X509_LOOKUP_add_dir function

  1. @RecordUse.new()
  2. @Native<Int Function(Pointer<X509_LOOKUP>, Pointer<Char>, Int)>(ffi.Pointer<X509_LOOKUP>, ffi.Pointer<ffi.Char>, ffi.Int)>(symbol: 'bssl_dart_X509_LOOKUP_add_dir')
int X509_LOOKUP_add_dir(
  1. Pointer<X509_LOOKUP> lookup,
  2. Pointer<Char> path,
  3. int type
)

X509_LOOKUP_add_dir configures |lookup| to load CRLs and trusted certificates from the directories in |path|. It returns one on success and zero on error. |lookup| must have been constructed with |X509_LOOKUP_hash_dir|.

WARNING: |path| is interpreted as a colon-separated (semicolon-separated on Windows) list of paths. It is not possible to configure a path containing the separator character. https://crbug.com/boringssl/691 tracks removing this behavior.

|type| should be one of the |X509_FILETYPE_*| constants and determines the format of the files. If |type| is |X509_FILETYPE_DEFAULT|, |path| is ignored and some default system path is used with |X509_FILETYPE_PEM|. See also |X509_STORE_set_default_paths|.

Trusted certificates should be named HASH.N and CRLs should be named HASH.rN. HASH is |X509_NAME_hash| of the certificate subject and CRL issuer, respectively, in hexadecimal. N is in decimal and counts hash collisions consecutively, starting from zero. For example, "002c0b4f.0" and "002c0b4f.r0".

WARNING: Objects from |path| are loaded on demand, but cached in memory on the |X509_STORE|. If a CA is removed from the directory, existing |X509_STORE|s will continue to trust it. Cache entries are not evicted for the lifetime of the |X509_STORE|.

WARNING: This mechanism is also not well-suited for CRL updates. |X509_STORE|s rely on this cache and never load the same CRL file twice. CRL updates must use a new file, with an incremented suffix, to be reflected in existing |X509_STORE|s. However, this means each CRL update will use additional storage and memory. Instead, configure inputs that vary per verification, such as CRLs, on each |X509_STORE_CTX| separately, using functions like |X509_STORE_CTX_set0_crl|.

Implementation

@meta.RecordUse()
@ffi.Native<
  ffi.Int Function(ffi.Pointer<X509_LOOKUP>, ffi.Pointer<ffi.Char>, ffi.Int)
>(symbol: 'bssl_dart_X509_LOOKUP_add_dir')
external int X509_LOOKUP_add_dir(
  ffi.Pointer<X509_LOOKUP> lookup,
  ffi.Pointer<ffi.Char> path,
  int type,
);