|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
RFC 5280 certificates: reading one out of the caller's DER (PROTOCORE_ENABLE_X509). More...
#include "protocore_config.h"Go to the source code of this file.
RFC 5280 certificates: reading one out of the caller's DER (PROTOCORE_ENABLE_X509).
A parse is a view, not a copy. Every field this reports is a pointer into the caller's own bytes and a length, so a certificate costs nothing but the struct below and the encoding it points at, and the encoding has to outlive the view.
The TBSCertificate's own bytes are reported too, because that is what the signature covers (sec 4.1.1.2): a verifier hashes exactly those octets, so they are handed back exactly as they arrived rather than re-encoded from the parsed fields.
This module reads and matches. It verifies nothing: a signature needs the key algorithms, and a chain needs a trust anchor and a clock, so both sit above this. What a certificate SAYS - the algorithm identifiers and X509Cert itself - is crypto/x509/x509_types, because a build that authenticates by raw public key needs those words without needing this parser.
Definition in file x509.h.