ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
x509_types.h
Go to the documentation of this file.
1// ProtoCore v1.0.16 - Copyright (C) 2026 Douglas Quigg (dstroy0) <dquigg123@gmail.com>
2// SPDX-License-Identifier: AGPL-3.0-or-later
3
4/**
5 * @file x509_types.h
6 * @brief What a certificate SAYS, as types: the algorithm identifiers and the parsed view.
7 *
8 * Vocabulary, not behaviour - no state, no entries, nothing to link. It is a module of its own
9 * because two paths need the words and only one needs the parser: a TLS connection that
10 * authenticates by RFC 7250 raw public key still carries the peer's key in an @ref X509Cert and
11 * still names a signature scheme as a @ref protocore_x509_sig_alg, while the RFC 5280 DER
12 * parsing behind PROTOCORE_ENABLE_X509 is exactly what such a build does not compile.
13 *
14 * A parsed certificate is a VIEW, not a copy: every @ref X509Bytes here points into the caller's
15 * own encoding, which has to outlive the view.
16 *
17 * @author Douglas Quigg (dstroy0)
18 * @date 2026
19 */
20
21#ifndef PROTOCORE_X509_TYPES_H
22#define PROTOCORE_X509_TYPES_H
23
24#include "protocore_config.h" // the entry point: the widths
25
27
28/** @brief The signature algorithms this profile reads (RFC 5280 sec 4.1.1.2). */
30{
31 PROTOCORE_X509_SIG_UNKNOWN = 0, ///< an algorithm this build does not verify
32 PROTOCORE_X509_SIG_RSA_SHA256, ///< sha256WithRSAEncryption, {pkcs-1 11} (RFC 8017 A.2.4)
33 PROTOCORE_X509_SIG_RSA_SHA384, ///< sha384WithRSAEncryption, {pkcs-1 12}
34 PROTOCORE_X509_SIG_RSA_SHA512, ///< sha512WithRSAEncryption, {pkcs-1 13}
35 PROTOCORE_X509_SIG_RSA_PSS, ///< id-RSASSA-PSS, {pkcs-1 10}
36 PROTOCORE_X509_SIG_ECDSA_SHA256, ///< ecdsa-with-SHA256, 1.2.840.10045.4.3.2 (RFC 5480 sec 2.1.1)
37 PROTOCORE_X509_SIG_ECDSA_SHA384, ///< ecdsa-with-SHA384, 1.2.840.10045.4.3.3
38 PROTOCORE_X509_SIG_ED25519, ///< id-Ed25519, 1.3.101.112 (RFC 8410 sec 3)
40
41/** @brief The public key algorithms this profile reads (RFC 5280 sec 4.1.2.7). */
43{
44 PROTOCORE_X509_KEY_UNKNOWN = 0, ///< an algorithm this build cannot use
45 PROTOCORE_X509_KEY_RSA, ///< rsaEncryption, {pkcs-1 1}
46 PROTOCORE_X509_KEY_EC_P256, ///< id-ecPublicKey over secp256r1 (RFC 5480 sec 2.1.1)
47 PROTOCORE_X509_KEY_ED25519, ///< id-Ed25519 (RFC 8410 sec 4)
49
50/** @name RFC 5280 sec 4.2.1.3 KeyUsage bits, in the order the BIT STRING numbers them.
51 * @{ */
52#define PROTOCORE_X509_KU_DIGITAL_SIGNATURE 0x0001u
53#define PROTOCORE_X509_KU_NON_REPUDIATION 0x0002u
54#define PROTOCORE_X509_KU_KEY_ENCIPHERMENT 0x0004u
55#define PROTOCORE_X509_KU_DATA_ENCIPHERMENT 0x0008u
56#define PROTOCORE_X509_KU_KEY_AGREEMENT 0x0010u
57#define PROTOCORE_X509_KU_KEY_CERT_SIGN 0x0020u
58#define PROTOCORE_X509_KU_CRL_SIGN 0x0040u
59/** @} */
60
61/** @brief A run of the caller's bytes: where a field is, and how much of it there is. */
62typedef struct
63{
64 const uint8_t *p; ///< into the caller's encoding
65 size_t len; ///< how many octets
66} X509Bytes;
67
68/**
69 * @brief One certificate, as a view over the DER it was read from.
70 *
71 * @var X509Cert::tbs the TBSCertificate's own octets, which the signature covers
72 * @var X509Cert::serial serialNumber's content, as it was encoded (sec 4.1.2.2 allows 20 octets)
73 * @var X509Cert::issuer the issuer Name, whole and encoded: a chain matches it against a
74 * subject byte for byte, so it is not decoded
75 * @var X509Cert::subject the subject Name, likewise
76 * @var X509Cert::spki the SubjectPublicKeyInfo's own octets, whole
77 * @var X509Cert::key subjectPublicKey's octets, past the BIT STRING's unused-bits count
78 * @var X509Cert::sig signatureValue's octets, likewise
79 * @var X509Cert::san the subjectAltName extension's value, or empty when absent
80 * @var X509Cert::not_before validity's start, seconds since the POSIX epoch (sec 4.1.2.5)
81 * @var X509Cert::not_after validity's end, likewise
82 * @var X509Cert::sig_alg what signed it
83 * @var X509Cert::key_alg what its public key is
84 * @var X509Cert::key_usage the KeyUsage bits, or 0 when the extension is absent
85 * @var X509Cert::path_len basicConstraints pathLenConstraint, when stated
86 * @var X509Cert::version 0, 1 or 2 for v1, v2, v3 (sec 4.1.2.1)
87 * @var X509Cert::is_ca basicConstraints cA (sec 4.2.1.9)
88 * @var X509Cert::has_bc the basicConstraints extension was present at all
89 * @var X509Cert::has_ku the keyUsage extension was present at all
90 * @var X509Cert::has_path_len pathLenConstraint was stated
91 */
116
118
119#endif // PROTOCORE_X509_TYPES_H
PROTO_ENUM_PACKED
Application protocol spoken on a listener port or connection slot.
A run of the caller's bytes: where a field is, and how much of it there is.
Definition x509_types.h:63
size_t len
how many octets
Definition x509_types.h:65
const uint8_t * p
into the caller's encoding
Definition x509_types.h:64
X509Bytes serial
Definition x509_types.h:95
X509Bytes issuer
Definition x509_types.h:96
X509Bytes spki
Definition x509_types.h:98
protocore_x509_sig_alg sig_alg
Definition x509_types.h:106
X509Bytes san
Definition x509_types.h:101
X509Bytes tbs
Definition x509_types.h:94
proto_bool has_bc
Definition x509_types.h:112
proto_bool has_ku
Definition x509_types.h:113
uint64_t not_after
Definition x509_types.h:104
protocore_x509_key_alg key_alg
Definition x509_types.h:107
proto_bool is_ca
Definition x509_types.h:111
X509Bytes sig
Definition x509_types.h:100
uint32_t path_len
Definition x509_types.h:109
X509Bytes subject
Definition x509_types.h:97
X509Bytes key
Definition x509_types.h:99
uint64_t not_before
Definition x509_types.h:103
uint8_t version
Definition x509_types.h:110
proto_bool has_path_len
Definition x509_types.h:114
uint16_t key_usage
Definition x509_types.h:108
#define PROTOCORE_BEGIN_DECLS
Give a header's declarations C linkage, so their symbol names carry no parameter types.
Definition types.h:96
_Bool proto_bool
The truth value.
Definition types.h:64
#define PROTOCORE_END_DECLS
Definition types.h:97
enum PROTO_ENUM_PACKED protocore_x509_key_alg
The public key algorithms this profile reads (RFC 5280 sec 4.1.2.7).
@ PROTOCORE_X509_SIG_ED25519
id-Ed25519, 1.3.101.112 (RFC 8410 sec 3)
Definition x509_types.h:38
@ PROTOCORE_X509_SIG_RSA_SHA256
sha256WithRSAEncryption, {pkcs-1 11} (RFC 8017 A.2.4)
Definition x509_types.h:32
@ PROTOCORE_X509_SIG_UNKNOWN
an algorithm this build does not verify
Definition x509_types.h:31
@ PROTOCORE_X509_SIG_ECDSA_SHA256
ecdsa-with-SHA256, 1.2.840.10045.4.3.2 (RFC 5480 sec 2.1.1)
Definition x509_types.h:36
@ PROTOCORE_X509_KEY_ED25519
id-Ed25519 (RFC 8410 sec 4)
Definition x509_types.h:47
@ PROTOCORE_X509_SIG_RSA_SHA384
sha384WithRSAEncryption, {pkcs-1 12}
Definition x509_types.h:33
@ PROTOCORE_X509_KEY_RSA
rsaEncryption, {pkcs-1 1}
Definition x509_types.h:45
@ PROTOCORE_X509_SIG_RSA_SHA512
sha512WithRSAEncryption, {pkcs-1 13}
Definition x509_types.h:34
@ PROTOCORE_X509_SIG_ECDSA_SHA384
ecdsa-with-SHA384, 1.2.840.10045.4.3.3
Definition x509_types.h:37
@ PROTOCORE_X509_KEY_EC_P256
id-ecPublicKey over secp256r1 (RFC 5480 sec 2.1.1)
Definition x509_types.h:46
@ PROTOCORE_X509_KEY_UNKNOWN
an algorithm this build cannot use
Definition x509_types.h:44
@ PROTOCORE_X509_SIG_RSA_PSS
id-RSASSA-PSS, {pkcs-1 10}
Definition x509_types.h:35
PROTOCORE_BEGIN_DECLS enum PROTO_ENUM_PACKED protocore_x509_sig_alg
The signature algorithms this profile reads (RFC 5280 sec 4.1.1.2).