24#ifndef PROTOCORE_X509_VERIFY_H
25#define PROTOCORE_X509_VERIFY_H
118 void (*
const signature)(uint8_t *work);
119 void (*
const validity)(uint8_t *work);
120 void (*
const may_sign)(uint8_t *work);
121 void (*
const link)(uint8_t *work);
122 void (*
const message)(uint8_t *work);
137static const X509VerifyNs X509Verify __attribute__((unused)) = {
PROTO_ENUM_PACKED
Application protocol spoken on a listener port or connection slot.
What an issuer check is given: the candidate, and how far down the chain it sits.
uint32_t depth
certificates below it in the path, 0 for the one that signs a leaf
const X509Cert * issuer
the candidate issuer
What a signature check is given: the certificate, and the one whose key signed it.
const X509Cert * cert
the certificate being checked
const X509Cert * issuer
the certificate whose subjectPublicKey signed it
What a message check is given: whose key verifies it, and the bytes it covers.
const uint8_t * msg
the bytes signed
const uint8_t * sig
the signature over them
const X509Cert * signer
the certificate whose subjectPublicKey verifies
protocore_x509_sig_alg alg
the scheme the signature is in
What a time check is given.
uint64_t now
seconds since the POSIX epoch
const X509Cert * cert
the certificate being checked
void(*const signature)(uint8_t *work)
X509MessageArgs message_args
protocore_x509_status status
X509IssuerArgs issuer_args
#define PROTOCORE_BEGIN_DECLS
Give a header's declarations C linkage, so their symbol names carry no parameter types.
_Bool proto_bool
The truth value.
#define PROTOCORE_END_DECLS
What a certificate SAYS, as types: the algorithm identifiers and the parsed view.
PROTOCORE_BEGIN_DECLS enum PROTO_ENUM_PACKED protocore_x509_sig_alg
The signature algorithms this profile reads (RFC 5280 sec 4.1.1.2).
PROTOCORE_BEGIN_DECLS enum PROTO_ENUM_PACKED protocore_x509_status
Why a link was refused. A caller that only needs yes or no reads ::X509VerifyNs::ok.
void protocore_x509_verify_validity(uint8_t *work)
void protocore_x509_verify_signature(uint8_t *work)
X509VerifyVars X509VerifyV
The operands and the outcome.
@ PROTOCORE_X509_OK
the link holds
@ PROTOCORE_X509_ERR_ISSUER_NAME
sec 6.1.3 (a)(4): the issuer name is not the subject above it
@ PROTOCORE_X509_ERR_NOT_A_CA
sec 6.1.4 (k): the issuer has no basicConstraints cA TRUE
@ PROTOCORE_X509_ERR_PATH_LEN
sec 6.1.4 (m): pathLenConstraint does not reach this far
@ PROTOCORE_X509_ERR_KEY_MALFORMED
the issuer's public key did not decode
@ PROTOCORE_X509_ERR_EXPIRED
sec 6.1.3 (a)(2): the current time is after notAfter
@ PROTOCORE_X509_ERR_ARGS
a certificate was not supplied
@ PROTOCORE_X509_ERR_SIG_MALFORMED
the signature did not decode
@ PROTOCORE_X509_ERR_NOT_YET_VALID
sec 6.1.3 (a)(2): the current time is before notBefore
@ PROTOCORE_X509_ERR_ALG_UNSUPPORTED
an algorithm this build does not verify
@ PROTOCORE_X509_ERR_BAD_SIGNATURE
it decoded, and it does not verify
@ PROTOCORE_X509_ERR_NO_CERT_SIGN
sec 6.1.4 (n): the issuer's keyUsage omits keyCertSign
uint8_t * protocore_x509_verify_span(void)
The PROTOCORE_X509_VERIFY_BORROW bytes a signature check runs out of.
void protocore_x509_verify_link(uint8_t *work)
void protocore_x509_verify_message(uint8_t *work)
void protocore_x509_verify_may_sign(uint8_t *work)