|
ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
|
Is this certificate signed by that one, and may that one sign it at all. More...
#include "crypto/x509/x509_types/x509_types.h"Go to the source code of this file.
Classes | |
| struct | X509LinkArgs |
| What a signature check is given: the certificate, and the one whose key signed it. More... | |
| struct | X509TimeArgs |
| What a time check is given. More... | |
| struct | X509IssuerArgs |
| What an issuer check is given: the candidate, and how far down the chain it sits. More... | |
| struct | X509MessageArgs |
| What a message check is given: whose key verifies it, and the bytes it covers. More... | |
| struct | X509VerifyVars |
| struct | X509VerifyNs |
| The entries. More... | |
Typedefs | |
| typedef PROTOCORE_BEGIN_DECLS enum PROTO_ENUM_PACKED | protocore_x509_status |
| Why a link was refused. A caller that only needs yes or no reads ::X509VerifyNs::ok. | |
Enumerations | |
| enum | PROTO_ENUM_PACKED { PROTOCORE_X509_OK = 0 , PROTOCORE_X509_ERR_ARGS , PROTOCORE_X509_ERR_ISSUER_NAME , PROTOCORE_X509_ERR_NOT_YET_VALID , PROTOCORE_X509_ERR_EXPIRED , PROTOCORE_X509_ERR_NOT_A_CA , PROTOCORE_X509_ERR_NO_CERT_SIGN , PROTOCORE_X509_ERR_PATH_LEN , PROTOCORE_X509_ERR_ALG_UNSUPPORTED , PROTOCORE_X509_ERR_KEY_MALFORMED , PROTOCORE_X509_ERR_SIG_MALFORMED , PROTOCORE_X509_ERR_BAD_SIGNATURE } |
| Why a link was refused. A caller that only needs yes or no reads ::X509VerifyNs::ok. More... | |
Functions | |
| void | protocore_x509_verify_signature (uint8_t *work) |
| void | protocore_x509_verify_validity (uint8_t *work) |
| void | protocore_x509_verify_may_sign (uint8_t *work) |
| void | protocore_x509_verify_link (uint8_t *work) |
| void | protocore_x509_verify_message (uint8_t *work) |
| uint8_t * | protocore_x509_verify_span (void) |
| The PROTOCORE_X509_VERIFY_BORROW bytes a signature check runs out of. | |
Variables | |
| X509VerifyVars | X509VerifyV |
| The operands and the outcome. | |
Is this certificate signed by that one, and may that one sign it at all.
RFC 5280 sec 6.1.3 (a): a certificate is checked against a working public key, a working issuer name and the current time. This is that check for one link of a chain - the leaf against its issuer - and the per-certificate conditions sec 6.1.4 (k), (l) and (n) put on an issuer before it is allowed to have signed anything.
Every check is separate and each reports its own verdict, so a caller that fails one knows which. A link that passes X509VerifyNs::link has been checked on all of them; the individual entries exist because a chain walk needs them at different points and a test needs them apart.
The signature covers the TBSCertificate's own octets (sec 4.1.1.2), which X509Cert::tbs carries unmodified, so nothing is re-encoded on the way to the verifier.
Definition in file x509_verify.h.
| typedef PROTOCORE_BEGIN_DECLS enum PROTO_ENUM_PACKED protocore_x509_status |
Why a link was refused. A caller that only needs yes or no reads ::X509VerifyNs::ok.
| enum PROTO_ENUM_PACKED |
Why a link was refused. A caller that only needs yes or no reads ::X509VerifyNs::ok.
Definition at line 32 of file x509_verify.h.
| void protocore_x509_verify_signature | ( | uint8_t * | work | ) |
| void protocore_x509_verify_validity | ( | uint8_t * | work | ) |
| void protocore_x509_verify_may_sign | ( | uint8_t * | work | ) |
| void protocore_x509_verify_link | ( | uint8_t * | work | ) |
| void protocore_x509_verify_message | ( | uint8_t * | work | ) |
| uint8_t * protocore_x509_verify_span | ( | void | ) |
The PROTOCORE_X509_VERIFY_BORROW bytes a signature check runs out of.
Stated beside the namespace rather than on it: an entry takes a borrow, and this is where that borrow comes from. RSA is what sizes it - a 2048-bit verification works over the modulus.
|
extern |
The operands and the outcome.