 {
3762     DWORD                       cbSize;
3763     HCRYPTPROV_LEGACY           hCryptProv;
3764     CRYPT_ALGORITHM_IDENTIFIER  ContentEncryptionAlgorithm;
3765     void                       *pvEncryptionAuxInfo;
3766     DWORD                       cRecipients;
3767     PCERT_INFO                 *rgpRecipientCert;
3768 #ifdef CMSG_ENVELOPED_ENCODE_INFO_HAS_CMS_FIELDS
3769     PCMSG_RECIPIENT_ENCODE_INFO rgCmsRecipients;
3770     DWORD                       cCertEncoded;
3771     PCERT_BLOB                  rgCertEncoded;
3772     DWORD                       cCrlEncoded;
3773     PCRL_BLOB                   rgCrlEncoded;
3774     DWORD                       cAttrCertEncoded;
3775     PCERT_BLOB                  rgAttrCertEncoded;
3776     DWORD                       cUnprotectedAttr;
3777     PCRYPT_ATTRIBUTE            rgUnprotectedAttr;
3778 #endif
3779 } CMSG_ENVELOPED_ENCODE_INFO, *PCMSG_ENVELOPED_ENCODE_INFO;
3780 
3781 typedef struct _CMSG_SIGNED_AND_ENVELOPED_ENCODE_INFO
3782 {
3783     DWORD                      cbSize;
3784     CMSG_SIGNED_ENCODE_INFO    SignedInfo;
3785     CMSG_ENVELOPED_ENCODE_INFO EnvelopedInfo;
3786 } CMSG_SIGNED_AND_ENVELOPED_ENCODE_INFO,
3787  *PCMSG_SIGNED_AND_ENVELOPED_ENCODE_INFO;
3788 
3789 typedef struct _CMSG_HASHED_ENCODE_INFO
3790 {
3791     DWORD                      cbSize;
3792     HCRYPTPROV_LEGACY          hCryptProv;
3793     CRYPT_ALGORITHM_IDENTIFIER HashAlgorithm;
3794     void                      *pvHashAuxInfo;
3795 } CMSG_HASHED_ENCODE_INFO, *PCMSG_HASHED_ENCODE_INFO;
3796 
3797 typedef struct _CMSG_ENCRYPTED_ENCODE_INFO
3798 {
3799     DWORD                      cbSize;
3800     CRYPT_ALGORITHM_IDENTIFIER ContentEncryptionAlgorithm;
3801     void                      *pvEncryptionAuxInfo;
3802 } CMSG_ENCRYPTED_ENCODE_INFO, *PCMSG_ENCRYPTED_ENCODE_INFO;
3803 
3804 #define CMSG_BARE_CONTENT_FLAG             0x00000001
3805 #define CMSG_LENGTH_ONLY_FLAG              0x00000002
3806 #define CMSG_DETACHED_FLAG                 0x00000004
3807 #define CMSG_AUTHENTICATED_ATTRIBUTES_FLAG 0x00000008
3808 #define CMSG_CONTENTS_OCTETS_FLAG          0x00000010
3809 #define CMSG_MAX_LENGTH_FLAG               0x00000020
3810 #define CMSG_CMS_ENCAPSULATED_CONTENT_FLAG 0x00000040
3811 #define CMSG_CRYPT_RELEASE_CONTEXT_FLAG    0x00008000
3812 
3813 #define CMSG_CTRL_VERIFY_SIGNATURE       1
3814 #define CMSG_CTRL_DECRYPT                2
3815 #define CMSG_CTRL_VERIFY_HASH            5
3816 #define CMSG_CTRL_ADD_SIGNER             6
3817 #define CMSG_CTRL_DEL_SIGNER             7
3818 #define CMSG_CTRL_ADD_SIGNER_UNAUTH_ATTR 8
3819 #define CMSG_CTRL_DEL_SIGNER_UNAUTH_ATTR 9
3820 #define CMSG_CTRL_ADD_CERT               10
3821 #define CMSG_CTRL_DEL_CERT               11
3822 #define CMSG_CTRL_ADD_CRL                12
3823 #define CMSG_CTRL_DEL_CRL                13
3824 #define CMSG_CTRL_ADD_ATTR_CERT          14
3825 #define CMSG_CTRL_DEL_ATTR_CERT          15
3826 #define CMSG_CTRL_KEY_TRANS_DECRYPT      16
3827 #define CMSG_CTRL_KEY_AGREE_DECRYPT      17
3828 #define CMSG_CTRL_MAIL_LIST_DECRYPT      18
3829 #define CMSG_CTRL_VERIFY_SIGNATURE_EX    19
3830 #define CMSG_CTRL_ADD_CMS_SIGNER_INFO    20
3831 
3832 typedef struct _CMSG_CTRL_DECRYPT_PARA
3833 {
3834     DWORD      cbSize;
3835     HCRYPTPROV hCryptProv;
3836     DWORD      dwKeySpec;
3837     DWORD      dwRecipientIndex;
3838 } CMSG_CTRL_DECRYPT_PARA, *PCMSG_CTRL_DECRYPT_PARA;
3839 
3840 typedef struct _CMSG_CTRL_ADD_SIGNER_UNAUTH_ATTR_PARA
3841 {
3842     DWORD           cbSize;
3843     DWORD           dwSignerIndex;
3844     CRYPT_DATA_BLOB blob;
3845 } CMSG_CTRL_ADD_SIGNER_UNAUTH_ATTR_PARA,
3846  *PCMSG_CTRL_ADD_SIGNER_UNAUTH_ATTR_PARA;
3847 
3848 typedef struct _CMSG_CTRL_DEL_SIGNER_UNAUTH_ATTR_PARA
3849 {
3850     DWORD           cbSize;
3851     DWORD           dwSignerIndex;
3852     DWORD           dwUnauthAttrIndex;
3853 } CMSG_CTRL_DEL_SIGNER_UNAUTH_ATTR_PARA,
3854  *PCMSG_CTRL_DEL_SIGNER_UNAUTH_ATTR_PARA;
3855 
3856 typedef struct _CMSG_CTRL_VERIFY_SIGNATURE_EX_PARA {
3857     DWORD      cbSize;
3858     HCRYPTPROV hCryptProv;
3859     DWORD      dwSignerIndex;
3860     DWORD      dwSignerType;
3861     void      *pvSigner;
3862 } CMSG_CTRL_VERIFY_SIGNATURE_EX_PARA, *PCMSG_CTRL_VERIFY_SIGNATURE_EX_PARA;
3863 
3864 #define CMSG_VERIFY_SIGNER_PUBKEY 1
3865 #define CMSG_VERIFY_SIGNER_CERT   2
3866 #define CMSG_VERIFY_SIGNER_CHAIN  3
3867 #define CMSG_VERIFY_SIGNER_NULL   4
3868 
3869 #define CMSG_TYPE_PARAM                  1
3870 #define CMSG_CONTENT_PARAM               2
3871 #define CMSG_BARE_CONTENT_PARAM          3
3872 #define CMSG_INNER_CONTENT_TYPE_PARAM    4
3873 #define CMSG_SIGNER_COUNT_PARAM          5
3874 #define CMSG_SIGNER_INFO_PARAM           6
3875 #define CMSG_SIGNER_CERT_INFO_PARAM      7
3876 #define CMSG_SIGNER_HASH_ALGORITHM_PARAM 8
3877 #define CMSG_SIGNER_AUTH_ATTR_PARAM      9
3878 #define CMSG_SIGNER_UNAUTH_ATTR_PARAM    10
3879 #define CMSG_CERT_COUNT_PARAM            11
3880 #define CMSG_CERT_PARAM                  12
3881 #define CMSG_CRL_COUNT_PARAM             13
3882 #define CMSG_CRL_PARAM                   14
3883 #define CMSG_ENVELOPE_ALGORITHM_PARAM    15
3884 #define CMSG_RECIPIENT_COUNT_PARAM       17
3885 #define CMSG_RECIPIENT_INDEX_PARAM       18
3886 #define CMSG_RECIPIENT_INFO_PARAM        19
3887 #define CMSG_HASH_ALGORITHM_PARAM        20
3888 #define CMSG_HASH_DATA_PARAM             21
3889 #define CMSG_COMPUTED_HASH_PARAM         22
3890 #define CMSG_ENCRYPT_PARAM               26
3891 #define CMSG_ENCRYPTED_DIGEST            27
3892 #define CMSG_ENCODED_SIGNER              28
3893 #define CMSG_ENCODED_MESSAGE             29
3894 #define CMSG_VERSION_PARAM               30
3895 #define CMSG_ATTR_CERT_COUNT_PARAM       31
3896 #define CMSG_ATTR_CERT_PARAM             32
3897 #define CMSG_CMS_RECIPIENT_COUNT_PARAM   33
3898 #define CMSG_CMS_RECIPIENT_INDEX_PARAM   34
3899 #define CMSG_CMS_RECIPIENT_ENCRYPTED_KEY_INDEX_PARAM 35
3900 #define CMSG_CMS_RECIPIENT_INFO_PARAM    36
3901 #define CMSG_UNPROTECTED_ATTR_PARAM      37
3902 #define CMSG_SIGNER_CERT_ID_PARAM        38
3903 #define CMSG_CMS_SIGNER_INFO_PARAM       39
3904 
3905 typedef struct _CMSG_CMS_SIGNER_INFO {
3906     DWORD                      dwVersion;
3907     CERT_ID                    SignerId;
3908     CRYPT_ALGORITHM_IDENTIFIER HashAlgorithm;
3909     CRYPT_ALGORITHM_IDENTIFIER HashEncryptionAlgorithm;
3910     CRYPT_DATA_BLOB            EncryptedHash;
3911     CRYPT_ATTRIBUTES           AuthAttrs;
3912     CRYPT_ATTRIBUTES           UnauthAttrs;
3913 } CMSG_CMS_SIGNER_INFO, *PCMSG_CMS_SIGNER_INFO;
3914 
3915 typedef CRYPT_ATTRIBUTES CMSG_ATTR, *PCMSG_ATTR;
3916 
3917 #define CMSG_SIGNED_DATA_V1               1
3918 #define CMSG_SIGNED_DATA_V3               3
3919 #define CMSG_SIGNED_DATA_PKCS_1_5_VERSION CMSG_SIGNED_DATA_V1
3920 #define CMSG_SIGNED_DATA_CMS_VERSION      CMSG_SIGNED_DATA_V3
3921 
3922 #define CMSG_SIGNER_INFO_V1               1
3923 #define CMSG_SIGNER_INFO_V3               3
3924 #define CMSG_SIGNER_INFO_PKCS_1_5_VERSION CMSG_SIGNER_INFO_V1
3925 #define CMSG_SIGNER_INFO_CMS_VERSION      CMSG_SIGNER_INFO_V3
3926 
3927 #define CMSG_HASHED_DATA_V0               0
3928 #define CMSG_HASHED_DATA_V2               2
3929 #define CMSG_HASHED_DATA_PKCS_1_5_VERSION CMSG_HASHED_DATA_V0
3930 #define CMSG_HASHED_DATA_CMS_VERSION      CMSG_HASHED_DATA_V2
3931 
3932 #define CMSG_ENVELOPED_DATA_V0               0
3933 #define CMSG_ENVELOPED_DATA_V2               2
3934 #define CMSG_ENVELOPED_DATA_PKCS_1_5_VERSION CMSG_ENVELOPED_DATA_V0
3935 #define CMSG_ENVELOPED_DATA_CMS_VERSION      CMSG_ENVELOPED_DATA_V2
3936 
3937 typedef struct _CMSG_KEY_TRANS_RECIPIENT_INFO {
3938     DWORD                      dwVersion;
3939     CERT_ID                    RecipientId;
3940     CRYPT_ALGORITHM_IDENTIFIER KeyEncryptionAlgorithm;
3941     CRYPT_DATA_BLOB            EncryptedKey;
3942 } CMSG_KEY_TRANS_RECIPIENT_INFO, *PCMSG_KEY_TRANS_RECIPIENT_INFO;
3943 
3944 typedef struct _CMSG_RECIPIENT_ENCRYPTED_KEY_INFO {
3945     CERT_ID                     RecipientId;
3946     CRYPT_DATA_BLOB             EncryptedKey;
3947     PCRYPT_ATTRIBUTE_TYPE_VALUE pOtherAttr;
3948 } CMSG_RECIPIENT_ENCRYPTED_KEY_INFO, *PCMSG_RECIPIENT_ENCRYPTED_KEY_INFO;
3949 
3950 typedef struct _CMSG_KEY_AGREE_RECIPIENT_INFO {
3951     DWORD                               dwVersion;
3952     DWORD                               dwOriginatorChoice;
3953     union {
3954         CERT_ID              OriginatorCertId;
3955         CERT_PUBLIC_KEY_INFO OriginatorPublicKeyInfo;
3956     } DUMMYUNIONNAME;
3957     CRYPT_ALGORITHM_IDENTIFIER          UserKeyingMaterial;
3958     DWORD                               cRecipientEncryptedKeys;
3959     PCMSG_RECIPIENT_ENCRYPTED_KEY_INFO *rgpRecipientEncryptedKeys;
3960 } CMSG_KEY_AGREE_RECIPIENT_INFO, *PCMSG_KEY_AGREE_RECIPIENT_INFO;
3961 
3962 #define CMSG_KEY_AGREE_ORIGINATOR_CERT       1
3963 #define CMSG_KEY_AGREE_ORIGINATOR_PUBLIC_KEY 2
3964 
3965 typedef struct _CMSG_MAIL_LIST_RECIPIENT_INFO {
3966     DWORD                       dwVersion;
3967     CRYPT_DATA_BLOB             KeyId;
3968     CRYPT_ALGORITHM_IDENTIFIER  KeyEncryptionAlgorithm;
3969     CRYPT_DATA_BLOB             EncryptedKey;
3970     FILETIME                    Date;
3971     PCRYPT_ATTRIBUTE_TYPE_VALUE pOtherAttr;
3972 } CMSG_MAIL_LIST_RECIPIENT_INFO, *PCMSG_MAIL_LIST_RECIPIENT_INFO;
3973 
3974 typedef struct _CMSG_CMS_RECIPIENT_INFO {
3975     DWORD dwRecipientChoice;
3976     union {
3977         PCMSG_KEY_TRANS_RECIPIENT_INFO pKeyTrans;
3978         PCMSG_KEY_AGREE_RECIPIENT_INFO pKeyAgree;
3979         PCMSG_MAIL_LIST_RECIPIENT_INFO pMailList;
3980     } DUMMYUNIONNAME;
3981 } CMSG_CMS_RECIPIENT_INFO, *PCMSG_CMS_RECIPIENT_INFO;
3982 
3983 #define CMSG_ENVELOPED_RECIPIENT_V0     0
3984 #define CMSG_ENVELOPED_RECIPIENT_V2     2
3985 #define CMSG_ENVELOPED_RECIPIENT_V3     3
3986 #define CMSG_ENVELOPED_RECIPIENT_V4     4
3987 #define CMSG_KEY_TRANS_PKCS_1_5_VERSION CMSG_ENVELOPED_RECIPIENT_V0
3988 #define CMSG_KEY_TRANS_CMS_VERSION      CMSG_ENVELOPED_RECIPIENT_V2
3989 #define CMSG_KEY_AGREE_VERSION          CMSG_ENVELOPED_RECIPIENT_V3
3990 #define CMSG_MAIL_LIST_VERSION          CMSG_ENVELOPED_RECIPIENT_V4
3991 
3992 typedef void * (WINAPI *PFN_CMSG_ALLOC)(_In_ size_t cb);
3993 typedef void (WINAPI *PFN_CMSG_FREE)(_Inout_ void *pv);
3994 
3995 typedef struct _CMSG_CONTENT_ENCRYPT_INFO {
3996     DWORD                       cbSize;
3997     HCRYPTPROV                  hCryptProv;
3998     CRYPT_ALGORITHM_IDENTIFIER  ContentEncryptionAlgorithm;
3999     void                       *pvEncryptionAuxInfo;
4000     DWORD                       cRecipients;
4001     PCMSG_RECIPIENT_ENCODE_INFO rgCmsRecipients;
4002     PFN_CMSG_ALLOC              pfnAlloc;
4003     PFN_CMSG_FREE               pfnFree;
4004     DWORD                       dwEncryptFlags;
4005     HCRYPTKEY                   hContentEncryptKey;
4006     DWORD                       dwFlags;
4007 } CMSG_CONTENT_ENCRYPT_INFO, *PCMSG_CONTENT_ENCRYPT_INFO;
4008 
4009 typedef struct _CMSG_KEY_TRANS_ENCRYPT_INFO {
4010     DWORD                       cbSize;
4011     DWORD                       dwRecipientIndex;
4012     CRYPT_ALGORITHM_IDENTIFIER  KeyEncryptionAlgorithm;
4013     CRYPT_DATA_BLOB             EncryptedKey;
4014     DWORD                       dwFlags;
4015 } CMSG_KEY_TRANS_ENCRYPT_INFO, *PCMSG_KEY_TRANS_ENCRYPT_INFO;
4016 
4017 typedef struct _CMSG_CTRL_KEY_TRANS_DECRYPT_PARA {
4018     DWORD                          cbSize;
4019     HCRYPTPROV                     hCryptProv;
4020     DWORD                          dwKeySpec;
4021     PCMSG_KEY_TRANS_RECIPIENT_INFO pKeyTrans;
4022     DWORD                          dwRecipientIndex;
4023 } CMSG_CTRL_KEY_TRANS_DECRYPT_PARA, *PCMSG_CTRL_KEY_TRANS_DECRYPT_PARA;
4024 
4025 typedef struct _CERT_STRONG_SIGN_SERIALIZED_INFO {
4026     DWORD    dwFlags;
4027     WCHAR    *pwszCNGSignHashAlgids;
4028     WCHAR    *pwszCNGPubKeyMinBitLengths;
4029 } CERT_STRONG_SIGN_SERIALIZED_INFO, *PCERT_STRONG_SIGN_SERIALIZED_INFO;
4030 
4031 typedef struct _CERT_STRONG_SIGN_PARA {
4032     DWORD    cbSize;
4033     DWORD    dwInfoChoice;
4034     union {
4035         void                               *pvInfo;
4036         CERT_STRONG_SIGN_SERIALIZED_INFO   *pSerializedInfo;
4037         char                               *pszOID;
4038     } DUMMYUNIONNAME;
4039 } CERT_STRONG_SIGN_PARA, *PCERT_STRONG_SIGN_PARA;
4040 
4041 typedef BOOL
4042 (WINAPI *PFN_CMSG_GEN_CONTENT_ENCRYPT_KEY)(
4043   _Inout_ PCMSG_CONTENT_ENCRYPT_INFO pContentEncryptInfo,
4044   _In_ DWORD dwFlags,
4045   _Reserved_ void *pvReserved);
4046 
4047 typedef BOOL
4048 (WINAPI *PFN_CMSG_EXPORT_KEY_TRANS)(
4049   _In_ PCMSG_CONTENT_ENCRYPT_INFO pContentEncryptInfo,
4050   _In_ PCMSG_KEY_TRANS_RECIPIENT_ENCODE_INFO pKeyTransEncodeInfo,
4051   _Inout_ PCMSG_KEY_TRANS_ENCRYPT_INFO pKeyTransEncryptInfo,
4052   _In_ DWORD dwFlags,
4053   _Reserved_ void *pvReserved);
4054 
4055 typedef BOOL
4056 (WINAPI *PFN_CMSG_IMPORT_KEY_TRANS)(
4057   _In_ PCRYPT_ALGORITHM_IDENTIFIER pContentEncryptionAlgorithm,
4058   _In_ PCMSG_CTRL_KEY_TRANS_DECRYPT_PARA pKeyTransDecryptPara,
4059   _In_ DWORD dwFlags,
4060   _Reserved_ void *pvReserved,
4061   _Out_ HCRYPTKEY *phContentEncryptKey);
4062 
4063 /* CryptMsgGetAndVerifySigner flags */
4064 #define CMSG_TRUSTED_SIGNER_FLAG   0x1
4065 #define CMSG_SIGNER_ONLY_FLAG      0x2
4066 #define CMSG_USE_SIGNER_INDEX_FLAG 0x4
4067 
4068 /* CryptMsgSignCTL flags */
4069 #define CMSG_CMS_ENCAPSULATED_CTL_FLAG 0x00008000
4070 
4071 /* CryptMsgEncodeAndSignCTL flags */
4072 #define CMSG_ENCODED_SORTED_CTL_FLAG               0x1
4073 #define CMSG_ENCODE_HASHED_SUBJECT_IDENTIFIER_FLAG 0x2
4074 
4075 /* PFXImportCertStore flags */
4076 #define CRYPT_USER_KEYSET           0x00001000
4077 #define PKCS12_IMPORT_RESERVED_MASK 0xffff0000
4078 /* PFXExportCertStore flags */
4079 #define REPORT_NO_PRIVATE_KEY                 0x00000001
4080 #define REPORT_NOT_ABLE_TO_EXPORT_PRIVATE_KEY 0x00000002
4081 #define EXPORT_PRIVATE_KEYS                   0x00000004
4082 #define PKCS12_EXPORT_RESERVED_MASK           0xffff0000
4083 
4084 #define CRYPT_USERDATA 0x00000001
4085 
4086 /* function declarations */
4087 /* advapi32.dll */
4088 WINADVAPI
4089 BOOL
4090 WINAPI
4091 CryptAcquireContextA(
4092   _Out_ HCRYPTPROV *,
4093   _In_opt_ LPCSTR,
4094   _In_opt_ LPCSTR,
4095   _In_ DWORD,
4096   _In_ DWORD);
4097 
4098 WINADVAPI
4099 BOOL
4100 WINAPI
4101 CryptAcquireContextW(
4102   _Out_ HCRYPTPROV *,
4103   _In_opt_ LPCWSTR,
4104   _In_opt_ LPCWSTR,
4105   _In_ DWORD,
4106   _In_ DWORD);
4107 
4108 #define CryptAcquireContext WINELIB_NAME_AW(CryptAcquireContext)
4109 
4110 WINADVAPI
4111 BOOL
4112 WINAPI
4113 CryptGenRandom(
4114   _In_ HCRYPTPROV hProv,
4115   _In_ DWORD dwLen,
4116   _Inout_updates_bytes_(dwLen) BYTE *pbBuffer);
4117 
4118 WINADVAPI
4119 BOOL
4120 WINAPI
4121 CryptContextAddRef(
4122   _In_ HCRYPTPROV,
4123   _Reserved_ DWORD *,
4124   _In_ DWORD);
4125 
4126 WINADVAPI
4127 BOOL
4128 WINAPI
4129 CryptCreateHash(
4130   _In_ HCRYPTPROV,
4131   _In_ ALG_ID,
4132   _In_ HCRYPTKEY,
4133   _In_ DWORD,
4134   _Out_ HCRYPTHASH *);
4135 
4136 _Success_(return != 0)
4137 WINADVAPI
4138 BOOL
4139 WINAPI
4140 CryptDecrypt(
4141   _In_ HCRYPTKEY hKey,
4142   _In_ HCRYPTHASH hHash,
4143   _In_ BOOL Final,
4144   _In_ DWORD dwFlags,
4145   _Inout_updates_bytes_to_(*pdwDataLen, *pdwDataLen) BYTE *pbData,
4146   _Inout_ DWORD *pdwDataLen);
4147 
4148 WINADVAPI
4149 BOOL
4150 WINAPI
4151 CryptDeriveKey(
4152   _In_ HCRYPTPROV,
4153   _In_ ALG_ID,
4154   _In_ HCRYPTHASH,
4155   _In_ DWORD,
4156   _Out_ HCRYPTKEY *);
4157 
4158 WINADVAPI BOOL WINAPI CryptDestroyHash(_In_ HCRYPTHASH);
4159 WINADVAPI BOOL WINAPI CryptDestroyKey(_In_ HCRYPTKEY);
4160 
4161 WINADVAPI
4162 BOOL
4163 WINAPI
4164 CryptDuplicateKey(
4165   _In_ HCRYPTKEY,
4166   _Reserved_ DWORD *,
4167   _In_ DWORD,
4168   _Out_ HCRYPTKEY *);
4169 
4170 WINADVAPI
4171 BOOL
4172 WINAPI
4173 CryptDuplicateHash(
4174   _In_ HCRYPTHASH,
4175   _Reserved_ DWORD *,
4176   _In_ DWORD,
4177   _Out_ HCRYPTHASH *);
4178 
4179 _Success_(return != 0)
4180 WINADVAPI
4181 BOOL
4182 WINAPI
4183 CryptEncrypt(
4184   _In_ HCRYPTKEY hKey,
4185   _In_ HCRYPTHASH hHash,
4186   _In_ BOOL Final,
4187   _In_ DWORD dwFlags,
4188   _Inout_updates_bytes_to_opt_(dwBufLen, *pdwDataLen) BYTE *pbData,
4189   _Inout_ DWORD *pdwDataLen,
4190   _In_ DWORD dwBufLen);
4191 
4192 _Success_(return != 0)
4193 WINADVAPI
4194 BOOL
4195 WINAPI
4196 CryptEnumProvidersA(
4197   _In_ DWORD dwIndex,
4198   _Reserved_ DWORD *pdwReserved,
4199   _In_ DWORD dwFlags,
4200   _Out_ DWORD *pdwProvType,
4201   _Out_writes_bytes_to_opt_(*pcbProvName, *pcbProvName) LPSTR szProvName,
4202   _Inout_ DWORD *pcbProvName);
4203 
4204 _Success_(return != 0)
4205 WINADVAPI
4206 BOOL
4207 WINAPI
4208 CryptEnumProvidersW(
4209   _In_ DWORD dwIndex,
4210   _Reserved_ DWORD *pdwReserved,
4211   _In_ DWORD dwFlags,
4212   _Out_ DWORD *pdwProvType,
4213   _Out_writes_bytes_to_opt_(*pcbProvName, *pcbProvName) LPWSTR szProvName,
4214   _Inout_ DWORD *pcbProvName);
4215 
4216 #define CryptEnumProviders WINELIB_NAME_AW(CryptEnumProviders)
4217 
4218 _Success_(return != 0)
4219 WINADVAPI
4220 BOOL
4221 WINAPI
4222 CryptEnumProviderTypesA(
4223   _In_ DWORD dwIndex,
4224   _Reserved_ DWORD *pdwReserved,
4225   _In_ DWORD dwFlags,
4226   _Out_ DWORD *pdwProvType,
4227   _Out_writes_bytes_to_opt_(*pcbTypeName, *pcbTypeName) LPSTR szTypeName,
4228   _Inout_ DWORD *pcbTypeName);
4229 
4230 _Success_(return != 0)
4231 WINADVAPI
4232 BOOL
4233 WINAPI
4234 CryptEnumProviderTypesW(
4235   _In_ DWORD dwIndex,
4236   _Reserved_ DWORD *pdwReserved,
4237   _In_ DWORD dwFlags,
4238   _Out_ DWORD *pdwProvType,
4239   _Out_writes_bytes_to_opt_(*pcbTypeName, *pcbTypeName) LPWSTR szTypeName,
4240   _Inout_ DWORD *pcbTypeName);
4241 
4242 #define CryptEnumProviderTypes WINELIB_NAME_AW(CryptEnumProviderTypes)
4243 
4244 WINADVAPI
4245 BOOL
4246 WINAPI
4247 CryptExportKey(
4248   _In_ HCRYPTKEY hKey,
4249   _In_ HCRYPTKEY hExpKey,
4250   _In_ DWORD dwBlobType,
4251   _In_ DWORD dwFlags,
4252   _Out_writes_bytes_to_opt_(*pdwDataLen, *pdwDataLen) BYTE *pbData,
4253   _Inout_ DWORD *pdwDataLen);
4254 
4255 WINADVAPI
4256 BOOL
4257 WINAPI
4258 CryptGenKey(
4259   _In_ HCRYPTPROV,
4260   _In_ ALG_ID,
4261   _In_ DWORD,
4262   _Out_ HCRYPTKEY *);
4263 
4264 WINADVAPI
4265 BOOL
4266 WINAPI
4267 CryptGetKeyParam(
4268   _In_ HCRYPTKEY hKey,
4269   _In_ DWORD dwParam,
4270   _Out_writes_bytes_to_opt_(*pdwDataLen, *pdwDataLen) BYTE *pbData,
4271   _Inout_ DWORD *pdwDataLen,
4272   _In_ DWORD dwFlags);
4273 
4274 WINADVAPI
4275 BOOL
4276 WINAPI
4277 CryptGetHashParam(
4278   _In_ HCRYPTHASH hHash,
4279   _In_ DWORD dwParam,
4280   _Out_writes_bytes_to_opt_(*pdwDataLen, *pdwDataLen) BYTE *pbData,
4281   _Inout_ DWORD *pdwDataLen,
4282   _In_ DWORD dwFlags);
4283 
4284 WINADVAPI
4285 BOOL
4286 WINAPI
4287 CryptGetProvParam(
4288   _In_ HCRYPTPROV hProv,
4289   _In_ DWORD dwParam,
4290   _Out_writes_bytes_to_opt_(*pdwDataLen, *pdwDataLen) BYTE *pbData,
4291   _Inout_ DWORD *pdwDataLen,
4292   _In_ DWORD dwFlags);
4293 
4294 _Success_(return != 0)
4295 WINADVAPI
4296 BOOL
4297 WINAPI
4298 CryptGetDefaultProviderA(
4299   _In_ DWORD dwProvType,
4300   _Reserved_ DWORD *pdwReserved,
4301   _In_ DWORD dwFlags,
4302   _Out_writes_bytes_to_opt_(*pcbProvName, *pcbProvName) LPSTR pszProvName,
4303   _Inout_ DWORD *pcbProvName);
4304 
4305 _Success_(return != 0)
4306 WINADVAPI
4307 BOOL
4308 WINAPI
4309 CryptGetDefaultProviderW(
4310   _In_ DWORD dwProvType,
4311   _Reserved_ DWORD *pdwReserved,
4312   _In_ DWORD dwFlags,
4313   _Out_writes_bytes_to_opt_(*pcbProvName, *pcbProvName) LPWSTR pszProvName,
4314   _Inout_ DWORD *pcbProvName);
4315 
4316 #define CryptGetDefaultProvider WINELIB_NAME_AW(CryptGetDefaultProvider)
4317 
4318 WINADVAPI BOOL WINAPI CryptGetUserKey(_In_ HCRYPTPROV, _In_ DWORD, _Out_ HCRYPTKEY *);
4319 
4320 WINADVAPI
4321 BOOL
4322 WINAPI
4323 CryptHashData(
4324   _In_ HCRYPTHASH hHash,
4325   _In_reads_bytes_(dwDataLen) CONST BYTE *pbData,
4326   _In_ DWORD dwDataLen,
4327   _In_ DWORD dwFlags);
4328 
4329 WINADVAPI BOOL WINAPI CryptHashSessionKey(_In_ HCRYPTHASH, _In_ HCRYPTKEY, _In_ DWORD);
4330 
4331 WINADVAPI
4332 BOOL
4333 WINAPI
4334 CryptImportKey(
4335   _In_ HCRYPTPROV hProv,
4336   _In_reads_bytes_(dwDataLen) CONST BYTE *pbData,
4337   _In_ DWORD dwDataLen,
4338   _In_ HCRYPTKEY hPubKey,
4339   _In_ DWORD dwFlags,
4340   _Out_ HCRYPTKEY *phKey);
4341 
4342 #if (NTDDI_VERSION >= NTDDI_WINXP)
4343 WINADVAPI BOOL WINAPI CryptReleaseContext(_In_ HCRYPTPROV, _In_ DWORD);
4344 #else
4345 WINADVAPI BOOL WINAPI CryptReleaseContext(_In_ HCRYPTPROV, _In_ ULONG_PTR);
4346 #endif
4347 
4348 WINADVAPI
4349 BOOL
4350 WINAPI
4351 CryptSetHashParam(
4352   _In_ HCRYPTHASH,
4353   _In_ DWORD,
4354   _In_ CONST BYTE *,
4355   _In_ DWORD);
4356 
4357 WINADVAPI
4358 BOOL
4359 WINAPI
4360 CryptSetKeyParam(
4361   _In_ HCRYPTKEY,
4362   _In_ DWORD,
4363   _In_ CONST BYTE *,
4364   _In_ DWORD);
4365 
4366 WINADVAPI BOOL WINAPI CryptSetProviderA(_In_ LPCSTR, _In_ DWORD);
4367 WINADVAPI BOOL WINAPI CryptSetProviderW(_In_ LPCWSTR, _In_ DWORD);
4368 
4369 #define CryptSetProvider WINELIB_NAME_AW(CryptSetProvider)
4370 
4371 WINADVAPI
4372 BOOL
4373 WINAPI
4374 CryptSetProviderExA(
4375   _In_ LPCSTR,
4376   _In_ DWORD,
4377   _Reserved_ DWORD *,
4378   _In_ DWORD);
4379 
4380 WINADVAPI
4381 BOOL
4382 WINAPI
4383 CryptSetProviderExW(
4384   _In_ LPCWSTR,
4385   _In_ DWORD,
4386   _Reserved_ DWORD *,
4387   _In_ DWORD);
4388 
4389 #define CryptSetProviderEx WINELIB_NAME_AW(CryptSetProviderEx)
4390 
4391 WINADVAPI BOOL WINAPI CryptSetProvParam(_In_ HCRYPTPROV, _In_ DWORD, _In_ CONST BYTE *, _In_ DWORD);
4392 
4393 WINADVAPI
4394 BOOL
4395 WINAPI
4396 CryptSignHashA(
4397   _In_ HCRYPTHASH hHash,
4398   _In_ DWORD dwKeySpec,
4399   _In_opt_ LPCSTR szDescription,
4400   _In_ DWORD dwFlags,
4401   _Out_writes_bytes_to_opt_(*pdwSigLen, *pdwSigLen) BYTE *pbSignature,
4402   _Inout_ DWORD *pdwSigLen);
4403 
4404 WINADVAPI
4405 BOOL
4406 WINAPI
4407 CryptSignHashW(
4408   _In_ HCRYPTHASH hHash,
4409   _In_ DWORD dwKeySpec,
4410   _In_opt_ LPCWSTR szDescription,
4411   _In_ DWORD dwFlags,
4412   _Out_writes_bytes_to_opt_(*pdwSigLen, *pdwSigLen) BYTE *pbSignature,
4413   _Inout_ DWORD *pdwSigLen);
4414 
4415 #define CryptSignHash WINELIB_NAME_AW(CryptSignHash)
4416 
4417 WINADVAPI
4418 BOOL
4419 WINAPI
4420 CryptVerifySignatureA(
4421   _In_ HCRYPTHASH hHash,
4422   _In_reads_bytes_(dwSigLen) CONST BYTE *pbSignature,
4423   _In_ DWORD dwSigLen,
4424   _In_ HCRYPTKEY hPubKey,
4425   _In_opt_ LPCSTR szDescription,
4426   _In_ DWORD dwFlags);
4427 
4428 WINADVAPI
4429 BOOL
4430 WINAPI
4431 CryptVerifySignatureW(
4432   _In_ HCRYPTHASH hHash,
4433   _In_reads_bytes_(dwSigLen) CONST BYTE *pbSignature,
4434   _In_ DWORD dwSigLen,
4435   _In_ HCRYPTKEY hPubKey,
4436   _In_opt_ LPCWSTR szDescription,
4437   _In_ DWORD dwFlags);
4438 
4439 #define CryptVerifySignature WINELIB_NAME_AW(CryptVerifySignature)
4440 
4441 /* crypt32.dll functions */
4442 LPVOID WINAPI CryptMemAlloc(_In_ ULONG cbSize) __WINE_ALLOC_SIZE(1);
4443 LPVOID WINAPI CryptMemRealloc(_In_opt_ LPVOID pv, _In_ ULONG cbSize) __WINE_ALLOC_SIZE(2);
4444 VOID   WINAPI CryptMemFree(_In_opt_ LPVOID pv);
4445 
4446 _Success_(return != 0)
4447 BOOL
4448 WINAPI
4449 CryptBinaryToStringA(
4450   _In_reads_bytes_(cbBinary) const BYTE *pbBinary,
4451   _In_ DWORD cbBinary,
4452   _In_ DWORD dwFlags,
4453   _Out_writes_to_opt_(*pcchString, *pcchString) LPSTR pszString,
4454   _Inout_ DWORD *pcchString);
4455 
4456 _Success_(return != 0)
4457 BOOL
4458 WINAPI
4459 CryptBinaryToStringW(
4460   _In_reads_bytes_(cbBinary) const BYTE *pbBinary,
4461   _In_ DWORD cbBinary,
4462   _In_ DWORD dwFlags,
4463   _Out_writes_to_opt_(*pcchString, *pcchString) LPWSTR pszString,
4464   _Inout_ DWORD *pcchString);
4465 
4466 #define CryptBinaryToString WINELIB_NAME_AW(CryptBinaryToString)
4467 
4468 BOOL
4469 WINAPI
4470 CryptStringToBinaryA(
4471   _In_reads_(cchString) LPCSTR pszString,
4472   _In_ DWORD cchString,
4473   _In_ DWORD dwFlags,
4474   _Out_writes_bytes_to_opt_(*pcbBinary, *pcbBinary) BYTE *pbBinary,
4475   _Inout_ DWORD  *pcbBinary,
4476   _Out_opt_ DWORD *pdwSkip,
4477   _Out_opt_ DWORD *pdwFlags);
4478 
4479 BOOL
4480 WINAPI
4481 CryptStringToBinaryW(
4482   _In_reads_(cchString) LPCWSTR pszString,
4483   _In_ DWORD cchString,
4484   _In_ DWORD dwFlags,
4485   _Out_writes_bytes_to_opt_(*pcbBinary, *pcbBinary) BYTE *pbBinary,
4486   _Inout_ DWORD  *pcbBinary,
4487   _Out_opt_ DWORD *pdwSkip,
4488   _Out_opt_ DWORD *pdwFlags);
4489 
4490 #define CryptStringToBinary WINELIB_NAME_AW(CryptStringToBinary)
4491 
4492 BOOL
4493 WINAPI
4494 CryptCreateAsyncHandle(
4495   _In_ DWORD dwFlags,
4496   _Out_ PHCRYPTASYNC phAsync);
4497 
4498 BOOL
4499 WINAPI
4500 CryptSetAsyncParam(
4501   _In_ HCRYPTASYNC hAsync,
4502   _In_ LPSTR pszParamOid,
4503   _In_opt_ LPVOID pvParam,
4504   __callback PFN_CRYPT_ASYNC_PARAM_FREE_FUNC pfnFree);
4505 
4506 BOOL
4507 WINAPI
4508 CryptGetAsyncParam(
4509   _In_ HCRYPTASYNC hAsync,
4510   _In_ LPSTR pszParamOid,
4511   _Outptr_opt_result_maybenull_ LPVOID* ppvParam,
4512   _Outptr_opt_result_maybenull_ __callback PFN_CRYPT_ASYNC_PARAM_FREE_FUNC* ppfnFree);
4513 
4514 BOOL
4515 WINAPI
4516 CryptRegisterDefaultOIDFunction(
4517   _In_ DWORD,
4518   _In_ LPCSTR,
4519   _In_ DWORD,
4520   _In_ LPCWSTR);
4521 
4522 BOOL
4523 WINAPI
4524 CryptRegisterOIDFunction(
4525   _In_ DWORD,
4526   _In_ LPCSTR,
4527   _In_ LPCSTR,
4528   _In_opt_ LPCWSTR,
4529   _In_opt_ LPCSTR);
4530 
4531 BOOL
4532 WINAPI
4533 CryptGetOIDFunctionValue(
4534   _In_ DWORD dwEncodingType,
4535   _In_ LPCSTR pszFuncName,
4536   _In_ LPCSTR pszOID,
4537   _In_opt_ LPCWSTR pwszValueName,
4538   _Out_opt_ DWORD *pdwValueType,
4539   _Out_writes_bytes_to_opt_(*pcbValueData, *pcbValueData) BYTE *pbValueData,
4540   _Inout_opt_ DWORD *pcbValueData);
4541 
4542 BOOL
4543 WINAPI
4544 CryptSetOIDFunctionValue(
4545   _In_ DWORD dwEncodingType,
4546   _In_ LPCSTR pszFuncName,
4547   _In_ LPCSTR pszOID,
4548   _In_opt_ LPCWSTR pwszValueName,
4549   _In_ DWORD dwValueType,
4550   _In_reads_bytes_opt_(cbValueData) const BYTE *pbValueData,
4551   _In_ DWORD cbValueData);
4552 
4553 BOOL WINAPI CryptUnregisterDefaultOIDFunction(_In_ DWORD, _In_ LPCSTR, _In_ LPCWSTR);
4554 BOOL WINAPI CryptUnregisterOIDFunction(_In_ DWORD, _In_ LPCSTR, _In_ LPCSTR);
4555 
4556 BOOL
4557 WINAPI
4558 CryptEnumOIDFunction(
4559   _In_ DWORD dwEncodingType,
4560   _In_opt_ LPCSTR pszFuncName,
4561   _In_opt_ LPCSTR pszOID,
4562   _In_ DWORD dwFlags,
4563   _Inout_opt_ void *pvArg,
4564   __callback PFN_CRYPT_ENUM_OID_FUNC pfnEnumOIDFunc);
4565 
4566 HCRYPTOIDFUNCSET WINAPI CryptInitOIDFunctionSet(_In_ LPCSTR, _In_ DWORD);
4567 
4568 _Success_(return != 0)
4569 BOOL
4570 WINAPI
4571 CryptGetDefaultOIDDllList(
4572   _In_ HCRYPTOIDFUNCSET hFuncSet,
4573   _In_ DWORD dwEncodingType,
4574   _Out_writes_to_opt_(*pcchDllList, *pcchDllList) _Post_ _NullNull_terminated_ WCHAR *pwszDllList,
4575   _Inout_ DWORD *pcchDllList);
4576 
4577 _Success_(return != 0)
4578 BOOL
4579 WINAPI
4580 CryptGetDefaultOIDFunctionAddress(
4581   _In_ HCRYPTOIDFUNCSET hFuncSet,
4582   _In_ DWORD dwEncodingType,
4583   _In_opt_ LPCWSTR pwszDll,
4584   _In_ DWORD dwFlags,
4585   _Outptr_ void **ppvFuncAddr,
4586   _Inout_ HCRYPTOIDFUNCADDR *phFuncAddr);
4587 
4588 _Success_(return != 0)
4589 BOOL
4590 WINAPI
4591 CryptGetOIDFunctionAddress(
4592   _In_ HCRYPTOIDFUNCSET hFuncSet,
4593   _In_ DWORD dwEncodingType,
4594   _In_ LPCSTR pszOID,
4595   _In_ DWORD dwFlags,
4596   _Outptr_ void **ppvFuncAddr,
4597   _Out_ HCRYPTOIDFUNCADDR *phFuncAddr);
4598 
4599 BOOL
4600 WINAPI
4601 CryptFreeOIDFunctionAddress(
4602   _In_ HCRYPTOIDFUNCADDR hFuncAddr,
4603   _In_ DWORD dwFlags);
4604 
4605 BOOL
4606 WINAPI
4607 CryptInstallOIDFunctionAddress(
4608   _In_opt_ HMODULE hModule,
4609   _In_ DWORD dwEncodingType,
4610   _In_ LPCSTR pszFuncName,
4611   _In_ DWORD cFuncEntry,
4612   _In_reads_(cFuncEntry) const CRYPT_OID_FUNC_ENTRY rgFuncEntry[],
4613   _In_ DWORD dwFlags);
4614 
4615 BOOL
4616 WINAPI
4617 CryptInstallDefaultContext(
4618   _In_ HCRYPTPROV hCryptProv,
4619   _In_ DWORD dwDefaultType,
4620   _In_opt_ const void *pvDefaultPara,
4621   _In_ DWORD dwFlags,
4622   _Reserved_ void *pvReserved,
4623   _Out_ HCRYPTDEFAULTCONTEXT *phDefaultContext);
4624 
4625 BOOL
4626 WINAPI
4627 CryptUninstallDefaultContext(
4628   _In_opt_ HCRYPTDEFAULTCONTEXT hDefaultContext,
4629   _In_ DWORD dwFlags,
4630   _Reserved_ void *pvReserved);
4631 
4632 BOOL
4633 WINAPI
4634 CryptEnumOIDInfo(
4635   _In_ DWORD dwGroupId,
4636   _In_ DWORD dwFlags,
4637   _Inout_opt_ void *pvArg,
4638   __callback PFN_CRYPT_ENUM_OID_INFO pfnEnumOIDInfo);
4639 
4640 PCCRYPT_OID_INFO
4641 WINAPI
4642 CryptFindOIDInfo(
4643   _In_ DWORD dwKeyType,
4644   _In_ void *pvKey,
4645   _In_ DWORD dwGroupId);
4646 
4647 BOOL WINAPI CryptRegisterOIDInfo(_In_ PCCRYPT_OID_INFO pInfo, _In_ DWORD dwFlags);
4648 BOOL WINAPI CryptUnregisterOIDInfo(_In_ PCCRYPT_OID_INFO pInfo);
4649 
4650 LPCWSTR WINAPI CryptFindLocalizedName(_In_ LPCWSTR pwszCryptName);
4651 
4652 LPCSTR WINAPI CertAlgIdToOID(_In_ DWORD dwAlgId);
4653 DWORD WINAPI CertOIDToAlgId(_In_ LPCSTR pszObjId);
4654 
4655 /* cert store functions */
4656 _Must_inspect_result_
4657 HCERTSTORE
4658 WINAPI
4659 CertOpenStore(
4660   _In_ LPCSTR lpszStoreProvider,
4661   _In_ DWORD dwEncodingType,
4662   _In_opt_ HCRYPTPROV_LEGACY hCryptProv,
4663   _In_ DWORD dwFlags,
4664   _In_opt_ const void *pvPara);
4665 
4666 HCERTSTORE
4667 WINAPI
4668 CertOpenSystemStoreA(
4669   _In_opt_ HCRYPTPROV_LEGACY hProv,
4670   _In_ LPCSTR szSubsystemProtocol);
4671 
4672 HCERTSTORE
4673 WINAPI
4674 CertOpenSystemStoreW(
4675   _In_opt_ HCRYPTPROV_LEGACY hProv,
4676   _In_ LPCWSTR szSubSystemProtocol);
4677 
4678 #define CertOpenSystemStore WINELIB_NAME_AW(CertOpenSystemStore)
4679 
4680 PCCERT_CONTEXT
4681 WINAPI
4682 CertEnumCertificatesInStore(
4683   _In_ HCERTSTORE hCertStore,
4684   _In_opt_ PCCERT_CONTEXT pPrev);
4685 
4686 PCCRL_CONTEXT
4687 WINAPI
4688 CertEnumCRLsInStore(
4689   _In_ HCERTSTORE hCertStore,
4690   _In_opt_ PCCRL_CONTEXT pPrevCrlContext);
4691 
4692 PCCTL_CONTEXT
4693 WINAPI
4694 CertEnumCTLsInStore(
4695   _In_ HCERTSTORE hCertStore,
4696   _In_opt_ PCCTL_CONTEXT pPrevCtlContext);
4697 
4698 BOOL
4699 WINAPI
4700 CertEnumSystemStoreLocation(
4701   _In_ DWORD dwFlags,
4702   _Inout_opt_ void *pvArg,
4703   __callback PFN_CERT_ENUM_SYSTEM_STORE_LOCATION pfnEnum);
4704 
4705 BOOL
4706 WINAPI
4707 CertEnumSystemStore(
4708   _In_ DWORD dwFlags,
4709   _In_opt_ void *pvSystemStoreLocationPara,
4710   _Inout_opt_ void *pvArg,
4711   __callback PFN_CERT_ENUM_SYSTEM_STORE pfnEnum);
4712 
4713 BOOL
4714 WINAPI
4715 CertEnumPhysicalStore(
4716   _In_ const void *pvSystemStore,
4717   _In_ DWORD dwFlags,
4718   _Inout_opt_ void *pvArg,
4719   __callback PFN_CERT_ENUM_PHYSICAL_STORE pfnEnum);
4720 
4721 BOOL
4722 WINAPI
4723 CertRegisterPhysicalStore(
4724   _In_ const void *pvSystemStore,
4725   _In_ DWORD dwFlags,
4726   _In_ LPCWSTR pwszStoreName,
4727   _In_ PCERT_PHYSICAL_STORE_INFO pStoreInfo,
4728   _Reserved_ void *pvReserved);
4729 
4730 BOOL
4731 WINAPI
4732 CertSaveStore(
4733   _In_ HCERTSTORE hCertStore,
4734   _In_ DWORD dwEncodingType,
4735   _In_ DWORD dwSaveAs,
4736   _In_ DWORD dwSaveTo,
4737   _Inout_ void *pvSaveToPara,
4738   _In_ DWORD dwFlags);
4739 
4740 BOOL
4741 WINAPI
4742 CertAddStoreToCollection(
4743   _In_ HCERTSTORE hCollectionStore,
4744   _In_opt_ HCERTSTORE hSiblingStore,
4745   _In_ DWORD dwUpdateFlags,
4746   _In_ DWORD dwPriority);
4747 
4748 void
4749 WINAPI
4750 CertRemoveStoreFromCollection(
4751   _In_ HCERTSTORE hCollectionStore,
4752   _In_ HCERTSTORE hSiblingStore);
4753 
4754 _Success_(return != 0)
4755 BOOL
4756 WINAPI
4757 CertCreateCertificateChainEngine(
4758   _In_ PCERT_CHAIN_ENGINE_CONFIG pConfig,
4759   _Out_ HCERTCHAINENGINE *phChainEngine);
4760 
4761 BOOL WINAPI CertResyncCertificateChainEngine(_In_opt_ HCERTCHAINENGINE hChainEngine);
4762 
4763 VOID WINAPI CertFreeCertificateChainEngine(_In_opt_ HCERTCHAINENGINE hChainEngine);
4764 
4765 _Success_(return != 0)
4766 BOOL
4767 WINAPI
4768 CertGetCertificateChain(
4769   _In_opt_ HCERTCHAINENGINE hChainEngine,
4770   _In_ PCCERT_CONTEXT pCertContext,
4771   _In_opt_ LPFILETIME pTime,
4772   _In_opt_ HCERTSTORE hAdditionalStore,
4773   _In_ PCERT_CHAIN_PARA pChainPara,
4774   _In_ DWORD dwFlags,
4775   _Reserved_ LPVOID pvReserved,
4776   _Out_ PCCERT_CHAIN_CONTEXT* ppChainContext);
4777 
4778 PCCERT_CHAIN_CONTEXT
4779 WINAPI
4780 CertDuplicateCertificateChain(
4781   _In_ PCCERT_CHAIN_CONTEXT pChainContext);
4782 
4783 VOID WINAPI CertFreeCertificateChain(_In_ PCCERT_CHAIN_CONTEXT pChainContext);
4784 
4785 PCCERT_CHAIN_CONTEXT
4786 WINAPI
4787 CertFindChainInStore(
4788   _In_ HCERTSTORE hCertStore,
4789   _In_ DWORD dwCertEncodingType,
4790   _In_ DWORD dwFindFlags,
4791   _In_ DWORD dwFindType,
4792   _In_opt_ const void *pvFindPara,
4793   _In_opt_ PCCERT_CHAIN_CONTEXT pPrevChainContext);
4794 
4795 BOOL
4796 WINAPI
4797 CertVerifyCertificateChainPolicy(
4798   _In_ LPCSTR pszPolicyOID,
4799   _In_ PCCERT_CHAIN_CONTEXT pChainContext,
4800   _In_ PCERT_CHAIN_POLICY_PARA pPolicyPara,
4801   _Inout_ PCERT_CHAIN_POLICY_STATUS pPolicyStatus);
4802 
4803 DWORD
4804 WINAPI
4805 CertEnumCertificateContextProperties(
4806   _In_ PCCERT_CONTEXT pCertContext,
4807   _In_ DWORD dwPropId);
4808 
4809 BOOL
4810 WINAPI
4811 CertGetCertificateContextProperty(
4812   _In_ PCCERT_CONTEXT pCertContext,
4813   _In_ DWORD dwPropId,
4814   _Out_writes_bytes_to_opt_(*pcbData, *pcbData) void *pvData,
4815   _Inout_ DWORD *pcbData);
4816 
4817 BOOL
4818 WINAPI
4819 CertSetCertificateContextProperty(
4820   _In_ PCCERT_CONTEXT pCertContext,
4821   _In_ DWORD dwPropId,
4822   _In_ DWORD dwFlags,
4823   _In_opt_ const void *pvData);
4824 
4825 DWORD
4826 WINAPI
4827 CertEnumCRLContextProperties(
4828   _In_ PCCRL_CONTEXT pCRLContext,
4829   _In_ DWORD dwPropId);
4830 
4831 BOOL
4832 WINAPI
4833 CertGetCRLContextProperty(
4834   _In_ PCCRL_CONTEXT pCrlContext,
4835   _In_ DWORD dwPropId,
4836   _Out_writes_bytes_to_opt_(*pcbData, *pcbData) void *pvData,
4837   _Inout_ DWORD *pcbData);
4838 
4839 BOOL
4840 WINAPI
4841 CertSetCRLContextProperty(
4842   _In_ PCCRL_CONTEXT pCrlContext,
4843   _In_ DWORD dwPropId,
4844   _In_ DWORD dwFlags,
4845   _In_opt_ const void *pvData);
4846 
4847 DWORD
4848 WINAPI
4849 CertEnumCTLContextProperties(
4850   _In_ PCCTL_CONTEXT pCTLContext,
4851   _In_ DWORD dwPropId);
4852 
4853 BOOL
4854 WINAPI
4855 CertEnumSubjectInSortedCTL(
4856   _In_ PCCTL_CONTEXT pCtlContext,
4857   _Inout_ void **ppvNextSubject,
4858   _Out_opt_ PCRYPT_DER_BLOB pSubjectIdentifier,
4859   _Out_opt_ PCRYPT_DER_BLOB pEncodedAttributes);
4860 
4861 BOOL
4862 WINAPI
4863 CertGetCTLContextProperty(
4864   _In_ PCCTL_CONTEXT pCtlContext,
4865   _In_ DWORD dwPropId,
4866   _Out_writes_bytes_to_opt_(*pcbData, *pcbData) void *pvData,
4867   _Inout_ DWORD *pcbData);
4868 
4869 BOOL
4870 WINAPI
4871 CertSetCTLContextProperty(
4872   _In_ PCCTL_CONTEXT pCtlContext,
4873   _In_ DWORD dwPropId,
4874   _In_ DWORD dwFlags,
4875   _In_opt_ const void *pvData);
4876 
4877 _Success_(return != 0)
4878 BOOL
4879 WINAPI
4880 CertGetStoreProperty(
4881   _In_ HCERTSTORE hCertStore,
4882   _In_ DWORD dwPropId,
4883   _Out_writes_bytes_to_opt_(*pcbData, *pcbData) void *pvData,
4884   _Inout_ DWORD *pcbData);
4885 
4886 BOOL
4887 WINAPI
4888 CertSetStoreProperty(
4889   _In_ HCERTSTORE hCertStore,
4890   _In_ DWORD dwPropId,
4891   _In_ DWORD dwFlags,
4892   _In_opt_ const void *pvData);
4893 
4894 BOOL
4895 WINAPI
4896 CertControlStore(
4897   _In_ HCERTSTORE hCertStore,
4898   _In_ DWORD dwFlags,
4899   _In_ DWORD dwCtrlType,
4900   _In_opt_ void const *pvCtrlPara);
4901 
4902 HCERTSTORE WINAPI CertDuplicateStore(_In_ HCERTSTORE hCertStore);
4903 
4904 BOOL WINAPI CertCloseStore(_In_opt_ HCERTSTORE hCertStore, _In_ DWORD dwFlags);
4905 
4906 BOOL WINAPI CertFreeCertificateContext(_In_opt_ PCCERT_CONTEXT pCertContext);
4907 
4908 BOOL WINAPI CertFreeCRLContext(_In_opt_ PCCRL_CONTEXT pCrlContext);
4909 
4910 BOOL WINAPI CertFreeCTLContext(_In_opt_ PCCTL_CONTEXT pCtlContext);
4911 
4912 _Success_(return != 0)
4913 BOOL
4914 WINAPI
4915 CertAddCertificateContextToStore(
4916   _In_opt_ HCERTSTORE hCertStore,
4917   _In_ PCCERT_CONTEXT pCertContext,
4918   _In_ DWORD dwAddDisposition,
4919   _Outptr_opt_ PCCERT_CONTEXT *ppStoreContext);
4920 
4921 _Success_(return != 0)
4922 BOOL
4923 WINAPI
4924 CertAddCRLContextToStore(
4925   _In_opt_ HCERTSTORE hCertStore,
4926   _In_ PCCRL_CONTEXT pCrlContext,
4927   _In_ DWORD dwAddDisposition,
4928   _Outptr_opt_ PCCRL_CONTEXT *ppStoreContext);
4929 
4930 _Success_(return != 0)
4931 BOOL
4932 WINAPI
4933 CertAddCTLContextToStore(
4934   _In_opt_ HCERTSTORE hCertStore,
4935   _In_ PCCTL_CONTEXT pCtlContext,
4936   _In_ DWORD dwAddDisposition,
4937   _Outptr_opt_ PCCTL_CONTEXT *ppStoreContext);
4938 
4939 _Success_(return != 0)
4940 BOOL
4941 WINAPI
4942 CertAddCertificateLinkToStore(
4943   _In_ HCERTSTORE hCertStore,
4944   _In_ PCCERT_CONTEXT pCertContext,
4945   _In_ DWORD dwAddDisposition,
4946   _Outptr_opt_ PCCERT_CONTEXT *ppStoreContext);
4947 
4948 _Success_(return != 0)
4949 BOOL
4950 WINAPI
4951 CertAddCRLLinkToStore(
4952   _In_ HCERTSTORE hCertStore,
4953   _In_ PCCRL_CONTEXT pCrlContext,
4954   _In_ DWORD dwAddDisposition,
4955   _Outptr_opt_ PCCRL_CONTEXT *ppStoreContext);
4956 
4957 _Success_(return != 0)
4958 BOOL
4959 WINAPI
4960 CertAddCTLLinkToStore(
4961   _In_ HCERTSTORE hCertStore,
4962   _In_ PCCTL_CONTEXT pCtlContext,
4963   _In_ DWORD dwAddDisposition,
4964   _Outptr_opt_ PCCTL_CONTEXT *ppStoreContext);
4965 
4966 _Success_(return != 0)
4967 BOOL
4968 WINAPI
4969 CertAddEncodedCertificateToStore(
4970   _In_opt_ HCERTSTORE hCertStore,
4971   _In_ DWORD dwCertEncodingType,
4972   _In_reads_bytes_(cbCertEncoded) const BYTE *pbCertEncoded,
4973   _In_ DWORD cbCertEncoded,
4974   _In_ DWORD dwAddDisposition,
4975   _Outptr_opt_ PCCERT_CONTEXT *ppCertContext);
4976 
4977 BOOL
4978 WINAPI
4979 CertAddEncodedCertificateToSystemStoreA(
4980   _In_ LPCSTR szCertStoreName,
4981   _In_reads_bytes_(cbCertEncoded) const BYTE *pbCertEncoded,
4982   _In_ DWORD cbCertEncoded);
4983 
4984 BOOL
4985 WINAPI
4986 CertAddEncodedCertificateToSystemStoreW(
4987   _In_ LPCWSTR szCertStoreName,
4988   _In_reads_bytes_(cbCertEncoded) const BYTE *pbCertEncoded,
4989   _In_ DWORD cbCertEncoded);
4990 
4991 #define CertAddEncodedCertificateToSystemStore \
4992  WINELIB_NAME_AW(CertAddEncodedCertificateToSystemStore)
4993 
4994 _Success_(return != 0)
4995 BOOL
4996 WINAPI
4997 CertAddEncodedCRLToStore(
4998   _In_opt_ HCERTSTORE hCertStore,
4999   _In_ DWORD dwCertEncodingType,
5000   _In_reads_bytes_(cbCrlEncoded) const BYTE *pbCrlEncoded,
5001   _In_ DWORD cbCrlEncoded,
5002   _In_ DWORD dwAddDisposition,
5003   _Outptr_opt_ PCCRL_CONTEXT *ppCrlContext);
5004 
5005 _Success_(return != 0)
5006 BOOL
5007 WINAPI
5008 CertAddEncodedCTLToStore(
5009   _In_opt_ HCERTSTORE hCertStore,
5010   _In_ DWORD dwMsgAndCertEncodingType,
5011   _In_reads_bytes_(cbCtlEncoded) const BYTE *pbCtlEncoded,
5012   _In_ DWORD cbCtlEncoded,
5013   _In_ DWORD dwAddDisposition,
5014   _Outptr_opt_ PCCTL_CONTEXT *ppCtlContext);
5015 
5016 _Success_(return != 0)
5017 BOOL
5018 WINAPI
5019 CertAddSerializedElementToStore(
5020   _In_opt_ HCERTSTORE hCertStore,
5021   _In_reads_bytes_(cbElement) const BYTE *pbElement,
5022   _In_ DWORD cbElement,
5023   _In_ DWORD dwAddDisposition,
5024   _In_ DWORD dwFlags,
5025   _In_ DWORD dwContextTypeFlags,
5026   _Out_opt_ DWORD *pdwContextType,
5027   _Outptr_opt_ const void **ppvContext);
5028 
5029 BOOL
5030 WINAPI
5031 CertCompareCertificate(
5032   _In_ DWORD dwCertEncodingType,
5033   _In_ PCERT_INFO pCertId1,
5034   _In_ PCERT_INFO pCertId2);
5035 
5036 BOOL
5037 WINAPI
5038 CertCompareCertificateName(
5039   _In_ DWORD dwCertEncodingType,
5040   _In_ PCERT_NAME_BLOB pCertName1,
5041   _In_ PCERT_NAME_BLOB pCertName2);
5042 
5043 BOOL
5044 WINAPI
5045 CertCompareIntegerBlob(
5046   _In_ PCRYPT_INTEGER_BLOB pInt1,
5047   _In_ PCRYPT_INTEGER_BLOB pInt2);
5048 
5049 BOOL
5050 WINAPI
5051 CertComparePublicKeyInfo(
5052   _In_ DWORD dwCertEncodingType,
5053   _In_ PCERT_PUBLIC_KEY_INFO pPublicKey1,
5054   _In_ PCERT_PUBLIC_KEY_INFO pPublicKey2);
5055 
5056 DWORD
5057 WINAPI
5058 CertGetPublicKeyLength(
5059   _In_ DWORD dwCertEncodingType,
5060   _In_ PCERT_PUBLIC_KEY_INFO pPublicKey);
5061 
5062 const void *
5063 WINAPI
5064 CertCreateContext(
5065   _In_ DWORD dwContextType,
5066   _In_ DWORD dwEncodingType,
5067   _In_reads_bytes_(cbEncoded) const BYTE *pbEncoded,
5068   _In_ DWORD cbEncoded,
5069   _In_ DWORD dwFlags,
5070   _In_opt_ PCERT_CREATE_CONTEXT_PARA pCreatePara);
5071 
5072 PCCERT_CONTEXT
5073 WINAPI
5074 CertCreateCertificateContext(
5075   _In_ DWORD dwCertEncodingType,
5076   _In_reads_bytes_(cbCertEncoded) const BYTE *pbCertEncoded,
5077   _In_ DWORD cbCertEncoded);
5078 
5079 PCCRL_CONTEXT
5080 WINAPI
5081 CertCreateCRLContext(
5082   _In_ DWORD dwCertEncodingType,
5083   _In_reads_bytes_(cbCrlEncoded) const BYTE *pbCrlEncoded,
5084   _In_ DWORD cbCrlEncoded);
5085 
5086 PCCTL_CONTEXT
5087 WINAPI
5088 CertCreateCTLContext(
5089   _In_ DWORD dwMsgAndCertEncodingType,
5090   _In_reads_bytes_(cbCtlEncoded) const BYTE *pbCtlEncoded,
5091   _In_ DWORD cbCtlEncoded);
5092 
5093 PCCERT_CONTEXT
5094 WINAPI
5095 CertCreateSelfSignCertificate(
5096   _In_opt_ HCRYPTPROV_OR_NCRYPT_KEY_HANDLE hProv,
5097   _In_ PCERT_NAME_BLOB pSubjectIssuerBlob,
5098   _In_ DWORD dwFlags,
5099   _In_opt_ PCRYPT_KEY_PROV_INFO pKeyProvInfo,
5100   _In_opt_ PCRYPT_ALGORITHM_IDENTIFIER pSignatureAlgorithm,
5101   _In_opt_ PSYSTEMTIME pStartTime,
5102   _In_opt_ PSYSTEMTIME pEndTime,
5103   _In_opt_ PCERT_EXTENSIONS pExtensions);
5104 
5105 BOOL WINAPI CertDeleteCertificateFromStore(_In_ PCCERT_CONTEXT pCertContext);
5106 
5107 BOOL WINAPI CertDeleteCRLFromStore(_In_ PCCRL_CONTEXT pCrlContext);
5108 
5109 BOOL WINAPI CertDeleteCTLFromStore(_In_ PCCTL_CONTEXT pCtlContext);
5110 
5111 PCCERT_CONTEXT
5112 WINAPI
5113 CertDuplicateCertificateContext(
5114   _In_opt_ PCCERT_CONTEXT pCertContext);
5115 
5116 PCCRL_CONTEXT WINAPI CertDuplicateCRLContext(_In_opt_ PCCRL_CONTEXT pCrlContext);
5117 
5118 PCCTL_CONTEXT WINAPI CertDuplicateCTLContext(_In_opt_ PCCTL_CONTEXT pCtlContext);
5119 
5120 PCCERT_CONTEXT
5121 WINAPI
5122 CertFindCertificateInStore(
5123   _In_ HCERTSTORE hCertStore,
5124   _In_ DWORD dwCertEncodingType,
5125   _In_ DWORD dwFindFlags,
5126   _In_ DWORD dwFindType,
5127   _In_opt_ const void *pvFindPara,
5128   _In_opt_ PCCERT_CONTEXT pPrevCertContext);
5129 
5130 PCCRL_CONTEXT
5131 WINAPI
5132 CertFindCRLInStore(
5133   _In_ HCERTSTORE hCertStore,
5134   _In_ DWORD dwCertEncodingType,
5135   _In_ DWORD dwFindFlags,
5136   _In_ DWORD dwFindType,
5137   _In_opt_ const void *pvFindPara,
5138   _In_opt_ PCCRL_CONTEXT pPrevCrlContext);
5139 
5140 PCCTL_CONTEXT
5141 WINAPI
5142 CertFindCTLInStore(
5143   _In_ HCERTSTORE hCertStore,
5144   _In_ DWORD dwMsgAndCertEncodingType,
5145   _In_ DWORD dwFindFlags,
5146   _In_ DWORD dwFindType,
5147   _In_opt_ const void *pvFindPara,
5148   _In_opt_ PCCTL_CONTEXT pPrevCtlContext);
5149 
5150 PCCERT_CONTEXT
5151 WINAPI
5152 CertGetIssuerCertificateFromStore(
5153   _In_ HCERTSTORE hCertStore,
5154   _In_ PCCERT_CONTEXT pSubjectContext,
5155   _In_opt_ PCCERT_CONTEXT pPrevIssuerContext,
5156   _Inout_ DWORD *pdwFlags);
5157 
5158 PCCERT_CONTEXT
5159 WINAPI
5160 CertGetSubjectCertificateFromStore(
5161   _In_ HCERTSTORE hCertStore,
5162   _In_ DWORD dwCertEncodingType,
5163   _In_ PCERT_INFO pCertId);
5164 
5165 PCCRL_CONTEXT
5166 WINAPI
5167 CertGetCRLFromStore(
5168   _In_ HCERTSTORE hCertStore,
5169   _In_opt_ PCCERT_CONTEXT pIssuerContext,
5170   _In_opt_ PCCRL_CONTEXT pPrevCrlContext,
5171   _Inout_ DWORD *pdwFlags);
5172 
5173 BOOL
5174 WINAPI
5175 CertSerializeCertificateStoreElement(
5176   _In_ PCCERT_CONTEXT pCertContext,
5177   _In_ DWORD dwFlags,
5178   _Out_writes_bytes_to_opt_(*pcbElement, *pcbElement) BYTE *pbElement,
5179   _Inout_ DWORD *pcbElement);
5180 
5181 BOOL
5182 WINAPI
5183 CertSerializeCRLStoreElement(
5184   _In_ PCCRL_CONTEXT pCrlContext,
5185   _In_ DWORD dwFlags,
5186   _Out_writes_bytes_to_opt_(*pcbElement, *pcbElement) BYTE *pbElement,
5187   _Inout_ DWORD *pcbElement);
5188 
5189 BOOL
5190 WINAPI
5191 CertSerializeCTLStoreElement(
5192   _In_ PCCTL_CONTEXT pCtlContext,
5193   _In_ DWORD dwFlags,
5194   _Out_writes_bytes_to_opt_(*pcbElement, *pcbElement) BYTE *pbElement,
5195   _Inout_ DWORD *pcbElement);
5196 
5197 BOOL
5198 WINAPI
5199 CertGetIntendedKeyUsage(
5200   _In_ DWORD dwCertEncodingType,
5201   _In_ PCERT_INFO pCertInfo,
5202   _Out_writes_bytes_all_(cbKeyUsage) BYTE *pbKeyUsage,
5203   _In_ DWORD cbKeyUsage);
5204 
5205 BOOL
5206 WINAPI
5207 CertGetEnhancedKeyUsage(
5208   _In_ PCCERT_CONTEXT pCertContext,
5209   _In_ DWORD dwFlags,
5210   _Out_writes_bytes_to_opt_(*pcbUsage, *pcbUsage) PCERT_ENHKEY_USAGE pUsage,
5211   _Inout_ DWORD *pcbUsage);
5212 
5213 BOOL
5214 WINAPI
5215 CertSetEnhancedKeyUsage(
5216   _In_ PCCERT_CONTEXT pCertContext,
5217   _In_opt_ PCERT_ENHKEY_USAGE pUsage);
5218 
5219 BOOL
5220 WINAPI
5221 CertAddEnhancedKeyUsageIdentifier(
5222   _In_ PCCERT_CONTEXT pCertContext,
5223   _In_ LPCSTR pszUsageIdentifier);
5224 
5225 BOOL
5226 WINAPI
5227 CertRemoveEnhancedKeyUsageIdentifier(
5228   _In_ PCCERT_CONTEXT pCertContext,
5229   _In_ LPCSTR pszUsageIdentifier);
5230 
5231 _Success_(return != 0)
5232 BOOL
5233 WINAPI
5234 CertGetValidUsages(
5235   _In_ DWORD cCerts,
5236   _In_reads_(cCerts) PCCERT_CONTEXT *rghCerts,
5237   _Out_ int *cNumOIDs,
5238   _Out_writes_bytes_to_opt_(*pcbOIDs, *pcbOIDs) LPSTR *rghOIDs,
5239   _Inout_ DWORD *pcbOIDs);
5240 
5241 BOOL
5242 WINAPI
5243 CryptEncodeObject(
5244   _In_ DWORD dwCertEncodingType,
5245   _In_ LPCSTR lpszStructType,
5246   _In_ const void *pvStructInfo,
5247   _Out_writes_bytes_to_opt_(*pcbEncoded, *pcbEncoded) BYTE *pbEncoded,
5248   _Inout_ DWORD *pcbEncoded);
5249 
5250 BOOL
5251 WINAPI
5252 CryptEncodeObjectEx(
5253   _In_ DWORD dwCertEncodingType,
5254   _In_ LPCSTR lpszStructType,
5255   _In_ const void *pvStructInfo,
5256   _In_ DWORD dwFlags,
5257   _In_opt_ PCRYPT_ENCODE_PARA pEncodePara,
5258   _Out_opt_ void *pvEncoded,
5259   _Inout_ DWORD *pcbEncoded);
5260 
5261 BOOL
5262 WINAPI
5263 CryptDecodeObject(
5264   _In_ DWORD dwCertEncodingType,
5265   _In_ LPCSTR lpszStructType,
5266   _In_reads_bytes_(cbEncoded) const BYTE *pbEncoded,
5267   _In_ DWORD cbEncoded,
5268   _In_ DWORD dwFlags,
5269   _Out_writes_bytes_to_opt_(*pcbStructInfo, *pcbStructInfo) void *pvStructInfo,
5270   _Inout_ DWORD *pcbStructInfo);
5271 
5272 BOOL
5273 WINAPI
5274 CryptDecodeObjectEx(
5275   _In_ DWORD dwCertEncodingType,
5276   _In_ LPCSTR lpszStructType,
5277   _In_reads_bytes_(cbEncoded) const BYTE *pbEncoded,
5278   _In_ DWORD cbEncoded,
5279   _In_ DWORD dwFlags,
5280   _In_opt_ PCRYPT_DECODE_PARA pDecodePara,
5281   _Out_opt_ void *pvStructInfo,
5282   _Inout_ DWORD *pcbStructInfo);
5283 
5284 BOOL
5285 WINAPI
5286 CryptFormatObject(
5287   _In_ DWORD dwCertEncodingType,
5288   _In_ DWORD dwFormatType,
5289   _In_ DWORD dwFormatStrType,
5290   _In_opt_ void *pFormatStruct,
5291   _In_opt_ LPCSTR lpszStructType,
5292   _In_reads_bytes_(cbEncoded) const BYTE *pbEncoded,
5293   _In_ DWORD cbEncoded,
5294   _At_((WCHAR *) pbFormat, _Out_writes_bytes_to_opt_(*pcbFormat, *pcbFormat)) void *pbFormat,
5295   _Inout_ DWORD *pcbFormat);
5296 
5297 BOOL
5298 WINAPI
5299 CryptHashCertificate(
5300   _In_opt_ HCRYPTPROV_LEGACY hCryptProv,
5301   _In_ ALG_ID Algid,
5302   _In_ DWORD dwFlags,
5303   _In_reads_bytes_(cbEncoded) const BYTE *pbEncoded,
5304   _In_ DWORD cbEncoded,
5305   _Out_writes_bytes_to_opt_(*pcbComputedHash, *pcbComputedHash) BYTE *pbComputedHash,
5306   _Inout_ DWORD *pcbComputedHash);
5307 
5308 BOOL
5309 WINAPI
5310 CryptHashPublicKeyInfo(
5311   _In_opt_ HCRYPTPROV_LEGACY hCryptProv,
5312   _In_ ALG_ID Algid,
5313   _In_ DWORD dwFlags,
5314   _In_ DWORD dwCertEncodingType,
5315   _In_ PCERT_PUBLIC_KEY_INFO pInfo,
5316   _Out_writes_bytes_to_opt_(*pcbComputedHash, *pcbComputedHash) BYTE *pbComputedHash,
5317   _Inout_ DWORD *pcbComputedHash);
5318 
5319 BOOL
5320 WINAPI
5321 CryptHashToBeSigned(
5322   _In_opt_ HCRYPTPROV_LEGACY hCryptProv,
5323   _In_ DWORD dwCertEncodingType,
5324   _In_reads_bytes_(cbEncoded) const BYTE *pbEncoded,
5325   _In_ DWORD cbEncoded,
5326   _Out_writes_bytes_to_opt_(*pcbComputedHash, *pcbComputedHash) BYTE *pbComputedHash,
5327   _Inout_ DWORD *pcbComputedHash);
5328 
5329 BOOL
5330 WINAPI
5331 CryptQueryObject(
5332   _In_ DWORD dwObjectType,
5333   _In_ const void *pvObject,
5334   _In_ DWORD dwExpectedContentTypeFlags,
5335   _In_ DWORD dwExpectedFormatTypeFlags,
5336   _In_ DWORD dwFlags,
5337   _Out_opt_ DWORD *pdwMsgAndCertEncodingType,
5338   _Out_opt_ DWORD *pdwContentType,
5339   _Out_opt_ DWORD *pdwFormatType,
5340   _Out_opt_ HCERTSTORE *phCertStore,
5341   _Out_opt_ HCRYPTMSG *phMsg,
5342   _Outptr_opt_result_maybenull_ const void **ppvContext);
5343 
5344 BOOL
5345 WINAPI
5346 CryptSignCertificate(
5347   _In_opt_ HCRYPTPROV_OR_NCRYPT_KEY_HANDLE hCryptProvOrNCryptKey,
5348   _In_opt_ DWORD dwKeySpec,
5349   _In_ DWORD dwCertEncodingType,
5350   _In_reads_bytes_(cbEncodedToBeSigned) const BYTE *pbEncodedToBeSigned,
5351   _In_ DWORD cbEncodedToBeSigned,
5352   _In_ PCRYPT_ALGORITHM_IDENTIFIER pSignatureAlgorithm,
5353   _In_opt_ const void *pvHashAuxInfo,
5354   _Out_writes_bytes_to_opt_(*pcbSignature, *pcbSignature) BYTE *pbSignature,
5355   _Inout_ DWORD *pcbSignature);
5356 
5357 BOOL
5358 WINAPI
5359 CryptSignAndEncodeCertificate(
5360   _In_opt_ HCRYPTPROV_OR_NCRYPT_KEY_HANDLE hCryptProvOrNCryptKey,
5361   _In_opt_ DWORD dwKeySpec,
5362   _In_ DWORD dwCertEncodingType,
5363   _In_ LPCSTR lpszStructType,
5364   _In_ const void *pvStructInfo,
5365   _In_ PCRYPT_ALGORITHM_IDENTIFIER pSignatureAlgorithm,
5366   _In_opt_ const void *pvHashAuxInfo,
5367   _Out_writes_bytes_to_opt_(*pcbEncoded, *pcbEncoded) BYTE *pbEncoded,
5368   _Inout_ DWORD *pcbEncoded);
5369 
5370 _Must_inspect_result_
5371 BOOL
5372 WINAPI
5373 CryptVerifyCertificateSignature(
5374   _In_opt_ HCRYPTPROV_LEGACY hCryptProv,
5375   _In_ DWORD dwCertEncodingType,
5376   _In_reads_bytes_(cbEncoded) const BYTE *pbEncoded,
5377   _In_ DWORD cbEncoded,
5378   _In_ PCERT_PUBLIC_KEY_INFO pPublicKey);
5379 
5380 _Must_inspect_result_
5381 BOOL
5382 WINAPI
5383 CryptVerifyCertificateSignatureEx(
5384   _In_opt_ HCRYPTPROV_LEGACY hCryptProv,
5385   _In_ DWORD dwCertEncodingType,
5386   _In_ DWORD dwSubjectType,
5387   _In_ void *pvSubject,
5388   _In_ DWORD dwIssuerType,
5389   _In_opt_ void *pvIssuer,
5390   _In_ DWORD dwFlags,
5391   _Inout_opt_ void *pvExtra);
5392 
5393 PCRYPT_ATTRIBUTE
5394 WINAPI
5395 CertFindAttribute(
5396   _In_ LPCSTR pszObjId,
5397   _In_ DWORD cAttr,
5398   _In_reads_(cAttr) CRYPT_ATTRIBUTE rgAttr[]);
5399 
5400 PCERT_EXTENSION
5401 WINAPI
5402 CertFindExtension(
5403   _In_ LPCSTR pszObjId,
5404   _In_ DWORD cExtensions,
5405   _In_reads_(cExtensions) CERT_EXTENSION rgExtensions[]);
5406 
5407 PCERT_RDN_ATTR
5408 WINAPI
5409 CertFindRDNAttr(
5410   _In_ LPCSTR pszObjId,
5411   _In_ PCERT_NAME_INFO pName);
5412 
5413 BOOL
5414 WINAPI
5415 CertFindSubjectInSortedCTL(
5416   _In_ PCRYPT_DATA_BLOB pSubjectIdentifier,
5417   _In_ PCCTL_CONTEXT pCtlContext,
5418   _In_ DWORD dwFlags,
5419   _Reserved_ void *pvReserved,
5420   _Out_opt_ PCRYPT_DER_BLOB pEncodedAttributes);
5421 
5422 BOOL
5423 WINAPI
5424 CertIsRDNAttrsInCertificateName(
5425   _In_ DWORD dwCertEncodingType,
5426   _In_ DWORD dwFlags,
5427   _In_ PCERT_NAME_BLOB pCertName,
5428   _In_ PCERT_RDN pRDN);
5429 
5430 BOOL
5431 WINAPI
5432 CertIsValidCRLForCertificate(
5433   _In_ PCCERT_CONTEXT pCert,
5434   _In_ PCCRL_CONTEXT pCrl,
5435   _In_ DWORD dwFlags,
5436   _Reserved_ void *pvReserved);
5437 
5438 BOOL
5439 WINAPI
5440 CertFindCertificateInCRL(
5441   _In_ PCCERT_CONTEXT pCert,
5442   _In_ PCCRL_CONTEXT pCrlContext,
5443   _In_ DWORD dwFlags,
5444   _Reserved_ void *pvReserved,
5445   _Outptr_result_maybenull_ PCRL_ENTRY *ppCrlEntry);
5446 
5447 BOOL
5448 WINAPI
5449 CertVerifyCRLRevocation(
5450   _In_ DWORD dwCertEncodingType,
5451   _In_ PCERT_INFO pCertId,
5452   _In_ DWORD cCrlInfo,
5453   _In_reads_(cCrlInfo) PCRL_INFO rgpCrlInfo[]);
5454 
5455 BOOL
5456 WINAPI
5457 CertVerifySubjectCertificateContext(
5458   _In_ PCCERT_CONTEXT pSubject,
5459   _In_opt_ PCCERT_CONTEXT pIssuer,
5460   _Inout_ DWORD *pdwFlags);
5461 
5462 LONG
5463 WINAPI
5464 CertVerifyCRLTimeValidity(
5465   _In_opt_ LPFILETIME pTimeToVerify,
5466   _In_ PCRL_INFO pCrlInfo);
5467 
5468 LONG
5469 WINAPI
5470 CertVerifyTimeValidity(
5471   _In_opt_ LPFILETIME pTimeToVerify,
5472   _In_ PCERT_INFO pCertInfo);
5473 
5474 BOOL
5475 WINAPI
5476 CertVerifyValidityNesting(
5477   _In_ PCERT_INFO pSubjectInfo,
5478   _In_ PCERT_INFO pIssuerInfo);
5479 
5480 BOOL
5481 WINAPI
5482 CertVerifyCTLUsage(
5483   _In_ DWORD dwEncodingType,
5484   _In_ DWORD dwSubjectType,
5485   _In_ void *pvSubject,
5486   _In_ PCTL_USAGE pSubjectUsage,
5487   _In_ DWORD dwFlags,
5488   _In_opt_ PCTL_VERIFY_USAGE_PARA pVerifyUsagePara,
5489   _Inout_ PCTL_VERIFY_USAGE_STATUS pVerifyUsageStatus);
5490 
5491 BOOL
5492 WINAPI
5493 CertVerifyRevocation(
5494   _In_ DWORD dwEncodingType,
5495   _In_ DWORD dwRevType,
5496   _In_ DWORD cContext,
5497   _In_reads_(cContext) PVOID rgpvContext[],
5498   _In_ DWORD dwFlags,
5499   _In_opt_ PCERT_REVOCATION_PARA pRevPara,
5500   _Inout_ PCERT_REVOCATION_STATUS pRevStatus);
5501 
5502 BOOL
5503 WINAPI
5504 CryptExportPublicKeyInfo(
5505   _In_ HCRYPTPROV_OR_NCRYPT_KEY_HANDLE hCryptProvOrNCryptKey,
5506   _In_opt_ DWORD dwKeySpec,
5507   _In_ DWORD dwCertEncodingType,
5508   _Out_writes_bytes_to_opt_(*pcbInfo, *pcbInfo) PCERT_PUBLIC_KEY_INFO pInfo,
5509   _Inout_ DWORD *pcbInfo);
5510 
5511 BOOL
5512 WINAPI
5513 CryptExportPublicKeyInfoEx(
5514   _In_ HCRYPTPROV_OR_NCRYPT_KEY_HANDLE hCryptProvOrNCryptKey,
5515   _In_opt_ DWORD dwKeySpec,
5516   _In_ DWORD dwCertEncodingType,
5517   _In_opt_ LPSTR pszPublicKeyObjId,
5518   _In_ DWORD dwFlags,
5519   _In_opt_ void *pvAuxInfo,
5520   _Out_writes_bytes_to_opt_(*pcbInfo, *pcbInfo) PCERT_PUBLIC_KEY_INFO pInfo,
5521   _Inout_ DWORD *pcbInfo);
5522 
5523 BOOL
5524 WINAPI
5525 CryptImportPublicKeyInfo(
5526   _In_ HCRYPTPROV hCryptProv,
5527   _In_ DWORD dwCertEncodingType,
5528   _In_ PCERT_PUBLIC_KEY_INFO pInfo,
5529   _Out_ HCRYPTKEY *phKey);
5530 
5531 BOOL
5532 WINAPI
5533 CryptImportPublicKeyInfoEx(
5534   _In_ HCRYPTPROV hCryptProv,
5535   _In_ DWORD dwCertEncodingType,
5536   _In_ PCERT_PUBLIC_KEY_INFO pInfo,
5537   _In_ ALG_ID aiKeyAlg,
5538   _In_ DWORD dwFlags,
5539   _In_opt_ void *pvAuxInfo,
5540   _Out_ HCRYPTKEY *phKey);
5541 
5542 BOOL
5543 WINAPI
5544 CryptAcquireCertificatePrivateKey(
5545   _In_ PCCERT_CONTEXT pCert,
5546   _In_ DWORD dwFlags,
5547   _In_opt_ void *pvParameters,
5548   _Out_ HCRYPTPROV_OR_NCRYPT_KEY_HANDLE *phCryptProvOrNCryptKey,
5549   _Out_opt_ DWORD *pdwKeySpec,
5550   _Out_opt_ BOOL *pfCallerFreeProvOrNCryptKey);
5551 
5552 BOOL
5553 WINAPI
5554 CryptFindCertificateKeyProvInfo(
5555   _In_ PCCERT_CONTEXT pCert,
5556   _In_ DWORD dwFlags,
5557   _Reserved_ void *pvReserved);
5558 
5559 BOOL WINAPI CryptProtectData( DATA_BLOB* pDataIn, LPCWSTR szDataDescr,
5560  DATA_BLOB* pOptionalEntropy, PVOID pvReserved,
5561  CRYPTPROTECT_PROMPTSTRUCT* pPromptStruct, DWORD dwFlags, DATA_BLOB* pDataOut );
5562 
5563 BOOL WINAPI CryptUnprotectData( DATA_BLOB* pDataIn, LPWSTR* ppszDataDescr,
5564  DATA_BLOB* pOptionalEntropy, PVOID pvReserved,
5565  CRYPTPROTECT_PROMPTSTRUCT* pPromptStruct, DWORD dwFlags, DATA_BLOB* pDataOut );
5566 
5567 DWORD
5568 WINAPI
5569 CertGetNameStringA(
5570   _In_ PCCERT_CONTEXT pCertContext,
5571   _In_ DWORD dwType,
5572   _In_ DWORD dwFlags,
5573   _In_opt_ void *pvTypePara,
5574   _Out_writes_to_opt_(cchNameString, return) LPSTR pszNameString,
5575   _In_ DWORD cchNameString);
5576 
5577 DWORD
5578 WINAPI
5579 CertGetNameStringW(
5580   _In_ PCCERT_CONTEXT pCertContext,
5581   _In_ DWORD dwType,
5582   _In_ DWORD dwFlags,
5583   _In_opt_ void *pvTypePara,
5584   _Out_writes_to_opt_(cchNameString, return) LPWSTR pszNameString,
5585   _In_ DWORD cchNameString);
5586 
5587 #define CertGetNameString WINELIB_NAME_AW(CertGetNameString)
5588 
5589 DWORD
5590 WINAPI
5591 CertRDNValueToStrA(
5592   _In_ DWORD dwValueType,
5593   _In_ PCERT_RDN_VALUE_BLOB pValue,
5594   _Out_writes_to_opt_(csz, return) LPSTR psz,
5595   _In_ DWORD csz);
5596 
5597 DWORD
5598 WINAPI
5599 CertRDNValueToStrW(
5600   _In_ DWORD dwValueType,
5601   _In_ PCERT_RDN_VALUE_BLOB pValue,
5602   _Out_writes_to_opt_(csz, return) LPWSTR psz,
5603   _In_ DWORD csz);
5604 
5605 #define CertRDNValueToStr WINELIB_NAME_AW(CertRDNValueToStr)
5606 
5607 DWORD
5608 WINAPI
5609 CertNameToStrA(
5610   _In_ DWORD dwCertEncodingType,
5611   _In_ PCERT_NAME_BLOB pName,
5612   _In_ DWORD dwStrType,
5613   _Out_writes_to_opt_(csz, return) LPSTR psz,
5614   _In_ DWORD csz);
5615 
5616 DWORD
5617 WINAPI
5618 CertNameToStrW(
5619   _In_ DWORD dwCertEncodingType,
5620   _In_ PCERT_NAME_BLOB pName,
5621   _In_ DWORD dwStrType,
5622   _Out_writes_to_opt_(csz, return) LPWSTR psz,
5623   _In_ DWORD csz);
5624 
5625 #define CertNameToStr WINELIB_NAME_AW(CertNameToStr)
5626 
5627 BOOL
5628 WINAPI
5629 CertStrToNameA(
5630   _In_ DWORD dwCertEncodingType,
5631   _In_ LPCSTR pszX500,
5632   _In_ DWORD dwStrType,
5633   _Reserved_ void *pvReserved,
5634   _Out_writes_bytes_to_opt_(*pcbEncoded, *pcbEncoded) BYTE *pbEncoded,
5635   _Inout_ DWORD *pcbEncoded,
5636   _Outptr_opt_result_maybenull_ LPCSTR *ppszError);
5637 
5638 BOOL
5639 WINAPI
5640 CertStrToNameW(
5641   _In_ DWORD dwCertEncodingType,
5642   _In_ LPCWSTR pszX500,
5643   _In_ DWORD dwStrType,
5644   _Reserved_ void *pvReserved,
5645   _Out_writes_bytes_to_opt_(*pcbEncoded, *pcbEncoded) BYTE *pbEncoded,
5646   _Inout_ DWORD *pcbEncoded,
5647   _Outptr_opt_result_maybenull_ LPCWSTR *ppszError);
5648 
5649 #define CertStrToName WINELIB_NAME_AW(CertStrToName)
5650 
5651 DWORD
5652 WINAPI
5653 CryptMsgCalculateEncodedLength(
5654   _In_ DWORD dwMsgEncodingType,
5655   _In_ DWORD dwFlags,
5656   _In_ DWORD dwMsgType,
5657   _In_ void const *pvMsgEncodeInfo,
5658   _In_opt_ LPSTR pszInnerContentObjID,
5659   _In_ DWORD cbData);
5660 
5661 BOOL WINAPI CryptMsgClose(_In_opt_ HCRYPTMSG hCryptMsg);
5662 
5663 BOOL
5664 WINAPI
5665 CryptMsgControl(
5666   _In_ HCRYPTMSG hCryptMsg,
5667   _In_ DWORD dwFlags,
5668   _In_ DWORD dwCtrlType,
5669   _In_opt_ void const *pvCtrlPara);
5670 
5671 BOOL
5672 WINAPI
5673 CryptMsgCountersign(
5674   _In_ HCRYPTMSG hCryptMsg,
5675   _In_ DWORD dwIndex,
5676   _In_ DWORD cCountersigners,
5677   _In_reads_(cCountersigners) PCMSG_SIGNER_ENCODE_INFO rgCountersigners);
5678 
5679 BOOL
5680 WINAPI
5681 CryptMsgCountersignEncoded(
5682   _In_ DWORD dwEncodingType,
5683   _In_reads_bytes_(cbSignerInfo) PBYTE pbSignerInfo,
5684   _In_ DWORD cbSignerInfo,
5685   _In_ DWORD cCountersigners,
5686   _In_reads_(cCountersigners) PCMSG_SIGNER_ENCODE_INFO rgCountersigners,
5687   _Out_writes_bytes_to_opt_(*pcbCountersignature, *pcbCountersignature) PBYTE pbCountersignature,
5688   _Inout_ PDWORD pcbCountersignature);
5689 
5690 HCRYPTMSG WINAPI CryptMsgDuplicate(_In_opt_ HCRYPTMSG hCryptMsg);
5691 
5692 BOOL
5693 WINAPI
5694 CryptMsgEncodeAndSignCTL(
5695   _In_ DWORD dwMsgEncodingType,
5696   _In_ PCTL_INFO pCtlInfo,
5697   _In_ PCMSG_SIGNED_ENCODE_INFO pSignInfo,
5698   _In_ DWORD dwFlags,
5699   _Out_writes_bytes_to_opt_(*pcbEncoded, *pcbEncoded) BYTE *pbEncoded,
5700   _Inout_ DWORD *pcbEncoded);
5701 
5702 _Success_(return == 0)
5703 BOOL
5704 WINAPI
5705 CryptMsgGetAndVerifySigner(
5706   _In_ HCRYPTMSG hCryptMsg,
5707   _In_ DWORD cSignerStore,
5708   _In_reads_opt_(cSignerStore) HCERTSTORE *rghSignerStore,
5709   _In_ DWORD dwFlags,
5710   _Outptr_opt_ PCCERT_CONTEXT *ppSigner,
5711   _Inout_opt_ DWORD *pdwSignerIndex);
5712 
5713 BOOL
5714 WINAPI
5715 CryptMsgGetParam(
5716   _In_ HCRYPTMSG hCryptMsg,
5717   _In_ DWORD dwParamType,
5718   _In_ DWORD dwIndex,
5719   _Out_writes_bytes_to_opt_(*pcbData, *pcbData) void *pvData,
5720   _Inout_ DWORD *pcbData);
5721 
5722 HCRYPTMSG
5723 WINAPI
5724 CryptMsgOpenToDecode(
5725   _In_ DWORD dwMsgEncodingType,
5726   _In_ DWORD dwFlags,
5727   _In_ DWORD dwMsgType,
5728   _In_opt_ HCRYPTPROV_LEGACY hCryptProv,
5729   _Reserved_ PCERT_INFO pRecipientInfo,
5730   _In_opt_ PCMSG_STREAM_INFO pStreamInfo);
5731 
5732 HCRYPTMSG
5733 WINAPI
5734 CryptMsgOpenToEncode(
5735   _In_ DWORD dwMsgEncodingType,
5736   _In_ DWORD dwFlags,
5737   _In_ DWORD dwMsgType,
5738   _In_ void const *pvMsgEncodeInfo,
5739   _In_opt_ LPSTR pszInnerContentObjID,
5740   _In_opt_ PCMSG_STREAM_INFO pStreamInfo);
5741 
5742 BOOL
5743 WINAPI
5744 CryptMsgSignCTL(
5745   _In_ DWORD dwMsgEncodingType,
5746   _In_reads_bytes_(cbCtlContent) BYTE *pbCtlContent,
5747   _In_ DWORD cbCtlContent,
5748   _In_ PCMSG_SIGNED_ENCODE_INFO pSignInfo,
5749   _In_ DWORD dwFlags,
5750   _Out_writes_bytes_to_opt_(*pcbEncoded, *pcbEncoded) BYTE *pbEncoded,
5751   _Inout_ DWORD *pcbEncoded);
5752 
5753 BOOL
5754 WINAPI
5755 CryptMsgUpdate(
5756   _In_ HCRYPTMSG hCryptMsg,
5757   _In_reads_bytes_opt_(cbData) const BYTE *pbData,
5758   _In_ DWORD cbData,
5759   _In_ BOOL fFinal);
5760 
5761 BOOL
5762 WINAPI
5763 CryptMsgVerifyCountersignatureEncoded(
5764   _In_opt_ HCRYPTPROV_LEGACY hCryptProv,
5765   _In_ DWORD dwEncodingType,
5766   _In_reads_bytes_(cbSignerInfo) PBYTE pbSignerInfo,
5767   _In_ DWORD cbSignerInfo,
5768   _In_reads_bytes_(cbSignerInfoCountersignature) PBYTE pbSignerInfoCountersignature,
5769   _In_ DWORD cbSignerInfoCountersignature,
5770   _In_ PCERT_INFO pciCountersigner);
5771 
5772 BOOL
5773 WINAPI
5774 CryptMsgVerifyCountersignatureEncodedEx(
5775   _In_opt_ HCRYPTPROV_LEGACY hCryptProv,
5776   _In_ DWORD dwEncodingType,
5777   _In_reads_bytes_(cbSignerInfo) PBYTE pbSignerInfo,
5778   _In_ DWORD cbSignerInfo,
5779   _In_reads_bytes_(cbSignerInfoCountersignature) PBYTE pbSignerInfoCountersignature,
5780   _In_ DWORD cbSignerInfoCountersignature,
5781   _In_ DWORD dwSignerType,
5782   _In_ void *pvSigner,
5783   _In_ DWORD dwFlags,
5784   _Inout_opt_ void *pvExtra);
5785 
5786 BOOL
5787 WINAPI
5788 CryptSignMessage(
5789   _In_ PCRYPT_SIGN_MESSAGE_PARA pSignPara,
5790   _In_ BOOL fDetachedSignature,
5791   _In_ DWORD cToBeSigned,
5792   _In_reads_opt_(cToBeSigned) const BYTE *rgpbToBeSigned[],
5793   _In_reads_(cToBeSigned) DWORD rgcbToBeSigned[],
5794   _Out_writes_bytes_to_opt_(*pcbSignedBlob, *pcbSignedBlob) BYTE *pbSignedBlob,
5795   _Inout_ DWORD *pcbSignedBlob);
5796 
5797 BOOL
5798 WINAPI
5799 CryptSignMessageWithKey(
5800   _In_ PCRYPT_KEY_SIGN_MESSAGE_PARA pSignPara,
5801   _In_reads_bytes_(cbToBeSigned) const BYTE *pbToBeSigned,
5802   _In_ DWORD cbToBeSigned,
5803   _Out_writes_bytes_to_opt_(*pcbSignedBlob, *pcbSignedBlob) BYTE *pbSignedBlob,
5804   _Inout_ DWORD *pcbSignedBlob);
5805 
5806 BOOL
5807 WINAPI
5808 CryptVerifyMessageSignature(
5809   _In_ PCRYPT_VERIFY_MESSAGE_PARA pVerifyPara,
5810   _In_ DWORD dwSignerIndex,
5811   _In_reads_bytes_(cbSignedBlob) const BYTE *pbSignedBlob,
5812   _In_ DWORD cbSignedBlob,
5813   _Out_writes_bytes_to_opt_(*pcbDecoded, *pcbDecoded) BYTE *pbDecoded,
5814   _Inout_opt_ DWORD *pcbDecoded,
5815   _Outptr_opt_result_maybenull_ PCCERT_CONTEXT *ppSignerCert);
5816 
5817 BOOL
5818 WINAPI
5819 CryptVerifyMessageSignatureWithKey(
5820   _In_ PCRYPT_KEY_VERIFY_MESSAGE_PARA pVerifyPara,
5821   _In_opt_ PCERT_PUBLIC_KEY_INFO pPublicKeyInfo,
5822   _In_reads_bytes_(cbSignedBlob) const BYTE *pbSignedBlob,
5823   _In_ DWORD cbSignedBlob,
5824   _Out_writes_bytes_to_opt_(*pcbDecoded, *pcbDecoded) BYTE *pbDecoded,
5825   _Inout_opt_ DWORD *pcbDecoded);
5826 
5827 BOOL
5828 WINAPI
5829 CryptVerifyDetachedMessageSignature(
5830   _In_ PCRYPT_VERIFY_MESSAGE_PARA pVerifyPara,
5831   _In_ DWORD dwSignerIndex,
5832   _In_reads_bytes_(cbDetachedSignBlob) const BYTE *pbDetachedSignBlob,
5833   _In_ DWORD cbDetachedSignBlob,
5834   _In_ DWORD cToBeSigned,
5835   _In_reads_(cToBeSigned) const BYTE *rgpbToBeSigned[],
5836   _In_reads_(cToBeSigned) DWORD rgcbToBeSigned[],
5837   _Outptr_opt_result_maybenull_ PCCERT_CONTEXT *ppSignerCert);
5838 
5839 LONG
5840 WINAPI
5841 CryptGetMessageSignerCount(
5842   _In_ DWORD dwMsgEncodingType,
5843   _In_reads_bytes_(cbSignedBlob) const BYTE *pbSignedBlob,
5844   _In_ DWORD cbSignedBlob);
5845 
5846 BOOL
5847 WINAPI
5848 CryptEncryptMessage(
5849   _In_ PCRYPT_ENCRYPT_MESSAGE_PARA pEncryptPara,
5850   _In_ DWORD cRecipientCert,
5851   _In_reads_(cRecipientCert) PCCERT_CONTEXT rgpRecipientCert[],
5852   _In_reads_bytes_opt_(cbToBeEncrypted) const BYTE *pbToBeEncrypted,
5853   _In_ DWORD cbToBeEncrypted,
5854   _Out_writes_bytes_to_opt_(*pcbEncryptedBlob, *pcbEncryptedBlob) BYTE *pbEncryptedBlob,
5855   _Inout_ DWORD *pcbEncryptedBlob);
5856 
5857 BOOL
5858 WINAPI
5859 CryptDecryptMessage(
5860   _In_ PCRYPT_DECRYPT_MESSAGE_PARA pDecryptPara,
5861   _In_reads_bytes_(cbEncryptedBlob) const BYTE *pbEncryptedBlob,
5862   _In_ DWORD cbEncryptedBlob,
5863   _Out_writes_bytes_to_opt_(*pcbDecrypted, *pcbDecrypted) BYTE *pbDecrypted,
5864   _Inout_opt_ DWORD *pcbDecrypted,
5865   _Outptr_opt_result_maybenull_ PCCERT_CONTEXT *ppXchgCert);
5866 
5867 BOOL
5868 WINAPI
5869 CryptSignAndEncryptMessage(
5870   _In_ PCRYPT_SIGN_MESSAGE_PARA pSignPara,
5871   _In_ PCRYPT_ENCRYPT_MESSAGE_PARA pEncryptPara,
5872   _In_ DWORD cRecipientCert,
5873   _In_reads_(cRecipientCert) PCCERT_CONTEXT rgpRecipientCert[],
5874   _In_reads_bytes_(cbToBeSignedAndEncrypted) const BYTE *pbToBeSignedAndEncrypted,
5875   _In_ DWORD cbToBeSignedAndEncrypted,
5876   _Out_writes_bytes_to_opt_(*pcbSignedAndEncryptedBlob, *pcbSignedAndEncryptedBlob) BYTE *pbSignedAndEncryptedBlob,
5877   _Inout_ DWORD *pcbSignedAndEncryptedBlob);
5878 
5879 BOOL
5880 WINAPI
5881 CryptDecryptAndVerifyMessageSignature(
5882   _In_ PCRYPT_DECRYPT_MESSAGE_PARA pDecryptPara,
5883   _In_ PCRYPT_VERIFY_MESSAGE_PARA pVerifyPara,
5884   _In_ DWORD dwSignerIndex,
5885   _In_reads_bytes_(cbEncryptedBlob) const BYTE *pbEncryptedBlob,
5886   _In_ DWORD cbEncryptedBlob,
5887   _Out_writes_bytes_to_opt_(*pcbDecrypted, *pcbDecrypted) BYTE *pbDecrypted,
5888   _Inout_opt_ DWORD *pcbDecrypted,
5889   _Outptr_opt_result_maybenull_ PCCERT_CONTEXT *ppXchgCert,
5890   _Outptr_opt_result_maybenull_ PCCERT_CONTEXT *ppSignerCert);
5891 
5892 HCERTSTORE
5893 WINAPI
5894 CryptGetMessageCertificates(
5895   _In_ DWORD dwMsgAndCertEncodingType,
5896   _In_opt_ HCRYPTPROV_LEGACY hCryptProv,
5897   _In_ DWORD dwFlags,
5898   _In_reads_bytes_(cbSignedBlob) const BYTE *pbSignedBlob,
5899   _In_ DWORD cbSignedBlob);
5900 
5901 BOOL
5902 WINAPI
5903 CryptDecodeMessage(
5904   _In_ DWORD dwMsgTypeFlags,
5905   _In_opt_ PCRYPT_DECRYPT_MESSAGE_PARA pDecryptPara,
5906   _In_opt_ PCRYPT_VERIFY_MESSAGE_PARA pVerifyPara,
5907   _In_ DWORD dwSignerIndex,
5908   _In_reads_bytes_(cbEncodedBlob) const BYTE *pbEncodedBlob,
5909   _In_ DWORD cbEncodedBlob,
5910   _In_ DWORD dwPrevInnerContentType,
5911   _Out_opt_ DWORD *pdwMsgType,
5912   _Out_opt_ DWORD *pdwInnerContentType,
5913   _Out_writes_bytes_to_opt_(*pcbDecoded, *pcbDecoded) BYTE *pbDecoded,
5914   _Inout_opt_ DWORD *pcbDecoded,
5915   _Outptr_opt_result_maybenull_ PCCERT_CONTEXT *ppXchgCert,
5916   _Outptr_opt_result_maybenull_ PCCERT_CONTEXT *ppSignerCert);
5917 
5918 BOOL
5919 WINAPI
5920 CryptHashMessage(
5921   _In_ PCRYPT_HASH_MESSAGE_PARA pHashPara,
5922   _In_ BOOL fDetachedHash,
5923   _In_ DWORD cToBeHashed,
5924   _In_reads_(cToBeHashed) const BYTE *rgpbToBeHashed[],
5925   _In_reads_(cToBeHashed) DWORD rgcbToBeHashed[],
5926   _Out_writes_bytes_to_opt_(*pcbHashedBlob, *pcbHashedBlob) BYTE *pbHashedBlob,
5927   _Inout_opt_ DWORD *pcbHashedBlob,
5928   _Out_writes_bytes_to_opt_(*pcbComputedHash, *pcbComputedHash) BYTE *pbComputedHash,
5929   _Inout_opt_ DWORD *pcbComputedHash);
5930 
5931 BOOL
5932 WINAPI
5933 CryptVerifyMessageHash(
5934   _In_ PCRYPT_HASH_MESSAGE_PARA pHashPara,
5935   _In_reads_bytes_(cbHashedBlob) BYTE *pbHashedBlob,
5936   _In_ DWORD cbHashedBlob,
5937   _Out_writes_bytes_to_opt_(*pcbToBeHashed, *pcbToBeHashed) BYTE *pbToBeHashed,
5938   _Inout_opt_ DWORD *pcbToBeHashed,
5939   _Out_writes_bytes_to_opt_(*pcbComputedHash, *pcbComputedHash) BYTE *pbComputedHash,
5940   _Inout_opt_ DWORD *pcbComputedHash);
5941 
5942 BOOL
5943 WINAPI
5944 CryptVerifyDetachedMessageHash(
5945   _In_ PCRYPT_HASH_MESSAGE_PARA pHashPara,
5946   _In_reads_bytes_(cbDetachedHashBlob) BYTE *pbDetachedHashBlob,
5947   _In_ DWORD cbDetachedHashBlob,
5948   _In_ DWORD cToBeHashed,
5949   _In_reads_(cToBeHashed) const BYTE *rgpbToBeHashed[],
5950   _In_reads_(cToBeHashed) DWORD rgcbToBeHashed[],
5951   _Out_writes_bytes_to_opt_(*pcbComputedHash, *pcbComputedHash) BYTE *pbComputedHash,
5952   _Inout_opt_ DWORD *pcbComputedHash);
5953 
5954 /* PFX functions */
5955 HCERTSTORE
5956 WINAPI
5957 PFXImportCertStore(
5958   _In_ CRYPT_DATA_BLOB *pPFX,
5959   _In_ LPCWSTR szPassword,
5960   _In_ DWORD dwFlags);
5961 
5962 BOOL WINAPI PFXIsPFXBlob(_In_ CRYPT_DATA_BLOB *pPFX);
5963 
5964 BOOL
5965 WINAPI
5966 PFXVerifyPassword(
5967   _In_ CRYPT_DATA_BLOB *pPFX,
5968   _In_ LPCWSTR szPassword,
5969   _In_ DWORD dwFlags);
5970 
5971 BOOL
5972 WINAPI
5973 PFXExportCertStoreEx(
5974   _In_ HCERTSTORE hStore,
5975   _Inout_ CRYPT_DATA_BLOB* pPFX,
5976   _In_ LPCWSTR szPassword,
5977   _In_ void* pvPara,
5978   _In_ DWORD dwFlags);
5979 
5980 BOOL
5981 WINAPI
5982 PFXExportCertStore(
5983   _In_ HCERTSTORE hStore,
5984   _Inout_ CRYPT_DATA_BLOB* pPFX,
5985   _In_ LPCWSTR szPassword,
5986   _In_ DWORD dwFlags);
5987 
5988 BOOL WINAPI PFXVerifyPassword(CRYPT_DATA_BLOB *pPFX, LPCWSTR szPassword,
5989  DWORD dwFlags);
5990 
5991 /* cryptnet.dll functions */
5992 BOOL WINAPI CryptCancelAsyncRetrieval(_In_opt_ HCRYPTASYNC hAsyncRetrieval);
5993 
5994 BOOL
5995 WINAPI
5996 CryptGetObjectUrl(
5997   _In_ LPCSTR pszUrlOid,
5998   _In_ LPVOID pvPara,
5999   _In_ DWORD dwFlags,
6000   _Out_writes_bytes_to_opt_(*pcbUrlArray, *pcbUrlArray) PCRYPT_URL_ARRAY pUrlArray,
6001   _Inout_ DWORD* pcbUrlArray,
6002   _Out_writes_bytes_to_opt_(*pcbUrlInfo, *pcbUrlInfo) PCRYPT_URL_INFO pUrlInfo,
6003   _Inout_opt_ DWORD* pcbUrlInfo,
6004   _Reserved_ LPVOID pvReserved);
6005 
6006 _Success_(return != 0)
6007 BOOL
6008 WINAPI
6009 CryptGetTimeValidObject(
6010   _In_ LPCSTR pszTimeValidOid,
6011   _In_ void *pvPara,
6012   _In_ PCCERT_CONTEXT pIssuer,
6013   _In_opt_ LPFILETIME pftValidFor,
6014   _In_ DWORD dwFlags,
6015   _In_ DWORD dwTimeout,
6016   _Outptr_opt_ void **ppvObject,
6017   _In_opt_ PCRYPT_CREDENTIALS pCredentials,
6018   _Inout_opt_ void *pvReserved);
6019 
6020 BOOL
6021 WINAPI
6022 CryptFlushTimeValidObject(
6023   _In_ LPCSTR pszFlushTimeValidOid,
6024   _In_ void *pvPara,
6025   _In_ PCCERT_CONTEXT pIssuer,
6026   _In_ DWORD dwFlags,
6027   _Reserved_ void *pvReserved);
6028 
6029 BOOL
6030 WINAPI
6031 CryptInstallCancelRetrieval(
6032   __callback PFN_CRYPT_CANCEL_RETRIEVAL pfnCancel,
6033   _In_opt_ const void *pvArg,
6034   _In_ DWORD dwFlags,
6035   _Reserved_ void *pvReserved);
6036 
6037 BOOL
6038 WINAPI
6039 CryptUninstallCancelRetrieval(
6040   _In_ DWORD dwFlags,
6041   _Reserved_ void *pvReserved);
6042 
6043 _Success_(return != 0)
6044 BOOL
6045 WINAPI
6046 CryptRetrieveObjectByUrlA(
6047   _In_ LPCSTR pszUrl,
6048   _In_opt_ LPCSTR pszObjectOid,
6049   _In_ DWORD dwRetrievalFlags,
6050   _In_ DWORD dwTimeout,
6051   _Outptr_ LPVOID* ppvObject,
6052   _In_opt_ HCRYPTASYNC hAsyncRetrieve,
6053   _In_opt_ PCRYPT_CREDENTIALS pCredentials,
6054   _In_opt_ LPVOID pvVerify,
6055   _Inout_opt_ PCRYPT_RETRIEVE_AUX_INFO pAuxInfo);
6056 
6057 _Success_(return != 0)
6058 BOOL
6059 WINAPI
6060 CryptRetrieveObjectByUrlW(
6061   _In_ LPCWSTR pszUrl,
6062   _In_opt_ LPCSTR pszObjectOid,
6063   _In_ DWORD dwRetrievalFlags,
6064   _In_ DWORD dwTimeout,
6065   _Outptr_ LPVOID* ppvObject,
6066   _In_opt_ HCRYPTASYNC hAsyncRetrieve,
6067   _In_opt_ PCRYPT_CREDENTIALS pCredentials,
6068   _In_opt_ LPVOID pvVerify,
6069   _Inout_opt_ PCRYPT_RETRIEVE_AUX_INFO pAuxInfo);
6070 
6071 #define CryptRetrieveObjectByUrl WINELIB_NAME_AW(CryptRetrieveObjectByUrl)
6072 
6073 /* Not found in crypt32.dll but in softpub.dll */
6074 HRESULT
6075 WINAPI
6076 FindCertsByIssuer(
6077   _Out_writes_bytes_to_opt_(*pcbCertChains, *pcbCertChains) PCERT_CHAIN pCertChains,
6078   _Inout_ DWORD *pcbCertChains,
6079   _Out_ DWORD *pcCertChains,
6080   _In_reads_bytes_opt_(cbEncodedIssuerName) BYTE* pbEncodedIssuerName,
6081   _In_ DWORD cbEncodedIssuerName,
6082   _In_opt_ LPCWSTR pwszPurpose,
6083   _In_ DWORD dwKeySpec);
6084 
6085 #ifdef _MSC_VER
6086 #pragma warning(pop)
6087 #endif
6088 
6089 #ifdef __cplusplus
6090 }
6091 #endif
6092 
6093 #endif
6094