hx509_revoke (3) - Linux Manuals
NAME
hx509 revokation checking functions -
Functions
int hx509_ocsp_request (hx509_context, hx509_certs, hx509_certs, hx509_cert, const AlgorithmIdentifier *, heim_octet_string *, heim_octet_string *)
int hx509_revoke_add_crl (hx509_context, hx509_revoke_ctx, const char *)
int hx509_revoke_add_ocsp (hx509_context, hx509_revoke_ctx, const char *)
void hx509_revoke_free (hx509_revoke_ctx *)
int hx509_revoke_init (hx509_context, hx509_revoke_ctx *)
int hx509_revoke_ocsp_print (hx509_context, const char *, FILE *)
int hx509_revoke_verify (hx509_context, hx509_revoke_ctx, hx509_certs, time_t, hx509_cert, hx509_cert)
Detailed Description
See the Revocation methods for description and examples.
Function Documentation
int hx509_ocsp_request (hx509_contextcontext, hx509_certsreqcerts, hx509_certspool, hx509_certsigner, const AlgorithmIdentifier *digest, heim_octet_string *request, heim_octet_string *nonce)
Create an OCSP request for a set of certificates.Parameters:
- 
context a hx509 context 
 reqcerts list of certificates to request ocsp data for
 pool certificate pool to use when signing
 signer certificate to use to sign the request
 digest the signing algorithm in the request, if NULL use the default signature algorithm,
 request the encoded request, free with free_heim_octet_string().
 nonce nonce in the request, free with free_heim_octet_string().
Returns:
- An hx509 error code, see hx509_get_error_string().
int hx509_revoke_add_crl (hx509_contextcontext, hx509_revoke_ctxctx, const char *path)
Add a CRL file to the revokation context.Parameters:
- 
context hx509 context 
 ctx hx509 revokation context
 path path to file that is going to be added to the context.
Returns:
- An hx509 error code, see hx509_get_error_string().
int hx509_revoke_add_ocsp (hx509_contextcontext, hx509_revoke_ctxctx, const char *path)
Add a OCSP file to the revokation context.Parameters:
- 
context hx509 context 
 ctx hx509 revokation context
 path path to file that is going to be added to the context.
Returns:
- An hx509 error code, see hx509_get_error_string().
void hx509_revoke_free (hx509_revoke_ctx *ctx)
Free a hx509 revokation context.Parameters:
- ctx context to be freed
int hx509_revoke_init (hx509_contextcontext, hx509_revoke_ctx *ctx)
Allocate a revokation context. Free with hx509_revoke_free().Parameters:
- 
context A hx509 context. 
 ctx returns a newly allocated revokation context.
Returns:
- An hx509 error code, see hx509_get_error_string().
int hx509_revoke_ocsp_print (hx509_contextcontext, const char *path, FILE *out)
Print the OCSP reply stored in a file.Parameters:
- 
context a hx509 context 
 path path to a file with a OCSP reply
 out the out FILE descriptor to print the reply on
Returns:
- An hx509 error code, see hx509_get_error_string().
int hx509_revoke_verify (hx509_contextcontext, hx509_revoke_ctxctx, hx509_certscerts, time_tnow, hx509_certcert, hx509_certparent_cert)
Check that a certificate is not expired according to a revokation context. Also need the parent certificte to the check OCSP parent identifier.Parameters:
- 
context hx509 context 
 ctx hx509 revokation context
 certs
 now
 cert
 parent_cert
Returns:
- An hx509 error code, see hx509_get_error_string().
Author
Generated automatically by Doxygen for Heimdalx509library from the source code.