ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
x509.h
Go to the documentation of this file.
1// ProtoCore v1.0.16 - Copyright (C) 2026 Douglas Quigg (dstroy0) <dquigg123@gmail.com>
2// SPDX-License-Identifier: AGPL-3.0-or-later
3
4/**
5 * @file x509.h
6 * @brief RFC 5280 certificates: reading one out of the caller's DER (PROTOCORE_ENABLE_X509).
7 *
8 * A parse is a view, not a copy. Every field this reports is a pointer into the caller's own bytes
9 * and a length, so a certificate costs nothing but the struct below and the encoding it points at,
10 * and the encoding has to outlive the view.
11 *
12 * The TBSCertificate's own bytes are reported too, because that is what the signature covers
13 * (sec 4.1.1.2): a verifier hashes exactly those octets, so they are handed back exactly as they
14 * arrived rather than re-encoded from the parsed fields.
15 *
16 * This module reads and matches. It verifies nothing: a signature needs the key algorithms, and a
17 * chain needs a trust anchor and a clock, so both sit above this. What a certificate SAYS - the
18 * algorithm identifiers and @ref X509Cert itself - is crypto/x509/x509_types, because a build
19 * that authenticates by raw public key needs those words without needing this parser.
20 *
21 * @author Douglas Quigg (dstroy0)
22 * @date 2026
23 */
24
25#ifndef PROTOCORE_X509_H
26#define PROTOCORE_X509_H
27
28#include "protocore_config.h" // the entry point: the enable gate below, and the widths
29
30#if PROTOCORE_ENABLE_X509
31
32#include "crypto/x509/x509_types/x509_types.h" // X509Cert: what a parse fills in
33
35
36/** @brief The encoding a parse reads. */
37typedef struct
38{
39 const uint8_t *der; ///< one Certificate, DER
40 size_t len; ///< how many octets
41} X509ParseArgs;
42
43/** @brief What a name match judges: the presented certificate, and the name asked for. */
44typedef struct
45{
46 const X509Cert *cert; ///< the certificate presented
47 const char *host; ///< the name the caller asked for, NUL terminated
48 size_t host_len; ///< its length, or 0 to measure it
49} X509MatchArgs;
50
51/**
52 * @brief Certificates: read one, and judge whether it speaks for a name.
53 *
54 * A caller sets the members a call takes, invokes it through ::X509, and reads the outcome off the
55 * same handle.
56 *
57 * @var X509Ns::parse_args the encoding a parse reads
58 * @var X509Ns::match_args the certificate and the name a match judges
59 * @var X509Ns::cert what a parse found
60 * @var X509Ns::ok a call's true/false outcome
61 * @var X509Ns::parse read one Certificate (sec 4.1). Refuses anything it cannot represent
62 * rather than reporting a partial view
63 * @var X509Ns::name_match whether the certificate speaks for @c match_args.host, by RFC 6125
64 * sec 6.4: the subjectAltName dNSName entries only, never the subject
65 * common name
66 *
67 * No storage member: a parse works in the caller's encoding and reports on this handle.
68 */
69typedef struct
70{
71 X509ParseArgs parse_args;
72 X509MatchArgs match_args;
73 X509Cert cert;
74 proto_bool ok;
75} X509Vars;
76
77/** @brief The operands and the outcome. */
78extern X509Vars X509V;
79
80/** @brief The entries. */
81typedef struct
82{
83 void (*const parse)(uint8_t *work);
84 void (*const name_match)(uint8_t *work);
85} X509Ns;
86
87// What the table binds, defined once in the .c and taking one parameter each: everything
88// else an entry needs is an operand in X509V or a region of the borrow at a fixed offset.
89void protocore_x509_parse(uint8_t *work);
90void protocore_x509_name_match(uint8_t *work);
91
92// `static const`, initialised HERE rather than `extern` against a definition in the .c: a
93// const object whose initializer every translation unit can see is a COMPILE-TIME FACT, so
94// `X509.parse(work)` resolves to a named function and becomes a DIRECT call. An extern table
95// leaves the call indirect and the symbol live at every level, -O2 -flto included.
96static const X509Ns X509 __attribute__((unused)) = {
97 .parse = protocore_x509_parse,
98 .name_match = protocore_x509_name_match,
99};
100
102
103#endif // PROTOCORE_ENABLE_X509
104
105#endif // PROTOCORE_X509_H
#define PROTOCORE_BEGIN_DECLS
Give a header's declarations C linkage, so their symbol names carry no parameter types.
Definition types.h:96
_Bool proto_bool
The truth value.
Definition types.h:64
#define PROTOCORE_END_DECLS
Definition types.h:97
What a certificate SAYS, as types: the algorithm identifiers and the parsed view.