bindings library

Raw ffigen-generated BoringSSL C bindings (bssl_dart), OPENSSL_cleanse-backed opensslAllocator, scoped BoringArena, and NativeHandle finalizer wrapper.

Classes

ACCESS_DESCRIPTION_st
An ACCESS_DESCRIPTION represents an AccessDescription structure (RFC 5280).
aes_key_st
aes_key_st should be an opaque type, but EVP requires that the size be known.
ASN1_ITEM_st
asn1_null_st
asn1_object_st
asn1_pctx_st
asn1_string_st
An asn1_string_st (aka |ASN1_STRING|) represents a value of a string-like ASN.1 type. It contains a |type| field, and a byte string |data| field with a type-specific representation. This type-specific representation does not always correspond to the DER encoding of the type.
asn1_type_st
An asn1_type_st (aka |ASN1_TYPE|) represents an arbitrary ASN.1 element, typically used for ANY types. It contains a |type| field and a |value| union dependent on |type|.
ASN1_VALUE_st
AUTHORITY_KEYID_st
A AUTHORITY_KEYID_st, aka |AUTHORITY_KEYID|, represents an AuthorityKeyIdentifier structure (RFC 5280).
BASIC_CONSTRAINTS_st
A BASIC_CONSTRAINTS_st, aka |BASIC_CONSTRAINTS| represents an BasicConstraints structure (RFC 5280).
bignum_ctx
bignum_st
Private functions
bio_method_st
bio_st
blake2b_state_st
bn_gencb_st
bn_gencb_st, or |BN_GENCB|, holds a callback function that is used by generation functions that can take a very long time to complete. Use |BN_GENCB_set| to initialise a |BN_GENCB| structure.
bn_mont_ctx_st
bn_primality_result_t
bn_primality_result_t enumerates the outcomes of primality-testing.
BoringArena
A scoped ffi.Allocator and resource tracker for calling BoringSSL.
buf_mem_st
buf_mem_st (aka |BUF_MEM|) is a generic buffer object used by OpenSSL.
cbb_buffer_st
cbb_child_st
cbb_st
cbs_st
CRYPTO ByteString
cmac_ctx_st
CMS_ContentInfo_st
CMS_SignerInfo_st
conf_st
conf_value_st
Config files.
crypto_buffer_pool_st
crypto_buffer_st
CRYPTO_dynlock
CRYPTO_dynlock_value
crypto_ex_data_st
crypto_iovec_st
crypto_iovec_st (aka |CRYPTO_IOVEC| combines a pointer to input data and a pointer to an output buffer with their common length. It is usually passed as an array of length of at most |CRYPTO_IOVEC_MAX|.
crypto_ivec_st
crypto_ivec_st (aka |CRYPTO_IVEC|) combines a pointer to input data with its length. It is usually passed as an array of length of at most |CRYPTO_IOVEC_MAX|.
crypto_must_be_null_st
ctr_drbg_state_st
dh_st
DIST_POINT_NAME_st
A DIST_POINT_NAME represents a DistributionPointName structure (RFC 5280). The |name| field contains the CHOICE value and is determined by |type|. If |type| is zero, |name| must be a |fullname|. If |type| is one, |name| must be a |relativename|.
DIST_POINT_st
A DIST_POINT_st, aka |DIST_POINT|, represents a DistributionPoint structure (RFC 5280).
div_t
drand48_data
DSA_SIG_st
DSA_SIG_st (aka |DSA_SIG|) contains a DSA signature as a pair of integers.
dsa_st
EC_builtin_curve
EC_builtin_curve describes a supported elliptic curve.
ec_group_st
ec_key_st
ec_method_st
ec_point_st
ecdsa_method_st
ecdsa_method_st is a structure of function pointers for implementing ECDSA. See engine.h.
ecdsa_sig_st
Low-level signing and verification.
EDIPartyName_st
engine_st
env_md_ctx_st
env_md_ctx_st is typoed ("evp" -> "env"), but the typo comes from OpenSSL and some consumers forward-declare these structures so we're leaving it alone.
env_md_st
evp_aead_ctx_st
An evp_aead_ctx_st (typedefed as |EVP_AEAD_CTX| in base.h) represents an AEAD algorithm configured with a specific key and message-independent IV.
evp_aead_ctx_st_state
AEAD operations.
evp_aead_direction_t
evp_aead_direction_t denotes the direction of an AEAD operation.
evp_aead_st
evp_cipher_ctx_st
evp_cipher_info_st
evp_cipher_st
evp_encode_ctx_st
evp_hpke_aead_st
evp_hpke_ctx_st
evp_hpke_kdf_st
evp_hpke_kem_st
evp_hpke_key_st
evp_kem_st
evp_md_pctx_ops
Internal constants and structures (hidden).
evp_pkey_alg_st
evp_pkey_ctx_st
evp_pkey_st
fd_set
fips_counter_t
fips_counter_t denotes specific APIs/algorithms. A counter is maintained for each in FIPS mode so that tests can be written to assert that the expected, FIPS functions are being called by a certain piece of code.
GENERAL_NAME_st
A GENERAL_NAME_st, aka |GENERAL_NAME|, represents an X.509 GeneralName. The |type| field determines which member of |d| is active. A |GENERAL_NAME| may also be empty, in which case |type| is -1 and |d| is NULL. Empty |GENERAL_NAME|s are invalid and will never be returned from the parser, but may be created temporarily, e.g. by |GENERAL_NAME_new|.
GENERAL_SUBTREE_st
A GENERAL_SUBTREE represents a GeneralSubtree structure (RFC 5280).
hmac_ctx_st
Private functions
imaxdiv_t
ISSUING_DIST_POINT_st
A ISSUING_DIST_POINT_st, aka |ISSUING_DIST_POINT|, represents a IssuingDistributionPoint structure (RFC 5280).
itimerspec
ldiv_t
lldiv_t
max_align_t
md4_state_st
md5_state_st
NAME_CONSTRAINTS_st
A NAME_CONSTRAINTS_st, aka |NAME_CONSTRAINTS|, represents a NameConstraints structure (RFC 5280).
NativeHandle<T extends NativeType>
A GC-managed wrapper around a BoringSSL Pointer<T> that attaches a shared ffi.NativeFinalizer and supports deterministic dispose.
Netscape_spkac_st
A Netscape_spkac_st, or |NETSCAPE_SPKAC|, represents a PublicKeyAndChallenge structure. This type is misnamed. The full SPKAC includes the signature, which is represented with the |NETSCAPE_SPKI| type.
Netscape_spki_st
A Netscape_spki_st, or |NETSCAPE_SPKI|, represents a SignedPublicKeyAndChallenge structure. Although this structure contains a |spkac| field of type |NETSCAPE_SPKAC|, these are misnamed. The SPKAC is the entire structure, not the signed portion.
NOTICEREF_st
A NOTICEREF represents a NoticeReference structure (RFC 5280).
obj_name_st
Deprecated functions.
openssl_method_common_st
openssl_method_common_st contains the common part of all method structures. This must be the first member of all method structures.
OpenSslAllocator
Implementation of ffi.Allocator using OPENSSL_malloc and OPENSSL_free.
ossl_init_settings_st
ossl_lib_ctx_st
ossl_param_st
otherName_st
General names.
pkcs12_st
PKCS7
PKCS7_SIGN_ENVELOPE
PKCS7_SIGNED
Deprecated functions.
pkcs8_priv_key_info_st
point_conversion_form_t
point_conversion_form_t enumerates forms, as defined in X9.62 (ECDSA), for the encoding of a elliptic curve point (x,y)
POLICY_CONSTRAINTS_st
A POLICY_CONSTRAINTS represents a PolicyConstraints structure (RFC 5280).
POLICY_MAPPING_st
A POLICY_MAPPING represents an individual element of a PolicyMappings structure (RFC 5280).
POLICYINFO_st
A POLICYINFO represents a PolicyInformation structure (RFC 5280).
POLICYQUALINFO_st
A POLICYQUALINFO represents a PolicyQualifierInfo structure (RFC 5280). |d| contains the qualifier field of the PolicyQualifierInfo. Its type is determined by |pqualid|. If |pqualid| is |NID_id_qt_cps|, |d| must be |cpsuri|. If |pqualid| is |NID_id_qt_unotice|, |d| must be |usernotice|. Otherwise, |d| must be |other|.
private_key_st
X.509 information.
rand_meth_st
rand_meth_st is typedefed to |RAND_METHOD| in base.h. It isn't used; it exists only to be the return type of |RAND_SSLeay|. It's external so that variables of this type can be initialized.
random_data
rc4_key_st
RIPEMD160state_st
rsa_meth_st
rsa_pss_params_st
An rsa_pss_params_st, aka |RSA_PSS_PARAMS|, represents a parsed RSASSA-PSS-params structure, as defined in (RFC 4055).
rsa_st
sha256_state_st
sha512_state_st
sha_state_st
sigevent
spake2_ctx_st
spake2_role_t
spake2_role_t enumerates the different “roles” in SPAKE2. The protocol requires that the symmetry of the two parties be broken so one participant must be “Alice” and the other be “Bob”.
srtp_protection_profile_st
ssl_cipher_st
ssl_credential_st
ssl_ctx_st
ssl_early_callback_ctx
ssl_ech_keys_st
ssl_method_st
ssl_private_key_method_st
ssl_quic_method_st
ssl_session_st
ssl_st
ssl_ticket_aead_method_st
st_ERR_FNS
stack_st
stack_st_ACCESS_DESCRIPTION
stack_st_ASN1_INTEGER
Integers and enumerated values.
stack_st_ASN1_OBJECT
Object identifiers.
stack_st_ASN1_TYPE
stack_st_BIO
Allocation and freeing.
stack_st_CONF_VALUE
stack_st_CRYPTO_BUFFER
PKCS#7.
stack_st_DIST_POINT
stack_st_GENERAL_NAME
stack_st_GENERAL_SUBTREE
stack_st_OPENSSL_STRING
stack_st_POLICY_MAPPING
stack_st_POLICYINFO
stack_st_POLICYQUALINFO
stack_st_void
stack_st_X509
stack_st_X509_ALGOR
Algorithm identifiers.
stack_st_X509_ATTRIBUTE
Attributes.
stack_st_X509_CRL
stack_st_X509_EXTENSION
Extension lists.
stack_st_X509_INFO
stack_st_X509_NAME
stack_st_X509_NAME_ENTRY
Names.
stack_st_X509_OBJECT
stack_st_X509_REVOKED
timespec
timeval
tm
trust_token_client_st
trust_token_issuer_st
trust_token_method_st
trust_token_st
UnnamedStruct
UnnamedStruct$1
UnnamedUnion
UnnamedUnion$1
UnnamedUnion$2
md_data contains the hash-specific context.
UnnamedUnion$3
UnnamedUnion$4
UnnamedUnion$5
UnnamedUnion$6
UnnamedUnion$7
wpa_supplicant accesses |h0|..|h4| so we must support those names for compatibility with it until it can be updated. Anonymous unions are only standard in C11, so disable this workaround in C++.
UnnamedUnion$8
USERNOTICE_st
A USERNOTICE represents a UserNotice structure (RFC 5280).
v3_ext_ctx
v3_ext_ctx, aka |X509V3_CTX|, contains additional context information for constructing extensions. Some string formats reference additional values in these objects. It must be initialized with |X509V3_set_ctx| or |X509V3_set_ctx_test| before use.
v3_ext_method
A v3_ext_method, aka |X509V3_EXT_METHOD|, is a deprecated type which defines a custom extension.
X509_algor_st
Private structures.
x509_attributes_st
X509_crl_st
X509_extension_st
X509_info_st
x509_lookup_method_st
x509_lookup_st
X509_name_entry_st
X509_name_st
x509_object_st
X509_pubkey_st
x509_purpose_st
X509_req_st
x509_revoked_st
X509_sig_st
x509_st
x509_store_ctx_st
x509_store_st
X509_VERIFY_PARAM_st

Extensions

AllocatorCopyBytes on Allocator
Copies Dart bytes into native memory.
CbbToBytes on Pointer<CBB>
Reads the contents of a CBB.
EvpPKeyInvoke2First on R Function(Pointer<EVP_PKEY>, A1)
Convenience extension to invoke a 2-argument C function (Pointer<EVP_PKEY>, A1) with a NativeHandle.
EvpPKeyInvoke2Last on R Function(A1, Pointer<EVP_PKEY>)
Convenience extension to invoke a 2-argument C function (A1, Pointer<EVP_PKEY>) with a NativeHandle.
NativeHandleInvoke1 on R Function(Pointer<P>)
Convenience extension to invoke a 1-argument C function taking Pointer<P> with a NativeHandle.
NativeHandleInvoke5Last on R Function(A1, A2, A3, A4, Pointer<P>)
Convenience extension to invoke a 5-argument C function (A1, A2, A3, A4, Pointer<P>) with a NativeHandle.
SymbolAddresses on _SymbolAddresses
The addresses of the functions releasing BoringSSL objects, for NativeFinalizers.

Constants

addresses → const _SymbolAddresses
AES_BLOCK_SIZE → const int
AES_DECRYPT → const int
AES_ENCRYPT → const int
AES_MAXNR → const int
CBS_ASN1_APPLICATION → const int
CBS_ASN1_BITSTRING → const int
CBS_ASN1_BMPSTRING → const int
CBS_ASN1_BOOLEAN → const int
CBS_ASN1_CLASS_MASK → const int
CBS_ASN1_CONSTRUCTED → const int
CBS_ASN1_CONTEXT_SPECIFIC → const int
CBS_ASN1_ENUMERATED → const int
CBS_ASN1_GENERALIZEDTIME → const int
CBS_ASN1_GENERALSTRING → const int
CBS_ASN1_GRAPHICSTRING → const int
CBS_ASN1_IA5STRING → const int
CBS_ASN1_INTEGER → const int
CBS_ASN1_NULL → const int
CBS_ASN1_NUMERICSTRING → const int
CBS_ASN1_OBJECT → const int
CBS_ASN1_OCTETSTRING → const int
CBS_ASN1_PRINTABLESTRING → const int
CBS_ASN1_PRIVATE → const int
CBS_ASN1_SEQUENCE → const int
CBS_ASN1_SET → const int
CBS_ASN1_T61STRING → const int
CBS_ASN1_TAG_NUMBER_MASK → const int
CBS_ASN1_TAG_SHIFT → const int
CBS_ASN1_UNIVERSAL → const int
CBS_ASN1_UNIVERSALSTRING → const int
CBS_ASN1_UTCTIME → const int
CBS_ASN1_UTF8STRING → const int
CBS_ASN1_VIDEOTEXSTRING → const int
CBS_ASN1_VISIBLESTRING → const int
EC_PKEY_NO_PARAMETERS → const int
EC_PKEY_NO_PUBKEY → const int
EC_R_BIGNUM_OUT_OF_RANGE → const int
EC_R_BUFFER_TOO_SMALL → const int
EC_R_COORDINATES_OUT_OF_RANGE → const int
EC_R_D2I_ECPKPARAMETERS_FAILURE → const int
EC_R_DECODE_ERROR → const int
EC_R_EC_GROUP_NEW_BY_NAME_FAILURE → const int
EC_R_ENCODE_ERROR → const int
EC_R_GROUP2PKPARAMETERS_FAILURE → const int
EC_R_GROUP_MISMATCH → const int
EC_R_I2D_ECPKPARAMETERS_FAILURE → const int
EC_R_INCOMPATIBLE_OBJECTS → const int
EC_R_INVALID_COFACTOR → const int
EC_R_INVALID_COMPRESSED_POINT → const int
EC_R_INVALID_COMPRESSION_BIT → const int
EC_R_INVALID_ENCODING → const int
EC_R_INVALID_FIELD → const int
EC_R_INVALID_FORM → const int
EC_R_INVALID_GROUP_ORDER → const int
EC_R_INVALID_PRIVATE_KEY → const int
EC_R_INVALID_SCALAR → const int
EC_R_MISSING_PARAMETERS → const int
EC_R_MISSING_PRIVATE_KEY → const int
EC_R_NON_NAMED_CURVE → const int
EC_R_NOT_INITIALIZED → const int
EC_R_PKPARAMETERS2GROUP_FAILURE → const int
EC_R_POINT_AT_INFINITY → const int
EC_R_POINT_IS_NOT_ON_CURVE → const int
EC_R_PUBLIC_KEY_VALIDATION_FAILED → const int
EC_R_SLOT_FULL → const int
EC_R_UNDEFINED_GENERATOR → const int
EC_R_UNKNOWN_GROUP → const int
EC_R_UNKNOWN_ORDER → const int
EC_R_WRONG_CURVE_PARAMETERS → const int
EC_R_WRONG_ORDER → const int
ERR_LIB_ASN1 → const int
ERR_LIB_BIO → const int
ERR_LIB_BN → const int
ERR_LIB_BUF → const int
ERR_LIB_CIPHER → const int
ERR_LIB_CMS → const int
ERR_LIB_COMP → const int
ERR_LIB_CONF → const int
ERR_LIB_CRYPTO → const int
ERR_LIB_DH → const int
ERR_LIB_DIGEST → const int
ERR_LIB_DSA → const int
ERR_LIB_EC → const int
ERR_LIB_ECDH → const int
ERR_LIB_ECDSA → const int
ERR_LIB_ENGINE → const int
ERR_LIB_EVP → const int
ERR_LIB_HKDF → const int
ERR_LIB_HMAC → const int
ERR_LIB_NONE → const int
ERR_LIB_OBJ → const int
ERR_LIB_OCSP → const int
ERR_LIB_PEM → const int
ERR_LIB_PKCS7 → const int
ERR_LIB_PKCS8 → const int
ERR_LIB_RAND → const int
ERR_LIB_RSA → const int
ERR_LIB_SSL → const int
ERR_LIB_SYS → const int
ERR_LIB_TRUST_TOKEN → const int
ERR_LIB_UI → const int
ERR_LIB_USER → const int
ERR_LIB_X509 → const int
ERR_LIB_X509V3 → const int
EVP_AEAD_DEFAULT_TAG_LENGTH → const int
EVP_AEAD_MAX_KEY_LENGTH → const int
EVP_AEAD_MAX_NONCE_LENGTH → const int
EVP_AEAD_MAX_OPEN_OVERHEAD → const int
EVP_AEAD_MAX_OVERHEAD → const int
EVP_CIPH_ALWAYS_CALL_INIT → const int
EVP_CIPH_CBC_MODE → const int
EVP_CIPH_CCM_MODE → const int
EVP_CIPH_CFB_MODE → const int
EVP_CIPH_CTR_MODE → const int
EVP_CIPH_CTRL_INIT → const int
EVP_CIPH_CUSTOM_COPY → const int
EVP_CIPH_CUSTOM_IV → const int
EVP_CIPH_ECB_MODE → const int
EVP_CIPH_FLAG_AEAD_CIPHER → const int
EVP_CIPH_FLAG_CUSTOM_CIPHER → const int
EVP_CIPH_FLAG_NON_FIPS_ALLOW → const int
EVP_CIPH_GCM_MODE → const int
EVP_CIPH_NO_PADDING → const int
EVP_CIPH_OCB_MODE → const int
EVP_CIPH_OFB_MODE → const int
EVP_CIPH_STREAM_CIPHER → const int
EVP_CIPH_VARIABLE_LENGTH → const int
EVP_CIPH_WRAP_MODE → const int
EVP_CIPH_XTS_MODE → const int
EVP_CIPHER_CTX_FLAG_WRAP_ALLOW → const int
EVP_CTRL_AEAD_GET_TAG → const int
EVP_CTRL_AEAD_SET_IV_FIXED → const int
EVP_CTRL_AEAD_SET_IVLEN → const int
EVP_CTRL_AEAD_SET_MAC_KEY → const int
EVP_CTRL_AEAD_SET_TAG → const int
EVP_CTRL_COPY → const int
EVP_CTRL_GCM_GET_TAG → const int
EVP_CTRL_GCM_IV_GEN → const int
EVP_CTRL_GCM_SET_IV_FIXED → const int
EVP_CTRL_GCM_SET_IV_INV → const int
EVP_CTRL_GCM_SET_IVLEN → const int
EVP_CTRL_GCM_SET_TAG → const int
EVP_CTRL_GET_IVLEN → const int
EVP_CTRL_GET_RC2_KEY_BITS → const int
EVP_CTRL_GET_RC5_ROUNDS → const int
EVP_CTRL_INIT → const int
EVP_CTRL_PBE_PRF_NID → const int
EVP_CTRL_RAND_KEY → const int
EVP_CTRL_SET_KEY_LENGTH → const int
EVP_CTRL_SET_RC2_KEY_BITS → const int
EVP_CTRL_SET_RC5_ROUNDS → const int
EVP_GCM_TLS_EXPLICIT_IV_LEN → const int
EVP_GCM_TLS_FIXED_IV_LEN → const int
EVP_GCM_TLS_TAG_LEN → const int
EVP_MAX_BLOCK_LENGTH → const int
EVP_MAX_IV_LENGTH → const int
EVP_MAX_KEY_LENGTH → const int
EVP_MAX_MD_BLOCK_SIZE → const int
EVP_MAX_MD_DATA_SIZE → const int
EVP_MAX_MD_SIZE → const int
EVP_MD_CTX_FLAG_NON_FIPS_ALLOW → const int
EVP_MD_FLAG_DIGALGID_ABSENT → const int
EVP_MD_FLAG_XOF → const int
EVP_PKEY_DH → const int
EVP_PKEY_DSA → const int
EVP_PKEY_EC → const int
EVP_PKEY_ED25519 → const int
EVP_PKEY_ED448 → const int
EVP_PKEY_HKDF → const int
EVP_PKEY_ML_DSA_44 → const int
EVP_PKEY_ML_DSA_65 → const int
EVP_PKEY_ML_DSA_87 → const int
EVP_PKEY_ML_KEM_1024 → const int
EVP_PKEY_ML_KEM_768 → const int
EVP_PKEY_NONE → const int
EVP_PKEY_RSA → const int
EVP_PKEY_RSA2 → const int
EVP_PKEY_RSA_PSS → const int
EVP_PKEY_X25519 → const int
EVP_PKEY_X448 → const int
EVP_PKEY_XWING → const int
EVP_R_BUFFER_TOO_SMALL → const int
EVP_R_COMMAND_NOT_SUPPORTED → const int
EVP_R_DECODE_ERROR → const int
EVP_R_DIFFERENT_KEY_TYPES → const int
EVP_R_DIFFERENT_PARAMETERS → const int
EVP_R_EMPTY_PSK → const int
EVP_R_ENCODE_ERROR → const int
EVP_R_EXPECTING_A_DH_KEY → const int
EVP_R_EXPECTING_A_DSA_KEY → const int
EVP_R_EXPECTING_A_EC_KEY → const int
EVP_R_EXPECTING_AN_RSA_KEY → const int
EVP_R_ILLEGAL_OR_UNSUPPORTED_PADDING_MODE → const int
EVP_R_INVALID_BUFFER_SIZE → const int
EVP_R_INVALID_CIPHERTEXT_LENGTH → const int
EVP_R_INVALID_DIGEST_LENGTH → const int
EVP_R_INVALID_DIGEST_TYPE → const int
EVP_R_INVALID_KEYBITS → const int
EVP_R_INVALID_MGF1_MD → const int
EVP_R_INVALID_OPERATION → const int
EVP_R_INVALID_PADDING_MODE → const int
EVP_R_INVALID_PARAMETERS → const int
EVP_R_INVALID_PEER_KEY → const int
EVP_R_INVALID_PSS_SALTLEN → const int
EVP_R_INVALID_SECRET_LENGTH → const int
EVP_R_INVALID_SIGNATURE → const int
EVP_R_KEYS_NOT_SET → const int
EVP_R_MEMORY_LIMIT_EXCEEDED → const int
EVP_R_MISSING_PARAMETERS → const int
EVP_R_MISSING_PUBLIC_KEY → const int
EVP_R_NO_DEFAULT_DIGEST → const int
EVP_R_NO_KEY_SET → const int
EVP_R_NO_MDC2_SUPPORT → const int
EVP_R_NO_NID_FOR_CURVE → const int
EVP_R_NO_OPERATION_SET → const int
EVP_R_NO_PARAMETERS_SET → const int
EVP_R_NOT_A_PRIVATE_KEY → const int
EVP_R_NOT_XOF_OR_INVALID_LENGTH → const int
EVP_R_OPERATION_NOT_INITIALIZED → const int
EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE → const int
EVP_R_OPERATON_NOT_INITIALIZED → const int
EVP_R_PRIVATE_KEY_WAS_NOT_SEED → const int
EVP_R_UNKNOWN_PUBLIC_KEY_TYPE → const int
EVP_R_UNSUPPORTED_ALGORITHM → const int
EVP_R_UNSUPPORTED_PUBLIC_KEY_TYPE → const int
HKDF_R_OUTPUT_TOO_LARGE → const int
MBSTRING_ASC → const int
MBSTRING_BMP → const int
MBSTRING_FLAG → const int
MBSTRING_UNIV → const int
MBSTRING_UTF8 → const int
NID_aaControls → const int
NID_ac_auditEntity → const int
NID_ac_proxying → const int
NID_ac_targeting → const int
NID_account → const int
NID_ad_ca_issuers → const int
NID_ad_dvcs → const int
NID_ad_OCSP → const int
NID_ad_timeStamping → const int
NID_aes_128_cbc → const int
NID_aes_128_cbc_hmac_sha1 → const int
NID_aes_128_ccm → const int
NID_aes_128_cfb1 → const int
NID_aes_128_cfb128 → const int
NID_aes_128_cfb8 → const int
NID_aes_128_ctr → const int
NID_aes_128_ecb → const int
NID_aes_128_gcm → const int
NID_aes_128_ofb128 → const int
NID_aes_128_xts → const int
NID_aes_192_cbc → const int
NID_aes_192_cbc_hmac_sha1 → const int
NID_aes_192_ccm → const int
NID_aes_192_cfb1 → const int
NID_aes_192_cfb128 → const int
NID_aes_192_cfb8 → const int
NID_aes_192_ctr → const int
NID_aes_192_ecb → const int
NID_aes_192_gcm → const int
NID_aes_192_ofb128 → const int
NID_aes_256_cbc → const int
NID_aes_256_cbc_hmac_sha1 → const int
NID_aes_256_ccm → const int
NID_aes_256_cfb1 → const int
NID_aes_256_cfb128 → const int
NID_aes_256_cfb8 → const int
NID_aes_256_ctr → const int
NID_aes_256_ecb → const int
NID_aes_256_gcm → const int
NID_aes_256_ofb128 → const int
NID_aes_256_xts → const int
NID_algorithm → const int
NID_ansi_X9_62 → const int
NID_any_policy → const int
NID_anyExtendedKeyUsage → const int
NID_aRecord → const int
NID_associatedDomain → const int
NID_associatedName → const int
NID_audio → const int
NID_auth_any → const int
NID_auth_ecdsa → const int
NID_auth_psk → const int
NID_auth_rsa → const int
NID_authority_key_identifier → const int
NID_authorityRevocationList → const int
NID_basic_constraints → const int
NID_bf_cbc → const int
NID_bf_cfb64 → const int
NID_bf_ecb → const int
NID_bf_ofb64 → const int
NID_biometricInfo → const int
NID_brainpoolP160r1 → const int
NID_brainpoolP160t1 → const int
NID_brainpoolP192r1 → const int
NID_brainpoolP192t1 → const int
NID_brainpoolP224r1 → const int
NID_brainpoolP224t1 → const int
NID_brainpoolP256r1 → const int
NID_brainpoolP256t1 → const int
NID_brainpoolP320r1 → const int
NID_brainpoolP320t1 → const int
NID_brainpoolP384r1 → const int
NID_brainpoolP384t1 → const int
NID_brainpoolP512r1 → const int
NID_brainpoolP512t1 → const int
NID_buildingName → const int
NID_businessCategory → const int
NID_cACertificate → const int
NID_camellia_128_cbc → const int
NID_camellia_128_cfb1 → const int
NID_camellia_128_cfb128 → const int
NID_camellia_128_cfb8 → const int
NID_camellia_128_ecb → const int
NID_camellia_128_ofb128 → const int
NID_camellia_192_cbc → const int
NID_camellia_192_cfb1 → const int
NID_camellia_192_cfb128 → const int
NID_camellia_192_cfb8 → const int
NID_camellia_192_ecb → const int
NID_camellia_192_ofb128 → const int
NID_camellia_256_cbc → const int
NID_camellia_256_cfb1 → const int
NID_camellia_256_cfb128 → const int
NID_camellia_256_cfb8 → const int
NID_camellia_256_ecb → const int
NID_camellia_256_ofb128 → const int
NID_caRepository → const int
NID_caseIgnoreIA5StringSyntax → const int
NID_cast5_cbc → const int
NID_cast5_cfb64 → const int
NID_cast5_ecb → const int
NID_cast5_ofb64 → const int
NID_certBag → const int
NID_certicom_arc → const int
NID_certificate_issuer → const int
NID_certificate_policies → const int
NID_certificateRevocationList → const int
NID_chacha20_poly1305 → const int
NID_clearance → const int
NID_client_auth → const int
NID_cmac → const int
NID_cNAMERecord → const int
NID_code_sign → const int
NID_commonName → const int
NID_countryName → const int
NID_crl_distribution_points → const int
NID_crl_number → const int
NID_crl_reason → const int
NID_crlBag → const int
NID_crossCertificatePair → const int
NID_cryptocom → const int
NID_cryptopro → const int
NID_data → const int
NID_dcObject → const int
NID_delta_crl → const int
NID_deltaRevocationList → const int
NID_des_cbc → const int
NID_des_cdmf → const int
NID_des_cfb1 → const int
NID_des_cfb64 → const int
NID_des_cfb8 → const int
NID_des_ecb → const int
NID_des_ede3_cbc → const int
NID_des_ede3_cfb1 → const int
NID_des_ede3_cfb64 → const int
NID_des_ede3_cfb8 → const int
NID_des_ede3_ecb → const int
NID_des_ede3_ofb64 → const int
NID_des_ede_cbc → const int
NID_des_ede_cfb64 → const int
NID_des_ede_ecb → const int
NID_des_ede_ofb64 → const int
NID_des_ofb64 → const int
NID_description → const int
NID_destinationIndicator → const int
NID_desx_cbc → const int
NID_dh_cofactor_kdf → const int
NID_dh_std_kdf → const int
NID_dhKeyAgreement → const int
NID_dhpublicnumber → const int
NID_dhSinglePass_cofactorDH_sha1kdf_scheme → const int
NID_dhSinglePass_cofactorDH_sha224kdf_scheme → const int
NID_dhSinglePass_cofactorDH_sha256kdf_scheme → const int
NID_dhSinglePass_cofactorDH_sha384kdf_scheme → const int
NID_dhSinglePass_cofactorDH_sha512kdf_scheme → const int
NID_dhSinglePass_stdDH_sha1kdf_scheme → const int
NID_dhSinglePass_stdDH_sha224kdf_scheme → const int
NID_dhSinglePass_stdDH_sha256kdf_scheme → const int
NID_dhSinglePass_stdDH_sha384kdf_scheme → const int
NID_dhSinglePass_stdDH_sha512kdf_scheme → const int
NID_Directory → const int
NID_distinguishedName → const int
NID_dITRedirect → const int
NID_dmdName → const int
NID_dnQualifier → const int
NID_dNSDomain → const int
NID_document → const int
NID_documentAuthor → const int
NID_documentIdentifier → const int
NID_documentLocation → const int
NID_documentPublisher → const int
NID_documentSeries → const int
NID_documentTitle → const int
NID_documentVersion → const int
NID_dod → const int
NID_Domain → const int
NID_domainComponent → const int
NID_domainRelatedObject → const int
NID_dsa → const int
NID_dsa_2 → const int
NID_dsa_with_SHA224 → const int
NID_dsa_with_SHA256 → const int
NID_dSAQuality → const int
NID_dsaWithSHA → const int
NID_dsaWithSHA1 → const int
NID_dsaWithSHA1_2 → const int
NID_dvcs → const int
NID_ecdsa_with_SHA1 → const int
NID_ecdsa_with_SHA224 → const int
NID_ecdsa_with_SHA256 → const int
NID_ecdsa_with_SHA384 → const int
NID_ecdsa_with_SHA512 → const int
NID_ecdsa_with_Specified → const int
NID_ED25519 → const int
NID_ED448 → const int
NID_email_protect → const int
NID_enhancedSearchGuide → const int
NID_Enterprises → const int
NID_Experimental → const int
NID_ext_key_usage → const int
NID_ext_req → const int
NID_facsimileTelephoneNumber → const int
NID_favouriteDrink → const int
NID_freshest_crl → const int
NID_friendlyCountry → const int
NID_friendlyCountryName → const int
NID_friendlyName → const int
NID_generationQualifier → const int
NID_givenName → const int
NID_gost89_cnt → const int
NID_hkdf → const int
NID_hmac → const int
NID_hmac_md5 → const int
NID_hmac_sha1 → const int
NID_hmacWithMD5 → const int
NID_hmacWithSHA1 → const int
NID_hmacWithSHA224 → const int
NID_hmacWithSHA256 → const int
NID_hmacWithSHA384 → const int
NID_hmacWithSHA512 → const int
NID_hold_instruction_call_issuer → const int
NID_hold_instruction_code → const int
NID_hold_instruction_none → const int
NID_hold_instruction_reject → const int
NID_homePostalAddress → const int
NID_homeTelephoneNumber → const int
NID_host → const int
NID_houseIdentifier → const int
NID_iA5StringSyntax → const int
NID_iana → const int
NID_id_aca → const int
NID_id_aca_accessIdentity → const int
NID_id_aca_authenticationInfo → const int
NID_id_aca_chargingIdentity → const int
NID_id_aca_encAttrs → const int
NID_id_aca_group → const int
NID_id_aca_role → const int
NID_id_ad → const int
NID_id_aes128_wrap → const int
NID_id_aes128_wrap_pad → const int
NID_id_aes192_wrap → const int
NID_id_aes192_wrap_pad → const int
NID_id_aes256_wrap → const int
NID_id_aes256_wrap_pad → const int
NID_id_alg → const int
NID_id_alg_des40 → const int
NID_id_alg_dh_pop → const int
NID_id_alg_dh_sig_hmac_sha1 → const int
NID_id_alg_noSignature → const int
NID_id_alg_PWRI_KEK → const int
NID_id_camellia128_wrap → const int
NID_id_camellia192_wrap → const int
NID_id_camellia256_wrap → const int
NID_id_cct → const int
NID_id_cct_crs → const int
NID_id_cct_PKIData → const int
NID_id_cct_PKIResponse → const int
NID_id_ce → const int
NID_id_cmc → const int
NID_id_cmc_addExtensions → const int
NID_id_cmc_confirmCertAcceptance → const int
NID_id_cmc_dataReturn → const int
NID_id_cmc_decryptedPOP → const int
NID_id_cmc_encryptedPOP → const int
NID_id_cmc_getCert → const int
NID_id_cmc_getCRL → const int
NID_id_cmc_identification → const int
NID_id_cmc_identityProof → const int
NID_id_cmc_lraPOPWitness → const int
NID_id_cmc_popLinkRandom → const int
NID_id_cmc_popLinkWitness → const int
NID_id_cmc_queryPending → const int
NID_id_cmc_recipientNonce → const int
NID_id_cmc_regInfo → const int
NID_id_cmc_responseInfo → const int
NID_id_cmc_revokeRequest → const int
NID_id_cmc_senderNonce → const int
NID_id_cmc_statusInfo → const int
NID_id_cmc_transactionId → const int
NID_id_ct_asciiTextWithCRLF → const int
NID_id_DHBasedMac → const int
NID_id_Gost28147_89 → const int
NID_id_Gost28147_89_cc → const int
NID_id_Gost28147_89_CryptoPro_A_ParamSet → const int
NID_id_Gost28147_89_CryptoPro_B_ParamSet → const int
NID_id_Gost28147_89_CryptoPro_C_ParamSet → const int
NID_id_Gost28147_89_CryptoPro_D_ParamSet → const int
NID_id_Gost28147_89_CryptoPro_KeyMeshing → const int
NID_id_Gost28147_89_CryptoPro_Oscar_1_0_ParamSet → const int
NID_id_Gost28147_89_CryptoPro_Oscar_1_1_ParamSet → const int
NID_id_Gost28147_89_CryptoPro_RIC_1_ParamSet → const int
NID_id_Gost28147_89_MAC → const int
NID_id_Gost28147_89_None_KeyMeshing → const int
NID_id_Gost28147_89_TestParamSet → const int
NID_id_GostR3410_2001 → const int
NID_id_GostR3410_2001_cc → const int
NID_id_GostR3410_2001_CryptoPro_A_ParamSet → const int
NID_id_GostR3410_2001_CryptoPro_B_ParamSet → const int
NID_id_GostR3410_2001_CryptoPro_C_ParamSet → const int
NID_id_GostR3410_2001_CryptoPro_XchA_ParamSet → const int
NID_id_GostR3410_2001_CryptoPro_XchB_ParamSet → const int
NID_id_GostR3410_2001_ParamSet_cc → const int
NID_id_GostR3410_2001_TestParamSet → const int
NID_id_GostR3410_2001DH → const int
NID_id_GostR3410_94 → const int
NID_id_GostR3410_94_a → const int
NID_id_GostR3410_94_aBis → const int
NID_id_GostR3410_94_b → const int
NID_id_GostR3410_94_bBis → const int
NID_id_GostR3410_94_cc → const int
NID_id_GostR3410_94_CryptoPro_A_ParamSet → const int
NID_id_GostR3410_94_CryptoPro_B_ParamSet → const int
NID_id_GostR3410_94_CryptoPro_C_ParamSet → const int
NID_id_GostR3410_94_CryptoPro_D_ParamSet → const int
NID_id_GostR3410_94_CryptoPro_XchA_ParamSet → const int
NID_id_GostR3410_94_CryptoPro_XchB_ParamSet → const int
NID_id_GostR3410_94_CryptoPro_XchC_ParamSet → const int
NID_id_GostR3410_94_TestParamSet → const int
NID_id_GostR3410_94DH → const int
NID_id_GostR3411_94 → const int
NID_id_GostR3411_94_CryptoProParamSet → const int
NID_id_GostR3411_94_prf → const int
NID_id_GostR3411_94_TestParamSet → const int
NID_id_GostR3411_94_with_GostR3410_2001 → const int
NID_id_GostR3411_94_with_GostR3410_2001_cc → const int
NID_id_GostR3411_94_with_GostR3410_94 → const int
NID_id_GostR3411_94_with_GostR3410_94_cc → const int
NID_id_hex_multipart_message → const int
NID_id_hex_partial_message → const int
NID_id_HMACGostR3411_94 → const int
NID_id_it → const int
NID_id_it_caKeyUpdateInfo → const int
NID_id_it_caProtEncCert → const int
NID_id_it_confirmWaitTime → const int
NID_id_it_currentCRL → const int
NID_id_it_encKeyPairTypes → const int
NID_id_it_implicitConfirm → const int
NID_id_it_keyPairParamRep → const int
NID_id_it_keyPairParamReq → const int
NID_id_it_origPKIMessage → const int
NID_id_it_preferredSymmAlg → const int
NID_id_it_revPassphrase → const int
NID_id_it_signKeyPairTypes → const int
NID_id_it_subscriptionRequest → const int
NID_id_it_subscriptionResponse → const int
NID_id_it_suppLangTags → const int
NID_id_it_unsupportedOIDs → const int
NID_id_kp → const int
NID_id_mod_attribute_cert → const int
NID_id_mod_cmc → const int
NID_id_mod_cmp → const int
NID_id_mod_cmp2000 → const int
NID_id_mod_crmf → const int
NID_id_mod_dvcs → const int
NID_id_mod_kea_profile_88 → const int
NID_id_mod_kea_profile_93 → const int
NID_id_mod_ocsp → const int
NID_id_mod_qualified_cert_88 → const int
NID_id_mod_qualified_cert_93 → const int
NID_id_mod_timestamp_protocol → const int
NID_id_on → const int
NID_id_on_permanentIdentifier → const int
NID_id_on_personalData → const int
NID_id_PasswordBasedMAC → const int
NID_id_pbkdf2 → const int
NID_id_pda → const int
NID_id_pda_countryOfCitizenship → const int
NID_id_pda_countryOfResidence → const int
NID_id_pda_dateOfBirth → const int
NID_id_pda_gender → const int
NID_id_pda_placeOfBirth → const int
NID_id_pe → const int
NID_id_pkip → const int
NID_id_pkix → const int
NID_id_pkix1_explicit_88 → const int
NID_id_pkix1_explicit_93 → const int
NID_id_pkix1_implicit_88 → const int
NID_id_pkix1_implicit_93 → const int
NID_id_pkix_mod → const int
NID_id_pkix_OCSP_acceptableResponses → const int
NID_id_pkix_OCSP_archiveCutoff → const int
NID_id_pkix_OCSP_basic → const int
NID_id_pkix_OCSP_CrlID → const int
NID_id_pkix_OCSP_extendedStatus → const int
NID_id_pkix_OCSP_noCheck → const int
NID_id_pkix_OCSP_Nonce → const int
NID_id_pkix_OCSP_path → const int
NID_id_pkix_OCSP_serviceLocator → const int
NID_id_pkix_OCSP_trustRoot → const int
NID_id_pkix_OCSP_valid → const int
NID_id_ppl → const int
NID_id_ppl_anyLanguage → const int
NID_id_ppl_inheritAll → const int
NID_id_qcs → const int
NID_id_qcs_pkixQCSyntax_v1 → const int
NID_id_qt → const int
NID_id_qt_cps → const int
NID_id_qt_unotice → const int
NID_id_regCtrl → const int
NID_id_regCtrl_authenticator → const int
NID_id_regCtrl_oldCertID → const int
NID_id_regCtrl_pkiArchiveOptions → const int
NID_id_regCtrl_pkiPublicationInfo → const int
NID_id_regCtrl_protocolEncrKey → const int
NID_id_regCtrl_regToken → const int
NID_id_regInfo → const int
NID_id_regInfo_certReq → const int
NID_id_regInfo_utf8Pairs → const int
NID_id_set → const int
NID_id_smime_aa → const int
NID_id_smime_aa_contentHint → const int
NID_id_smime_aa_contentIdentifier → const int
NID_id_smime_aa_contentReference → const int
NID_id_smime_aa_dvcs_dvc → const int
NID_id_smime_aa_encapContentType → const int
NID_id_smime_aa_encrypKeyPref → const int
NID_id_smime_aa_equivalentLabels → const int
NID_id_smime_aa_ets_archiveTimeStamp → const int
NID_id_smime_aa_ets_certCRLTimestamp → const int
NID_id_smime_aa_ets_CertificateRefs → const int
NID_id_smime_aa_ets_certValues → const int
NID_id_smime_aa_ets_commitmentType → const int
NID_id_smime_aa_ets_contentTimestamp → const int
NID_id_smime_aa_ets_escTimeStamp → const int
NID_id_smime_aa_ets_otherSigCert → const int
NID_id_smime_aa_ets_RevocationRefs → const int
NID_id_smime_aa_ets_revocationValues → const int
NID_id_smime_aa_ets_signerAttr → const int
NID_id_smime_aa_ets_signerLocation → const int
NID_id_smime_aa_ets_sigPolicyId → const int
NID_id_smime_aa_macValue → const int
NID_id_smime_aa_mlExpandHistory → const int
NID_id_smime_aa_msgSigDigest → const int
NID_id_smime_aa_receiptRequest → const int
NID_id_smime_aa_securityLabel → const int
NID_id_smime_aa_signatureType → const int
NID_id_smime_aa_signingCertificate → const int
NID_id_smime_aa_smimeEncryptCerts → const int
NID_id_smime_aa_timeStampToken → const int
NID_id_smime_alg → const int
NID_id_smime_alg_3DESwrap → const int
NID_id_smime_alg_CMS3DESwrap → const int
NID_id_smime_alg_CMSRC2wrap → const int
NID_id_smime_alg_ESDH → const int
NID_id_smime_alg_ESDHwith3DES → const int
NID_id_smime_alg_ESDHwithRC2 → const int
NID_id_smime_alg_RC2wrap → const int
NID_id_smime_cd → const int
NID_id_smime_cd_ldap → const int
NID_id_smime_ct → const int
NID_id_smime_ct_authData → const int
NID_id_smime_ct_compressedData → const int
NID_id_smime_ct_contentInfo → const int
NID_id_smime_ct_DVCSRequestData → const int
NID_id_smime_ct_DVCSResponseData → const int
NID_id_smime_ct_publishCert → const int
NID_id_smime_ct_receipt → const int
NID_id_smime_ct_TDTInfo → const int
NID_id_smime_ct_TSTInfo → const int
NID_id_smime_cti → const int
NID_id_smime_cti_ets_proofOfApproval → const int
NID_id_smime_cti_ets_proofOfCreation → const int
NID_id_smime_cti_ets_proofOfDelivery → const int
NID_id_smime_cti_ets_proofOfOrigin → const int
NID_id_smime_cti_ets_proofOfReceipt → const int
NID_id_smime_cti_ets_proofOfSender → const int
NID_id_smime_mod → const int
NID_id_smime_mod_cms → const int
NID_id_smime_mod_ess → const int
NID_id_smime_mod_ets_eSignature_88 → const int
NID_id_smime_mod_ets_eSignature_97 → const int
NID_id_smime_mod_ets_eSigPolicy_88 → const int
NID_id_smime_mod_ets_eSigPolicy_97 → const int
NID_id_smime_mod_msg_v3 → const int
NID_id_smime_mod_oid → const int
NID_id_smime_spq → const int
NID_id_smime_spq_ets_sqt_unotice → const int
NID_id_smime_spq_ets_sqt_uri → const int
NID_idea_cbc → const int
NID_idea_cfb64 → const int
NID_idea_ecb → const int
NID_idea_ofb64 → const int
NID_identified_organization → const int
NID_Independent → const int
NID_info → const int
NID_info_access → const int
NID_inhibit_any_policy → const int
NID_initials → const int
NID_international_organizations → const int
NID_internationaliSDNNumber → const int
NID_invalidity_date → const int
NID_ipsec3 → const int
NID_ipsec4 → const int
NID_ipsecEndSystem → const int
NID_ipsecTunnel → const int
NID_ipsecUser → const int
NID_iso → const int
NID_ISO_US → const int
NID_issuer_alt_name → const int
NID_issuing_distribution_point → const int
NID_itu_t → const int
NID_janetMailbox → const int
NID_joint_iso_itu_t → const int
NID_key_usage → const int
NID_keyBag → const int
NID_kisa → const int
NID_kx_any → const int
NID_kx_ecdhe → const int
NID_kx_psk → const int
NID_kx_rsa → const int
NID_lastModifiedBy → const int
NID_lastModifiedTime → const int
NID_localityName → const int
NID_localKeyID → const int
NID_LocalKeySet → const int
NID_Mail → const int
NID_mailPreferenceOption → const int
NID_Management → const int
NID_manager → const int
NID_md2 → const int
NID_md2WithRSAEncryption → const int
NID_md4 → const int
NID_md4WithRSAEncryption → const int
NID_md5 → const int
NID_md5_sha1 → const int
NID_md5WithRSA → const int
NID_md5WithRSAEncryption → const int
NID_mdc2 → const int
NID_mdc2WithRSA → const int
NID_member → const int
NID_member_body → const int
NID_mgf1 → const int
NID_mime_mhs → const int
NID_mime_mhs_bodies → const int
NID_mime_mhs_headings → const int
NID_ML_DSA_44 → const int
NID_ML_DSA_65 → const int
NID_ML_DSA_87 → const int
NID_ML_KEM_1024 → const int
NID_ML_KEM_768 → const int
NID_mobileTelephoneNumber → const int
NID_ms_code_com → const int
NID_ms_code_ind → const int
NID_ms_csp_name → const int
NID_ms_ctl_sign → const int
NID_ms_efs → const int
NID_ms_ext_req → const int
NID_ms_sgc → const int
NID_ms_smartcard_login → const int
NID_ms_upn → const int
NID_mXRecord → const int
NID_name → const int
NID_name_constraints → const int
NID_netscape → const int
NID_netscape_base_url → const int
NID_netscape_ca_policy_url → const int
NID_netscape_ca_revocation_url → const int
NID_netscape_cert_extension → const int
NID_netscape_cert_sequence → const int
NID_netscape_cert_type → const int
NID_netscape_comment → const int
NID_netscape_data_type → const int
NID_netscape_renewal_url → const int
NID_netscape_revocation_url → const int
NID_netscape_ssl_server_name → const int
NID_no_rev_avail → const int
NID_ns_sgc → const int
NID_nSRecord → const int
NID_OCSP_sign → const int
NID_org → const int
NID_organizationalStatus → const int
NID_organizationalUnitName → const int
NID_organizationName → const int
NID_otherMailbox → const int
NID_owner → const int
NID_pagerTelephoneNumber → const int
NID_pbe_WithSHA1And128BitRC2_CBC → const int
NID_pbe_WithSHA1And128BitRC4 → const int
NID_pbe_WithSHA1And2_Key_TripleDES_CBC → const int
NID_pbe_WithSHA1And3_Key_TripleDES_CBC → const int
NID_pbe_WithSHA1And40BitRC2_CBC → const int
NID_pbe_WithSHA1And40BitRC4 → const int
NID_pbes2 → const int
NID_pbeWithMD2AndDES_CBC → const int
NID_pbeWithMD2AndRC2_CBC → const int
NID_pbeWithMD5AndCast5_CBC → const int
NID_pbeWithMD5AndDES_CBC → const int
NID_pbeWithMD5AndRC2_CBC → const int
NID_pbeWithSHA1AndDES_CBC → const int
NID_pbeWithSHA1AndRC2_CBC → const int
NID_pbmac1 → const int
NID_personalSignature → const int
NID_personalTitle → const int
NID_photo → const int
NID_physicalDeliveryOfficeName → const int
NID_pilot → const int
NID_pilotAttributeSyntax → const int
NID_pilotAttributeType → const int
NID_pilotAttributeType27 → const int
NID_pilotDSA → const int
NID_pilotGroups → const int
NID_pilotObject → const int
NID_pilotObjectClass → const int
NID_pilotOrganization → const int
NID_pilotPerson → const int
NID_pkcs → const int
NID_pkcs1 → const int
NID_pkcs3 → const int
NID_pkcs5 → const int
NID_pkcs7 → const int
NID_pkcs7_data → const int
NID_pkcs7_digest → const int
NID_pkcs7_encrypted → const int
NID_pkcs7_enveloped → const int
NID_pkcs7_signed → const int
NID_pkcs7_signedAndEnveloped → const int
NID_pkcs8ShroudedKeyBag → const int
NID_pkcs9 → const int
NID_pkcs9_challengePassword → const int
NID_pkcs9_contentType → const int
NID_pkcs9_countersignature → const int
NID_pkcs9_emailAddress → const int
NID_pkcs9_extCertAttributes → const int
NID_pkcs9_messageDigest → const int
NID_pkcs9_signingTime → const int
NID_pkcs9_unstructuredAddress → const int
NID_pkcs9_unstructuredName → const int
NID_policy_constraints → const int
NID_policy_mappings → const int
NID_postalAddress → const int
NID_postalCode → const int
NID_postOfficeBox → const int
NID_preferredDeliveryMethod → const int
NID_presentationAddress → const int
NID_Private → const int
NID_private_key_usage_period → const int
NID_protocolInformation → const int
NID_proxyCertInfo → const int
NID_pseudonym → const int
NID_pSpecified → const int
NID_pss → const int
NID_qcStatements → const int
NID_qualityLabelledData → const int
NID_rc2_40_cbc → const int
NID_rc2_64_cbc → const int
NID_rc2_cbc → const int
NID_rc2_cfb64 → const int
NID_rc2_ecb → const int
NID_rc2_ofb64 → const int
NID_rc4 → const int
NID_rc4_40 → const int
NID_rc4_hmac_md5 → const int
NID_rc5_cbc → const int
NID_rc5_cfb64 → const int
NID_rc5_ecb → const int
NID_rc5_ofb64 → const int
NID_registeredAddress → const int
NID_rFC822localPart → const int
NID_rfc822Mailbox → const int
NID_ripemd160 → const int
NID_ripemd160WithRSA → const int
NID_role → const int
NID_roleOccupant → const int
NID_room → const int
NID_roomNumber → const int
NID_rsa → const int
NID_rsadsi → const int
NID_rsaEncryption → const int
NID_rsaesOaep → const int
NID_rsaOAEPEncryptionSET → const int
NID_rsaSignature → const int
NID_rsassaPss → const int
NID_safeContentsBag → const int
NID_sbgp_autonomousSysNum → const int
NID_sbgp_ipAddrBlock → const int
NID_sbgp_routerIdentifier → const int
NID_sdsiCertificate → const int
NID_searchGuide → const int
NID_secp112r1 → const int
NID_secp112r2 → const int
NID_secp128r1 → const int
NID_secp128r2 → const int
NID_secp160k1 → const int
NID_secp160r1 → const int
NID_secp160r2 → const int
NID_secp192k1 → const int
NID_secp224k1 → const int
NID_secp224r1 → const int
NID_secp256k1 → const int
NID_secp384r1 → const int
NID_secp521r1 → const int
NID_secretary → const int
NID_secretBag → const int
NID_sect113r1 → const int
NID_sect113r2 → const int
NID_sect131r1 → const int
NID_sect131r2 → const int
NID_sect163k1 → const int
NID_sect163r1 → const int
NID_sect163r2 → const int
NID_sect193r1 → const int
NID_sect193r2 → const int
NID_sect233k1 → const int
NID_sect233r1 → const int
NID_sect239k1 → const int
NID_sect283k1 → const int
NID_sect283r1 → const int
NID_sect409k1 → const int
NID_sect409r1 → const int
NID_sect571k1 → const int
NID_sect571r1 → const int
NID_Security → const int
NID_seeAlso → const int
NID_seed_cbc → const int
NID_seed_cfb128 → const int
NID_seed_ecb → const int
NID_seed_ofb128 → const int
NID_selected_attribute_types → const int
NID_serialNumber → const int
NID_server_auth → const int
NID_set_addPolicy → const int
NID_set_attr → const int
NID_set_brand → const int
NID_set_brand_AmericanExpress → const int
NID_set_brand_Diners → const int
NID_set_brand_IATA_ATA → const int
NID_set_brand_JCB → const int
NID_set_brand_MasterCard → const int
NID_set_brand_Novus → const int
NID_set_brand_Visa → const int
NID_set_certExt → const int
NID_set_ctype → const int
NID_set_msgExt → const int
NID_set_policy → const int
NID_set_policy_root → const int
NID_set_rootKeyThumb → const int
NID_setAttr_Cert → const int
NID_setAttr_GenCryptgrm → const int
NID_setAttr_IssCap → const int
NID_setAttr_IssCap_CVM → const int
NID_setAttr_IssCap_Sig → const int
NID_setAttr_IssCap_T2 → const int
NID_setAttr_PGWYcap → const int
NID_setAttr_SecDevSig → const int
NID_setAttr_T2cleartxt → const int
NID_setAttr_T2Enc → const int
NID_setAttr_Token_B0Prime → const int
NID_setAttr_Token_EMV → const int
NID_setAttr_TokenType → const int
NID_setAttr_TokICCsig → const int
NID_setCext_cCertRequired → const int
NID_setCext_certType → const int
NID_setCext_hashedRoot → const int
NID_setCext_IssuerCapabilities → const int
NID_setCext_merchData → const int
NID_setCext_PGWYcapabilities → const int
NID_setCext_setExt → const int
NID_setCext_setQualf → const int
NID_setCext_TokenIdentifier → const int
NID_setCext_TokenType → const int
NID_setCext_Track2Data → const int
NID_setCext_tunneling → const int
NID_setct_AcqCardCodeMsg → const int
NID_setct_AcqCardCodeMsgTBE → const int
NID_setct_AuthReqTBE → const int
NID_setct_AuthReqTBS → const int
NID_setct_AuthResBaggage → const int
NID_setct_AuthResTBE → const int
NID_setct_AuthResTBEX → const int
NID_setct_AuthResTBS → const int
NID_setct_AuthResTBSX → const int
NID_setct_AuthRevReqBaggage → const int
NID_setct_AuthRevReqTBE → const int
NID_setct_AuthRevReqTBS → const int
NID_setct_AuthRevResBaggage → const int
NID_setct_AuthRevResData → const int
NID_setct_AuthRevResTBE → const int
NID_setct_AuthRevResTBEB → const int
NID_setct_AuthRevResTBS → const int
NID_setct_AuthTokenTBE → const int
NID_setct_AuthTokenTBS → const int
NID_setct_BatchAdminReqData → const int
NID_setct_BatchAdminReqTBE → const int
NID_setct_BatchAdminResData → const int
NID_setct_BatchAdminResTBE → const int
NID_setct_BCIDistributionTBS → const int
NID_setct_CapReqTBE → const int
NID_setct_CapReqTBEX → const int
NID_setct_CapReqTBS → const int
NID_setct_CapReqTBSX → const int
NID_setct_CapResData → const int
NID_setct_CapResTBE → const int
NID_setct_CapRevReqTBE → const int
NID_setct_CapRevReqTBEX → const int
NID_setct_CapRevReqTBS → const int
NID_setct_CapRevReqTBSX → const int
NID_setct_CapRevResData → const int
NID_setct_CapRevResTBE → const int
NID_setct_CapTokenData → const int
NID_setct_CapTokenSeq → const int
NID_setct_CapTokenTBE → const int
NID_setct_CapTokenTBEX → const int
NID_setct_CapTokenTBS → const int
NID_setct_CardCInitResTBS → const int
NID_setct_CertInqReqTBS → const int
NID_setct_CertReqData → const int
NID_setct_CertReqTBE → const int
NID_setct_CertReqTBEX → const int
NID_setct_CertReqTBS → const int
NID_setct_CertResData → const int
NID_setct_CertResTBE → const int
NID_setct_CredReqTBE → const int
NID_setct_CredReqTBEX → const int
NID_setct_CredReqTBS → const int
NID_setct_CredReqTBSX → const int
NID_setct_CredResData → const int
NID_setct_CredResTBE → const int
NID_setct_CredRevReqTBE → const int
NID_setct_CredRevReqTBEX → const int
NID_setct_CredRevReqTBS → const int
NID_setct_CredRevReqTBSX → const int
NID_setct_CredRevResData → const int
NID_setct_CredRevResTBE → const int
NID_setct_CRLNotificationResTBS → const int
NID_setct_CRLNotificationTBS → const int
NID_setct_ErrorTBS → const int
NID_setct_HODInput → const int
NID_setct_MeAqCInitResTBS → const int
NID_setct_OIData → const int
NID_setct_PANData → const int
NID_setct_PANOnly → const int
NID_setct_PANToken → const int
NID_setct_PCertReqData → const int
NID_setct_PCertResTBS → const int
NID_setct_PI → const int
NID_setct_PI_TBS → const int
NID_setct_PIData → const int
NID_setct_PIDataUnsigned → const int
NID_setct_PIDualSignedTBE → const int
NID_setct_PInitResData → const int
NID_setct_PIUnsignedTBE → const int
NID_setct_PResData → const int
NID_setct_RegFormReqTBE → const int
NID_setct_RegFormResTBS → const int
NID_setext_cv → const int
NID_setext_genCrypt → const int
NID_setext_miAuth → const int
NID_setext_pinAny → const int
NID_setext_pinSecure → const int
NID_setext_track2 → const int
NID_sha → const int
NID_sha1 → const int
NID_sha1WithRSA → const int
NID_sha1WithRSAEncryption → const int
NID_sha224 → const int
NID_sha224WithRSAEncryption → const int
NID_sha256 → const int
NID_sha256WithRSAEncryption → const int
NID_sha384 → const int
NID_sha384WithRSAEncryption → const int
NID_sha512 → const int
NID_sha512_256 → const int
NID_sha512WithRSAEncryption → const int
NID_shaWithRSAEncryption → const int
NID_simpleSecurityObject → const int
NID_sinfo_access → const int
NID_singleLevelQuality → const int
NID_SMIME → const int
NID_SMIMECapabilities → const int
NID_SNMPv2 → const int
NID_sOARecord → const int
NID_stateOrProvinceName → const int
NID_streetAddress → const int
NID_subject_alt_name → const int
NID_subject_directory_attributes → const int
NID_subject_key_identifier → const int
NID_subtreeMaximumQuality → const int
NID_subtreeMinimumQuality → const int
NID_supportedAlgorithms → const int
NID_supportedApplicationContext → const int
NID_surname → const int
NID_sxnet → const int
NID_target_information → const int
NID_telephoneNumber → const int
NID_teletexTerminalIdentifier → const int
NID_telexNumber → const int
NID_textEncodedORAddress → const int
NID_textNotice → const int
NID_time_stamp → const int
NID_title → const int
NID_ucl → const int
NID_undef → const int
NID_uniqueMember → const int
NID_userCertificate → const int
NID_userClass → const int
NID_userId → const int
NID_userPassword → const int
NID_wap → const int
NID_wap_wsg → const int
NID_wap_wsg_idm_ecid_wtls1 → const int
NID_wap_wsg_idm_ecid_wtls10 → const int
NID_wap_wsg_idm_ecid_wtls11 → const int
NID_wap_wsg_idm_ecid_wtls12 → const int
NID_wap_wsg_idm_ecid_wtls3 → const int
NID_wap_wsg_idm_ecid_wtls4 → const int
NID_wap_wsg_idm_ecid_wtls5 → const int
NID_wap_wsg_idm_ecid_wtls6 → const int
NID_wap_wsg_idm_ecid_wtls7 → const int
NID_wap_wsg_idm_ecid_wtls8 → const int
NID_wap_wsg_idm_ecid_wtls9 → const int
NID_whirlpool → const int
NID_x121Address → const int
NID_X25519 → const int
NID_X25519Kyber768Draft00 → const int
NID_X25519MLKEM768 → const int
NID_X448 → const int
NID_X500 → const int
NID_X500algorithms → const int
NID_x500UniqueIdentifier → const int
NID_X509 → const int
NID_x509Certificate → const int
NID_x509Crl → const int
NID_X9_57 → const int
NID_X9_62_c2onb191v4 → const int
NID_X9_62_c2onb191v5 → const int
NID_X9_62_c2onb239v4 → const int
NID_X9_62_c2onb239v5 → const int
NID_X9_62_c2pnb163v1 → const int
NID_X9_62_c2pnb163v2 → const int
NID_X9_62_c2pnb163v3 → const int
NID_X9_62_c2pnb176v1 → const int
NID_X9_62_c2pnb208w1 → const int
NID_X9_62_c2pnb272w1 → const int
NID_X9_62_c2pnb304w1 → const int
NID_X9_62_c2pnb368w1 → const int
NID_X9_62_c2tnb191v1 → const int
NID_X9_62_c2tnb191v2 → const int
NID_X9_62_c2tnb191v3 → const int
NID_X9_62_c2tnb239v1 → const int
NID_X9_62_c2tnb239v2 → const int
NID_X9_62_c2tnb239v3 → const int
NID_X9_62_c2tnb359v1 → const int
NID_X9_62_c2tnb431r1 → const int
NID_X9_62_characteristic_two_field → const int
NID_X9_62_id_characteristic_two_basis → const int
NID_X9_62_id_ecPublicKey → const int
NID_X9_62_onBasis → const int
NID_X9_62_ppBasis → const int
NID_X9_62_prime192v1 → const int
NID_X9_62_prime192v2 → const int
NID_X9_62_prime192v3 → const int
NID_X9_62_prime239v1 → const int
NID_X9_62_prime239v2 → const int
NID_X9_62_prime239v3 → const int
NID_X9_62_prime256v1 → const int
NID_X9_62_prime_field → const int
NID_X9_62_tpBasis → const int
NID_X9cm → const int
NID_X_Wing → const int
NID_zlib_compression → const int
opensslAllocator → const OpenSslAllocator
An ffi.Allocator backed by BoringSSL's OPENSSL_malloc and OPENSSL_free.
RSA_3 → const int
RSA_F4 → const int
RSA_FLAG_EXT_PKEY → const int
RSA_FLAG_LARGE_PUBLIC_EXPONENT → const int
RSA_FLAG_NO_BLINDING → const int
RSA_FLAG_NO_PUBLIC_EXPONENT → const int
RSA_FLAG_OPAQUE → const int
RSA_METHOD_FLAG_NO_CHECK → const int
RSA_NO_PADDING → const int
RSA_PKCS1_OAEP_PADDING → const int
RSA_PKCS1_PADDING → const int
RSA_PKCS1_PSS_PADDING → const int
RSA_PSS_SALTLEN_AUTO → const int
RSA_PSS_SALTLEN_DIGEST → const int
RSA_R_BAD_E_VALUE → const int
RSA_R_BAD_ENCODING → const int
RSA_R_BAD_FIXED_HEADER_DECRYPT → const int
RSA_R_BAD_PAD_BYTE_COUNT → const int
RSA_R_BAD_RSA_PARAMETERS → const int
RSA_R_BAD_SIGNATURE → const int
RSA_R_BAD_VERSION → const int
RSA_R_BLOCK_TYPE_IS_NOT_01 → const int
RSA_R_BLOCK_TYPE_IS_NOT_02 → const int
RSA_R_BN_NOT_INITIALIZED → const int
RSA_R_CANNOT_RECOVER_MULTI_PRIME_KEY → const int
RSA_R_CRT_PARAMS_ALREADY_GIVEN → const int
RSA_R_CRT_VALUES_INCORRECT → const int
RSA_R_D_E_NOT_CONGRUENT_TO_1 → const int
RSA_R_D_OUT_OF_RANGE → const int
RSA_R_DATA_LEN_NOT_EQUAL_TO_MOD_LEN → const int
RSA_R_DATA_TOO_LARGE → const int
RSA_R_DATA_TOO_LARGE_FOR_KEY_SIZE → const int
RSA_R_DATA_TOO_LARGE_FOR_MODULUS → const int
RSA_R_DATA_TOO_SMALL → const int
RSA_R_DATA_TOO_SMALL_FOR_KEY_SIZE → const int
RSA_R_DIGEST_TOO_BIG_FOR_RSA_KEY → const int
RSA_R_EMPTY_PUBLIC_KEY → const int
RSA_R_ENCODE_ERROR → const int
RSA_R_FIRST_OCTET_INVALID → const int
RSA_R_INCONSISTENT_SET_OF_CRT_VALUES → const int
RSA_R_INTERNAL_ERROR → const int
RSA_R_INVALID_MESSAGE_LENGTH → const int
RSA_R_KEY_SIZE_TOO_SMALL → const int
RSA_R_LAST_OCTET_INVALID → const int
RSA_R_MODULUS_TOO_LARGE → const int
RSA_R_MUST_HAVE_AT_LEAST_TWO_PRIMES → const int
RSA_R_N_NOT_EQUAL_P_Q → const int
RSA_R_NO_PUBLIC_EXPONENT → const int
RSA_R_NULL_BEFORE_BLOCK_MISSING → const int
RSA_R_OAEP_DECODING_ERROR → const int
RSA_R_ONLY_ONE_OF_P_Q_GIVEN → const int
RSA_R_OUTPUT_BUFFER_TOO_SMALL → const int
RSA_R_PADDING_CHECK_FAILED → const int
RSA_R_PKCS_DECODING_ERROR → const int
RSA_R_PUBLIC_KEY_VALIDATION_FAILED → const int
RSA_R_SLEN_CHECK_FAILED → const int
RSA_R_SLEN_RECOVERY_FAILED → const int
RSA_R_TOO_LONG → const int
RSA_R_TOO_MANY_ITERATIONS → const int
RSA_R_UNKNOWN_ALGORITHM_TYPE → const int
RSA_R_UNKNOWN_PADDING_TYPE → const int
RSA_R_VALUE_MISSING → const int
RSA_R_WRONG_SIGNATURE_LENGTH → const int
V_ASN1_ANY → const int
V_ASN1_APPLICATION → const int
V_ASN1_BIT_STRING → const int
V_ASN1_BMPSTRING → const int
V_ASN1_BOOLEAN → const int
V_ASN1_CONSTRUCTED → const int
V_ASN1_CONTEXT_SPECIFIC → const int
V_ASN1_ENUMERATED → const int
V_ASN1_EOC → const int
V_ASN1_EXTERNAL → const int
V_ASN1_GENERALIZEDTIME → const int
V_ASN1_GENERALSTRING → const int
V_ASN1_GRAPHICSTRING → const int
V_ASN1_IA5STRING → const int
V_ASN1_INTEGER → const int
V_ASN1_ISO64STRING → const int
V_ASN1_MAX_UNIVERSAL → const int
V_ASN1_NEG → const int
V_ASN1_NEG_ENUMERATED → const int
V_ASN1_NEG_INTEGER → const int
V_ASN1_NULL → const int
V_ASN1_NUMERICSTRING → const int
V_ASN1_OBJECT → const int
V_ASN1_OBJECT_DESCRIPTOR → const int
V_ASN1_OCTET_STRING → const int
V_ASN1_OTHER → const int
V_ASN1_PRIMITIVE_TAG → const int
V_ASN1_PRINTABLESTRING → const int
V_ASN1_PRIVATE → const int
V_ASN1_REAL → const int
V_ASN1_SEQUENCE → const int
V_ASN1_SET → const int
V_ASN1_T61STRING → const int
V_ASN1_TELETEXSTRING → const int
V_ASN1_UNDEF → const int
V_ASN1_UNIVERSAL → const int
V_ASN1_UNIVERSALSTRING → const int
V_ASN1_UTCTIME → const int
V_ASN1_UTF8STRING → const int
V_ASN1_VIDEOTEXSTRING → const int
V_ASN1_VISIBLESTRING → const int
X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT → const int
X509_CHECK_FLAG_MULTI_LABEL_WILDCARDS → const int
X509_CHECK_FLAG_NEVER_CHECK_SUBJECT → const int
X509_CHECK_FLAG_NO_PARTIAL_WILDCARDS → const int
X509_CHECK_FLAG_NO_WILDCARDS → const int
X509_CHECK_FLAG_SINGLE_LABEL_SUBDOMAINS → const int
X509_CRL_VERSION_1 → const int
X509_CRL_VERSION_2 → const int
X509_FILETYPE_ASN1 → const int
X509_FILETYPE_DEFAULT → const int
X509_FILETYPE_PEM → const int
X509_FLAG_COMPAT → const int
X509_FLAG_NO_ATTRIBUTES → const int
X509_FLAG_NO_AUX → const int
X509_FLAG_NO_EXTENSIONS → const int
X509_FLAG_NO_HEADER → const int
X509_FLAG_NO_IDS → const int
X509_FLAG_NO_ISSUER → const int
X509_FLAG_NO_PUBKEY → const int
X509_FLAG_NO_SERIAL → const int
X509_FLAG_NO_SIGDUMP → const int
X509_FLAG_NO_SIGNAME → const int
X509_FLAG_NO_SUBJECT → const int
X509_FLAG_NO_VALIDITY → const int
X509_FLAG_NO_VERSION → const int
X509_L_ADD_DIR → const int
X509_L_FILE_LOAD → const int
X509_LU_CRL → const int
X509_LU_NONE → const int
X509_LU_PKEY → const int
X509_LU_X509 → const int
X509_PURPOSE_ANY → const int
X509_PURPOSE_CRL_SIGN → const int
X509_PURPOSE_NS_SSL_SERVER → const int
X509_PURPOSE_OCSP_HELPER → const int
X509_PURPOSE_SMIME_ENCRYPT → const int
X509_PURPOSE_SMIME_SIGN → const int
X509_PURPOSE_SSL_CLIENT → const int
X509_PURPOSE_SSL_SERVER → const int
X509_PURPOSE_TIMESTAMP_SIGN → const int
X509_R_AKID_MISMATCH → const int
X509_R_BAD_PKCS7_VERSION → const int
X509_R_BAD_X509_FILETYPE → const int
X509_R_BASE64_DECODE_ERROR → const int
X509_R_CANT_CHECK_DH_KEY → const int
X509_R_CERT_ALREADY_IN_HASH_TABLE → const int
X509_R_CRL_ALREADY_DELTA → const int
X509_R_CRL_VERIFY_FAILURE → const int
X509_R_DELTA_CRL_WITHOUT_CRL_NUMBER → const int
X509_R_IDP_MISMATCH → const int
X509_R_INVALID_BIT_STRING_BITS_LEFT → const int
X509_R_INVALID_DIRECTORY → const int
X509_R_INVALID_FIELD_FOR_VERSION → const int
X509_R_INVALID_FIELD_NAME → const int
X509_R_INVALID_PARAMETER → const int
X509_R_INVALID_POLICY_EXTENSION → const int
X509_R_INVALID_PSS_PARAMETERS → const int
X509_R_INVALID_TRUST → const int
X509_R_INVALID_VERSION → const int
X509_R_ISSUER_MISMATCH → const int
X509_R_KEY_TYPE_MISMATCH → const int
X509_R_KEY_VALUES_MISMATCH → const int
X509_R_LOADING_CERT_DIR → const int
X509_R_LOADING_DEFAULTS → const int
X509_R_NAME_TOO_LONG → const int
X509_R_NEWER_CRL_NOT_NEWER → const int
X509_R_NO_CERT_SET_FOR_US_TO_VERIFY → const int
X509_R_NO_CERTIFICATE_FOUND → const int
X509_R_NO_CERTIFICATE_OR_CRL_FOUND → const int
X509_R_NO_CERTIFICATES_INCLUDED → const int
X509_R_NO_CRL_FOUND → const int
X509_R_NO_CRL_NUMBER → const int
X509_R_NO_CRLS_INCLUDED → const int
X509_R_NOT_PKCS7_SIGNED_DATA → const int
X509_R_PUBLIC_KEY_DECODE_ERROR → const int
X509_R_PUBLIC_KEY_ENCODE_ERROR → const int
X509_R_SHOULD_RETRY → const int
X509_R_SIGNATURE_ALGORITHM_MISMATCH → const int
X509_R_UNKNOWN_KEY_TYPE → const int
X509_R_UNKNOWN_NID → const int
X509_R_UNKNOWN_PURPOSE_ID → const int
X509_R_UNKNOWN_TRUST_ID → const int
X509_R_UNSUPPORTED_ALGORITHM → const int
X509_R_WRONG_LOOKUP_TYPE → const int
X509_R_WRONG_TYPE → const int
X509_REQ_VERSION_1 → const int
X509_TRUST_COMPAT → const int
X509_TRUST_EMAIL → const int
X509_TRUST_OBJECT_SIGN → const int
X509_TRUST_REJECTED → const int
X509_TRUST_SSL_CLIENT → const int
X509_TRUST_SSL_SERVER → const int
X509_TRUST_TRUSTED → const int
X509_TRUST_TSA → const int
X509_TRUST_UNTRUSTED → const int
X509_V_ERR_AKID_ISSUER_SERIAL_MISMATCH → const int
X509_V_ERR_AKID_SKID_MISMATCH → const int
X509_V_ERR_APPLICATION_VERIFICATION → const int
X509_V_ERR_CERT_CHAIN_TOO_LONG → const int
X509_V_ERR_CERT_HAS_EXPIRED → const int
X509_V_ERR_CERT_NOT_YET_VALID → const int
X509_V_ERR_CERT_REJECTED → const int
X509_V_ERR_CERT_REVOKED → const int
X509_V_ERR_CERT_SIGNATURE_FAILURE → const int
X509_V_ERR_CERT_UNTRUSTED → const int
X509_V_ERR_CRL_HAS_EXPIRED → const int
X509_V_ERR_CRL_NOT_YET_VALID → const int
X509_V_ERR_CRL_PATH_VALIDATION_ERROR → const int
X509_V_ERR_CRL_SIGNATURE_FAILURE → const int
X509_V_ERR_DEPTH_ZERO_SELF_SIGNED_CERT → const int
X509_V_ERR_DIFFERENT_CRL_SCOPE → const int
X509_V_ERR_EMAIL_MISMATCH → const int
X509_V_ERR_ERROR_IN_CERT_NOT_AFTER_FIELD → const int
X509_V_ERR_ERROR_IN_CERT_NOT_BEFORE_FIELD → const int
X509_V_ERR_ERROR_IN_CRL_LAST_UPDATE_FIELD → const int
X509_V_ERR_ERROR_IN_CRL_NEXT_UPDATE_FIELD → const int
X509_V_ERR_EXCLUDED_VIOLATION → const int
X509_V_ERR_HOSTNAME_MISMATCH → const int
X509_V_ERR_INVALID_CA → const int
X509_V_ERR_INVALID_CALL → const int
X509_V_ERR_INVALID_EXTENSION → const int
X509_V_ERR_INVALID_NON_CA → const int
X509_V_ERR_INVALID_POLICY_EXTENSION → const int
X509_V_ERR_INVALID_PURPOSE → const int
X509_V_ERR_IP_ADDRESS_MISMATCH → const int
X509_V_ERR_KEYUSAGE_NO_CERTSIGN → const int
X509_V_ERR_KEYUSAGE_NO_CRL_SIGN → const int
X509_V_ERR_KEYUSAGE_NO_DIGITAL_SIGNATURE → const int
X509_V_ERR_NAME_CONSTRAINTS_WITHOUT_SANS → const int
X509_V_ERR_NO_EXPLICIT_POLICY → const int
X509_V_ERR_OUT_OF_MEM → const int
X509_V_ERR_PATH_LENGTH_EXCEEDED → const int
X509_V_ERR_PERMITTED_VIOLATION → const int
X509_V_ERR_PROXY_CERTIFICATES_NOT_ALLOWED → const int
X509_V_ERR_PROXY_PATH_LENGTH_EXCEEDED → const int
X509_V_ERR_SELF_SIGNED_CERT_IN_CHAIN → const int
X509_V_ERR_STORE_LOOKUP → const int
X509_V_ERR_SUBJECT_ISSUER_MISMATCH → const int
X509_V_ERR_SUBTREE_MINMAX → const int
X509_V_ERR_UNABLE_TO_DECODE_ISSUER_PUBLIC_KEY → const int
X509_V_ERR_UNABLE_TO_DECRYPT_CERT_SIGNATURE → const int
X509_V_ERR_UNABLE_TO_DECRYPT_CRL_SIGNATURE → const int
X509_V_ERR_UNABLE_TO_GET_CRL → const int
X509_V_ERR_UNABLE_TO_GET_CRL_ISSUER → const int
X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT → const int
X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY → const int
X509_V_ERR_UNABLE_TO_VERIFY_LEAF_SIGNATURE → const int
X509_V_ERR_UNHANDLED_CRITICAL_CRL_EXTENSION → const int
X509_V_ERR_UNHANDLED_CRITICAL_EXTENSION → const int
X509_V_ERR_UNNESTED_RESOURCE → const int
X509_V_ERR_UNSPECIFIED → const int
X509_V_ERR_UNSUPPORTED_CONSTRAINT_SYNTAX → const int
X509_V_ERR_UNSUPPORTED_CONSTRAINT_TYPE → const int
X509_V_ERR_UNSUPPORTED_EXTENSION_FEATURE → const int
X509_V_ERR_UNSUPPORTED_NAME_SYNTAX → const int
X509_V_FLAG_ALLOW_PROXY_CERTS → const int
X509_V_FLAG_CB_ISSUER_CHECK → const int
X509_V_FLAG_CHECK_SS_SIGNATURE → const int
X509_V_FLAG_CRL_CHECK → const int
X509_V_FLAG_CRL_CHECK_ALL → const int
X509_V_FLAG_EXPLICIT_POLICY → const int
X509_V_FLAG_EXTENDED_CRL_SUPPORT → const int
X509_V_FLAG_IGNORE_CRITICAL → const int
X509_V_FLAG_INHIBIT_ANY → const int
X509_V_FLAG_INHIBIT_MAP → const int
X509_V_FLAG_NO_ALT_CHAINS → const int
X509_V_FLAG_NO_CHECK_TIME → const int
X509_V_FLAG_NOTIFY_POLICY → const int
X509_V_FLAG_PARTIAL_CHAIN → const int
X509_V_FLAG_POLICY_CHECK → const int
X509_V_FLAG_TRUSTED_FIRST → const int
X509_V_FLAG_USE_CHECK_TIME → const int
X509_V_FLAG_USE_DELTAS → const int
X509_V_FLAG_X509_STRICT → const int
X509_V_OK → const int
X509_VERSION_1 → const int
X509_VERSION_2 → const int
X509_VERSION_3 → const int

Functions

a2i_IPADDRESS(Pointer<Char> ipasc) → Pointer<ASN1_OCTET_STRING>
a2i_IPADDRESS decodes |ipasc| as the textual representation of an IPv4 or IPv6 address. On success, it returns a newly-allocated |ASN1_OCTET_STRING| containing the decoded IP address. IPv4 addresses are represented as 4-byte strings and IPv6 addresses as 16-byte strings. On failure, it returns NULL.
a2i_IPADDRESS_NC(Pointer<Char> ipasc) → Pointer<ASN1_OCTET_STRING>
a2i_IPADDRESS_NC decodes |ipasc| as the textual representation of an IPv4 or IPv6 address range. On success, it returns a newly-allocated |ASN1_OCTET_STRING| containing the decoded IP address, followed by the decoded mask. IPv4 ranges are represented as 8-byte strings and IPv6 ranges as 32-byte strings. On failure, it returns NULL.
ACCESS_DESCRIPTION_free(Pointer<ACCESS_DESCRIPTION> desc) → void
ACCESS_DESCRIPTION_free releases memory associated with |desc|.
ACCESS_DESCRIPTION_new() → Pointer<ACCESS_DESCRIPTION>
ACCESS_DESCRIPTION_new returns a newly-allocated, empty |ACCESS_DESCRIPTION| object, or NULL on error.
AES_cbc_encrypt(Pointer<Uint8> in$, Pointer<Uint8> out, int len, Pointer<AES_KEY> key, Pointer<Uint8> ivec, int enc) → void
AES_cbc_encrypt encrypts (or decrypts, if |enc| == |AES_DECRYPT|) |len| bytes from |in| to |out|. The length must be a multiple of the block size. This function may be called in-place with |in| equal to |out|, but otherwise the buffers may not partially overlap. A partial overlap may overwrite input data before it is read.
AES_cfb128_encrypt(Pointer<Uint8> in$, Pointer<Uint8> out, int len, Pointer<AES_KEY> key, Pointer<Uint8> ivec, Pointer<Int> num, int enc) → void
AES_cfb128_encrypt encrypts (or decrypts, if |enc| == |AES_DECRYPT|) |len| bytes from |in| to |out|. The |num| parameter must be set to zero on the first call. This function may be called in-place with |in| equal to |out|, but otherwise the buffers may not partially overlap. A partial overlap may overwrite input data before it is read.
AES_ctr128_encrypt(Pointer<Uint8> in$, Pointer<Uint8> out, int len, Pointer<AES_KEY> key, Pointer<Uint8> ivec, Pointer<Uint8> ecount_buf, Pointer<UnsignedInt> num) → void
AES_ctr128_encrypt encrypts (or decrypts, it's the same in CTR mode) |len| bytes from |in| to |out|. The |num| parameter must be set to zero on the first call and |ivec| will be incremented. This function may be called in-place with |in| equal to |out|, but otherwise the buffers may not partially overlap. A partial overlap may overwrite input data before it is read.
AES_decrypt(Pointer<Uint8> in$, Pointer<Uint8> out, Pointer<AES_KEY> key) → void
AES_decrypt decrypts a single block from |in| to |out| with |key|. The |in| and |out| pointers may overlap.
AES_ecb_encrypt(Pointer<Uint8> in$, Pointer<Uint8> out, Pointer<AES_KEY> key, int enc) → void
AES_ecb_encrypt encrypts (or decrypts, if |enc| == |AES_DECRYPT|) a single, 16 byte block from |in| to |out|. This function may be called in-place with |in| equal to |out|, but otherwise the buffers may not partially overlap. A partial overlap may overwrite input data before it is read.
AES_encrypt(Pointer<Uint8> in$, Pointer<Uint8> out, Pointer<AES_KEY> key) → void
AES_encrypt encrypts a single block from |in| to |out| with |key|. The |in| and |out| pointers may overlap.
AES_ofb128_encrypt(Pointer<Uint8> in$, Pointer<Uint8> out, int len, Pointer<AES_KEY> key, Pointer<Uint8> ivec, Pointer<Int> num) → void
AES_ofb128_encrypt encrypts (or decrypts, it's the same in OFB mode) |len| bytes from |in| to |out|. The |num| parameter must be set to zero on the first call. This function may be called in-place with |in| equal to |out|, but otherwise the buffers may not partially overlap. A partial overlap may overwrite input data before it is read.
AES_set_decrypt_key(Pointer<Uint8> key, int bits, Pointer<AES_KEY> aeskey) → int
AES_set_decrypt_key configures |aeskey| to decrypt with the |bits|-bit key, |key|. |key| must point to |bits|/8 bytes. It returns zero on success and a negative number if |bits| is an invalid AES key size.
AES_set_encrypt_key(Pointer<Uint8> key, int bits, Pointer<AES_KEY> aeskey) → int
AES_set_encrypt_key configures |aeskey| to encrypt with the |bits|-bit key, |key|. |key| must point to |bits|/8 bytes. It returns zero on success and a negative number if |bits| is an invalid AES key size.
AES_unwrap_key(Pointer<AES_KEY> key, Pointer<Uint8> iv, Pointer<Uint8> out, Pointer<Uint8> in$, int in_len) → int
AES_unwrap_key performs AES key unwrap on |in| which must be a multiple of 8 bytes. |iv| must point to an 8 byte value or be NULL to use the default IV. |key| must have been configured for decryption. On success, it writes |in_len| - 8 bytes to |out| and returns |in_len| - 8. Otherwise, it returns -1.
AES_unwrap_key_padded(Pointer<AES_KEY> key, Pointer<Uint8> out, Pointer<Size> out_len, int max_out, Pointer<Uint8> in$, int in_len) → int
AES_unwrap_key_padded performs a padded AES key unwrap on |in| which must be a multiple of 8 bytes. |key| must have been configured for decryption. On success it writes at most |max_out| bytes to |out|, sets |*out_len| to the number of bytes written, and returns one. On failure it returns zero. Setting |max_out| to |in_len| is a sensible estimate.
AES_wrap_key(Pointer<AES_KEY> key, Pointer<Uint8> iv, Pointer<Uint8> out, Pointer<Uint8> in$, int in_len) → int
AES_wrap_key performs AES key wrap on |in| which must be a multiple of 8 bytes. |iv| must point to an 8 byte value or be NULL to use the default IV. |key| must have been configured for encryption. On success, it writes |in_len| + 8 bytes to |out| and returns |in_len| + 8. Otherwise, it returns -1.
AES_wrap_key_padded(Pointer<AES_KEY> key, Pointer<Uint8> out, Pointer<Size> out_len, int max_out, Pointer<Uint8> in$, int in_len) → int
AES_wrap_key_padded performs a padded AES key wrap on |in| which must be between 1 and 2^32-1 bytes. |key| must have been configured for encryption. On success it writes at most |max_out| bytes of ciphertext to |out|, sets |*out_len| to the number of bytes written, and returns one. On failure it returns zero. To ensure success, set |max_out| to at least |in_len| + 15.
ASN1_BIT_STRING_check(Pointer<ASN1_OCTET_STRING> str, Pointer<UnsignedChar> flags, int flags_len) → int
ASN1_BIT_STRING_check returns one if |str| only contains bits that are set in the |flags_len| bytes pointed by |flags|. Otherwise it returns zero. Bits in |flags| are arranged according to the DER representation, so bit 0 corresponds to the MSB of |flags0|.
ASN1_BIT_STRING_free(Pointer<ASN1_OCTET_STRING> str) → void
ASN1_BIT_STRING_free calls |ASN1_STRING_free|.
ASN1_BIT_STRING_get_bit(Pointer<ASN1_OCTET_STRING> str, int n) → int
ASN1_BIT_STRING_get_bit returns one if bit |n| of |a| is in bounds and set, and zero otherwise. |n| is indexed beginning from zero.
ASN1_BIT_STRING_new() → Pointer<ASN1_OCTET_STRING>
ASN1_BIT_STRING_new calls |ASN1_STRING_type_new| with |V_ASN1_BIT_STRING|.
ASN1_BIT_STRING_num_bytes(Pointer<ASN1_OCTET_STRING> str, Pointer<Size> out) → int
ASN1_BIT_STRING_num_bytes computes the length of |str| in bytes. If |str|'s bit length is a multiple of 8, it sets |*out| to the byte length and returns one. Otherwise, it returns zero.
ASN1_BIT_STRING_set(Pointer<ASN1_OCTET_STRING> str, Pointer<Uint8> data, int length) → int
ASN1_BIT_STRING_set calls |ASN1_STRING_set|.
ASN1_BIT_STRING_set1(Pointer<ASN1_OCTET_STRING> str, Pointer<Uint8> data, int length, int unused_bits) → int
ASN1_BIT_STRING_set1 sets |str| to a BIT STRING containing |length| bytes from |data|. It returns one on success and zero on error. The least significant |unused_bits| of the last byte of |data| are removed from the bit string. The removed bits must all be zero. |unused_bits| must be between 0 and 7, and must be 0 if |length| is zero.
ASN1_BIT_STRING_set_bit(Pointer<ASN1_OCTET_STRING> str, int n, int value) → int
ASN1_BIT_STRING_set_bit sets bit |n| of |str| to one if |value| is non-zero and zero if |value| is zero, resizing |str| as needed. It then truncates trailing zeros in |str| to align with the DER representation for a bit string with named bits. It returns one on success and zero on error. |n| is indexed beginning from zero.
ASN1_BIT_STRING_unused_bits(Pointer<ASN1_OCTET_STRING> str) → int
ASN1_BIT_STRING_unused_bits returns the number of unused bits in the last byte of |str|. If |str| is empty (i.e. |ASN1_STRING_length| is zero), this always returns zero. Otherwise it returns a number between 0 and 7.
ASN1_BMPSTRING_free(Pointer<ASN1_OCTET_STRING> str) → void
The following functions call |ASN1_STRING_free|.
ASN1_BMPSTRING_new() → Pointer<ASN1_OCTET_STRING>
The following functions call |ASN1_STRING_type_new| with the corresponding |V_ASN1_*| constant.
ASN1_digest(Pointer<i2d_of_void> i2d, Pointer<EVP_MD> type, Pointer<Char> data, Pointer<UnsignedChar> md, Pointer<UnsignedInt> len) → int
ASN1_digest serializes |data| with |i2d| and then hashes the result with |type|. On success, it returns one, writes the digest to |md|, and sets |*len| to the digest length if non-NULL. On error, it returns zero.
ASN1_ENUMERATED_free(Pointer<ASN1_OCTET_STRING> str) → void
ASN1_ENUMERATED_free calls |ASN1_STRING_free|.
ASN1_ENUMERATED_get(Pointer<ASN1_OCTET_STRING> a) → int
ASN1_ENUMERATED_get returns the value of |a| as a |long|, or -1 if |a| is out of range or the wrong type.
ASN1_ENUMERATED_get_int64(Pointer<Int64> out, Pointer<ASN1_OCTET_STRING> a) → int
ASN1_ENUMERATED_get_int64 converts |a| to a |int64_t|. On success, it returns one and sets |*out| to the result. If |a| did not fit or has the wrong type, it returns zero.
ASN1_ENUMERATED_get_uint64(Pointer<Uint64> out, Pointer<ASN1_OCTET_STRING> a) → int
ASN1_ENUMERATED_get_uint64 converts |a| to a |uint64_t|. On success, it returns one and sets |*out| to the result. If |a| did not fit or has the wrong type, it returns zero.
ASN1_ENUMERATED_new() → Pointer<ASN1_OCTET_STRING>
ASN1_ENUMERATED_new calls |ASN1_STRING_type_new| with |V_ASN1_ENUMERATED|. The resulting object has value zero.
ASN1_ENUMERATED_set(Pointer<ASN1_OCTET_STRING> a, int v) → int
ASN1_ENUMERATED_set sets |a| to an ENUMERATED with value |v|. It returns one on success and zero on error.
ASN1_ENUMERATED_set_int64(Pointer<ASN1_OCTET_STRING> out, int v) → int
ASN1_ENUMERATED_set_int64 sets |a| to an ENUMERATED with value |v|. It returns one on success and zero on error.
ASN1_ENUMERATED_set_uint64(Pointer<ASN1_OCTET_STRING> out, int v) → int
ASN1_ENUMERATED_set_uint64 sets |a| to an ENUMERATED with value |v|. It returns one on success and zero on error.
ASN1_ENUMERATED_to_BN(Pointer<ASN1_OCTET_STRING> ai, Pointer<BIGNUM> bn) → Pointer<BIGNUM>
ASN1_ENUMERATED_to_BN sets |bn| to the value of |ai| and returns |bn| on success or NULL or error. If |bn| is NULL, it returns a newly-allocated |BIGNUM| on success instead, which the caller must release with |BN_free|.
ASN1_GENERALIZEDTIME_adj(Pointer<ASN1_OCTET_STRING> s, int posix_time, int offset_day, int offset_sec) → Pointer<ASN1_OCTET_STRING>
ASN1_GENERALIZEDTIME_adj adds |offset_day| days and |offset_sec| seconds to |posix_time| and writes the result to |s| as a GeneralizedTime. It returns |s| on success and NULL on error. If |s| is NULL, it returns a newly-allocated |ASN1_GENERALIZEDTIME| instead.
ASN1_GENERALIZEDTIME_check(Pointer<ASN1_OCTET_STRING> a) → int
ASN1_GENERALIZEDTIME_check returns one if |a| is a valid GeneralizedTime and zero otherwise.
ASN1_GENERALIZEDTIME_free(Pointer<ASN1_OCTET_STRING> str) → void
ASN1_GENERALIZEDTIME_free calls |ASN1_STRING_free|.
ASN1_GENERALIZEDTIME_new() → Pointer<ASN1_OCTET_STRING>
ASN1_GENERALIZEDTIME_new calls |ASN1_STRING_type_new| with |V_ASN1_GENERALIZEDTIME|. The resulting object contains empty contents and must be initialized to be a valid GeneralizedTime.
ASN1_GENERALIZEDTIME_print(Pointer<BIO> out, Pointer<ASN1_OCTET_STRING> a) → int
ASN1_GENERALIZEDTIME_print writes a human-readable representation of |a| to |out|. It returns one on success and zero on error.
ASN1_GENERALIZEDTIME_set(Pointer<ASN1_OCTET_STRING> s, int posix_time) → Pointer<ASN1_OCTET_STRING>
ASN1_GENERALIZEDTIME_set represents |posix_time| as a GeneralizedTime and writes the result to |s|. It returns |s| on success and NULL on error. If |s| is NULL, it returns a newly-allocated |ASN1_GENERALIZEDTIME| instead.
ASN1_GENERALIZEDTIME_set_string(Pointer<ASN1_OCTET_STRING> s, Pointer<Char> str) → int
ASN1_GENERALIZEDTIME_set_string sets |s| to a GeneralizedTime whose contents are a copy of |str|. It returns one on success and zero on error or if |str| is not a valid GeneralizedTime.
ASN1_GENERALSTRING_free(Pointer<ASN1_OCTET_STRING> str) → void
ASN1_GENERALSTRING_new() → Pointer<ASN1_OCTET_STRING>
ASN1_get_object(Pointer<Pointer<UnsignedChar>> inp, Pointer<Long> out_length, Pointer<Int> out_tag, Pointer<Int> out_class, int max_len) → int
ASN1_get_object parses a BER element from up to |max_len| bytes at |*inp|. It returns |V_ASN1_CONSTRUCTED| if it successfully parsed a constructed element, zero if it successfully parsed a primitive element, and 0x80 on error. On success, it additionally advances |*inp| to the element body, sets |*out_length|, |*out_tag|, and |*out_class| to the element's length, tag number, and tag class, respectively,
ASN1_IA5STRING_free(Pointer<ASN1_OCTET_STRING> str) → void
ASN1_IA5STRING_new() → Pointer<ASN1_OCTET_STRING>
ASN1_INTEGER_cmp(Pointer<ASN1_OCTET_STRING> x, Pointer<ASN1_OCTET_STRING> y) → int
ASN1_INTEGER_cmp compares the values of |x| and |y|. It returns an integer equal to, less than, or greater than zero if |x| is equal to, less than, or greater than |y|, respectively.
ASN1_INTEGER_dup(Pointer<ASN1_OCTET_STRING> x) → Pointer<ASN1_OCTET_STRING>
ASN1_INTEGER_dup calls |ASN1_STRING_dup|.
ASN1_INTEGER_free(Pointer<ASN1_OCTET_STRING> str) → void
ASN1_INTEGER_free calls |ASN1_STRING_free|.
ASN1_INTEGER_get(Pointer<ASN1_OCTET_STRING> a) → int
ASN1_INTEGER_get returns the value of |a| as a |long|, or -1 if |a| is out of range or the wrong type.
ASN1_INTEGER_get_int64(Pointer<Int64> out, Pointer<ASN1_OCTET_STRING> a) → int
ASN1_INTEGER_get_int64 converts |a| to a |int64_t|. On success, it returns one and sets |*out| to the result. If |a| did not fit or has the wrong type, it returns zero.
ASN1_INTEGER_get_uint64(Pointer<Uint64> out, Pointer<ASN1_OCTET_STRING> a) → int
ASN1_INTEGER_get_uint64 converts |a| to a |uint64_t|. On success, it returns one and sets |*out| to the result. If |a| did not fit or has the wrong type, it returns zero.
ASN1_INTEGER_new() → Pointer<ASN1_OCTET_STRING>
ASN1_INTEGER_new calls |ASN1_STRING_type_new| with |V_ASN1_INTEGER|. The resulting object has value zero.
ASN1_INTEGER_set(Pointer<ASN1_OCTET_STRING> a, int v) → int
ASN1_INTEGER_set sets |a| to an INTEGER with value |v|. It returns one on success and zero on error.
ASN1_INTEGER_set_int64(Pointer<ASN1_OCTET_STRING> out, int v) → int
ASN1_INTEGER_set_int64 sets |a| to an INTEGER with value |v|. It returns one on success and zero on error.
ASN1_INTEGER_set_uint64(Pointer<ASN1_OCTET_STRING> out, int v) → int
ASN1_INTEGER_set_uint64 sets |a| to an INTEGER with value |v|. It returns one on success and zero on error.
ASN1_INTEGER_to_BN(Pointer<ASN1_OCTET_STRING> ai, Pointer<BIGNUM> bn) → Pointer<BIGNUM>
ASN1_INTEGER_to_BN sets |bn| to the value of |ai| and returns |bn| on success or NULL or error. If |bn| is NULL, it returns a newly-allocated |BIGNUM| on success instead, which the caller must release with |BN_free|.
ASN1_item_d2i(Pointer<Pointer<ASN1_VALUE>> out, Pointer<Pointer<UnsignedChar>> inp, int len, Pointer<ASN1_ITEM> it) → Pointer<ASN1_VALUE>
ASN1_item_d2i parses the ASN.1 type |it| from up to |len| bytes at |*inp|. It behaves like |d2i_SAMPLE|, except that |out| and the return value are cast to |ASN1_VALUE| pointers.
ASN1_item_d2i_bio(Pointer<ASN1_ITEM> it, Pointer<BIO> in$, Pointer<Void> out) → Pointer<Void>
ASN1_item_d2i_fp(Pointer<ASN1_ITEM> it, Pointer<FILE> in$, Pointer<Void> out) → Pointer<Void>
The following functions behave like |ASN1_item_d2i| but read from |in| instead. |out| is the same parameter as in |ASN1_item_d2i|, but written with |void*| instead. The return values similarly match.
ASN1_item_digest(Pointer<ASN1_ITEM> it, Pointer<EVP_MD> type, Pointer<Void> data, Pointer<UnsignedChar> md, Pointer<UnsignedInt> len) → int
ASN1_item_digest serializes |data| with |it| and then hashes the result with |type|. On success, it returns one, writes the digest to |md|, and sets |*len| to the digest length if non-NULL. On error, it returns zero.
ASN1_item_dup(Pointer<ASN1_ITEM> it, Pointer<Void> x) → Pointer<Void>
ASN1_item_dup returns a newly-allocated copy of |x|, or NULL on error. |x| must be an object of |it|'s C type.
ASN1_item_free(Pointer<ASN1_VALUE> val, Pointer<ASN1_ITEM> it) → void
ASN1_item_free releases memory associated with |val|, which must be an object of the C type corresponding to |it|.
ASN1_item_i2d(Pointer<ASN1_VALUE> val, Pointer<Pointer<UnsignedChar>> outp, Pointer<ASN1_ITEM> it) → int
ASN1_item_i2d marshals |val| as the ASN.1 type associated with |it|, as described in |i2d_SAMPLE|.
ASN1_item_i2d_bio(Pointer<ASN1_ITEM> it, Pointer<BIO> out, Pointer<Void> in$) → int
ASN1_item_i2d_fp(Pointer<ASN1_ITEM> it, Pointer<FILE> out, Pointer<Void> in$) → int
The following functions behave like |ASN1_item_i2d| but write to |out| instead. |in| is the same parameter as in |ASN1_item_i2d|, but written with |void*| instead.
ASN1_item_new(Pointer<ASN1_ITEM> it) → Pointer<ASN1_VALUE>
ASN1_item_new allocates a new value of the C type corresponding to |it|, or NULL on error. On success, the caller must release the value with |ASN1_item_free|, or the corresponding C type's free function, when done. The new value will initialize fields of the value to some default state, such as an empty string. Note, however, that this default state sometimes omits required values, such as with CHOICE types.
ASN1_item_pack(Pointer<Void> obj, Pointer<ASN1_ITEM> it, Pointer<Pointer<ASN1_OCTET_STRING>> out) → Pointer<ASN1_OCTET_STRING>
ASN1_item_pack marshals |obj| as |it|'s ASN.1 type. If |out| is NULL, it returns a newly-allocated |ASN1_STRING| with the result, or NULL on error. If |out| is non-NULL, but |*out| is NULL, it does the same but additionally sets |*out| to the result. If both |out| and |*out| are non-NULL, it writes the result to |*out| and returns |*out| on success or NULL on error.
ASN1_item_sign(Pointer<ASN1_ITEM> it, Pointer<X509_ALGOR> algor1, Pointer<X509_ALGOR> algor2, Pointer<ASN1_OCTET_STRING> signature, Pointer<Void> data, Pointer<EVP_PKEY> pkey, Pointer<EVP_MD> type) → int
ASN1_item_sign serializes |data| with |it| and then signs the result with the private key |pkey|. It returns the length of the signature on success and zero on error. On success, it writes the signature to |signature| and the signature algorithm to each of |algor1| and |algor2|. Either of |algor1| or |algor2| may be NULL to ignore them. This function uses digest algorithm |md|, or |pkey|'s default if NULL. Other signing parameters use |pkey|'s defaults. To customize them, use |ASN1_item_sign_ctx|.
ASN1_item_sign_ctx(Pointer<ASN1_ITEM> it, Pointer<X509_ALGOR> algor1, Pointer<X509_ALGOR> algor2, Pointer<ASN1_OCTET_STRING> signature, Pointer<Void> asn, Pointer<EVP_MD_CTX> ctx) → int
ASN1_item_sign_ctx behaves like |ASN1_item_sign| except the signature is signed with |ctx|, |ctx|, which must have been initialized with |EVP_DigestSignInit|. The caller should configure the corresponding |EVP_PKEY_CTX| with any additional parameters before calling this function.
ASN1_item_unpack(Pointer<ASN1_OCTET_STRING> oct, Pointer<ASN1_ITEM> it) → Pointer<Void>
ASN1_item_unpack parses |oct|'s contents as |it|'s ASN.1 type. It returns a newly-allocated instance of |it|'s C type on success, or NULL on error.
ASN1_item_verify(Pointer<ASN1_ITEM> it, Pointer<X509_ALGOR> algor1, Pointer<ASN1_OCTET_STRING> signature, Pointer<Void> data, Pointer<EVP_PKEY> pkey) → int
ASN1_item_verify serializes |data| with |it| and then verifies |signature| is a valid signature for the result with |algor1| and |pkey|. It returns one on success and zero on error. The signature and algorithm are interpreted as in X.509.
ASN1_mbstring_copy(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Uint8> in$, int len, int inform, int mask) → int
ASN1_mbstring_copy converts |len| bytes from |in| to an ASN.1 string. If |len| is -1, |in| must be NUL-terminated and the length is determined by |strlen|. |in| is decoded according to |inform|, which must be one of |MBSTRING_*|. |mask| determines the set of valid output types and is a bitmask containing a subset of |B_ASN1_PRINTABLESTRING|, |B_ASN1_IA5STRING|, |B_ASN1_T61STRING|, |B_ASN1_BMPSTRING|, |B_ASN1_UNIVERSALSTRING|, and |B_ASN1_UTF8STRING|, in that preference order. This function chooses the first output type in |mask| which can represent |in|. It interprets T61String as Latin-1, rather than T.61.
ASN1_mbstring_ncopy(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Uint8> in$, int len, int inform, int mask, int minsize, int maxsize) → int
ASN1_mbstring_ncopy behaves like |ASN1_mbstring_copy| but returns an error if the input is less than |minsize| or greater than |maxsize| codepoints long. A |maxsize| value of zero is ignored. Note the sizes are measured in codepoints, not output bytes.
ASN1_NULL_free(Pointer<ASN1_NULL> null$) → void
ASN1_NULL_free does nothing.
ASN1_NULL_new() → Pointer<ASN1_NULL>
ASN1_NULL_new returns an opaque, non-NULL pointer. It is safe to call |ASN1_NULL_free| on the result, but not necessary.
ASN1_OBJECT_create(int nid, Pointer<Uint8> data, int len, Pointer<Char> sn, Pointer<Char> ln) → Pointer<ASN1_OBJECT>
ASN1_OBJECT_create returns a newly-allocated |ASN1_OBJECT| with |len| bytes from |data| as the encoded OID, or NULL on error. |data| should contain the DER-encoded identifier, excluding the tag and length.
ASN1_OBJECT_free(Pointer<ASN1_OBJECT> a) → void
ASN1_OBJECT_free releases memory associated with |a|. If |a| is a static |ASN1_OBJECT|, returned from |OBJ_nid2obj|, this function does nothing.
ASN1_object_size(int constructed, int length, int tag) → int
ASN1_object_size returns the number of bytes needed to encode a DER or BER value with length |length| and tag number |tag|, or -1 on error. |tag| should not include the constructed bit or tag class. If |constructed| is zero or one, the result uses a definite-length encoding with minimally-encoded length, as in DER. If |constructed| is two, the result uses BER indefinite-length encoding.
ASN1_OCTET_STRING_cmp(Pointer<ASN1_OCTET_STRING> a, Pointer<ASN1_OCTET_STRING> b) → int
ASN1_OCTET_STRING_cmp calls |ASN1_STRING_cmp|.
ASN1_OCTET_STRING_dup(Pointer<ASN1_OCTET_STRING> a) → Pointer<ASN1_OCTET_STRING>
ASN1_OCTET_STRING_dup calls |ASN1_STRING_dup|.
ASN1_OCTET_STRING_free(Pointer<ASN1_OCTET_STRING> str) → void
ASN1_OCTET_STRING_new() → Pointer<ASN1_OCTET_STRING>
ASN1_OCTET_STRING_set(Pointer<ASN1_OCTET_STRING> str, Pointer<UnsignedChar> data, int len) → int
ASN1_OCTET_STRING_set calls |ASN1_STRING_set|.
ASN1_PRINTABLESTRING_free(Pointer<ASN1_OCTET_STRING> str) → void
ASN1_PRINTABLESTRING_new() → Pointer<ASN1_OCTET_STRING>
ASN1_put_eoc(Pointer<Pointer<UnsignedChar>> outp) → int
ASN1_put_eoc writes two zero bytes to |*outp|, advances |*outp| to point past those bytes, and returns two.
ASN1_put_object(Pointer<Pointer<UnsignedChar>> outp, int constructed, int length, int tag, int xclass) → void
ASN1_put_object writes the header for a DER or BER element to |*outp| and advances |*outp| by the number of bytes written. The caller is responsible for ensuring |outp| has enough space for the output. The header describes an element with length |length|, tag number |tag|, and class |xclass|. |xclass| should be one of the |V_ASN1_| tag class constants. The element is primitive if |constructed| is zero and constructed if it is one or two. If |constructed| is two, |length| is ignored and the element uses indefinite-length encoding.
ASN1_STRING_cmp(Pointer<ASN1_OCTET_STRING> a, Pointer<ASN1_OCTET_STRING> b) → int
ASN1_STRING_cmp compares |a| and |b|'s type and contents. It returns an integer equal to, less than, or greater than zero if |a| is equal to, less than, or greater than |b|, respectively. This function compares by length, then data, then type. Note the data compared is the |ASN1_STRING| internal representation and the type order is arbitrary. While this comparison is suitable for sorting, callers should not rely on the exact order when |a| and |b| are different types.
ASN1_STRING_copy(Pointer<ASN1_OCTET_STRING> dst, Pointer<ASN1_OCTET_STRING> str) → int
ASN1_STRING_copy sets |dst| to a copy of |str|. It returns one on success and zero on error.
ASN1_STRING_data(Pointer<ASN1_OCTET_STRING> str) → Pointer<UnsignedChar>
ASN1_STRING_data returns a mutable pointer to |str|'s contents. Callers should use |ASN1_STRING_length| to determine the length of the string. The string may have embedded NUL bytes and may not be NUL-terminated.
ASN1_STRING_dup(Pointer<ASN1_OCTET_STRING> str) → Pointer<ASN1_OCTET_STRING>
ASN1_STRING_dup returns a newly-allocated copy of |str|, or NULL on error.
ASN1_STRING_free(Pointer<ASN1_OCTET_STRING> str) → void
ASN1_STRING_free releases memory associated with |str|.
ASN1_STRING_get0_data(Pointer<ASN1_OCTET_STRING> str) → Pointer<UnsignedChar>
ASN1_STRING_get0_data returns a pointer to |str|'s contents. Callers should use |ASN1_STRING_length| to determine the length of the string. The string may have embedded NUL bytes and may not be NUL-terminated.
ASN1_STRING_get_default_mask() → int
ASN1_STRING_get_default_mask returns |B_ASN1_UTF8STRING|.
ASN1_STRING_length(Pointer<ASN1_OCTET_STRING> str) → int
ASN1_STRING_length returns the length of |str|, in bytes.
ASN1_STRING_new() → Pointer<ASN1_OCTET_STRING>
ASN1_STRING_new returns a newly-allocated empty |ASN1_STRING| object with an arbitrary type. Prefer one of the type-specific constructors, such as |ASN1_OCTET_STRING_new|, or |ASN1_STRING_type_new|.
ASN1_STRING_print(Pointer<BIO> out, Pointer<ASN1_OCTET_STRING> str) → int
ASN1_STRING_print writes a human-readable representation of |str| to |out|. It returns one on success and zero on error. Unprintable characters are replaced with '.'.
ASN1_STRING_print_ex(Pointer<BIO> out, Pointer<ASN1_OCTET_STRING> str, int flags) → int
ASN1_STRING_print_ex writes a human-readable representation of |str| to |out|. It returns the number of bytes written on success and -1 on error. If |out| is NULL, it returns the number of bytes it would have written, without writing anything.
ASN1_STRING_print_ex_fp(Pointer<FILE> fp, Pointer<ASN1_OCTET_STRING> str, int flags) → int
ASN1_STRING_print_ex_fp behaves like |ASN1_STRING_print_ex| but writes to a |FILE| rather than a |BIO|.
ASN1_STRING_set(Pointer<ASN1_OCTET_STRING> str, Pointer<Void> data, int len) → int
ASN1_STRING_set sets the contents of |str| to a copy of |len| bytes from |data|. It returns one on success and zero on error. If |data| is NULL, it updates the length and allocates the buffer as needed, but does not initialize the contents.
ASN1_STRING_set0(Pointer<ASN1_OCTET_STRING> str, Pointer<Void> data, int len) → void
ASN1_STRING_set0 sets the contents of |str| to |len| bytes from |data|. It takes ownership of |data|, which must have been allocated with |OPENSSL_malloc|.
ASN1_STRING_set_by_NID(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<UnsignedChar> in$, int len, int inform, int nid) → Pointer<ASN1_OCTET_STRING>
ASN1_STRING_set_by_NID behaves like |ASN1_mbstring_ncopy|, but determines |mask|, |minsize|, and |maxsize| based on |nid|. When |nid| is a recognized X.509 attribute type, it will pick a suitable ASN.1 string type and bounds. For most attribute types, it preferentially chooses UTF8String. If |nid| is unrecognized, it uses UTF8String by default. This function will also enforce any known attribute-specific constraints on the sizes of the string and fail if the size is invalid. In RFC 5280, these bounds are specified by constraints like "SIZE (1..ub-common-name)" in ASN.1.
ASN1_STRING_set_default_mask(int mask) → void
ASN1_STRING_set_default_mask does nothing.
ASN1_STRING_set_default_mask_asc(Pointer<Char> p) → int
ASN1_STRING_set_default_mask_asc returns one.
ASN1_STRING_TABLE_add(int nid, int minsize, int maxsize, int mask, int flags) → int
ASN1_STRING_TABLE_add registers the corresponding parameters with |nid|, for use with |ASN1_STRING_set_by_NID|. It returns one on success and zero on error. It is an error to call this function if |nid| is a built-in NID, or was already registered by a previous call.
ASN1_STRING_TABLE_cleanup() → void
ASN1_STRING_TABLE_cleanup does nothing.
ASN1_STRING_to_UTF8(Pointer<Pointer<UnsignedChar>> out, Pointer<ASN1_OCTET_STRING> in$) → int
ASN1_STRING_to_UTF8 converts |in| to UTF-8. On success, sets |*out| to a newly-allocated buffer containing the resulting string and returns the length of the string. The caller must call |OPENSSL_free| to release |*out| when done. On error, it returns a negative number.
ASN1_STRING_type(Pointer<ASN1_OCTET_STRING> str) → int
ASN1_STRING_type returns the type of |str|. This value will be one of the |V_ASN1_*| constants.
ASN1_STRING_type_new(int type) → Pointer<ASN1_OCTET_STRING>
ASN1_STRING_type_new returns a newly-allocated empty |ASN1_STRING| object of type |type|, or NULL on error.
ASN1_T61STRING_free(Pointer<ASN1_OCTET_STRING> str) → void
ASN1_T61STRING_new() → Pointer<ASN1_OCTET_STRING>
ASN1_tag2bit(int tag) → int
ASN1_tag2bit converts |tag| from the tag number of a universal type to a corresponding |B_ASN1_*| constant, or zero if |tag| has no bitmask.
ASN1_tag2str(int tag) → Pointer<Char>
ASN1_tag2str returns a string representation of |tag|, interpret as a tag number for a universal type, or |V_ASN1_NEG_*|.
ASN1_TIME_adj(Pointer<ASN1_OCTET_STRING> s, int posix_time, int offset_day, int offset_sec) → Pointer<ASN1_OCTET_STRING>
ASN1_TIME_adj adds |offset_day| days and |offset_sec| seconds to |posix_time| and writes the result to |s|. As in RFC 5280, section 4.1.2.5, it uses UTCTime when the time fits and GeneralizedTime otherwise. It returns |s| on success and NULL on error. If |s| is NULL, it returns a newly-allocated |ASN1_GENERALIZEDTIME| instead.
ASN1_TIME_check(Pointer<ASN1_OCTET_STRING> t) → int
ASN1_TIME_check returns one if |t| is a valid UTCTime or GeneralizedTime, and zero otherwise. |t|'s type determines which check is performed. This function does not enforce that UTCTime was used when possible.
ASN1_TIME_diff(Pointer<Int> out_days, Pointer<Int> out_seconds, Pointer<ASN1_OCTET_STRING> from, Pointer<ASN1_OCTET_STRING> to) → int
ASN1_TIME_diff computes |to| - |from|. On success, it sets |*out_days| to the difference in days, rounded towards zero, sets |*out_seconds| to the remainder, and returns one. On error, it returns zero.
ASN1_TIME_free(Pointer<ASN1_OCTET_STRING> str) → void
ASN1_TIME_free releases memory associated with |str|.
ASN1_TIME_new() → Pointer<ASN1_OCTET_STRING>
ASN1_TIME_new returns a newly-allocated |ASN1_TIME| with type -1, or NULL on error. The resulting |ASN1_TIME| is not a valid X.509 Time until initialized with a value.
ASN1_TIME_print(Pointer<BIO> out, Pointer<ASN1_OCTET_STRING> a) → int
ASN1_TIME_print writes a human-readable representation of |a| to |out|. It returns one on success and zero on error.
ASN1_TIME_set(Pointer<ASN1_OCTET_STRING> s, int time) → Pointer<ASN1_OCTET_STRING>
ASN1_TIME_set is exactly the same as |ASN1_TIME_set_posix| but with a time_t as input for compatibility.
ASN1_TIME_set_posix(Pointer<ASN1_OCTET_STRING> s, int posix_time) → Pointer<ASN1_OCTET_STRING>
ASN1_TIME_set_posix represents |posix_time| as a GeneralizedTime or UTCTime and writes the result to |s|. As in RFC 5280, section 4.1.2.5, it uses UTCTime when the time fits and GeneralizedTime otherwise. It returns |s| on success and NULL on error. If |s| is NULL, it returns a newly-allocated |ASN1_TIME| instead.
ASN1_TIME_set_string(Pointer<ASN1_OCTET_STRING> s, Pointer<Char> str) → int
ASN1_TIME_set_string behaves like |ASN1_UTCTIME_set_string| if |str| is a valid UTCTime, and |ASN1_GENERALIZEDTIME_set_string| if |str| is a valid GeneralizedTime. If |str| is neither, it returns zero.
ASN1_TIME_set_string_X509(Pointer<ASN1_OCTET_STRING> s, Pointer<Char> str) → int
ASN1_TIME_set_string_X509 behaves like |ASN1_TIME_set_string| except it additionally converts GeneralizedTime to UTCTime if it is in the range where UTCTime is used. See RFC 5280, section 4.1.2.5.
ASN1_TIME_to_generalizedtime(Pointer<ASN1_OCTET_STRING> t, Pointer<Pointer<ASN1_OCTET_STRING>> out) → Pointer<ASN1_OCTET_STRING>
ASN1_TIME_to_generalizedtime converts |t| to a GeneralizedTime. If |out| is NULL, it returns a newly-allocated |ASN1_GENERALIZEDTIME| on success, or NULL on error. If |out| is non-NULL and |*out| is NULL, it additionally sets |*out| to the result. If |out| and |*out| are non-NULL, it instead updates the object pointed by |*out| and returns |*out| on success or NULL on error.
ASN1_TIME_to_posix(Pointer<ASN1_OCTET_STRING> t, Pointer<Int64> out) → int
ASN1_TIME_to_posix converts |t| to a POSIX time value in |out|. On success, one is returned. On failure, zero is returned.
ASN1_TIME_to_posix_nonstandard(Pointer<ASN1_OCTET_STRING> t, Pointer<Int64> out) → int
ASN1_TIME_to_posix_nonstandard converts |t| to a POSIX time value in |out|. It is exactly the same as |ASN1_TIME_to_posix| but allows for non-standard four-digit timezone offsets on UTC times. On success, one is returned. On failure, zero is returned. |ASN1_TIME_to_posix| should normally be used instead of this function.
ASN1_TIME_to_time_t(Pointer<ASN1_OCTET_STRING> t, Pointer<Long> out) → int
ASN1_TIME_to_time_t converts |t| to a time_t value in |out|. On success, one is returned. On failure, zero is returned. This function will fail if the time can not be represented in a time_t.
ASN1_TYPE_cmp(Pointer<ASN1_TYPE> a, Pointer<ASN1_TYPE> b) → int
ASN1_TYPE_cmp returns zero if |a| and |b| are equal and some non-zero value otherwise. Note this function can only be used for equality checks, not an ordering.
ASN1_TYPE_free(Pointer<ASN1_TYPE> a) → void
ASN1_TYPE_free releases memory associated with |a|.
ASN1_TYPE_get(Pointer<ASN1_TYPE> a) → int
ASN1_TYPE_get returns the type of |a|, which will be one of the |V_ASN1_*| constants, or zero if |a| is not fully initialized.
ASN1_TYPE_new() → Pointer<ASN1_TYPE>
ASN1_TYPE_new returns a newly-allocated |ASN1_TYPE|, or NULL on allocation failure. The resulting object has type -1 and must be initialized to be a valid ANY value.
ASN1_TYPE_set(Pointer<ASN1_TYPE> a, int type, Pointer<Void> value) → void
ASN1_TYPE_set sets |a| to an |ASN1_TYPE| of type |type| and value |value|, releasing the previous contents of |a|.
ASN1_TYPE_set1(Pointer<ASN1_TYPE> a, int type, Pointer<Void> value) → int
ASN1_TYPE_set1 behaves like |ASN1_TYPE_set| except it does not take ownership of |value|. It returns one on success and zero on error.
ASN1_UNIVERSALSTRING_free(Pointer<ASN1_OCTET_STRING> str) → void
ASN1_UNIVERSALSTRING_new() → Pointer<ASN1_OCTET_STRING>
ASN1_UTCTIME_adj(Pointer<ASN1_OCTET_STRING> s, int posix_time, int offset_day, int offset_sec) → Pointer<ASN1_OCTET_STRING>
ASN1_UTCTIME_adj adds |offset_day| days and |offset_sec| seconds to |posix_time| and writes the result to |s| as a UTCTime. It returns |s| on success and NULL on error. If |s| is NULL, it returns a newly-allocated |ASN1_UTCTIME| instead.
ASN1_UTCTIME_check(Pointer<ASN1_OCTET_STRING> a) → int
ASN1_UTCTIME_check returns one if |a| is a valid UTCTime and zero otherwise.
ASN1_UTCTIME_free(Pointer<ASN1_OCTET_STRING> str) → void
ASN1_UTCTIME_free calls |ASN1_STRING_free|.
ASN1_UTCTIME_new() → Pointer<ASN1_OCTET_STRING>
ASN1_UTCTIME_new calls |ASN1_STRING_type_new| with |V_ASN1_UTCTIME|. The resulting object contains empty contents and must be initialized to be a valid UTCTime.
ASN1_UTCTIME_print(Pointer<BIO> out, Pointer<ASN1_OCTET_STRING> a) → int
ASN1_UTCTIME_print writes a human-readable representation of |a| to |out|. It returns one on success and zero on error.
ASN1_UTCTIME_set(Pointer<ASN1_OCTET_STRING> s, int posix_time) → Pointer<ASN1_OCTET_STRING>
ASN1_UTCTIME_set represents |posix_time| as a UTCTime and writes the result to |s|. It returns |s| on success and NULL on error. If |s| is NULL, it returns a newly-allocated |ASN1_UTCTIME| instead.
ASN1_UTCTIME_set_string(Pointer<ASN1_OCTET_STRING> s, Pointer<Char> str) → int
ASN1_UTCTIME_set_string sets |s| to a UTCTime whose contents are a copy of |str|. It returns one on success and zero on error or if |str| is not a valid UTCTime.
ASN1_UTF8STRING_free(Pointer<ASN1_OCTET_STRING> str) → void
ASN1_UTF8STRING_new() → Pointer<ASN1_OCTET_STRING>
ASN1_VISIBLESTRING_free(Pointer<ASN1_OCTET_STRING> str) → void
ASN1_VISIBLESTRING_new() → Pointer<ASN1_OCTET_STRING>
AUTHORITY_INFO_ACCESS_free(Pointer<AUTHORITY_INFO_ACCESS> aia) → void
AUTHORITY_INFO_ACCESS_free releases memory associated with |aia|.
AUTHORITY_INFO_ACCESS_new() → Pointer<AUTHORITY_INFO_ACCESS>
AUTHORITY_INFO_ACCESS_new returns a newly-allocated, empty |AUTHORITY_INFO_ACCESS| object, or NULL on error.
AUTHORITY_KEYID_free(Pointer<AUTHORITY_KEYID> akid) → void
AUTHORITY_KEYID_free releases memory associated with |akid|.
AUTHORITY_KEYID_new() → Pointer<AUTHORITY_KEYID>
AUTHORITY_KEYID_new returns a newly-allocated, empty |AUTHORITY_KEYID| object, or NULL on error.
BASIC_CONSTRAINTS_free(Pointer<BASIC_CONSTRAINTS> bcons) → void
BASIC_CONSTRAINTS_free releases memory associated with |bcons|.
BASIC_CONSTRAINTS_new() → Pointer<BASIC_CONSTRAINTS>
BASIC_CONSTRAINTS_new returns a newly-allocated, empty |BASIC_CONSTRAINTS| object, or NULL on error.
BIO_append_filename(Pointer<BIO> bio, Pointer<Char> filename) → int
BIO_append_filename opens |filename| for appending and sets the result as the |FILE| for |bio|. It returns one on success and zero otherwise. The |FILE| will be closed when |bio| is freed. On Windows, the file is opened in binary mode.
BIO_callback_ctrl(Pointer<BIO> bio, int cmd, Pointer<BIO_info_cb> fp) → int
BIO_callback_ctrl allows the callback function to be manipulated. The |cmd| arg will generally be |BIO_CTRL_SET_CALLBACK| but arbitrary command values can be interpreted by the |BIO|.
BIO_clear_flags(Pointer<BIO> bio, int flags) → void
BIO_clear_flags ANDs |bio->flags| with the bitwise-complement of |flags|. Unless otherwise documented, flags are private to either BoringSSL or the custom |BIO_METHOD|.
BIO_clear_retry_flags(Pointer<BIO> bio) → void
BIO_clear_retry_flags clears the |BIO_FLAGS_READ|, |BIO_FLAGS_WRITE|, |BIO_FLAGS_IO_SPECIAL| and |BIO_FLAGS_SHOULD_RETRY| flags from |bio|.
BIO_copy_next_retry(Pointer<BIO> bio) → void
BIO_copy_next_retry sets the retry flags and |retry_reason| of |bio| from the next BIO in the chain.
BIO_ctrl(Pointer<BIO> bio, int cmd, int larg, Pointer<Void> parg) → int
BIO_ctrl sends the control request |cmd| to |bio|. The |cmd| argument should be one of the |BIO_C_*| values.
BIO_ctrl_get_read_request(Pointer<BIO> bio) → int
BIO_ctrl_get_read_request returns the number of bytes that the other side of |bio| tried (unsuccessfully) to read.
BIO_ctrl_get_write_guarantee(Pointer<BIO> bio) → int
BIO_ctrl_get_write_guarantee returns the number of bytes that |bio| (which must have been returned by |BIO_new_bio_pair|) will accept on the next |BIO_write| call.
BIO_ctrl_pending(Pointer<BIO> bio) → int
BIO_ctrl_pending calls |BIO_pending| and exists only for compatibility with OpenSSL.
BIO_do_connect(Pointer<BIO> bio) → int
BIO_do_connect connects |bio| if it has not been connected yet. It returns one on success and <= 0 otherwise.
BIO_eof(Pointer<BIO> bio) → int
BIO_eof returns non-zero when |bio| has reached end-of-file. The precise meaning of which depends on the concrete type of |bio|. Note that in the case of BIO_pair this always returns non-zero.
BIO_find_type(Pointer<BIO> bio, int type) → Pointer<BIO>
BIO_find_type walks a chain of BIOs and returns the first that matches |type|, which is one of the |BIO_TYPE_*| values.
BIO_flush(Pointer<BIO> bio) → int
BIO_flush flushes any buffered output. It returns one on success and zero otherwise.
BIO_free(Pointer<BIO> bio) → int
BIO_free decrements the reference count of |bio|. If the reference count drops to zero, it calls the destroy callback, if present, on the method and frees |bio| itself. If |bio| is part of a chain (see |BIO_push|), this will also free the next |BIO| in the chain, and so on.
BIO_free_all(Pointer<BIO> bio) → void
BIO_free_all calls |BIO_free|. Code that targets BoringSSL does not need to call a separate free function for |BIO|s that are part of a chain.
BIO_get_data(Pointer<BIO> bio) → Pointer<Void>
BIO_get_data returns custom data on |bio| set by |BIO_get_data|.
BIO_get_ex_data(Pointer<BIO> bio, int idx) → Pointer<Void>
BIO_get_ex_new_index(int argl, Pointer<Void> argp, Pointer<Int> unused, Pointer<CRYPTO_EX_dup> dup_unused, Pointer<CRYPTO_EX_free> free_func) → int
ex_data functions.
BIO_get_fd(Pointer<BIO> bio, Pointer<Int> out_fd) → int
BIO_get_fd returns the file descriptor currently in use by |bio| or -1 if |bio| does not wrap a file descriptor. If there is a file descriptor and |out_fd| is not NULL, it also sets |*out_fd| to the file descriptor.
BIO_get_fp(Pointer<BIO> bio, Pointer<Pointer<FILE>> out_file) → int
BIO_get_fp sets |*out_file| to the current |FILE| for |bio|. It returns one on success and zero otherwise.
BIO_get_init(Pointer<BIO> bio) → int
BIO_get_init returns whether |bio| has been fully initialized.
BIO_get_mem_data(Pointer<BIO> bio, Pointer<Pointer<Char>> contents) → int
BIO_get_mem_data sets |*contents| to point to the current contents of |bio| and returns the length of the data.
BIO_get_mem_ptr(Pointer<BIO> bio, Pointer<Pointer<BUF_MEM>> out) → int
BIO_get_mem_ptr sets |*out| to a BUF_MEM containing the current contents of |bio|. It returns one on success or zero on error.
BIO_get_new_index() → int
BIO_get_new_index returns a new "type" value for a custom |BIO|, or -1 on error.
BIO_get_retry_flags(Pointer<BIO> bio) → int
BIO_get_retry_flags gets the |BIO_FLAGS_READ|, |BIO_FLAGS_WRITE|, |BIO_FLAGS_IO_SPECIAL| and |BIO_FLAGS_SHOULD_RETRY| flags from |bio|.
BIO_get_retry_reason(Pointer<BIO> bio) → int
BIO_get_retry_reason returns the special I/O operation that needs to be retried. The return value is one of the |BIO_RR_*| values.
BIO_get_shutdown(Pointer<BIO> bio) → int
BIO_get_shutdown returns the method-specific "shutdown" bit.
BIO_gets(Pointer<BIO> bio, Pointer<Char> buf, int size) → int
BIO_gets reads a line from |bio| and writes at most |size| bytes into |buf|. It returns the number of bytes read or a negative number on error. This function's output always includes a trailing NUL byte, so it will read at most |size - 1| bytes.
BIO_hexdump(Pointer<BIO> bio, Pointer<Uint8> data, int len, int indent) → int
BIO_hexdump writes a hex dump of |data| to |bio|. Each line will be indented by |indent| spaces. It returns one on success and zero otherwise.
BIO_indent(Pointer<BIO> bio, int indent, int max_indent) → int
BIO_indent prints min(|indent|, |max_indent|) spaces. It returns one on success and zero otherwise.
BIO_int_ctrl(Pointer<BIO> bp, int cmd, int larg, int iarg) → int
BIO_int_ctrl acts like |BIO_ctrl| but passes the address of a copy of |iarg| as |parg|.
BIO_mem_contents(Pointer<BIO> bio, Pointer<Pointer<Uint8>> out_contents, Pointer<Size> out_len) → int
BIO_mem_contents sets |*out_contents| to point to the current contents of |bio| and |*out_len| to contain the length of that data. It returns one on success and zero otherwise.
BIO_meth_free(Pointer<BIO_METHOD> method) → void
BIO_meth_free releases memory associated with |method|.
BIO_meth_get_callback_ctrl(Pointer<BIO_METHOD> method) → Pointer<NativeFunction<Long Function(Pointer<BIO>, Int, Pointer<BIO_info_cb>)>>
BIO_meth_get_create(Pointer<BIO_METHOD> method) → Pointer<NativeFunction<Int Function(Pointer<BIO>)>>
BIO_meth_get_ctrl(Pointer<BIO_METHOD> method) → Pointer<NativeFunction<Long Function(Pointer<BIO>, Int, Long, Pointer<Void>)>>
BIO_meth_get_destroy(Pointer<BIO_METHOD> method) → Pointer<NativeFunction<Int Function(Pointer<BIO>)>>
BIO_meth_get_gets(Pointer<BIO_METHOD> method) → Pointer<NativeFunction<Int Function(Pointer<BIO>, Pointer<Char>, Int)>>
BIO_meth_get_puts(Pointer<BIO_METHOD> method) → Pointer<NativeFunction<Int Function(Pointer<BIO>, Pointer<Char>)>>
BIO_meth_get_read(Pointer<BIO_METHOD> method) → Pointer<NativeFunction<Int Function(Pointer<BIO>, Pointer<Char>, Int)>>
BIO_meth_get_write(Pointer<BIO_METHOD> method) → Pointer<NativeFunction<Int Function(Pointer<BIO>, Pointer<Char>, Int)>>
The following functions return function pointers, possibly NULL, which are compatible with the corresponding |BIO_meth_set_*| function. |method| must be |BIO_s_socket| or the program will abort.
BIO_meth_new(int type, Pointer<Char> name) → Pointer<BIO_METHOD>
BIO_meth_new returns a newly-allocated |BIO_METHOD| or NULL on allocation error. The |type| specifies the type that will be returned by |BIO_method_type|. If this is unnecessary, this value may be zero. The |name| parameter is vestigial and may be NULL.
BIO_meth_set_callback_ctrl(Pointer<BIO_METHOD> method, Pointer<NativeFunction<Long Function(Pointer<BIO>, Int, Pointer<BIO_info_cb>)>> callback_ctrl_func) → int
BIO_meth_set_callback_ctrl sets the implementation of |BIO_callback_ctrl| for |method| and returns one.
BIO_meth_set_create(Pointer<BIO_METHOD> method, Pointer<NativeFunction<Int Function(Pointer<BIO>)>> create_func) → int
BIO_meth_set_create sets a function to be called on |BIO_new| for |method| and returns one. The function should return one on success and zero on error.
BIO_meth_set_ctrl(Pointer<BIO_METHOD> method, Pointer<NativeFunction<Long Function(Pointer<BIO>, Int, Long, Pointer<Void>)>> ctrl_func) → int
BIO_meth_set_ctrl sets the implementation of |BIO_ctrl| for |method| and returns one.
BIO_meth_set_destroy(Pointer<BIO_METHOD> method, Pointer<NativeFunction<Int Function(Pointer<BIO>)>> destroy_func) → int
BIO_meth_set_destroy sets a function to release data associated with a |BIO| and returns one. The function's return value is ignored.
BIO_meth_set_gets(Pointer<BIO_METHOD> method, Pointer<NativeFunction<Int Function(Pointer<BIO>, Pointer<Char>, Int)>> gets_func) → int
BIO_meth_set_gets sets the implementation of |BIO_gets| for |method| and returns one.
BIO_meth_set_puts(Pointer<BIO_METHOD> method, Pointer<NativeFunction<Int Function(Pointer<BIO>, Pointer<Char>)>> puts) → int
BIO_meth_set_puts returns one. |BIO_puts| is implemented with |BIO_write| in BoringSSL.
BIO_meth_set_read(Pointer<BIO_METHOD> method, Pointer<NativeFunction<Int Function(Pointer<BIO>, Pointer<Char>, Int)>> read_func) → int
BIO_meth_set_read sets the implementation of |BIO_read| for |method| and returns one.
BIO_meth_set_write(Pointer<BIO_METHOD> method, Pointer<NativeFunction<Int Function(Pointer<BIO>, Pointer<Char>, Int)>> write_func) → int
BIO_meth_set_write sets the implementation of |BIO_write| for |method| and returns one. |BIO_METHOD|s which implement |BIO_write| should also implement |BIO_CTRL_FLUSH|. (See |BIO_meth_set_ctrl|.)
BIO_method_type(Pointer<BIO> bio) → int
BIO_method_type returns the type of |bio|, which is one of the |BIO_TYPE_*| values.
BIO_new(Pointer<BIO_METHOD> method) → Pointer<BIO>
BIO_new creates a new BIO with the given method and a reference count of one. It returns the fresh |BIO|, or NULL on error.
BIO_new_bio_pair(Pointer<Pointer<BIO>> out1, int writebuf1, Pointer<Pointer<BIO>> out2, int writebuf2) → int
BIO_new_bio_pair sets |*out1| and |*out2| to two freshly created BIOs where data written to one can be read from the other and vice versa. The |writebuf1| argument gives the size of the buffer used in |*out1| and |writebuf2| for |*out2|. It returns one on success and zero on error.
BIO_new_connect(Pointer<Char> host_and_optional_port) → Pointer<BIO>
BIO_new_connect returns a BIO that connects to the given hostname and port. The |host_and_optional_port| argument should be of the form "www.example.com" or "www.example.com:443". If the port is omitted, it must be provided with |BIO_set_conn_port|.
BIO_new_fd(int fd, int close_flag) → Pointer<BIO>
BIO_new_fd creates a new file descriptor BIO wrapping |fd|. If |close_flag| is non-zero, then |fd| will be closed when the BIO is.
BIO_new_file(Pointer<Char> filename, Pointer<Char> mode) → Pointer<BIO>
BIO_new_file creates a file BIO by opening |filename| with the given mode. See the |fopen| manual page for details of the mode argument. On Windows, files may be opened in either binary or text mode so, as in |fopen|, callers must specify the desired option in |mode|.
BIO_new_fp(Pointer<FILE> file, int flags) → Pointer<BIO>
BIO_new_fp creates a new file BIO that wraps |file|. If |flags| contains |BIO_CLOSE|, then |fclose| will be called on |file| when the BIO is closed.
BIO_new_mem_buf(Pointer<Void> buf, int len) → Pointer<BIO>
BIO_new_mem_buf creates read-only BIO that reads from |len| bytes at |buf|. It returns the BIO or NULL on error. This function does not copy or take ownership of |buf|. The caller must ensure the memory pointed to by |buf| outlives the |BIO|.
BIO_new_socket(int fd, int close_flag) → Pointer<BIO>
BIO_new_socket allocates and initialises a fresh BIO which will read and write to the socket |fd|. If |close_flag| is |BIO_CLOSE| then closing the BIO will close |fd|. It returns the fresh |BIO| or NULL on error.
BIO_next(Pointer<BIO> bio) → Pointer<BIO>
BIO_next returns the next BIO in the chain after |bio|, or NULL if there is no such BIO.
BIO_number_read(Pointer<BIO> bio) → int
BIO_number_read returns the number of bytes that have been read from |bio|.
BIO_number_written(Pointer<BIO> bio) → int
BIO_number_written returns the number of bytes that have been written to |bio|.
BIO_pending(Pointer<BIO> bio) → int
BIO_pending returns the number of bytes pending to be read.
BIO_pop(Pointer<BIO> bio) → Pointer<BIO>
BIO_pop removes |bio| from the head of a chain and returns the next BIO in the chain, or NULL if there is no next BIO.
BIO_printf(Pointer<BIO> bio, Pointer<Char> format) → int
BIO_printf behaves like |printf| but outputs to |bio| rather than a |FILE|. It returns the number of bytes written or a negative number on error.
BIO_ptr_ctrl(Pointer<BIO> bp, int cmd, int larg) → Pointer<Char>
BIO_ptr_ctrl acts like |BIO_ctrl| but passes the address of a |void*| pointer as |parg| and returns the value that is written to it, or NULL if the control request returns <= 0.
BIO_push(Pointer<BIO> bio, Pointer<BIO> appended_bio) → Pointer<BIO>
BIO_push adds |appended_bio| to the end of the chain with |bio| at the head. It returns |bio|. Note that |appended_bio| may be the head of a chain itself and thus this function can be used to join two chains.
BIO_puts(Pointer<BIO> bio, Pointer<Char> buf) → int
BIO_puts writes a NUL terminated string from |buf| to |bio|. It returns the number of bytes written or a negative number on error.
BIO_read(Pointer<BIO> bio, Pointer<Void> data, int len) → int
BIO_read attempts to read |len| bytes into |data|. It returns the number of bytes read, zero on EOF, or a negative number on error.
BIO_read_asn1(Pointer<BIO> bio, Pointer<Pointer<Uint8>> out, Pointer<Size> out_len, int max_len) → int
BIO_read_asn1 reads a single ASN.1 object from |bio|. If successful it sets |*out| to be an allocated buffer (that should be freed with |OPENSSL_free|), |*out_size| to the length, in bytes, of that buffer and returns one. Otherwise it returns zero.
BIO_read_filename(Pointer<BIO> bio, Pointer<Char> filename) → int
BIO_read_filename opens |filename| for reading and sets the result as the |FILE| for |bio|. It returns one on success and zero otherwise. The |FILE| will be closed when |bio| is freed. On Windows, the file is opened in binary mode.
BIO_reset(Pointer<BIO> bio) → int
BIO_reset resets |bio| to its initial state, the precise meaning of which depends on the concrete type of |bio|. It normally returns one on success and <= 0 otherwise. However, for file and fd BIOs, it returns zero on success and a negative number on error.
BIO_rw_filename(Pointer<BIO> bio, Pointer<Char> filename) → int
BIO_rw_filename opens |filename| for reading and writing and sets the result as the |FILE| for |bio|. It returns one on success and zero otherwise. The |FILE| will be closed when |bio| is freed. On Windows, the file is opened in binary mode.
BIO_s_connect() → Pointer<BIO_METHOD>
BIO_s_fd() → Pointer<BIO_METHOD>
BIO_s_fd returns a |BIO_METHOD| for file descriptor fds.
BIO_s_file() → Pointer<BIO_METHOD>
BIO_s_file returns a BIO_METHOD that wraps a |FILE|.
BIO_s_mem() → Pointer<BIO_METHOD>
BIO_s_mem returns a |BIO_METHOD| that uses a in-memory buffer.
BIO_s_socket() → Pointer<BIO_METHOD>
BIO_seek(Pointer<BIO> bio, int offset) → int
BIO_seek sets the file offset of |bio| to |offset|. It returns a non-negative number on success and a negative number on error. If |bio| is a file descriptor |BIO|, it returns the resulting file offset on success. If |bio| is a file |BIO|, it returns zero on success.
BIO_set_close(Pointer<BIO> bio, int close_flag) → int
BIO_set_close sets the close flag for |bio|. The meaning of which depends on the type of |bio| but, for example, a memory BIO interprets the close flag as meaning that it owns its buffer. It returns one on success and zero otherwise.
BIO_set_conn_hostname(Pointer<BIO> bio, Pointer<Char> host_and_optional_port) → int
BIO_set_conn_hostname sets |host_and_optional_port| as the hostname and optional port that |bio| will connect to. If the port is omitted, it must be provided with |BIO_set_conn_port|.
BIO_set_conn_int_port(Pointer<BIO> bio, Pointer<Int> port) → int
BIO_set_conn_int_port sets |*port| as the port that |bio| will connect to. It returns one on success and zero otherwise.
BIO_set_conn_port(Pointer<BIO> bio, Pointer<Char> port_str) → int
BIO_set_conn_port sets |port_str| as the port or service name that |bio| will connect to. It returns one on success and zero otherwise.
BIO_set_data(Pointer<BIO> bio, Pointer<Void> ptr) → void
BIO_set_data sets custom data on |bio|. It may be retried with |BIO_get_data|.
BIO_set_ex_data(Pointer<BIO> bio, int idx, Pointer<Void> arg) → int
BIO_set_fd(Pointer<BIO> bio, int fd, int close_flag) → int
BIO_set_fd sets the file descriptor of |bio| to |fd|. If |close_flag| is non-zero then |fd| will be closed when |bio| is. It returns one on success or zero on error.
BIO_set_flags(Pointer<BIO> bio, int flags) → void
BIO_set_flags ORs |flags| with |bio->flags|. Unless otherwise documented, flags are private to either BoringSSL or the custom |BIO_METHOD|.
BIO_set_fp(Pointer<BIO> bio, Pointer<FILE> file, int flags) → int
BIO_set_fp sets the |FILE| for |bio|. If |flags| contains |BIO_CLOSE| then |fclose| will be called on |file| when |bio| is closed. It returns one on success and zero otherwise.
BIO_set_init(Pointer<BIO> bio, int init) → void
BIO_set_init sets whether |bio| has been fully initialized. Until fully initialized, |BIO_read| and |BIO_write| will fail.
BIO_set_mem_buf(Pointer<BIO> bio, Pointer<BUF_MEM> b, int take_ownership) → int
BIO_set_mem_buf sets |b| as the contents of |bio|. If |take_ownership| is non-zero, then |b| will be freed when |bio| is closed. Returns one on success or zero otherwise.
BIO_set_mem_eof_return(Pointer<BIO> bio, int eof_value) → int
BIO_set_mem_eof_return sets the value that will be returned from reading |bio| when empty. If |eof_value| is zero then an empty memory BIO will return EOF (that is it will return zero and |BIO_should_retry| will be false). If |eof_value| is non zero then it will return |eof_value| when it is empty and it will set the read retry flag (that is |BIO_read_retry| is true). To avoid ambiguity with a normal positive return value, |eof_value| should be set to a negative value, typically -1.
BIO_set_nbio(Pointer<BIO> bio, int on) → int
BIO_set_nbio sets whether |bio| will use non-blocking I/O operations. It returns one on success and zero otherwise. This only works for connect BIOs and must be called before |bio| is connected to take effect.
BIO_set_retry_read(Pointer<BIO> bio) → void
BIO_set_retry_read sets the |BIO_FLAGS_READ| and |BIO_FLAGS_SHOULD_RETRY| flags on |bio|.
BIO_set_retry_reason(Pointer<BIO> bio, int reason) → void
BIO_set_retry_reason sets the special I/O operation that needs to be retried to |reason|, which should be one of the |BIO_RR_*| values.
BIO_set_retry_special(Pointer<BIO> bio) → void
BIO_set_retry_write(Pointer<BIO> bio) → void
BIO_set_retry_write sets the |BIO_FLAGS_WRITE| and |BIO_FLAGS_SHOULD_RETRY| flags on |bio|.
BIO_set_shutdown(Pointer<BIO> bio, int shutdown) → void
BIO_set_shutdown sets a method-specific "shutdown" bit on |bio|.
BIO_set_write_buffer_size(Pointer<BIO> bio, int buffer_size) → int
BIO_set_write_buffer_size returns zero.
BIO_should_io_special(Pointer<BIO> bio) → int
BIO_should_io_special returns non-zero if |bio| encountered a temporary error while performing a special I/O operation, indicating that the caller should retry. The operation that caused the error is returned by |BIO_get_retry_reason|.
BIO_should_read(Pointer<BIO> bio) → int
BIO_should_read returns non-zero if |bio| encountered a temporary error while reading (i.e. EAGAIN), indicating that the caller should retry the read.
BIO_should_retry(Pointer<BIO> bio) → int
BIO_should_retry returns non-zero if the reason that caused a failed I/O operation is temporary and thus the operation should be retried. Otherwise, it was a permanent error and it returns zero.
BIO_should_write(Pointer<BIO> bio) → int
BIO_should_write returns non-zero if |bio| encountered a temporary error while writing (i.e. EAGAIN), indicating that the caller should retry the write.
BIO_shutdown_wr(Pointer<BIO> bio) → int
BIO_shutdown_wr marks |bio| as closed, from the point of view of the other side of the pair. Future |BIO_write| calls on |bio| will fail. It returns one on success and zero otherwise.
BIO_snprintf(Pointer<Char> buf, int n, Pointer<Char> format) → int
BIO_snprintf has the same behavior as snprintf(3).
BIO_tell(Pointer<BIO> bio) → int
BIO_tell returns the file offset of |bio|, or a negative number on error or if |bio| does not support the operation.
BIO_test_flags(Pointer<BIO> bio, int flags) → int
BIO_test_flags returns |bio->flags| AND |flags|.
BIO_up_ref(Pointer<BIO> bio) → int
BIO_up_ref increments the reference count of |bio| and returns one.
BIO_vfree(Pointer<BIO> bio) → void
BIO_vfree performs the same actions as |BIO_free|, but has a void return value. This is provided for API-compat.
BIO_vsnprintf(Pointer<Char> buf, int n, Pointer<Char> format, Pointer<__va_list_tag> args) → int
BIO_vsnprintf has the same behavior as vsnprintf(3).
BIO_wpending(Pointer<BIO> bio) → int
BIO_wpending returns the number of bytes pending to be written.
BIO_write(Pointer<BIO> bio, Pointer<Void> data, int len) → int
BIO_write writes |len| bytes from |data| to |bio|. It returns the number of bytes written or a negative number on error.
BIO_write_all(Pointer<BIO> bio, Pointer<Void> data, int len) → int
BIO_write_all writes |len| bytes from |data| to |bio|, looping as necessary. It returns one if all bytes were successfully written and zero on error.
BIO_write_filename(Pointer<BIO> bio, Pointer<Char> filename) → int
BIO_write_filename opens |filename| for writing and sets the result as the |FILE| for |bio|. It returns one on success and zero otherwise. The |FILE| will be closed when |bio| is freed. On Windows, the file is opened in binary mode.
BN_abs_is_word(Pointer<BIGNUM> bn, int w) → int
BN_abs_is_word returns one if the absolute value of |bn| equals |w| and zero otherwise.
BN_add(Pointer<BIGNUM> r, Pointer<BIGNUM> a, Pointer<BIGNUM> b) → int
BN_add sets |r| = |a| + |b|, where |r| may be the same pointer as either |a| or |b|. It returns one on success and zero on allocation failure.
BN_add_word(Pointer<BIGNUM> a, int w) → int
BN_add_word adds |w| to |a|. It returns one on success and zero otherwise.
BN_asc2bn(Pointer<Pointer<BIGNUM>> outp, Pointer<Char> in$) → int
BN_asc2bn acts like |BN_dec2bn| or |BN_hex2bn| depending on whether |in| begins with "0X" or "0x" (indicating hex) or not (indicating decimal). A leading '-' is still permitted and comes before the optional 0X/0x. It returns one on success or zero on error.
BN_bin2bn(Pointer<Uint8> in$, int len, Pointer<BIGNUM> ret) → Pointer<BIGNUM>
BN_bin2bn sets |*ret| to the value of |len| bytes from |in|, interpreted as a big-endian number, and returns |ret|. If |ret| is NULL then a fresh |BIGNUM| is allocated and returned. It returns NULL on allocation failure.
BN_bn2bin(Pointer<BIGNUM> in$, Pointer<Uint8> out) → int
BN_bn2bin serialises the absolute value of |in| to |out| as a big-endian integer, which must have |BN_num_bytes| of space available. It returns the number of bytes written. Note this function leaks the magnitude of |in|. If |in| is secret, use |BN_bn2bin_padded| instead.
BN_bn2bin_padded(Pointer<Uint8> out, int len, Pointer<BIGNUM> in$) → int
BN_bn2bin_padded serialises the absolute value of |in| to |out| as a big-endian integer. The integer is padded with leading zeros up to size |len|. If |len| is smaller than |BN_num_bytes|, the function fails and returns 0. Otherwise, it returns 1.
BN_bn2binpad(Pointer<BIGNUM> in$, Pointer<Uint8> out, int len) → int
BN_bn2binpad behaves like |BN_bn2bin_padded|, but it returns |len| on success and -1 on error.
BN_bn2cbb_padded(Pointer<CBB> out, int len, Pointer<BIGNUM> in$) → int
BN_bn2cbb_padded behaves like |BN_bn2bin_padded| but writes to a |CBB|.
BN_bn2dec(Pointer<BIGNUM> a) → Pointer<Char>
BN_bn2dec returns an allocated string that contains a NUL-terminated, decimal representation of |bn|. If |bn| is negative, the first char in the resulting string will be '-'. Returns NULL on allocation failure.
BN_bn2hex(Pointer<BIGNUM> bn) → Pointer<Char>
BN_bn2hex returns an allocated string that contains a NUL-terminated, hex representation of |bn|. If |bn| is negative, the first char in the resulting string will be '-'. Returns NULL on allocation failure.
BN_bn2le_padded(Pointer<Uint8> out, int len, Pointer<BIGNUM> in$) → int
BN_bn2le_padded serialises the absolute value of |in| to |out| as a little-endian integer, which must have |len| of space available, padding out the remainder of out with zeros. If |len| is smaller than |BN_num_bytes|, the function fails and returns 0. Otherwise, it returns 1.
BN_bn2lebinpad(Pointer<BIGNUM> in$, Pointer<Uint8> out, int len) → int
BN_bn2lebinpad behaves like |BN_bn2le_padded|, but it returns |len| on success and -1 on error.
BN_bn2mpi(Pointer<BIGNUM> in$, Pointer<Uint8> out) → int
BN_bn2mpi serialises the value of |in| to |out|, using a format that consists of the number's length in bytes represented as a 4-byte big-endian number, and the number itself in big-endian format, where the most significant bit signals a negative number. (The representation of numbers with the MSB set is prefixed with null byte). |out| must have sufficient space available; to find the needed amount of space, call the function with |out| set to NULL.
BN_clear(Pointer<BIGNUM> bn) → void
BN_clear sets |bn| to zero and erases the old data.
BN_clear_bit(Pointer<BIGNUM> a, int n) → int
BN_clear_bit clears the |n|th, least-significant bit in |a|. For example, if |a| is 3, clearing bit zero will make it two. It returns one on success or zero on allocation failure.
BN_clear_free(Pointer<BIGNUM> bn) → void
BN_clear_free erases and frees the data referenced by |bn| and, if |bn| was originally allocated on the heap, frees |bn| also.
BN_cmp(Pointer<BIGNUM> a, Pointer<BIGNUM> b) → int
BN_cmp returns a value less than, equal to or greater than zero if |a| is less than, equal to or greater than |b|, respectively.
BN_cmp_word(Pointer<BIGNUM> a, int b) → int
BN_cmp_word is like |BN_cmp| except it takes its second argument as a |BN_ULONG| instead of a |BIGNUM|.
BN_copy(Pointer<BIGNUM> dest, Pointer<BIGNUM> src) → Pointer<BIGNUM>
BN_copy sets |dest| equal to |src| and returns |dest| or NULL on allocation failure.
BN_count_low_zero_bits(Pointer<BIGNUM> bn) → int
BN_count_low_zero_bits returns the number of low-order zero bits in |bn|, or the number of factors of two which divide it. It returns zero if |bn| is zero.
BN_CTX_end(Pointer<BN_CTX> ctx) → void
BN_CTX_end invalidates all |BIGNUM|s returned from |BN_CTX_get| since the matching |BN_CTX_start| call.
BN_CTX_free(Pointer<BN_CTX> ctx) → void
BN_CTX_free frees all BIGNUMs contained in |ctx| and then frees |ctx| itself.
BN_CTX_get(Pointer<BN_CTX> ctx) → Pointer<BIGNUM>
BN_CTX_get returns a new |BIGNUM|, or NULL on allocation failure. Once |BN_CTX_get| has returned NULL, all future calls will also return NULL until |BN_CTX_end| is called.
BN_CTX_new() → Pointer<BN_CTX>
BN_CTX_new returns a new, empty BN_CTX or NULL on allocation failure.
BN_CTX_start(Pointer<BN_CTX> ctx) → void
BN_CTX_start "pushes" a new entry onto the |ctx| stack and allows future calls to |BN_CTX_get|.
BN_dec2bn(Pointer<Pointer<BIGNUM>> outp, Pointer<Char> in$) → int
BN_dec2bn parses the leading decimal number from |in|, which may be proceeded by a '-' to indicate a negative number and may contain trailing, non-decimal data. If |outp| is not NULL, it constructs a BIGNUM equal to the decimal number and stores it in |*outp|. If |*outp| is NULL then it allocates a new BIGNUM and updates |*outp|. It returns the number of bytes of |in| processed or zero on error.
BN_div(Pointer<BIGNUM> quotient, Pointer<BIGNUM> rem, Pointer<BIGNUM> numerator, Pointer<BIGNUM> divisor, Pointer<BN_CTX> ctx) → int
BN_div divides |numerator| by |divisor| and places the result in |quotient| and the remainder in |rem|. Either of |quotient| or |rem| may be NULL, in which case the respective value is not returned. It returns one on success or zero on error. It is an error condition if |divisor| is zero.
BN_div_word(Pointer<BIGNUM> numerator, int divisor) → int
BN_div_word sets |numerator| = |numerator|/|divisor| and returns the remainder or (BN_ULONG)-1 on error.
BN_dup(Pointer<BIGNUM> src) → Pointer<BIGNUM>
BN_dup allocates a new BIGNUM and sets it equal to |src|. It returns the allocated BIGNUM on success or NULL otherwise.
BN_enhanced_miller_rabin_primality_test(Pointer<UnsignedInt> out_result, Pointer<BIGNUM> w, int checks, Pointer<BN_CTX> ctx, Pointer<BN_GENCB> cb) → int
BN_enhanced_miller_rabin_primality_test tests whether |w| is probably a prime number using the Enhanced Miller-Rabin Test (FIPS 186-5 B.3.2) with |checks| iterations and returns the result in |out_result|. Enhanced Miller-Rabin tests primality for odd integers greater than 3, returning |bn_probably_prime| if the number is probably prime, |bn_non_prime_power_composite| if the number is a composite that is not the power of a single prime, and |bn_composite| otherwise. It returns one on success and zero on failure. If |cb| is not NULL, then it is called during each iteration of the primality test.
BN_equal_consttime(Pointer<BIGNUM> a, Pointer<BIGNUM> b) → int
BN_equal_consttime returns one if |a| is equal to |b|, and zero otherwise. It takes an amount of time dependent on the sizes of |a| and |b|, but independent of the contents (including the signs) of |a| and |b|.
BN_exp(Pointer<BIGNUM> r, Pointer<BIGNUM> a, Pointer<BIGNUM> p, Pointer<BN_CTX> ctx) → int
BN_exp sets |r| equal to |a|^{|p|}. It does so with a square-and-multiply algorithm that leaks side-channel information. It returns one on success or zero otherwise.
BN_free(Pointer<BIGNUM> bn) → void
BN_free frees the data referenced by |bn| and, if |bn| was originally allocated on the heap, frees |bn| also.
BN_from_montgomery(Pointer<BIGNUM> ret, Pointer<BIGNUM> a, Pointer<BN_MONT_CTX> mont, Pointer<BN_CTX> ctx) → int
BN_from_montgomery sets |ret| equal to |a| * R^-1, i.e. translates values out of the Montgomery domain. |a| is assumed to be in the range [0, nR), where |n| is the Montgomery modulus. Note n < R, so inputs in the range [0, nn) are valid. This function returns one on success or zero on error.
BN_gcd(Pointer<BIGNUM> r, Pointer<BIGNUM> a, Pointer<BIGNUM> b, Pointer<BN_CTX> ctx) → int
BN_gcd sets |r| = gcd(|a|, |b|). It returns one on success and zero otherwise.
BN_GENCB_call(Pointer<BN_GENCB> callback, int event, int n) → int
BN_GENCB_call calls |callback|, if not NULL, and returns the return value of the callback, or 1 if |callback| is NULL.
BN_GENCB_free(Pointer<BN_GENCB> callback) → void
BN_GENCB_free releases memory associated with |callback|.
BN_GENCB_get_arg(Pointer<BN_GENCB> callback) → Pointer<Void>
BN_GENCB_get_arg returns |callback->arg|.
BN_GENCB_new() → Pointer<BN_GENCB>
BN_GENCB_new returns a newly-allocated |BN_GENCB| object, or NULL on allocation failure. The result must be released with |BN_GENCB_free| when done.
BN_GENCB_set(Pointer<BN_GENCB> callback, Pointer<NativeFunction<Int Function(Int, Int, Pointer<BN_GENCB>)>> f, Pointer<Void> arg) → void
BN_GENCB_set configures |callback| to call |f| and sets |callout->arg| to |arg|.
BN_generate_prime_ex(Pointer<BIGNUM> ret, int bits, int safe, Pointer<BIGNUM> add, Pointer<BIGNUM> rem, Pointer<BN_GENCB> cb) → int
BN_generate_prime_ex sets |ret| to a prime number of |bits| length. If safe is non-zero then the prime will be such that (ret-1)/2 is also a prime. (This is needed for Diffie-Hellman groups to ensure that the only subgroups are of size 2 and (p-1)/2.).
BN_get_rfc3526_prime_1536(Pointer<BIGNUM> ret) → Pointer<BIGNUM>
BN_get_rfc3526_prime_1536 sets |*ret| to the 1536-bit MODP group from RFC 3526 and returns |ret|. If |ret| is NULL then a fresh |BIGNUM| is allocated and returned. It returns NULL on allocation failure. The generator for this group is 2.
BN_get_rfc3526_prime_2048(Pointer<BIGNUM> ret) → Pointer<BIGNUM>
BN_get_rfc3526_prime_2048 sets |*ret| to the 2048-bit MODP group from RFC 3526 and returns |ret|. If |ret| is NULL then a fresh |BIGNUM| is allocated and returned. It returns NULL on allocation failure. The generator for this group is 2.
BN_get_rfc3526_prime_3072(Pointer<BIGNUM> ret) → Pointer<BIGNUM>
BN_get_rfc3526_prime_3072 sets |*ret| to the 3072-bit MODP group from RFC 3526 and returns |ret|. If |ret| is NULL then a fresh |BIGNUM| is allocated and returned. It returns NULL on allocation failure. The generator for this group is 2.
BN_get_rfc3526_prime_4096(Pointer<BIGNUM> ret) → Pointer<BIGNUM>
BN_get_rfc3526_prime_4096 sets |*ret| to the 4096-bit MODP group from RFC 3526 and returns |ret|. If |ret| is NULL then a fresh |BIGNUM| is allocated and returned. It returns NULL on allocation failure. The generator for this group is 2.
BN_get_rfc3526_prime_6144(Pointer<BIGNUM> ret) → Pointer<BIGNUM>
BN_get_rfc3526_prime_6144 sets |*ret| to the 6144-bit MODP group from RFC 3526 and returns |ret|. If |ret| is NULL then a fresh |BIGNUM| is allocated and returned. It returns NULL on allocation failure. The generator for this group is 2.
BN_get_rfc3526_prime_8192(Pointer<BIGNUM> ret) → Pointer<BIGNUM>
BN_get_rfc3526_prime_8192 sets |*ret| to the 8192-bit MODP group from RFC 3526 and returns |ret|. If |ret| is NULL then a fresh |BIGNUM| is allocated and returned. It returns NULL on allocation failure. The generator for this group is 2.
BN_get_u64(Pointer<BIGNUM> bn, Pointer<Uint64> out) → int
BN_get_u64 sets |*out| to the absolute value of |bn| as a |uint64_t| and returns one. If |bn| is too large to be represented as a |uint64_t|, it returns zero.
BN_get_word(Pointer<BIGNUM> bn) → int
BN_get_word returns the absolute value of |bn| as a single word. If |bn| is too large to be represented as a single word, the maximum possible value will be returned.
BN_hex2bn(Pointer<Pointer<BIGNUM>> outp, Pointer<Char> in$) → int
BN_hex2bn parses the leading hex number from |in|, which may be proceeded by a '-' to indicate a negative number and may contain trailing, non-hex data. If |outp| is not NULL, it constructs a BIGNUM equal to the hex number and stores it in |*outp|. If |*outp| is NULL then it allocates a new BIGNUM and updates |*outp|. It returns the number of bytes of |in| processed or zero on error.
BN_init(Pointer<BIGNUM> bn) → void
BN_init initialises a stack allocated |BIGNUM|.
BN_is_bit_set(Pointer<BIGNUM> a, int n) → int
BN_is_bit_set returns one if the |n|th least-significant bit in |a| exists and is set. Otherwise, it returns zero.
BN_is_negative(Pointer<BIGNUM> bn) → int
BN_is_negative returns one if |bn| is negative and zero otherwise.
BN_is_odd(Pointer<BIGNUM> bn) → int
BN_is_odd returns one if |bn| is odd and zero otherwise.
BN_is_one(Pointer<BIGNUM> bn) → int
BN_is_one returns one if |bn| equals one and zero otherwise.
BN_is_pow2(Pointer<BIGNUM> a) → int
BN_is_pow2 returns 1 if |a| is a power of two, and 0 otherwise.
BN_is_prime_ex(Pointer<BIGNUM> candidate, int checks, Pointer<BN_CTX> ctx, Pointer<BN_GENCB> cb) → int
BN_is_prime_ex acts the same as |BN_is_prime_fasttest_ex| with |do_trial_division| set to zero.
BN_is_prime_fasttest_ex(Pointer<BIGNUM> candidate, int checks, Pointer<BN_CTX> ctx, int do_trial_division, Pointer<BN_GENCB> cb) → int
BN_is_prime_fasttest_ex returns one if |candidate| is probably a prime number by the Miller-Rabin test, zero if it's certainly not and -1 on error.
BN_is_word(Pointer<BIGNUM> bn, int w) → int
BN_is_word returns one if |bn| is exactly |w| and zero otherwise.
BN_is_zero(Pointer<BIGNUM> bn) → int
BN_is_zero returns one if |bn| is zero and zero otherwise.
BN_le2bn(Pointer<Uint8> in$, int len, Pointer<BIGNUM> ret) → Pointer<BIGNUM>
BN_le2bn calls |BN_lebin2bn|.
BN_lebin2bn(Pointer<Uint8> in$, int len, Pointer<BIGNUM> ret) → Pointer<BIGNUM>
BN_lebin2bn sets |*ret| to the value of |len| bytes from |in|, interpreted as a little-endian number, and returns |ret|. If |ret| is NULL then a fresh |BIGNUM| is allocated and returned. It returns NULL on allocation failure.
BN_lshift(Pointer<BIGNUM> r, Pointer<BIGNUM> a, int n) → int
BN_lshift sets |r| equal to |a| << n. The |a| and |r| arguments may be the same |BIGNUM|. It returns one on success and zero on allocation failure.
BN_lshift1(Pointer<BIGNUM> r, Pointer<BIGNUM> a) → int
BN_lshift1 sets |r| equal to |a| << 1, where |r| and |a| may be the same pointer. It returns one on success and zero on allocation failure.
BN_marshal_asn1(Pointer<CBB> cbb, Pointer<BIGNUM> bn) → int
BN_marshal_asn1 marshals |bn| as a non-negative DER INTEGER and appends the result to |cbb|. It returns one on success and zero on failure.
BN_mask_bits(Pointer<BIGNUM> a, int n) → int
BN_mask_bits truncates |a| so that it is only |n| bits long. It returns one on success or zero if |n| is negative.
BN_mod_add(Pointer<BIGNUM> r, Pointer<BIGNUM> a, Pointer<BIGNUM> b, Pointer<BIGNUM> m, Pointer<BN_CTX> ctx) → int
BN_mod_add sets |r| = |a| + |b| mod |m|. It returns one on success and zero on error.
BN_mod_add_quick(Pointer<BIGNUM> r, Pointer<BIGNUM> a, Pointer<BIGNUM> b, Pointer<BIGNUM> m) → int
BN_mod_add_quick acts like |BN_mod_add| but requires that |a| and |b| be non-negative and less than |m|.
BN_mod_exp(Pointer<BIGNUM> r, Pointer<BIGNUM> a, Pointer<BIGNUM> p, Pointer<BIGNUM> m, Pointer<BN_CTX> ctx) → int
BN_mod_exp sets |r| equal to |a|^{|p|} mod |m|. It does so with the best algorithm for the values provided. It returns one on success or zero otherwise. The |BN_mod_exp_mont_consttime| variant must be used if the exponent is secret.
BN_mod_exp2_mont(Pointer<BIGNUM> r, Pointer<BIGNUM> a1, Pointer<BIGNUM> p1, Pointer<BIGNUM> a2, Pointer<BIGNUM> p2, Pointer<BIGNUM> m, Pointer<BN_CTX> ctx, Pointer<BN_MONT_CTX> mont) → int
BN_mod_exp2_mont calculates (a1^p1) * (a2^p2) mod m. It returns 1 on success or zero otherwise.
BN_mod_exp_mont(Pointer<BIGNUM> r, Pointer<BIGNUM> a, Pointer<BIGNUM> p, Pointer<BIGNUM> m, Pointer<BN_CTX> ctx, Pointer<BN_MONT_CTX> mont) → int
BN_mod_exp_mont behaves like |BN_mod_exp| but treats |a| as secret and requires 0 <= |a| < |m|.
BN_mod_exp_mont_consttime(Pointer<BIGNUM> rr, Pointer<BIGNUM> a, Pointer<BIGNUM> p, Pointer<BIGNUM> m, Pointer<BN_CTX> ctx, Pointer<BN_MONT_CTX> mont) → int
BN_mod_exp_mont_consttime behaves like |BN_mod_exp| but treats |a|, |p|, and |m| as secret and requires 0 <= |a| < |m|.
BN_mod_exp_mont_word(Pointer<BIGNUM> r, int a, Pointer<BIGNUM> p, Pointer<BIGNUM> m, Pointer<BN_CTX> ctx, Pointer<BN_MONT_CTX> mont) → int
BN_mod_exp_mont_word is like |BN_mod_exp_mont| except that the base |a| is given as a |BN_ULONG| instead of a |BIGNUM *|. It returns one on success or zero otherwise.
BN_mod_inverse(Pointer<BIGNUM> out, Pointer<BIGNUM> a, Pointer<BIGNUM> n, Pointer<BN_CTX> ctx) → Pointer<BIGNUM>
BN_mod_inverse sets |out| equal to |a|^-1, mod |n|. If |out| is NULL, a fresh BIGNUM is allocated. It returns the result or NULL on error.
BN_mod_inverse_blinded(Pointer<BIGNUM> out, Pointer<Int> out_no_inverse, Pointer<BIGNUM> a, Pointer<BN_MONT_CTX> mont, Pointer<BN_CTX> ctx) → int
BN_mod_inverse_blinded sets |out| equal to |a|^-1, mod |n|, where |n| is the Montgomery modulus for |mont|. |a| must be non-negative and must be less than |n|. |n| must be greater than 1. |a| is blinded (masked by a random value) to protect it against side-channel attacks. On failure, if the failure was caused by |a| having no inverse mod |n| then |*out_no_inverse| will be set to one; otherwise it will be set to zero.
BN_mod_inverse_odd(Pointer<BIGNUM> out, Pointer<Int> out_no_inverse, Pointer<BIGNUM> a, Pointer<BIGNUM> n, Pointer<BN_CTX> ctx) → int
BN_mod_inverse_odd sets |out| equal to |a|^-1, mod |n|. |a| must be non-negative and must be less than |n|. |n| must be odd. This function shouldn't be used for secret values; use |BN_mod_inverse_blinded| instead. Or, if |n| is guaranteed to be prime, use |BN_mod_exp_mont_consttime(out, a, m_minus_2, m, ctx, m_mont)|, taking advantage of Fermat's Little Theorem. It returns one on success or zero on failure. On failure, if the failure was caused by |a| having no inverse mod |n| then |*out_no_inverse| will be set to one; otherwise it will be set to zero.
BN_mod_lshift(Pointer<BIGNUM> r, Pointer<BIGNUM> a, int n, Pointer<BIGNUM> m, Pointer<BN_CTX> ctx) → int
BN_mod_lshift sets |r| = (|a| << n) mod |m|, where |r| and |a| may be the same pointer. It returns one on success and zero on error.
BN_mod_lshift1(Pointer<BIGNUM> r, Pointer<BIGNUM> a, Pointer<BIGNUM> m, Pointer<BN_CTX> ctx) → int
BN_mod_lshift1 sets |r| = (|a| << 1) mod |m|, where |r| and |a| may be the same pointer. It returns one on success and zero on error.
BN_mod_lshift1_quick(Pointer<BIGNUM> r, Pointer<BIGNUM> a, Pointer<BIGNUM> m) → int
BN_mod_lshift1_quick acts like |BN_mod_lshift1| but requires that |a| be non-negative and less than |m|.
BN_mod_lshift_quick(Pointer<BIGNUM> r, Pointer<BIGNUM> a, int n, Pointer<BIGNUM> m) → int
BN_mod_lshift_quick acts like |BN_mod_lshift| but requires that |a| be non-negative and less than |m|.
BN_mod_mul(Pointer<BIGNUM> r, Pointer<BIGNUM> a, Pointer<BIGNUM> b, Pointer<BIGNUM> m, Pointer<BN_CTX> ctx) → int
BN_mod_mul sets |r| = |a|*|b| mod |m|. It returns one on success and zero on error.
BN_mod_mul_montgomery(Pointer<BIGNUM> r, Pointer<BIGNUM> a, Pointer<BIGNUM> b, Pointer<BN_MONT_CTX> mont, Pointer<BN_CTX> ctx) → int
BN_mod_mul_montgomery set |r| equal to |a| * |b|, in the Montgomery domain. Both |a| and |b| must already be in the Montgomery domain (by |BN_to_montgomery|). In particular, |a| and |b| are assumed to be in the range [0, n), where |n| is the Montgomery modulus. It returns one on success or zero on error.
BN_mod_pow2(Pointer<BIGNUM> r, Pointer<BIGNUM> a, int e) → int
BN_mod_pow2 sets |r| = |a| mod 2^|e|. It returns 1 on success and 0 on error.
BN_mod_sqr(Pointer<BIGNUM> r, Pointer<BIGNUM> a, Pointer<BIGNUM> m, Pointer<BN_CTX> ctx) → int
BN_mod_sqr sets |r| = |a|^2 mod |m|. It returns one on success and zero on error.
BN_mod_sqrt(Pointer<BIGNUM> in$, Pointer<BIGNUM> a, Pointer<BIGNUM> p, Pointer<BN_CTX> ctx) → Pointer<BIGNUM>
BN_mod_sqrt returns a newly-allocated |BIGNUM|, r, such that r^2 == a (mod p). It returns NULL on error or if |a| is not a square mod |p|. In the latter case, it will add |BN_R_NOT_A_SQUARE| to the error queue. If |a| is a square and |p| > 2, there are two possible square roots. This function may return either and may even select one non-deterministically.
BN_mod_sub(Pointer<BIGNUM> r, Pointer<BIGNUM> a, Pointer<BIGNUM> b, Pointer<BIGNUM> m, Pointer<BN_CTX> ctx) → int
BN_mod_sub sets |r| = |a| - |b| mod |m|. It returns one on success and zero on error.
BN_mod_sub_quick(Pointer<BIGNUM> r, Pointer<BIGNUM> a, Pointer<BIGNUM> b, Pointer<BIGNUM> m) → int
BN_mod_sub_quick acts like |BN_mod_sub| but requires that |a| and |b| be non-negative and less than |m|.
BN_mod_word(Pointer<BIGNUM> a, int w) → int
BN_mod_word returns |a| mod |w| or (BN_ULONG)-1 on error.
BN_MONT_CTX_copy(Pointer<BN_MONT_CTX> to, Pointer<BN_MONT_CTX> from) → Pointer<BN_MONT_CTX>
BN_MONT_CTX_copy sets |to| equal to |from|. It returns |to| on success or NULL on error.
BN_MONT_CTX_free(Pointer<BN_MONT_CTX> mont) → void
BN_MONT_CTX_free frees memory associated with |mont|.
BN_MONT_CTX_new() → Pointer<BN_MONT_CTX>
BN_MONT_CTX_new returns a fresh |BN_MONT_CTX| or NULL on allocation failure. Use |BN_MONT_CTX_new_for_modulus| instead.
BN_MONT_CTX_new_consttime(Pointer<BIGNUM> mod, Pointer<BN_CTX> ctx) → Pointer<BN_MONT_CTX>
BN_MONT_CTX_new_consttime behaves like |BN_MONT_CTX_new_for_modulus| but treats |mod| as secret.
BN_MONT_CTX_new_for_modulus(Pointer<BIGNUM> mod, Pointer<BN_CTX> ctx) → Pointer<BN_MONT_CTX>
BN_MONT_CTX_new_for_modulus returns a fresh |BN_MONT_CTX| given the modulus, |mod| or NULL on error. Note this function assumes |mod| is public.
BN_MONT_CTX_set(Pointer<BN_MONT_CTX> mont, Pointer<BIGNUM> mod, Pointer<BN_CTX> ctx) → int
BN_MONT_CTX_set sets up a Montgomery context given the modulus, |mod|. It returns one on success and zero on error. Use |BN_MONT_CTX_new_for_modulus| instead.
BN_mpi2bn(Pointer<Uint8> in$, int len, Pointer<BIGNUM> out) → Pointer<BIGNUM>
BN_mpi2bn parses |len| bytes from |in| and returns the resulting value. The bytes at |in| are expected to be in the format emitted by |BN_bn2mpi|.
BN_mul(Pointer<BIGNUM> r, Pointer<BIGNUM> a, Pointer<BIGNUM> b, Pointer<BN_CTX> ctx) → int
BN_mul sets |r| = |a| * |b|, where |r| may be the same pointer as |a| or |b|. Returns one on success and zero otherwise.
BN_mul_word(Pointer<BIGNUM> bn, int w) → int
BN_mul_word sets |bn| = |bn| * |w|. It returns one on success or zero on allocation failure.
BN_new() → Pointer<BIGNUM>
BN_new creates a new, allocated BIGNUM and initialises it.
BN_nnmod(Pointer<BIGNUM> rem, Pointer<BIGNUM> numerator, Pointer<BIGNUM> divisor, Pointer<BN_CTX> ctx) → int
BN_nnmod is a non-negative modulo function. It acts like |BN_mod|, but 0 <= |rem| < |divisor| is always true. It returns one on success and zero on error.
BN_nnmod_pow2(Pointer<BIGNUM> r, Pointer<BIGNUM> a, int e) → int
BN_nnmod_pow2 sets |r| = |a| mod 2^|e| where |r| is always positive. It returns 1 on success and 0 on error.
BN_num_bits(Pointer<BIGNUM> bn) → int
BN_num_bits returns the minimum number of bits needed to represent the absolute value of |bn|.
BN_num_bits_word(int l) → int
BN_num_bytes(Pointer<BIGNUM> bn) → int
BN_num_bytes returns the minimum number of bytes needed to represent the absolute value of |bn|.
BN_one(Pointer<BIGNUM> bn) → int
BN_one sets |bn| to one. It returns one on success or zero on allocation failure.
BN_parse_asn1_unsigned(Pointer<CBS> cbs, Pointer<BIGNUM> ret) → int
BN_parse_asn1_unsigned parses a non-negative DER INTEGER from |cbs| writes the result to |ret|. It returns one on success and zero on failure.
BN_primality_test(Pointer<Int> is_probably_prime, Pointer<BIGNUM> candidate, int checks, Pointer<BN_CTX> ctx, int do_trial_division, Pointer<BN_GENCB> cb) → int
BN_primality_test sets |*is_probably_prime| to one if |candidate| is probably a prime number by the Miller-Rabin test or zero if it's certainly not.
BN_print(Pointer<BIO> bio, Pointer<BIGNUM> a) → int
BN_print writes a hex encoding of |a| to |bio|. It returns one on success and zero on error.
BN_print_fp(Pointer<FILE> fp, Pointer<BIGNUM> a) → int
BN_print_fp acts like |BIO_print|, but wraps |fp| in a |BIO| first.
BN_pseudo_rand(Pointer<BIGNUM> rnd, int bits, int top, int bottom) → int
BN_pseudo_rand is an alias for |BN_rand|.
BN_pseudo_rand_range(Pointer<BIGNUM> rnd, Pointer<BIGNUM> range) → int
BN_pseudo_rand_range is an alias for BN_rand_range.
BN_rand(Pointer<BIGNUM> rnd, int bits, int top, int bottom) → int
BN_rand sets |rnd| to a random number of length |bits|. It returns one on success and zero otherwise.
BN_rand_range(Pointer<BIGNUM> rnd, Pointer<BIGNUM> range) → int
BN_rand_range is equivalent to |BN_rand_range_ex| with |min_inclusive| set to zero and |max_exclusive| set to |range|.
BN_rand_range_ex(Pointer<BIGNUM> r, int min_inclusive, Pointer<BIGNUM> max_exclusive) → int
BN_rand_range_ex sets |rnd| to a random value in [min_inclusive..max_exclusive). It returns one on success and zero otherwise.
BN_rshift(Pointer<BIGNUM> r, Pointer<BIGNUM> a, int n) → int
BN_rshift sets |r| equal to |a| >> n, where |r| and |a| may be the same pointer. It returns one on success and zero on allocation failure.
BN_rshift1(Pointer<BIGNUM> r, Pointer<BIGNUM> a) → int
BN_rshift1 sets |r| equal to |a| >> 1, where |r| and |a| may be the same pointer. It returns one on success and zero on allocation failure.
BN_secure_new() → Pointer<BIGNUM>
BN_secure_new calls |BN_new|.
BN_set_bit(Pointer<BIGNUM> a, int n) → int
BN_set_bit sets the |n|th, least-significant bit in |a|. For example, if |a| is 2 then setting bit zero will make it 3. It returns one on success or zero on allocation failure.
BN_set_negative(Pointer<BIGNUM> bn, int sign) → void
BN_set_negative sets the sign of |bn|.
BN_set_u64(Pointer<BIGNUM> bn, int value) → int
BN_set_u64 sets |bn| to |value|. It returns one on success or zero on allocation failure.
BN_set_word(Pointer<BIGNUM> bn, int value) → int
BN_set_word sets |bn| to |value|. It returns one on success or zero on allocation failure.
BN_sqr(Pointer<BIGNUM> r, Pointer<BIGNUM> a, Pointer<BN_CTX> ctx) → int
BN_sqr sets |r| = |a|^2 (i.e. squares), where |r| may be the same pointer as |a|. Returns one on success and zero otherwise. This is more efficient than BN_mul(r, a, a, ctx).
BN_sqrt(Pointer<BIGNUM> out_sqrt, Pointer<BIGNUM> in$, Pointer<BN_CTX> ctx) → int
BN_sqrt sets |*out_sqrt| (which may be the same |BIGNUM| as |in|) to the square root of |in|, using |ctx|. It returns one on success or zero on error. Negative numbers and non-square numbers will result in an error with appropriate errors on the error queue.
BN_sub(Pointer<BIGNUM> r, Pointer<BIGNUM> a, Pointer<BIGNUM> b) → int
BN_sub sets |r| = |a| - |b|, where |r| may be the same pointer as either |a| or |b|. It returns one on success and zero on allocation failure.
BN_sub_word(Pointer<BIGNUM> a, int w) → int
BN_sub_word subtracts |w| from |a|. It returns one on success and zero on allocation failure.
BN_to_ASN1_ENUMERATED(Pointer<BIGNUM> bn, Pointer<ASN1_OCTET_STRING> ai) → Pointer<ASN1_OCTET_STRING>
BN_to_ASN1_ENUMERATED sets |ai| to an ENUMERATED with value |bn| and returns |ai| on success or NULL or error. If |ai| is NULL, it returns a newly-allocated |ASN1_ENUMERATED| on success instead, which the caller must release with |ASN1_ENUMERATED_free|.
BN_to_ASN1_INTEGER(Pointer<BIGNUM> bn, Pointer<ASN1_OCTET_STRING> ai) → Pointer<ASN1_OCTET_STRING>
BN_to_ASN1_INTEGER sets |ai| to an INTEGER with value |bn| and returns |ai| on success or NULL or error. If |ai| is NULL, it returns a newly-allocated |ASN1_INTEGER| on success instead, which the caller must release with |ASN1_INTEGER_free|.
BN_to_montgomery(Pointer<BIGNUM> ret, Pointer<BIGNUM> a, Pointer<BN_MONT_CTX> mont, Pointer<BN_CTX> ctx) → int
BN_to_montgomery sets |ret| equal to |a| in the Montgomery domain. |a| is assumed to be in the range [0, n), where |n| is the Montgomery modulus. It returns one on success or zero on error.
BN_uadd(Pointer<BIGNUM> r, Pointer<BIGNUM> a, Pointer<BIGNUM> b) → int
BN_uadd sets |r| = |a| + |b|, considering only the absolute values of |a| and |b|. |r| may be the same pointer as either |a| or |b|. It returns one on success and zero on allocation failure.
BN_ucmp(Pointer<BIGNUM> a, Pointer<BIGNUM> b) → int
BN_ucmp returns a value less than, equal to or greater than zero if the absolute value of |a| is less than, equal to or greater than the absolute value of |b|, respectively.
BN_usub(Pointer<BIGNUM> r, Pointer<BIGNUM> a, Pointer<BIGNUM> b) → int
BN_usub sets |r| = |a| - |b|, considering only the absolute values of |a| and |b|. The result must be non-negative, i.e. |b| <= |a|. |r| may be the same pointer as either |a| or |b|. It returns one on success and zero on error.
BN_value_one() → Pointer<BIGNUM>
BN_value_one returns a static BIGNUM with value 1.
BN_zero(Pointer<BIGNUM> bn) → void
BN_zero sets |bn| to zero.
BORINGSSL_self_test() → int
BORINGSSL_self_test triggers most of the FIPS KAT-based self tests. It returns one on success and zero on error. It currently skips the SLH-DSA tests, which take a really long time to run.
BORINGSSL_self_test_all() → int
BORINGSSL_self_test_all triggers all of the FIPS KAT-based self tests. This is the 'self-test' entry point required by FIPS 140. It returns one on success and zero on error. This test will take a very long time to run. You probably do not want to run this in a resource or time constrained test.
BUF_MEM_append(Pointer<BUF_MEM> buf, Pointer<Void> in$, int len) → int
BUF_MEM_append appends |in| to |buf|. It returns one on success and zero on error.
BUF_MEM_free(Pointer<BUF_MEM> buf) → void
BUF_MEM_free frees |buf->data| if needed and then frees |buf| itself.
BUF_MEM_grow(Pointer<BUF_MEM> buf, int len) → int
BUF_MEM_grow ensures that |buf| has length |len| and allocates memory if needed. If the length of |buf| increased, the new bytes are filled with zeros. It returns the length of |buf|, or zero if there's an error.
BUF_MEM_grow_clean(Pointer<BUF_MEM> buf, int len) → int
BUF_MEM_grow_clean calls |BUF_MEM_grow|. BoringSSL always zeros memory allocated memory on free.
BUF_MEM_new() → Pointer<BUF_MEM>
BUF_MEM_new creates a new BUF_MEM which has no allocated data buffer.
BUF_MEM_reserve(Pointer<BUF_MEM> buf, int cap) → int
BUF_MEM_reserve ensures |buf| has capacity |cap| and allocates memory if needed. It returns one on success and zero on error.
BUF_memdup(Pointer<Void> data, int size) → Pointer<Void>
BUF_memdup calls |OPENSSL_memdup|.
BUF_strdup(Pointer<Char> str) → Pointer<Char>
BUF_strdup calls |OPENSSL_strdup|.
BUF_strlcat(Pointer<Char> dst, Pointer<Char> src, int dst_size) → int
BUF_strlcat calls |OPENSSL_strlcat|.
BUF_strlcpy(Pointer<Char> dst, Pointer<Char> src, int dst_size) → int
BUF_strlcpy calls |OPENSSL_strlcpy|.
BUF_strndup(Pointer<Char> str, int size) → Pointer<Char>
BUF_strndup calls |OPENSSL_strndup|.
BUF_strnlen(Pointer<Char> str, int max_len) → int
BUF_strnlen calls |OPENSSL_strnlen|.
c2i_ASN1_BIT_STRING(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OCTET_STRING>
c2i_ASN1_BIT_STRING decodes |len| bytes from |*inp| as the contents of a DER-encoded BIT STRING, excluding the tag and length. It behaves like |d2i_SAMPLE| except, on success, it always consumes all |len| bytes.
c2i_ASN1_INTEGER(Pointer<Pointer<ASN1_OCTET_STRING>> in$, Pointer<Pointer<Uint8>> outp, int len) → Pointer<ASN1_OCTET_STRING>
c2i_ASN1_INTEGER decodes |len| bytes from |*inp| as the contents of a DER-encoded INTEGER, excluding the tag and length. It behaves like |d2i_SAMPLE| except, on success, it always consumes all |len| bytes.
c2i_ASN1_OBJECT(Pointer<Pointer<ASN1_OBJECT>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OBJECT>
c2i_ASN1_OBJECT decodes |len| bytes from |*inp| as the contents of a DER-encoded OBJECT IDENTIFIER, excluding the tag and length. It behaves like |d2i_SAMPLE| except, on success, it always consumes all |len| bytes.
CBB_add_asn1(Pointer<CBB> cbb, Pointer<CBB> out_contents, int tag) → int
CBB_add_asn1 sets |*out_contents| to a |CBB| into which the contents of an ASN.1 object can be written. The |tag| argument will be used as the tag for the object. It returns one on success or zero on error.
CBB_add_asn1_bool(Pointer<CBB> cbb, int value) → int
CBB_add_asn1_bool writes an ASN.1 BOOLEAN into |cbb| which is true iff |value| is non-zero. It returns one on success and zero on error.
CBB_add_asn1_element(Pointer<CBB> cbb, int tag, Pointer<Uint8> data, int data_len) → int
CBB_add_asn1_element adds an ASN.1 element with the specified tag and contents. It returns one on success and zero on error. This is a convenience function over |CBB_add_asn1| when the data is already available.
CBB_add_asn1_int64(Pointer<CBB> cbb, int value) → int
CBB_add_asn1_int64 writes an ASN.1 INTEGER into |cbb| using |CBB_add_asn1| and writes |value| in its contents. It returns one on success and zero on error.
CBB_add_asn1_int64_with_tag(Pointer<CBB> cbb, int value, int tag) → int
CBB_add_asn1_int64_with_tag behaves like |CBB_add_asn1_int64| but uses |tag| as the tag instead of INTEGER. This is useful if the INTEGER type uses implicit tagging.
CBB_add_asn1_octet_string(Pointer<CBB> cbb, Pointer<Uint8> data, int data_len) → int
CBB_add_asn1_octet_string writes an ASN.1 OCTET STRING into |cbb| with the given contents. It returns one on success and zero on error.
CBB_add_asn1_oid_component(Pointer<CBB> cbb, int value) → int
CBB_add_asn1_oid_component appends a single OID component to |cbb|. It returns one on success and zero on error.
CBB_add_asn1_oid_from_text(Pointer<CBB> cbb, Pointer<Char> text, int len) → int
CBB_add_asn1_oid_from_text decodes |len| bytes from |text| as an ASCII OID representation, e.g. "1.2.840.113554.4.1.72585", and writes the DER-encoded contents to |cbb|. It returns one on success and zero on malloc failure or if |text| was invalid. It does not include the OBJECT IDENTIFIER framing, only the element's contents.
CBB_add_asn1_relative_oid_from_text(Pointer<CBB> cbb, Pointer<Char> text, int len) → int
CBB_add_asn1_relative_oid_from_text decodes |len| bytes from |text| as an ASCII RELATIVE-OID representation, e.g. "32473.1", and writes the DER-encoded contents to |cbb|. It returns one on success and zero on malloc failure or if |text| was invalid. It does not include any framing, only the element's contents.
CBB_add_asn1_uint64(Pointer<CBB> cbb, int value) → int
CBB_add_asn1_uint64 writes an ASN.1 INTEGER into |cbb| using |CBB_add_asn1| and writes |value| in its contents. It returns one on success and zero on error.
CBB_add_asn1_uint64_with_tag(Pointer<CBB> cbb, int value, int tag) → int
CBB_add_asn1_uint64_with_tag behaves like |CBB_add_asn1_uint64| but uses |tag| as the tag instead of INTEGER. This is useful if the INTEGER type uses implicit tagging.
CBB_add_bytes(Pointer<CBB> cbb, Pointer<Uint8> data, int len) → int
CBB_add_bytes appends |len| bytes from |data| to |cbb|. It returns one on success and zero otherwise.
CBB_add_latin1(Pointer<CBB> cbb, int u) → int
CBB_add_space(Pointer<CBB> cbb, Pointer<Pointer<Uint8>> out_data, int len) → int
CBB_add_space appends |len| bytes to |cbb| and sets |*out_data| to point to the beginning of that space. The caller must then write |len| bytes of actual contents to |*out_data|. It returns one on success and zero otherwise.
CBB_add_u16(Pointer<CBB> cbb, int value) → int
CBB_add_u16 appends a 16-bit, big-endian number from |value| to |cbb|. It returns one on success and zero otherwise.
CBB_add_u16_length_prefixed(Pointer<CBB> cbb, Pointer<CBB> out_contents) → int
CBB_add_u16_length_prefixed sets |*out_contents| to a new child of |cbb|. The data written to |*out_contents| will be prefixed in |cbb| with a 16-bit, big-endian length. It returns one on success or zero on error.
CBB_add_u16le(Pointer<CBB> cbb, int value) → int
CBB_add_u16le appends a 16-bit, little-endian number from |value| to |cbb|. It returns one on success and zero otherwise.
CBB_add_u24(Pointer<CBB> cbb, int value) → int
CBB_add_u24 appends a 24-bit, big-endian number from |value| to |cbb|. It returns one on success and zero otherwise.
CBB_add_u24_length_prefixed(Pointer<CBB> cbb, Pointer<CBB> out_contents) → int
CBB_add_u24_length_prefixed sets |*out_contents| to a new child of |cbb|. The data written to |*out_contents| will be prefixed in |cbb| with a 24-bit, big-endian length. It returns one on success or zero on error.
CBB_add_u32(Pointer<CBB> cbb, int value) → int
CBB_add_u32 appends a 32-bit, big-endian number from |value| to |cbb|. It returns one on success and zero otherwise.
CBB_add_u32le(Pointer<CBB> cbb, int value) → int
CBB_add_u32le appends a 32-bit, little-endian number from |value| to |cbb|. It returns one on success and zero otherwise.
CBB_add_u64(Pointer<CBB> cbb, int value) → int
CBB_add_u64 appends a 64-bit, big-endian number from |value| to |cbb|. It returns one on success and zero otherwise.
CBB_add_u64le(Pointer<CBB> cbb, int value) → int
CBB_add_u64le appends a 64-bit, little-endian number from |value| to |cbb|. It returns one on success and zero otherwise.
CBB_add_u8(Pointer<CBB> cbb, int value) → int
CBB_add_u8 appends an 8-bit number from |value| to |cbb|. It returns one on success and zero otherwise.
CBB_add_u8_length_prefixed(Pointer<CBB> cbb, Pointer<CBB> out_contents) → int
CBB_add_u8_length_prefixed sets |*out_contents| to a new child of |cbb|. The data written to |*out_contents| will be prefixed in |cbb| with an 8-bit length. It returns one on success or zero on error.
CBB_add_ucs2_be(Pointer<CBB> cbb, int u) → int
CBB_add_utf32_be(Pointer<CBB> cbb, int u) → int
CBB_add_utf8(Pointer<CBB> cbb, int u) → int
The following functions encode |u| to |cbb| with the corresponding encoding. They return one on success and zero on error. Error conditions include |u| being an invalid code point, or |u| being unencodable in the specified encoding.
CBB_add_zeros(Pointer<CBB> cbb, int len) → int
CBB_add_zeros append |len| bytes with value zero to |cbb|. It returns one on success and zero otherwise.
CBB_cleanup(Pointer<CBB> cbb) → void
CBB_cleanup frees all resources owned by |cbb| and other |CBB| objects writing to the same buffer. This should be used in an error case where a serialisation is abandoned.
CBB_data(Pointer<CBB> cbb) → Pointer<Uint8>
CBB_data returns a pointer to the bytes written to |cbb|. It does not flush |cbb|. The pointer is valid until the next operation to |cbb|.
CBB_did_write(Pointer<CBB> cbb, int len) → int
CBB_did_write advances |cbb| by |len| bytes, assuming the space has been written to by the caller. It returns one on success and zero on error.
CBB_discard(Pointer<CBB> cbb, int len) → void
CBB_discard discards the last |len| bytes written to |cbb|. The process will abort if |cbb| has an unflushed child, or its length is smaller than |len|.
CBB_discard_child(Pointer<CBB> cbb) → void
CBB_discard_child discards the current unflushed child of |cbb|. Neither the child's contents nor the length prefix will be included in the output.
CBB_finish(Pointer<CBB> cbb, Pointer<Pointer<Uint8>> out_data, Pointer<Size> out_len) → int
CBB_finish completes any pending length prefix and sets |*out_data| to a malloced buffer and |*out_len| to the length of that buffer. The caller takes ownership of the buffer and, unless the buffer was fixed with |CBB_init_fixed|, must call |OPENSSL_free| when done.
CBB_flush(Pointer<CBB> cbb) → int
CBB_flush causes any pending length prefixes to be written out and any child |CBB| objects of |cbb| to be invalidated. This allows |cbb| to continue to be used after the children go out of scope, e.g. when local |CBB| objects are added as children to a |CBB| that persists after a function returns. This function returns one on success or zero on error.
CBB_flush_asn1_set_of(Pointer<CBB> cbb) → int
CBB_flush_asn1_set_of calls |CBB_flush| on |cbb| and then reorders the contents for a DER-encoded ASN.1 SET OF type. It returns one on success and zero on failure. DER canonicalizes SET OF contents by sorting lexicographically by encoding. Call this function when encoding a SET OF type in an order that is not already known to be canonical.
CBB_get_utf8_len(int u) → int
CBB_get_utf8_len returns the number of bytes needed to represent |u| in UTF-8.
CBB_init(Pointer<CBB> cbb, int initial_capacity) → int
CBB_init initialises |cbb| with |initial_capacity|. Since a |CBB| grows as needed, the |initial_capacity| is just a hint. It returns one on success or zero on allocation failure.
CBB_init_fixed(Pointer<CBB> cbb, Pointer<Uint8> buf, int len) → int
CBB_init_fixed initialises |cbb| to write to |len| bytes at |buf|. Since |buf| cannot grow, trying to write more than |len| bytes will cause CBB functions to fail. This function is infallible and always returns one. It is safe, but not necessary, to call |CBB_cleanup| on |cbb|.
CBB_len(Pointer<CBB> cbb) → int
CBB_len returns the number of bytes written to |cbb|. It does not flush |cbb|.
CBB_reserve(Pointer<CBB> cbb, Pointer<Pointer<Uint8>> out_data, int len) → int
CBB_reserve ensures |cbb| has room for |len| additional bytes and sets |*out_data| to point to the beginning of that space. It returns one on success and zero otherwise. The caller may write up to |len| bytes to |*out_data| and call |CBB_did_write| to complete the write. |*out_data| is valid until the next operation on |cbb| or an ancestor |CBB|.
CBB_zero(Pointer<CBB> cbb) → void
CBB_zero sets an uninitialised |cbb| to the zero state. It must be initialised with |CBB_init| or |CBB_init_fixed| before use, but it is safe to call |CBB_cleanup| without a successful |CBB_init|. This may be used for more uniform cleanup of a |CBB|.
CBS_asn1_bitstring_has_bit(Pointer<CBS> cbs, int bit) → int
CBS_asn1_bitstring_has_bit returns one if |cbs| is a valid ASN.1 BIT STRING body and the specified bit is present and set. Otherwise, it returns zero. |bit| is indexed starting from zero.
CBS_asn1_oid_to_text(Pointer<CBS> cbs) → Pointer<Char>
CBS_asn1_oid_to_text interprets |cbs| as DER-encoded ASN.1 OBJECT IDENTIFIER contents (not including the element framing) and returns the ASCII representation (e.g., "1.2.840.113554.4.1.72585") in a newly-allocated string, or NULL on failure. The caller must release the result with |OPENSSL_free|.
CBS_asn1_relative_oid_to_text(Pointer<CBS> cbs) → Pointer<Char>
CBS_asn1_relative_oid_to_text interprets |cbs| as DER-encoded ASN.1 RELATIVE-OID contents (not including the element framing) and returns the ASCII representation (e.g., "32473.1") in a newly-allocated string, or NULL on failure. The caller must release the result with |OPENSSL_free|.
CBS_contains_zero_byte(Pointer<CBS> cbs) → int
CBS_contains_zero_byte returns one if the current contents of |cbs| contains a NUL byte and zero otherwise.
CBS_copy_bytes(Pointer<CBS> cbs, Pointer<Uint8> out, int len) → int
CBS_copy_bytes copies the next |len| bytes from |cbs| to |out| and advances |cbs|. It returns one on success and zero on error.
CBS_get_any_asn1(Pointer<CBS> cbs, Pointer<CBS> out, Pointer<CBS_ASN1_TAG> out_tag) → int
CBS_get_any_asn1 sets |*out| to contain the next ASN.1 element from |*cbs| (not including tag and length bytes), sets |*out_tag| to the tag number, and advances |*cbs|. It returns one on success and zero on error. Either of |out| and |out_tag| may be NULL to ignore the value.
CBS_get_any_asn1_element(Pointer<CBS> cbs, Pointer<CBS> out, Pointer<CBS_ASN1_TAG> out_tag, Pointer<Size> out_header_len) → int
CBS_get_any_asn1_element sets |*out| to contain the next ASN.1 element from |*cbs| (including header bytes) and advances |*cbs|. It sets |*out_tag| to the tag number and |*out_header_len| to the length of the ASN.1 header. Each of |out|, |out_tag|, and |out_header_len| may be NULL to ignore the value.
CBS_get_any_ber_asn1_element(Pointer<CBS> cbs, Pointer<CBS> out, Pointer<CBS_ASN1_TAG> out_tag, Pointer<Size> out_header_len, Pointer<Int> out_ber_found, Pointer<Int> out_indefinite) → int
CBS_get_any_ber_asn1_element acts the same as |CBS_get_any_asn1_element| but also allows indefinite-length elements to be returned and does not enforce that lengths are minimal. It sets |*out_indefinite| to one if the length was indefinite and zero otherwise. If indefinite, |*out_header_len| and |CBS_len(out)| will be equal as only the header is returned (although this is also true for empty elements so |*out_indefinite| should be checked). If |out_ber_found| is not NULL then it is set to one if any case of invalid DER but valid BER is found, and to zero otherwise.
CBS_get_asn1(Pointer<CBS> cbs, Pointer<CBS> out, int tag_value) → int
CBS_get_asn1 sets |*out| to the contents of DER-encoded, ASN.1 element (not including tag and length bytes) and advances |cbs| over it. The ASN.1 element must match |tag_value|. It returns one on success and zero on error.
CBS_get_asn1_bool(Pointer<CBS> cbs, Pointer<Int> out) → int
CBS_get_asn1_bool gets an ASN.1 BOOLEAN from |cbs| and sets |*out| to zero or one based on its value. It returns one on success or zero on error.
CBS_get_asn1_element(Pointer<CBS> cbs, Pointer<CBS> out, int tag_value) → int
CBS_get_asn1_element acts like |CBS_get_asn1| but |out| will include the ASN.1 header bytes too.
CBS_get_asn1_int64(Pointer<CBS> cbs, Pointer<Int64> out) → int
CBS_get_asn1_int64 gets an ASN.1 INTEGER from |cbs| using |CBS_get_asn1| and sets |*out| to its value. It returns one on success and zero on error, where error includes the integer being too large to represent in 64 bits.
CBS_get_asn1_int64_with_tag(Pointer<CBS> cbs, Pointer<Int64> out, int tag) → int
CBS_get_asn1_int64_with_tag gets an ASN.1 INTEGER from |cbs| using |CBS_get_asn1| and sets |*out| to its value. |tag| is used to handle to handle implicitly tagged INTEGER fields. It returns one on success and zero on error, where error includes the integer being too large to represent in 64 bits.
CBS_get_asn1_uint64(Pointer<CBS> cbs, Pointer<Uint64> out) → int
CBS_get_asn1_uint64 gets an ASN.1 INTEGER from |cbs| using |CBS_get_asn1| and sets |*out| to its value. It returns one on success and zero on error, where error includes the integer being negative, or too large to represent in 64 bits.
CBS_get_asn1_uint64_with_tag(Pointer<CBS> cbs, Pointer<Uint64> out, int tag) → int
CBS_get_asn1_uint64_with_tag gets an ASN.1 INTEGER from |cbs| using |CBS_get_asn1| and sets |*out| to its value. |tag| is used to handle to handle implicitly tagged INTEGER fields. It returns one on success and zero on error, where error includes the integer being negative, or too large to represent in 64 bits.
CBS_get_bytes(Pointer<CBS> cbs, Pointer<CBS> out, int len) → int
CBS_get_bytes sets |*out| to the next |len| bytes from |cbs| and advances |cbs|. It returns one on success and zero on error.
CBS_get_last_u8(Pointer<CBS> cbs, Pointer<Uint8> out) → int
CBS_get_last_u8 sets |*out| to the last uint8_t from |cbs| and shortens |cbs|. It returns one on success and zero on error.
CBS_get_latin1(Pointer<CBS> cbs, Pointer<CBS_ASN1_TAG> out) → int
CBS_get_optional_asn1(Pointer<CBS> cbs, Pointer<CBS> out, Pointer<Int> out_present, int tag) → int
CBS_get_optional_asn1 gets an optional explicitly-tagged element from |cbs| tagged with |tag| and sets |*out| to its contents, or ignores it if |out| is NULL. If present and if |out_present| is not NULL, it sets |*out_present| to one, otherwise zero. It returns one on success, whether or not the element was present, and zero on decode failure.
CBS_get_optional_asn1_bool(Pointer<CBS> cbs, Pointer<Int> out, int tag, int default_value) → int
CBS_get_optional_asn1_bool gets an optional, explicitly-tagged BOOLEAN from |cbs|. If present, it sets |*out| to either zero or one, based on the boolean. Otherwise, it sets |*out| to |default_value|. It returns one on success, whether or not the element was present, and zero on decode failure.
CBS_get_optional_asn1_octet_string(Pointer<CBS> cbs, Pointer<CBS> out, Pointer<Int> out_present, int tag) → int
CBS_get_optional_asn1_octet_string gets an optional explicitly-tagged OCTET STRING from |cbs|. If present, it sets |*out| to the string and |*out_present| to one. Otherwise, it sets |*out| to empty and |*out_present| to zero. |out_present| may be NULL. It returns one on success, whether or not the element was present, and zero on decode failure.
CBS_get_optional_asn1_uint64(Pointer<CBS> cbs, Pointer<Uint64> out, int tag, int default_value) → int
CBS_get_optional_asn1_uint64 gets an optional explicitly-tagged INTEGER from |cbs|. If present, it sets |*out| to the value. Otherwise, it sets |*out| to |default_value|. It returns one on success, whether or not the element was present, and zero on decode failure.
CBS_get_u16(Pointer<CBS> cbs, Pointer<Uint16> out) → int
CBS_get_u16 sets |*out| to the next, big-endian uint16_t from |cbs| and advances |cbs|. It returns one on success and zero on error.
CBS_get_u16_length_prefixed(Pointer<CBS> cbs, Pointer<CBS> out) → int
CBS_get_u16_length_prefixed sets |*out| to the contents of a 16-bit, big-endian, length-prefixed value from |cbs| and advances |cbs| over it. It returns one on success and zero on error.
CBS_get_u16le(Pointer<CBS> cbs, Pointer<Uint16> out) → int
CBS_get_u16le sets |*out| to the next, little-endian uint16_t from |cbs| and advances |cbs|. It returns one on success and zero on error.
CBS_get_u24(Pointer<CBS> cbs, Pointer<CBS_ASN1_TAG> out) → int
CBS_get_u24 sets |*out| to the next, big-endian 24-bit value from |cbs| and advances |cbs|. It returns one on success and zero on error.
CBS_get_u24_length_prefixed(Pointer<CBS> cbs, Pointer<CBS> out) → int
CBS_get_u24_length_prefixed sets |*out| to the contents of a 24-bit, big-endian, length-prefixed value from |cbs| and advances |cbs| over it. It returns one on success and zero on error.
CBS_get_u32(Pointer<CBS> cbs, Pointer<CBS_ASN1_TAG> out) → int
CBS_get_u32 sets |*out| to the next, big-endian uint32_t value from |cbs| and advances |cbs|. It returns one on success and zero on error.
CBS_get_u32le(Pointer<CBS> cbs, Pointer<CBS_ASN1_TAG> out) → int
CBS_get_u32le sets |*out| to the next, little-endian uint32_t value from |cbs| and advances |cbs|. It returns one on success and zero on error.
CBS_get_u64(Pointer<CBS> cbs, Pointer<Uint64> out) → int
CBS_get_u64 sets |*out| to the next, big-endian uint64_t value from |cbs| and advances |cbs|. It returns one on success and zero on error.
CBS_get_u64_decimal(Pointer<CBS> cbs, Pointer<Uint64> out) → int
CBS_get_u64_decimal reads a decimal integer from |cbs| and writes it to |*out|. It stops reading at the end of the string, or the first non-digit character. It returns one on success and zero on error. This function behaves analogously to |strtoul| except it does not accept empty inputs, leading zeros, or negative values.
CBS_get_u64le(Pointer<CBS> cbs, Pointer<Uint64> out) → int
CBS_get_u64le sets |*out| to the next, little-endian uint64_t value from |cbs| and advances |cbs|. It returns one on success and zero on error.
CBS_get_u8(Pointer<CBS> cbs, Pointer<Uint8> out) → int
CBS_get_u8 sets |*out| to the next uint8_t from |cbs| and advances |cbs|. It returns one on success and zero on error.
CBS_get_u8_length_prefixed(Pointer<CBS> cbs, Pointer<CBS> out) → int
CBS_get_u8_length_prefixed sets |*out| to the contents of an 8-bit, length-prefixed value from |cbs| and advances |cbs| over it. It returns one on success and zero on error.
CBS_get_ucs2_be(Pointer<CBS> cbs, Pointer<CBS_ASN1_TAG> out) → int
CBS_get_until_first(Pointer<CBS> cbs, Pointer<CBS> out, int c) → int
CBS_get_until_first finds the first instance of |c| in |cbs|. If found, it sets |*out| to the text before the match, advances |cbs| over it, and returns one. Otherwise, it returns zero and leaves |cbs| unmodified.
CBS_get_until_first_not_of(Pointer<CBS> cbs, Pointer<CBS> out, Pointer<Char> chars) → int
CBS_get_until_first_not_of finds the first byte in |cbs| that does not match any of the characters in |chars|, which is a NUL-terminated C string. If found, it sets |*out| to the text before the match, advances |cbs| over it, and returns one. Otherwise, it returns zero and leaves |cbs| unmodified.
CBS_get_until_first_of(Pointer<CBS> cbs, Pointer<CBS> out, Pointer<Char> chars) → int
CBS_get_until_first_of finds the first byte in |cbs| matching one of the characters in |chars|, which is a NUL-terminated C string. If found, it sets |*out| to the text before the match, advances |cbs| over it, and returns one. Otherwise, it returns zero and leaves |cbs| unmodified.
CBS_get_utf32_be(Pointer<CBS> cbs, Pointer<CBS_ASN1_TAG> out) → int
CBS_get_utf8(Pointer<CBS> cbs, Pointer<CBS_ASN1_TAG> out) → int
The following functions read one Unicode code point from |cbs| with the corresponding encoding and store it in |*out|. They return one on success and zero on error.
CBS_is_unsigned_asn1_integer(Pointer<CBS> cbs) → int
CBS_is_unsigned_asn1_integer returns one if |cbs| is a valid non-negative ASN.1 INTEGER body and zero otherwise.
CBS_is_valid_asn1_bitstring(Pointer<CBS> cbs) → int
CBS_is_valid_asn1_bitstring returns one if |cbs| is a valid ASN.1 BIT STRING body and zero otherwise.
CBS_is_valid_asn1_integer(Pointer<CBS> cbs, Pointer<Int> out_is_negative) → int
CBS_is_valid_asn1_integer returns one if |cbs| is a valid ASN.1 INTEGER, body and zero otherwise. On success, if |out_is_negative| is non-NULL, |*out_is_negative| will be set to one if |cbs| is negative and zero otherwise.
CBS_is_valid_asn1_oid(Pointer<CBS> cbs) → int
CBS_is_valid_asn1_oid returns one if |cbs| is a valid DER-encoded ASN.1 OBJECT IDENTIFIER contents (not including the element framing) and zero otherwise. This function tolerates arbitrarily large OID components.
CBS_is_valid_asn1_relative_oid(Pointer<CBS> cbs) → int
CBS_is_valid_asn1_relative_oid returns one if |cbs| is a valid DER-encoded ASN.1 RELATIVE-OID contents (not including the element framing) and zero otherwise. This function tolerates arbitrarily large OID components.
CBS_mem_equal(Pointer<CBS> cbs, Pointer<Uint8> data, int len) → int
CBS_mem_equal compares the current contents of |cbs| with the |len| bytes starting at |data|. If they're equal, it returns one, otherwise zero. If the lengths match, it uses a constant-time comparison.
CBS_parse_generalized_time(Pointer<CBS> cbs, Pointer<tm> out_tm, int allow_timezone_offset) → int
CBS_parse_generalized_time returns one if |cbs| is a valid DER-encoded, ASN.1 GeneralizedTime body within the limitations imposed by RFC 5280, or zero otherwise. If |allow_timezone_offset| is non-zero, four-digit timezone offsets, which would not be allowed by DER, are permitted. On success, if |out_tm| is non-NULL, |*out_tm| will be zeroed, and then set to the corresponding time in UTC. This function does not compute |out_tm->tm_wday| or |out_tm->tm_yday|.
CBS_parse_utc_time(Pointer<CBS> cbs, Pointer<tm> out_tm, int allow_timezone_offset) → int
CBS_parse_utc_time returns one if |cbs| is a valid DER-encoded, ASN.1 UTCTime body within the limitations imposed by RFC 5280, or zero otherwise. If |allow_timezone_offset| is non-zero, four-digit timezone offsets, which would not be allowed by DER, are permitted. On success, if |out_tm| is non-NULL, |*out_tm| will be zeroed, and then set to the corresponding time in UTC. This function does not compute |out_tm->tm_wday| or |out_tm->tm_yday|.
CBS_peek_asn1_tag(Pointer<CBS> cbs, int tag_value) → int
CBS_peek_asn1_tag looks ahead at the next ASN.1 tag and returns one if the next ASN.1 element on |cbs| would have tag |tag_value|. If |cbs| is empty or the tag does not match, it returns zero. Note: if it returns one, CBS_get_asn1 may still fail if the rest of the element is malformed.
CBS_skip(Pointer<CBS> cbs, int len) → int
CBS_skip advances |cbs| by |len| bytes. It returns one on success and zero otherwise.
CBS_stow(Pointer<CBS> cbs, Pointer<Pointer<Uint8>> out_ptr, Pointer<Size> out_len) → int
CBS_stow copies the current contents of |cbs| into |*out_ptr| and |*out_len|. If |*out_ptr| is not NULL, the contents are freed with OPENSSL_free. It returns one on success and zero on allocation failure. On success, |*out_ptr| should be freed with OPENSSL_free. If |cbs| is empty, |*out_ptr| will be NULL.
CBS_strdup(Pointer<CBS> cbs, Pointer<Pointer<Char>> out_ptr) → int
CBS_strdup copies the current contents of |cbs| into |*out_ptr| as a NUL-terminated C string. If |*out_ptr| is not NULL, the contents are freed with OPENSSL_free. It returns one on success and zero on allocation failure. On success, |*out_ptr| should be freed with OPENSSL_free.
CERTIFICATEPOLICIES_free(Pointer<CERTIFICATEPOLICIES> policies) → void
CERTIFICATEPOLICIES_free releases memory associated with |policies|.
CERTIFICATEPOLICIES_new() → Pointer<CERTIFICATEPOLICIES>
CERTIFICATEPOLICIES_new returns a newly-allocated, empty |CERTIFICATEPOLICIES| object, or NULL on error.
CONF_modules_free() → void
CONF_modules_free does nothing.
CONF_modules_load_file(Pointer<Char> filename, Pointer<Char> appname, int flags) → int
CONF_modules_load_file returns one. BoringSSL is defined to have no config file options, thus loading from |filename| always succeeds by doing nothing.
CONF_modules_unload(int all) → void
CONF_modules_unload does nothing.
CRL_DIST_POINTS_free(Pointer<CRL_DIST_POINTS> crldp) → void
CRL_DIST_POINTS_free releases memory associated with |crldp|.
CRL_DIST_POINTS_new() → Pointer<CRL_DIST_POINTS>
CRL_DIST_POINTS_new returns a newly-allocated, empty |CRL_DIST_POINTS| object, or NULL on error.
CRYPTO_BUFFER_alloc(Pointer<Pointer<Uint8>> out_data, int len) → Pointer<CRYPTO_BUFFER>
CRYPTO_BUFFER_alloc creates an unpooled |CRYPTO_BUFFER| of the given size and writes the underlying data pointer to |*out_data|. It returns NULL on error.
CRYPTO_BUFFER_data(Pointer<CRYPTO_BUFFER> buf) → Pointer<Uint8>
CRYPTO_BUFFER_data returns a pointer to the data contained in |buf|.
CRYPTO_BUFFER_dup_ref(Pointer<CRYPTO_BUFFER> buf) → Pointer<CRYPTO_BUFFER>
CRYPTO_BUFFER_dup_ref increments the reference count of |buf| and returns |buf|. The caller must call |CRYPTO_BUFFER_free| on the result to release the reference.
CRYPTO_BUFFER_free(Pointer<CRYPTO_BUFFER> buf) → void
CRYPTO_BUFFER_free decrements the reference count of |buf|. If there are no other references, or if the only remaining reference is from a pool, then |buf| will be freed.
CRYPTO_BUFFER_init_CBS(Pointer<CRYPTO_BUFFER> buf, Pointer<CBS> out) → void
CRYPTO_BUFFER_init_CBS initialises |out| to point at the data from |buf|.
CRYPTO_BUFFER_len(Pointer<CRYPTO_BUFFER> buf) → int
CRYPTO_BUFFER_len returns the length, in bytes, of the data contained in |buf|.
CRYPTO_BUFFER_new(Pointer<Uint8> data, int len, Pointer<CRYPTO_BUFFER_POOL> pool) → Pointer<CRYPTO_BUFFER>
CRYPTO_BUFFER_new returns a |CRYPTO_BUFFER| containing a copy of |data|, or else NULL on error. If |pool| is not NULL then the returned value may be a reference to a previously existing |CRYPTO_BUFFER| that contained the same data. Otherwise, the returned, fresh |CRYPTO_BUFFER| will be added to the pool.
CRYPTO_BUFFER_new_from_CBS(Pointer<CBS> cbs, Pointer<CRYPTO_BUFFER_POOL> pool) → Pointer<CRYPTO_BUFFER>
CRYPTO_BUFFER_new_from_CBS acts the same as |CRYPTO_BUFFER_new|.
CRYPTO_BUFFER_new_from_static_data_unsafe(Pointer<Uint8> data, int len, Pointer<CRYPTO_BUFFER_POOL> pool) → Pointer<CRYPTO_BUFFER>
CRYPTO_BUFFER_new_from_static_data_unsafe behaves like |CRYPTO_BUFFER_new| but does not copy |data|. |data| must be immutable and last for the lifetime of the address space.
CRYPTO_BUFFER_POOL_free(Pointer<CRYPTO_BUFFER_POOL> pool) → void
CRYPTO_BUFFER_POOL_free decrements the reference count of |pool| and frees it if the reference count drops to zero.
CRYPTO_BUFFER_POOL_new() → Pointer<CRYPTO_BUFFER_POOL>
CRYPTO_BUFFER_POOL_new returns a freshly allocated |CRYPTO_BUFFER_POOL| or NULL on error.
CRYPTO_BUFFER_POOL_up_ref(Pointer<CRYPTO_BUFFER_POOL> pool) → int
CRYPTO_BUFFER_POOL_up_ref increments the reference count of |pool| and returns one. It does not mutate |pool| for thread-safety purposes and may be used concurrently.
CRYPTO_BUFFER_up_ref(Pointer<CRYPTO_BUFFER> buf) → int
CRYPTO_BUFFER_up_ref increments the reference count of |buf| and returns one.
CRYPTO_cleanup_all_ex_data() → void
CRYPTO_cleanup_all_ex_data does nothing.
CRYPTO_fips_186_2_prf(Pointer<Uint8> out, int out_len, Pointer<Uint8> xkey) → void
CRYPTO_fips_186_2_prf derives |out_len| bytes from |xkey| using the PRF defined in FIPS 186-2, Appendix 3.1, with change notice 1 applied. The b parameter is 160 and seed, XKEY, is also 160 bits. The optional XSEED user input is all zeros.
CRYPTO_free(Pointer<Void> ptr, Pointer<Char> file, int line) → void
CRYPTO_free calls |OPENSSL_free|. |file| and |line| are ignored.
CRYPTO_get_dynlock_create_callback() → Pointer<NativeFunction<Pointer<CRYPTO_dynlock_value> Function(Pointer<Char>, Int)>>
CRYPTO_get_dynlock_create_callback returns NULL.
CRYPTO_get_dynlock_destroy_callback() → Pointer<NativeFunction<Void Function(Pointer<CRYPTO_dynlock_value>, Pointer<Char>, Int)>>
CRYPTO_get_dynlock_destroy_callback returns NULL.
CRYPTO_get_dynlock_lock_callback() → Pointer<NativeFunction<Void Function(Int, Pointer<CRYPTO_dynlock_value>, Pointer<Char>, Int)>>
CRYPTO_get_dynlock_lock_callback returns NULL.
CRYPTO_get_lock_name(int lock_num) → Pointer<Char>
CRYPTO_get_lock_name returns a fixed, dummy string.
CRYPTO_get_locking_callback() → Pointer<NativeFunction<Void Function(Int, Int, Pointer<Char>, Int)>>
CRYPTO_get_locking_callback returns NULL.
CRYPTO_has_asm() → int
CRYPTO_has_asm returns one unless BoringSSL was built with OPENSSL_NO_ASM, in which case it returns zero.
CRYPTO_is_confidential_build() → int
CRYPTO_is_confidential_build returns one if the linked version of BoringSSL has been built with the BORINGSSL_CONFIDENTIAL define and zero otherwise.
CRYPTO_library_init() → void
CRYPTO_library_init does nothing. Historically, it was needed in some build configurations to initialization the library. This is no longer necessary.
CRYPTO_malloc(int size, Pointer<Char> file, int line) → Pointer<Void>
CRYPTO_malloc calls |OPENSSL_malloc|. |file| and |line| are ignored.
CRYPTO_malloc_init() → int
CRYPTO_malloc_init returns one.
CRYPTO_memcmp(Pointer<Void> a, Pointer<Void> b, int len) → int
CRYPTO_memcmp returns zero iff the |len| bytes at |a| and |b| are equal. It takes an amount of time dependent on |len|, but independent of the contents of |a| and |b|. Unlike memcmp, it cannot be used to put elements into a defined order as the return value when a != b is undefined, other than to be non-zero.
CRYPTO_num_locks() → int
CRYPTO_num_locks returns one. (This is non-zero that callers who allocate sizeof(lock) times this value don't get zero and then fail because malloc(0) returned NULL.)
CRYPTO_pre_sandbox_init() → void
CRYPTO_pre_sandbox_init initializes the crypto library, pre-acquiring some unusual resources to aid running in sandboxed environments. It is safe to call this function multiple times and concurrently from multiple threads.
CRYPTO_realloc(Pointer<Void> ptr, int new_size, Pointer<Char> file, int line) → Pointer<Void>
CRYPTO_realloc calls |OPENSSL_realloc|. |file| and |line| are ignored.
CRYPTO_secure_malloc_init(int size, int min_size) → int
CRYPTO_secure_malloc_init returns zero.
CRYPTO_secure_malloc_initialized() → int
CRYPTO_secure_malloc_initialized returns zero.
CRYPTO_secure_used() → int
CRYPTO_secure_used returns zero.
CRYPTO_set_add_lock_callback(Pointer<NativeFunction<Int Function(Pointer<Int> num, Int amount, Int lock_num, Pointer<Char> file, Int line)>> func) → void
CRYPTO_set_add_lock_callback does nothing.
CRYPTO_set_dynlock_create_callback(Pointer<NativeFunction<Pointer<CRYPTO_dynlock_value> Function(Pointer<Char>, Int)>> dyn_create_function) → void
CRYPTO_set_dynlock_create_callback does nothing.
CRYPTO_set_dynlock_destroy_callback(Pointer<NativeFunction<Void Function(Pointer<CRYPTO_dynlock_value>, Pointer<Char>, Int)>> dyn_destroy_function) → void
CRYPTO_set_dynlock_destroy_callback does nothing.
CRYPTO_set_dynlock_lock_callback(Pointer<NativeFunction<Void Function(Int, Pointer<CRYPTO_dynlock_value>, Pointer<Char>, Int)>> dyn_lock_function) → void
CRYPTO_set_dynlock_lock_callback does nothing.
CRYPTO_set_id_callback(Pointer<NativeFunction<UnsignedLong Function()>> func) → void
CRYPTO_set_id_callback does nothing.
CRYPTO_set_locking_callback(Pointer<NativeFunction<Void Function(Int, Int, Pointer<Char>, Int)>> func) → void
CRYPTO_set_locking_callback does nothing.
CRYPTO_THREADID_current(Pointer<Int> id) → void
CRYPTO_THREADID_current does nothing.
CRYPTO_THREADID_set_callback(Pointer<NativeFunction<Void Function(Pointer<Int> threadid)>> threadid_func) → int
CRYPTO_THREADID_set_callback returns one.
CRYPTO_THREADID_set_numeric(Pointer<Int> id, int val) → void
CRYPTO_THREADID_set_numeric does nothing.
CRYPTO_THREADID_set_pointer(Pointer<Int> id, Pointer<Void> ptr) → void
CRYPTO_THREADID_set_pointer does nothing.
d2i_ASN1_BIT_STRING(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OCTET_STRING>
d2i_ASN1_BIT_STRING parses up to |len| bytes from |*inp| as a DER-encoded ASN.1 BIT STRING, as described in |d2i_SAMPLE|.
d2i_ASN1_BMPSTRING(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OCTET_STRING>
The following functions parse up to |len| bytes from |*inp| as a DER-encoded ASN.1 value of the corresponding type, as described in |d2i_SAMPLE|.
d2i_ASN1_BOOLEAN(Pointer<Int> out, Pointer<Pointer<UnsignedChar>> inp, int len) → int
d2i_ASN1_BOOLEAN parses a DER-encoded ASN.1 BOOLEAN from up to |len| bytes at |*inp|. On success, it advances |*inp| by the number of bytes read and returns the result. If |out| is non-NULL, it additionally writes the result to |*out|. On error, it returns |ASN1_BOOLEAN_NONE|.
d2i_ASN1_ENUMERATED(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OCTET_STRING>
d2i_ASN1_ENUMERATED parses up to |len| bytes from |*inp| as a DER-encoded ASN.1 ENUMERATED, as described in |d2i_SAMPLE|.
d2i_ASN1_GENERALIZEDTIME(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OCTET_STRING>
d2i_ASN1_GENERALIZEDTIME parses up to |len| bytes from |*inp| as a DER-encoded ASN.1 GeneralizedTime, as described in |d2i_SAMPLE|.
d2i_ASN1_GENERALSTRING(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OCTET_STRING>
d2i_ASN1_IA5STRING(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OCTET_STRING>
d2i_ASN1_INTEGER(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OCTET_STRING>
d2i_ASN1_INTEGER parses up to |len| bytes from |*inp| as a DER-encoded ASN.1 INTEGER, as described in |d2i_SAMPLE|.
d2i_ASN1_NULL(Pointer<Pointer<ASN1_NULL>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_NULL>
d2i_ASN1_NULL parses a DER-encoded ASN.1 NULL value from up to |len| bytes at |*inp|, as described in |d2i_SAMPLE|.
d2i_ASN1_OBJECT(Pointer<Pointer<ASN1_OBJECT>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OBJECT>
d2i_ASN1_OBJECT parses a DER-encoded ASN.1 OBJECT IDENTIFIER from up to |len| bytes at |*inp|, as described in |d2i_SAMPLE|.
d2i_ASN1_OCTET_STRING(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OCTET_STRING>
d2i_ASN1_PRINTABLESTRING(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OCTET_STRING>
d2i_ASN1_SEQUENCE_ANY(Pointer<Pointer<ASN1_SEQUENCE_ANY>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_SEQUENCE_ANY>
d2i_ASN1_SEQUENCE_ANY parses up to |len| bytes from |*inp| as a DER-encoded ASN.1 SEQUENCE OF ANY structure, as described in |d2i_SAMPLE|. The resulting |ASN1_SEQUENCE_ANY| owns its contents and thus must be released with |sk_ASN1_TYPE_pop_free| and |ASN1_TYPE_free|, not |sk_ASN1_TYPE_free|.
d2i_ASN1_SET_ANY(Pointer<Pointer<ASN1_SEQUENCE_ANY>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_SEQUENCE_ANY>
d2i_ASN1_SET_ANY parses up to |len| bytes from |*inp| as a DER-encoded ASN.1 SET OF ANY structure, as described in |d2i_SAMPLE|. The resulting |ASN1_SEQUENCE_ANY| owns its contents and thus must be released with |sk_ASN1_TYPE_pop_free| and |ASN1_TYPE_free|, not |sk_ASN1_TYPE_free|.
d2i_ASN1_T61STRING(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OCTET_STRING>
d2i_ASN1_TIME(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OCTET_STRING>
d2i_ASN1_TIME parses up to |len| bytes from |*inp| as a DER-encoded X.509 Time (RFC 5280), as described in |d2i_SAMPLE|.
d2i_ASN1_TYPE(Pointer<Pointer<ASN1_TYPE>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_TYPE>
d2i_ASN1_TYPE parses up to |len| bytes from |*inp| as an ASN.1 value of any type, as described in |d2i_SAMPLE|. Note this function only validates primitive, universal types supported by this library. Values of type |V_ASN1_SEQUENCE|, |V_ASN1_SET|, |V_ASN1_OTHER|, or an unsupported primitive type must be validated by the caller when interpreting.
d2i_ASN1_UNIVERSALSTRING(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OCTET_STRING>
d2i_ASN1_UTCTIME(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OCTET_STRING>
d2i_ASN1_UTCTIME parses up to |len| bytes from |*inp| as a DER-encoded ASN.1 UTCTime, as described in |d2i_SAMPLE|.
d2i_ASN1_UTF8STRING(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OCTET_STRING>
d2i_ASN1_VISIBLESTRING(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OCTET_STRING>
d2i_AUTHORITY_INFO_ACCESS(Pointer<Pointer<AUTHORITY_INFO_ACCESS>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<AUTHORITY_INFO_ACCESS>
d2i_AUTHORITY_INFO_ACCESS parses up to |len| bytes from |*inp| as a DER-encoded AuthorityInfoAccessSyntax (RFC 5280), as described in |d2i_SAMPLE|.
d2i_AUTHORITY_KEYID(Pointer<Pointer<AUTHORITY_KEYID>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<AUTHORITY_KEYID>
d2i_AUTHORITY_KEYID parses up to |len| bytes from |*inp| as a DER-encoded AuthorityKeyIdentifier (RFC 5280), as described in |d2i_SAMPLE|.
d2i_AutoPrivateKey(Pointer<Pointer<EVP_PKEY>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<EVP_PKEY>
d2i_AutoPrivateKey acts the same as |d2i_PrivateKey|, but detects the type of the private key.
d2i_BASIC_CONSTRAINTS(Pointer<Pointer<BASIC_CONSTRAINTS>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<BASIC_CONSTRAINTS>
d2i_BASIC_CONSTRAINTS parses up to |len| bytes from |*inp| as a DER-encoded BasicConstraints (RFC 5280), as described in |d2i_SAMPLE|.
d2i_CERTIFICATEPOLICIES(Pointer<Pointer<CERTIFICATEPOLICIES>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<CERTIFICATEPOLICIES>
d2i_CERTIFICATEPOLICIES parses up to |len| bytes from |*inp| as a DER-encoded CertificatePolicies (RFC 5280), as described in |d2i_SAMPLE|.
d2i_CRL_DIST_POINTS(Pointer<Pointer<CRL_DIST_POINTS>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<CRL_DIST_POINTS>
d2i_CRL_DIST_POINTS parses up to |len| bytes from |*inp| as a DER-encoded CRLDistributionPoints (RFC 5280), as described in |d2i_SAMPLE|.
d2i_DHparams(Pointer<Pointer<DH>> ret, Pointer<Pointer<UnsignedChar>> inp, int len) → Pointer<DH>
d2i_DHparams parses a DER-encoded DHParameter structure (PKCS #3) from |len| bytes at |*inp|, as in |d2i_SAMPLE|.
d2i_DHparams_bio(Pointer<BIO> bp, Pointer<Pointer<DH>> dh) → Pointer<DH>
d2i_DIRECTORYSTRING(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OCTET_STRING>
d2i_DIRECTORYSTRING parses up to |len| bytes from |*inp| as a DER-encoded X.509 DirectoryString (RFC 5280), as described in |d2i_SAMPLE|.
d2i_DISPLAYTEXT(Pointer<Pointer<ASN1_OCTET_STRING>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ASN1_OCTET_STRING>
d2i_DISPLAYTEXT parses up to |len| bytes from |*inp| as a DER-encoded X.509 DisplayText (RFC 5280), as described in |d2i_SAMPLE|.
d2i_DSA_PUBKEY(Pointer<Pointer<DSA>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<DSA>
d2i_DSA_PUBKEY parses a DSA public key as a DER-encoded SubjectPublicKeyInfo from |len| bytes at |*inp|, as described in |d2i_SAMPLE|. SubjectPublicKeyInfo structures containing other key types are rejected.
d2i_DSA_PUBKEY_bio(Pointer<BIO> bp, Pointer<Pointer<DSA>> dsa) → Pointer<DSA>
d2i_DSA_PUBKEY_fp(Pointer<FILE> fp, Pointer<Pointer<DSA>> dsa) → Pointer<DSA>
d2i_DSA_SIG(Pointer<Pointer<DSA_SIG>> out_sig, Pointer<Pointer<Uint8>> inp, int len) → Pointer<DSA_SIG>
d2i_DSA_SIG parses a DER-encoded DSA-Sig-Value structure from |len| bytes at |*inp|, as described in |d2i_SAMPLE|.
d2i_DSAparams(Pointer<Pointer<DSA>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<DSA>
d2i_DSAparams parses a DER-encoded Dss-Parms structure (RFC 3279) from |len| bytes at |*inp|, as described in |d2i_SAMPLE|.
d2i_DSAPrivateKey(Pointer<Pointer<DSA>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<DSA>
d2i_DSAPrivateKey parses a DER-encoded DSA private key from |len| bytes at |*inp|, as described in |d2i_SAMPLE|.
d2i_DSAPrivateKey_bio(Pointer<BIO> bp, Pointer<Pointer<DSA>> dsa) → Pointer<DSA>
d2i_DSAPrivateKey_fp(Pointer<FILE> fp, Pointer<Pointer<DSA>> dsa) → Pointer<DSA>
d2i_DSAPublicKey(Pointer<Pointer<DSA>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<DSA>
d2i_DSAPublicKey parses a DER-encoded DSA public key from |len| bytes at |*inp|, as described in |d2i_SAMPLE|.
d2i_EC_PUBKEY(Pointer<Pointer<EC_KEY>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<EC_KEY>
d2i_EC_PUBKEY parses an EC public key as a DER-encoded SubjectPublicKeyInfo from |len| bytes at |*inp|, as described in |d2i_SAMPLE|. SubjectPublicKeyInfo structures containing other key types are rejected.
d2i_EC_PUBKEY_bio(Pointer<BIO> bp, Pointer<Pointer<EC_KEY>> eckey) → Pointer<EC_KEY>
d2i_EC_PUBKEY_fp(Pointer<FILE> fp, Pointer<Pointer<EC_KEY>> eckey) → Pointer<EC_KEY>
d2i_ECDSA_SIG(Pointer<Pointer<ECDSA_SIG>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ECDSA_SIG>
d2i_ECDSA_SIG parses aa DER-encoded ECDSA-Sig-Value structure from |len| bytes at |*inp|, as described in |d2i_SAMPLE|.
d2i_ECParameters(Pointer<Pointer<EC_KEY>> out_key, Pointer<Pointer<Uint8>> inp, int len) → Pointer<EC_KEY>
d2i_ECParameters parses a DER-encoded ECParameters structure (RFC 5480) from |len| bytes at |*inp|, as described in |d2i_SAMPLE|. It returns the result as an |EC_KEY| with parameters, but no key, configured.
d2i_ECPKParameters(Pointer<Pointer<EC_GROUP>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<EC_GROUP>
d2i_ECPKParameters parses a DER-encoded ECParameters structure (RFC 5480) from |len| bytes at |*inp|, as described in |d2i_SAMPLE|. For legacy reasons, it recognizes the specifiedCurve form, but only for curves that are already supported as named curves.
d2i_ECPrivateKey(Pointer<Pointer<EC_KEY>> out_key, Pointer<Pointer<Uint8>> inp, int len) → Pointer<EC_KEY>
d2i_ECPrivateKey parses a DER-encoded ECPrivateKey structure (RFC 5915) from |len| bytes at |*inp|, as described in |d2i_SAMPLE|. On input, if |*out_key| is non-NULL and has a group configured, the parameters field may be omitted but must match that group if present.
d2i_ECPrivateKey_bio(Pointer<BIO> bp, Pointer<Pointer<EC_KEY>> eckey) → Pointer<EC_KEY>
d2i_ECPrivateKey_fp(Pointer<FILE> fp, Pointer<Pointer<EC_KEY>> eckey) → Pointer<EC_KEY>
d2i_EXTENDED_KEY_USAGE(Pointer<Pointer<EXTENDED_KEY_USAGE>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<EXTENDED_KEY_USAGE>
d2i_EXTENDED_KEY_USAGE parses up to |len| bytes from |*inp| as a DER-encoded ExtKeyUsageSyntax (RFC 5280), as described in |d2i_SAMPLE|.
d2i_GENERAL_NAME(Pointer<Pointer<GENERAL_NAME>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<GENERAL_NAME>
d2i_GENERAL_NAME parses up to |len| bytes from |*inp| as a DER-encoded X.509 GeneralName (RFC 5280), as described in |d2i_SAMPLE|.
d2i_GENERAL_NAMES(Pointer<Pointer<GENERAL_NAMES>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<GENERAL_NAMES>
d2i_GENERAL_NAMES parses up to |len| bytes from |*inp| as a DER-encoded SEQUENCE OF GeneralName, as described in |d2i_SAMPLE|.
d2i_ISSUING_DIST_POINT(Pointer<Pointer<ISSUING_DIST_POINT>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<ISSUING_DIST_POINT>
d2i_ISSUING_DIST_POINT parses up to |len| bytes from |*inp| as a DER-encoded IssuingDistributionPoint (RFC 5280), as described in |d2i_SAMPLE|.
d2i_NETSCAPE_SPKAC(Pointer<Pointer<NETSCAPE_SPKAC>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<NETSCAPE_SPKAC>
d2i_NETSCAPE_SPKAC parses up to |len| bytes from |*inp| as a DER-encoded PublicKeyAndChallenge structure, as described in |d2i_SAMPLE|.
d2i_NETSCAPE_SPKI(Pointer<Pointer<NETSCAPE_SPKI>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<NETSCAPE_SPKI>
d2i_NETSCAPE_SPKI parses up to |len| bytes from |*inp| as a DER-encoded SignedPublicKeyAndChallenge structure, as described in |d2i_SAMPLE|.
d2i_PKCS7(Pointer<Pointer<PKCS7>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<PKCS7>
d2i_PKCS7 parses a BER-encoded, PKCS#7 signed data ContentInfo structure from |len| bytes at |*inp|, as described in |d2i_SAMPLE|.
d2i_PKCS7_bio(Pointer<BIO> bio, Pointer<Pointer<PKCS7>> out) → Pointer<PKCS7>
d2i_PKCS7_bio behaves like |d2i_PKCS7| but reads the input from |bio|. If the length of the object is indefinite the full contents of |bio| are read.
d2i_PKCS8_bio(Pointer<BIO> bp, Pointer<Pointer<X509_SIG>> p8) → Pointer<X509_SIG>
d2i_PKCS8_fp(Pointer<FILE> fp, Pointer<Pointer<X509_SIG>> p8) → Pointer<X509_SIG>
d2i_PKCS8_PRIV_KEY_INFO(Pointer<Pointer<PKCS8_PRIV_KEY_INFO>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<PKCS8_PRIV_KEY_INFO>
d2i_PKCS8_PRIV_KEY_INFO parses up to |len| bytes from |*inp| as a DER-encoded PrivateKeyInfo, as described in |d2i_SAMPLE|.
d2i_PKCS8_PRIV_KEY_INFO_bio(Pointer<BIO> bp, Pointer<Pointer<PKCS8_PRIV_KEY_INFO>> p8inf) → Pointer<PKCS8_PRIV_KEY_INFO>
d2i_PKCS8_PRIV_KEY_INFO_fp(Pointer<FILE> fp, Pointer<Pointer<PKCS8_PRIV_KEY_INFO>> p8inf) → Pointer<PKCS8_PRIV_KEY_INFO>
d2i_PKCS8PrivateKey_bio(Pointer<BIO> bp, Pointer<Pointer<EVP_PKEY>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<EVP_PKEY>
d2i_PKCS8PrivateKey_fp(Pointer<FILE> fp, Pointer<Pointer<EVP_PKEY>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<EVP_PKEY>
d2i_PrivateKey(int type, Pointer<Pointer<EVP_PKEY>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<EVP_PKEY>
d2i_PrivateKey parses a DER-encoded private key from |len| bytes at |*inp|, as described in |d2i_SAMPLE|. The private key must have type |type|, otherwise it will be rejected.
d2i_PrivateKey_bio(Pointer<BIO> bp, Pointer<Pointer<EVP_PKEY>> a) → Pointer<EVP_PKEY>
d2i_PrivateKey_bio behaves like |d2i_AutoPrivateKey|, but reads from |bp| instead.
d2i_PrivateKey_fp(Pointer<FILE> fp, Pointer<Pointer<EVP_PKEY>> a) → Pointer<EVP_PKEY>
d2i_PUBKEY(Pointer<Pointer<EVP_PKEY>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<EVP_PKEY>
d2i_PUBKEY parses a DER-encoded SubjectPublicKeyInfo from |len| bytes at |*inp|, as described in |d2i_SAMPLE|.
d2i_PUBKEY_bio(Pointer<BIO> bp, Pointer<Pointer<EVP_PKEY>> a) → Pointer<EVP_PKEY>
d2i_PUBKEY_fp(Pointer<FILE> fp, Pointer<Pointer<EVP_PKEY>> a) → Pointer<EVP_PKEY>
d2i_PublicKey(int type, Pointer<Pointer<EVP_PKEY>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<EVP_PKEY>
d2i_PublicKey parses a public key from |len| bytes at |*inp| in a type- specific format specified by |type|, as described in |d2i_SAMPLE|.
d2i_RSA_PSS_PARAMS(Pointer<Pointer<RSA_PSS_PARAMS>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<RSA_PSS_PARAMS>
d2i_RSA_PSS_PARAMS parses up to |len| bytes from |*inp| as a DER-encoded RSASSA-PSS-params (RFC 4055), as described in |d2i_SAMPLE|.
d2i_RSA_PUBKEY(Pointer<Pointer<RSA>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<RSA>
d2i_RSA_PUBKEY parses an RSA public key as a DER-encoded SubjectPublicKeyInfo from |len| bytes at |*inp|, as described in |d2i_SAMPLE|. SubjectPublicKeyInfo structures containing other key types are rejected.
d2i_RSA_PUBKEY_bio(Pointer<BIO> bp, Pointer<Pointer<RSA>> rsa) → Pointer<RSA>
d2i_RSA_PUBKEY_fp(Pointer<FILE> fp, Pointer<Pointer<RSA>> rsa) → Pointer<RSA>
d2i_RSAPrivateKey(Pointer<Pointer<RSA>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<RSA>
d2i_RSAPrivateKey parses a DER-encoded RSAPrivateKey structure (RFC 8017) from |len| bytes at |*inp|, as described in |d2i_SAMPLE|.
d2i_RSAPrivateKey_bio(Pointer<BIO> bp, Pointer<Pointer<RSA>> rsa) → Pointer<RSA>
d2i_RSAPrivateKey_fp(Pointer<FILE> fp, Pointer<Pointer<RSA>> rsa) → Pointer<RSA>
d2i_RSAPublicKey(Pointer<Pointer<RSA>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<RSA>
d2i_RSAPublicKey parses a DER-encoded RSAPublicKey structure (RFC 8017) from |len| bytes at |*inp|, as described in |d2i_SAMPLE|.
d2i_RSAPublicKey_bio(Pointer<BIO> bp, Pointer<Pointer<RSA>> rsa) → Pointer<RSA>
d2i_RSAPublicKey_fp(Pointer<FILE> fp, Pointer<Pointer<RSA>> rsa) → Pointer<RSA>
d2i_X509(Pointer<Pointer<X509>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<X509>
d2i_X509 parses up to |len| bytes from |*inp| as a DER-encoded X.509 Certificate (RFC 5280), as described in |d2i_SAMPLE|.
d2i_X509_ALGOR(Pointer<Pointer<X509_ALGOR>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<X509_ALGOR>
d2i_X509_ALGOR parses up to |len| bytes from |*inp| as a DER-encoded AlgorithmIdentifier, as described in |d2i_SAMPLE|.
d2i_X509_ATTRIBUTE(Pointer<Pointer<X509_ATTRIBUTE>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<X509_ATTRIBUTE>
d2i_X509_ATTRIBUTE parses up to |len| bytes from |*inp| as a DER-encoded Attribute (RFC 2986), as described in |d2i_SAMPLE|.
d2i_X509_AUX(Pointer<Pointer<X509>> x509, Pointer<Pointer<Uint8>> inp, int length) → Pointer<X509>
d2i_X509_AUX parses up to |length| bytes from |*inp| as a DER-encoded X.509 Certificate (RFC 5280), followed optionally by a separate, OpenSSL-specific structure with auxiliary properties. It behaves as described in |d2i_SAMPLE|.
d2i_X509_bio(Pointer<BIO> bp, Pointer<Pointer<X509>> x509) → Pointer<X509>
The following functions behave like the corresponding unsuffixed |d2i_| functions, but read the result from |bp| instead. Callers using these functions with memory |BIO|s to parse structures already in memory should use |d2i_| instead.
d2i_X509_CRL(Pointer<Pointer<X509_CRL>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<X509_CRL>
d2i_X509_CRL parses up to |len| bytes from |*inp| as a DER-encoded X.509 CertificateList (RFC 5280), as described in |d2i_SAMPLE|.
d2i_X509_CRL_bio(Pointer<BIO> bp, Pointer<Pointer<X509_CRL>> crl) → Pointer<X509_CRL>
d2i_X509_CRL_fp(Pointer<FILE> fp, Pointer<Pointer<X509_CRL>> crl) → Pointer<X509_CRL>
d2i_X509_EXTENSION(Pointer<Pointer<X509_EXTENSION>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<X509_EXTENSION>
d2i_X509_EXTENSION parses up to |len| bytes from |*inp| as a DER-encoded X.509 Extension (RFC 5280), as described in |d2i_SAMPLE|.
d2i_X509_EXTENSIONS(Pointer<Pointer<X509_EXTENSIONS>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<X509_EXTENSIONS>
d2i_X509_EXTENSIONS parses up to |len| bytes from |*inp| as a DER-encoded SEQUENCE OF Extension (RFC 5280), as described in |d2i_SAMPLE|.
d2i_X509_fp(Pointer<FILE> fp, Pointer<Pointer<X509>> x509) → Pointer<X509>
The following functions behave like the corresponding |d2i_*_bio| functions, but read from |fp| instead.
d2i_X509_NAME(Pointer<Pointer<X509_NAME>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<X509_NAME>
d2i_X509_NAME parses up to |len| bytes from |*inp| as a DER-encoded X.509 Name (RFC 5280), as described in |d2i_SAMPLE|.
d2i_X509_PUBKEY(Pointer<Pointer<X509_PUBKEY>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<X509_PUBKEY>
d2i_X509_PUBKEY parses up to |len| bytes from |*inp| as a DER-encoded SubjectPublicKeyInfo, as described in |d2i_SAMPLE|.
d2i_X509_REQ(Pointer<Pointer<X509_REQ>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<X509_REQ>
d2i_X509_REQ parses up to |len| bytes from |*inp| as a DER-encoded CertificateRequest (RFC 2986), as described in |d2i_SAMPLE|.
d2i_X509_REQ_bio(Pointer<BIO> bp, Pointer<Pointer<X509_REQ>> req) → Pointer<X509_REQ>
d2i_X509_REQ_fp(Pointer<FILE> fp, Pointer<Pointer<X509_REQ>> req) → Pointer<X509_REQ>
d2i_X509_REVOKED(Pointer<Pointer<X509_REVOKED>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<X509_REVOKED>
d2i_X509_REVOKED parses up to |len| bytes from |*inp| as a DER-encoded X.509 CRL entry, as described in |d2i_SAMPLE|.
d2i_X509_SIG(Pointer<Pointer<X509_SIG>> out, Pointer<Pointer<Uint8>> inp, int len) → Pointer<X509_SIG>
d2i_X509_SIG parses up to |len| bytes from |*inp| as a DER-encoded algorithm and octet string pair, as described in |d2i_SAMPLE|.
DH_bits(Pointer<DH> dh) → int
DH_bits returns the size of |dh|'s group modulus, in bits.
DH_check(Pointer<DH> dh, Pointer<Int> out_flags) → int
DH_check checks the suitability of |dh| as a Diffie-Hellman group. and sets |DH_CHECK_*| flags in |*out_flags| if it finds any errors. It returns one if |*out_flags| was successfully set and zero on error.
DH_check_pub_key(Pointer<DH> dh, Pointer<BIGNUM> pub_key, Pointer<Int> out_flags) → int
DH_check_pub_key checks the suitability of |pub_key| as a public key for the DH group in |dh| and sets |DH_CHECK_PUBKEY_*| flags in |*out_flags| if it finds any errors. It returns one if |*out_flags| was successfully set and zero on error.
DH_compute_key(Pointer<Uint8> out, Pointer<BIGNUM> peers_key, Pointer<DH> dh) → int
DH_compute_key behaves like |DH_compute_key_padded| but, contrary to PKCS #3, returns a variable-length shared key with leading zeros. It returns the number of bytes written, or a negative number on error. |out| must have |DH_size| bytes of space.
DH_compute_key_hashed(Pointer<DH> dh, Pointer<Uint8> out, Pointer<Size> out_len, int max_out_len, Pointer<BIGNUM> peers_key, Pointer<EVP_MD> digest) → int
DH_compute_key_hashed calculates the shared key between |dh| and |peers_key| and hashes it with the given |digest|. If the hash output is less than |max_out_len| bytes then it writes the hash output to |out| and sets |*out_len| to the number of bytes written. Otherwise it signals an error. It returns one on success or zero on error.
DH_compute_key_padded(Pointer<Uint8> out, Pointer<BIGNUM> peers_key, Pointer<DH> dh) → int
DH_compute_key_padded calculates the shared key between |dh| and |peers_key| and writes it as a big-endian integer into |out|, padded up to |DH_size| bytes. It returns the number of bytes written, which is always |DH_size|, or a negative number on error. |out| must have |DH_size| bytes of space.
DH_free(Pointer<DH> dh) → void
DH_free decrements the reference count of |dh| and frees it if the reference count drops to zero.
DH_generate_key(Pointer<DH> dh) → int
DH_generate_key generates a new, random, private key and stores it in |dh|, if |dh| does not already have a private key. Otherwise, it updates |dh|'s public key to match the private key. It returns one on success and zero on error.
DH_generate_parameters_ex(Pointer<DH> dh, int prime_bits, int generator, Pointer<BN_GENCB> cb) → int
DH_generate_parameters_ex generates a suitable Diffie-Hellman group with a prime that is |prime_bits| long and stores it in |dh|. The generator of the group will be |generator|, which should be |DH_GENERATOR_2| unless there's a good reason to use a different value. The |cb| argument contains a callback function that will be called during the generation. See the documentation in |bn.h| about this. In addition to the callback invocations from |BN|, |cb| will also be called with |event| equal to three when the generation is complete.
DH_get0_g(Pointer<DH> dh) → Pointer<BIGNUM>
DH_get0_g returns |dh|'s group generator.
DH_get0_key(Pointer<DH> dh, Pointer<Pointer<BIGNUM>> out_pub_key, Pointer<Pointer<BIGNUM>> out_priv_key) → void
DH_get0_key sets |*out_pub_key| and |*out_priv_key|, if non-NULL, to |dh|'s public and private key, respectively. If |dh| is a public key, the private key will be set to NULL.
DH_get0_p(Pointer<DH> dh) → Pointer<BIGNUM>
DH_get0_p returns |dh|'s group modulus.
DH_get0_pqg(Pointer<DH> dh, Pointer<Pointer<BIGNUM>> out_p, Pointer<Pointer<BIGNUM>> out_q, Pointer<Pointer<BIGNUM>> out_g) → void
DH_get0_pqg sets |*out_p|, |*out_q|, and |*out_g|, if non-NULL, to |dh|'s p, q, and g parameters, respectively.
DH_get0_priv_key(Pointer<DH> dh) → Pointer<BIGNUM>
DH_get0_priv_key returns |dh|'s private key, or NULL if |dh| is a public key.
DH_get0_pub_key(Pointer<DH> dh) → Pointer<BIGNUM>
DH_get0_pub_key returns |dh|'s public key.
DH_get0_q(Pointer<DH> dh) → Pointer<BIGNUM>
DH_get0_q returns the size of |dh|'s subgroup, or NULL if it is unset.
DH_get_rfc7919_2048() → Pointer<DH>
DH_get_rfc7919_2048 returns the group ffdhe2048 from https://tools.ietf.org/html/rfc7919#appendix-A.1. It returns NULL if out of memory.
DH_marshal_parameters(Pointer<CBB> cbb, Pointer<DH> dh) → int
DH_marshal_parameters marshals |dh| as a DER-encoded DHParameter structure (PKCS #3) and appends the result to |cbb|. It returns one on success and zero on error.
DH_new() → Pointer<DH>
DH_new returns a new, empty DH object or NULL on error.
DH_parse_parameters(Pointer<CBS> cbs) → Pointer<DH>
DH_parse_parameters decodes a DER-encoded DHParameter structure (PKCS #3) from |cbs| and advances |cbs|. It returns a newly-allocated |DH| or NULL on error.
DH_set0_key(Pointer<DH> dh, Pointer<BIGNUM> pub_key, Pointer<BIGNUM> priv_key) → int
DH_set0_key sets |dh|'s public and private key to the specified values. If NULL, the field is left unchanged. On success, it takes ownership of each argument and returns one. Otherwise, it returns zero.
DH_set0_pqg(Pointer<DH> dh, Pointer<BIGNUM> p, Pointer<BIGNUM> q, Pointer<BIGNUM> g) → int
DH_set0_pqg sets |dh|'s p, q, and g parameters to the specified values. If NULL, the field is left unchanged. On success, it takes ownership of each argument and returns one. Otherwise, it returns zero. |q| may be NULL, but |p| and |g| must either be specified or already configured on |dh|.
DH_set_length(Pointer<DH> dh, int priv_length) → int
DH_set_length sets the number of bits to use for the secret exponent when calling |DH_generate_key| on |dh| and returns one. If unset, |DH_generate_key| will use the bit length of p.
DH_size(Pointer<DH> dh) → int
DH_size returns the number of bytes in the DH group's prime.
DH_up_ref(Pointer<DH> dh) → int
DH_up_ref increments the reference count of |dh| and returns one. It does not mutate |dh| for thread-safety purposes and may be used concurrently.
DHparams_dup(Pointer<DH> dh) → Pointer<DH>
DHparams_dup allocates a fresh |DH| and copies the parameters from |dh| into it. It returns the new |DH| or NULL on error.
DIRECTORYSTRING_free(Pointer<ASN1_OCTET_STRING> str) → void
DIRECTORYSTRING_free calls |ASN1_STRING_free|.
DIRECTORYSTRING_new() → Pointer<ASN1_OCTET_STRING>
DIRECTORYSTRING_new returns a newly-allocated |ASN1_STRING| with type -1, or NULL on error. The resulting |ASN1_STRING| is not a valid X.509 DirectoryString until initialized with a value.
DISPLAYTEXT_free(Pointer<ASN1_OCTET_STRING> str) → void
DISPLAYTEXT_free calls |ASN1_STRING_free|.
DISPLAYTEXT_new() → Pointer<ASN1_OCTET_STRING>
DISPLAYTEXT_new returns a newly-allocated |ASN1_STRING| with type -1, or NULL on error. The resulting |ASN1_STRING| is not a valid X.509 DisplayText until initialized with a value.
DIST_POINT_free(Pointer<DIST_POINT> dp) → void
DIST_POINT_free releases memory associated with |dp|.
DIST_POINT_NAME_free(Pointer<DIST_POINT_NAME> name) → void
DIST_POINT_NAME_free releases memory associated with |name|.
DIST_POINT_NAME_new() → Pointer<DIST_POINT_NAME>
DIST_POINT_NAME_new returns a newly-allocated, empty |DIST_POINT_NAME| object, or NULL on error.
DIST_POINT_new() → Pointer<DIST_POINT>
DIST_POINT_new returns a newly-allocated, empty |DIST_POINT| object, or NULL on error.
DSA_bits(Pointer<DSA> dsa) → int
DSA_bits returns the size of |dsa|'s group modulus, in bits.
DSA_check_signature(Pointer<Int> out_valid, Pointer<Uint8> digest, int digest_len, Pointer<Uint8> sig, int sig_len, Pointer<DSA> dsa) → int
DSA_check_signature sets |*out_valid| to zero. Then it verifies that |sig| is a valid, ASN.1 signature, by the public key in |dsa|, of the hash in |digest|. If so, it sets |*out_valid| to one.
DSA_do_check_signature(Pointer<Int> out_valid, Pointer<Uint8> digest, int digest_len, Pointer<DSA_SIG> sig, Pointer<DSA> dsa) → int
DSA_do_check_signature sets |*out_valid| to zero. Then it verifies that |sig| is a valid signature, by the public key in |dsa| of the hash in |digest| and, if so, it sets |*out_valid| to one.
DSA_do_sign(Pointer<Uint8> digest, int digest_len, Pointer<DSA> dsa) → Pointer<DSA_SIG>
DSA_do_sign returns a signature of the hash in |digest| by the key in |dsa| and returns an allocated, DSA_SIG structure, or NULL on error.
DSA_do_verify(Pointer<Uint8> digest, int digest_len, Pointer<DSA_SIG> sig, Pointer<DSA> dsa) → int
DSA_do_verify verifies that |sig| is a valid signature, by the public key in |dsa|, of the hash in |digest|. It returns one if so, zero if invalid and -1 on error.
DSA_dup_DH(Pointer<DSA> dsa) → Pointer<DH>
DSA_dup_DH returns a |DH| constructed from the parameters of |dsa|. This is sometimes needed when Diffie-Hellman parameters are stored in the form of DSA parameters. It returns an allocated |DH| on success or NULL on error.
DSA_free(Pointer<DSA> dsa) → void
DSA_free decrements the reference count of |dsa| and frees it if the reference count drops to zero.
DSA_generate_key(Pointer<DSA> dsa) → int
DSA_generate_key generates a public/private key pair in |dsa|, which must already have parameters setup. It returns one on success and zero on error.
DSA_generate_parameters_ex(Pointer<DSA> dsa, int bits, Pointer<Uint8> seed, int seed_len, Pointer<Int> out_counter, Pointer<UnsignedLong> out_h, Pointer<BN_GENCB> cb) → int
DSA_generate_parameters_ex generates a set of DSA parameters by following the procedure given in FIPS 186-4, appendix A. (http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf)
DSA_get0_g(Pointer<DSA> dsa) → Pointer<BIGNUM>
DSA_get0_g returns |dsa|'s group generator.
DSA_get0_key(Pointer<DSA> dsa, Pointer<Pointer<BIGNUM>> out_pub_key, Pointer<Pointer<BIGNUM>> out_priv_key) → void
DSA_get0_key sets |*out_pub_key| and |*out_priv_key|, if non-NULL, to |dsa|'s public and private key, respectively. If |dsa| is a public key, the private key will be set to NULL.
DSA_get0_p(Pointer<DSA> dsa) → Pointer<BIGNUM>
DSA_get0_p returns |dsa|'s group modulus.
DSA_get0_pqg(Pointer<DSA> dsa, Pointer<Pointer<BIGNUM>> out_p, Pointer<Pointer<BIGNUM>> out_q, Pointer<Pointer<BIGNUM>> out_g) → void
DSA_get0_pqg sets |*out_p|, |*out_q|, and |*out_g|, if non-NULL, to |dsa|'s p, q, and g parameters, respectively.
DSA_get0_priv_key(Pointer<DSA> dsa) → Pointer<BIGNUM>
DSA_get0_priv_key returns |dsa|'s private key, or NULL if |dsa| is a public key.
DSA_get0_pub_key(Pointer<DSA> dsa) → Pointer<BIGNUM>
DSA_get0_pub_key returns |dsa|'s public key.
DSA_get0_q(Pointer<DSA> dsa) → Pointer<BIGNUM>
DSA_get0_q returns the size of |dsa|'s subgroup.
DSA_get_ex_data(Pointer<DSA> dsa, int idx) → Pointer<Void>
DSA_get_ex_new_index(int argl, Pointer<Void> argp, Pointer<Int> unused, Pointer<CRYPTO_EX_dup> dup_unused, Pointer<CRYPTO_EX_free> free_func) → int
ex_data functions.
DSA_marshal_parameters(Pointer<CBB> cbb, Pointer<DSA> dsa) → int
DSA_marshal_parameters marshals |dsa| as a DER-encoded Dss-Parms structure (RFC 3279) and appends the result to |cbb|. It returns one on success and zero on failure.
DSA_marshal_private_key(Pointer<CBB> cbb, Pointer<DSA> dsa) → int
DSA_marshal_private_key marshals |dsa| as a DER-encoded DSA private key and appends the result to |cbb|. It returns one on success and zero on failure.
DSA_marshal_public_key(Pointer<CBB> cbb, Pointer<DSA> dsa) → int
DSA_marshal_public_key marshals |dsa| as a DER-encoded DSA public key and appends the result to |cbb|. It returns one on success and zero on failure.
DSA_new() → Pointer<DSA>
DSA_new returns a new, empty DSA object or NULL on error.
DSA_parse_parameters(Pointer<CBS> cbs) → Pointer<DSA>
DSA_parse_parameters parses a DER-encoded Dss-Parms structure (RFC 3279) from |cbs| and advances |cbs|. It returns a newly-allocated |DSA| or NULL on error.
DSA_parse_private_key(Pointer<CBS> cbs) → Pointer<DSA>
DSA_parse_private_key parses a DER-encoded DSA private key from |cbs| and advances |cbs|. It returns a newly-allocated |DSA| or NULL on error.
DSA_parse_public_key(Pointer<CBS> cbs) → Pointer<DSA>
DSA_parse_public_key parses a DER-encoded DSA public key from |cbs| and advances |cbs|. It returns a newly-allocated |DSA| or NULL on error.
DSA_set0_key(Pointer<DSA> dsa, Pointer<BIGNUM> pub_key, Pointer<BIGNUM> priv_key) → int
DSA_set0_key sets |dsa|'s public and private key to |pub_key| and |priv_key|, respectively, if non-NULL. On success, it takes ownership of each argument and returns one. Otherwise, it returns zero.
DSA_set0_pqg(Pointer<DSA> dsa, Pointer<BIGNUM> p, Pointer<BIGNUM> q, Pointer<BIGNUM> g) → int
DSA_set0_pqg sets |dsa|'s parameters to |p|, |q|, and |g|, if non-NULL, and takes ownership of them. On success, it takes ownership of each argument and returns one. Otherwise, it returns zero.
DSA_set_ex_data(Pointer<DSA> dsa, int idx, Pointer<Void> arg) → int
DSA_SIG_free(Pointer<DSA_SIG> sig) → void
DSA_SIG_free frees the contents of |sig| and then frees |sig| itself.
DSA_SIG_get0(Pointer<DSA_SIG> sig, Pointer<Pointer<BIGNUM>> out_r, Pointer<Pointer<BIGNUM>> out_s) → void
DSA_SIG_get0 sets |*out_r| and |*out_s|, if non-NULL, to the two components of |sig|.
DSA_SIG_marshal(Pointer<CBB> cbb, Pointer<DSA_SIG> sig) → int
DSA_SIG_marshal marshals |sig| as a DER-encoded DSA-Sig-Value and appends the result to |cbb|. It returns one on success and zero on error.
DSA_SIG_new() → Pointer<DSA_SIG>
DSA_SIG_new returns a freshly allocated, DIG_SIG structure or NULL on error. Both |r| and |s| in the signature will be NULL.
DSA_SIG_parse(Pointer<CBS> cbs) → Pointer<DSA_SIG>
DSA_SIG_parse parses a DER-encoded DSA-Sig-Value structure from |cbs| and advances |cbs|. It returns a newly-allocated |DSA_SIG| or NULL on error.
DSA_SIG_set0(Pointer<DSA_SIG> sig, Pointer<BIGNUM> r, Pointer<BIGNUM> s) → int
DSA_SIG_set0 sets |sig|'s components to |r| and |s|, neither of which may be NULL. On success, it takes ownership of each argument and returns one. Otherwise, it returns zero.
DSA_sign(int type, Pointer<Uint8> digest, int digest_len, Pointer<Uint8> out_sig, Pointer<UnsignedInt> out_siglen, Pointer<DSA> dsa) → int
DSA_sign signs |digest| with the key in |dsa| and writes the resulting signature, in ASN.1 form, to |out_sig| and the length of the signature to |*out_siglen|. There must be, at least, |DSA_size(dsa)| bytes of space in |out_sig|. It returns one on success and zero otherwise.
DSA_size(Pointer<DSA> dsa) → int
DSA_size returns the size, in bytes, of an ASN.1 encoded, DSA signature generated by |dsa|. Parameters must already have been setup in |dsa|.
DSA_up_ref(Pointer<DSA> dsa) → int
DSA_up_ref increments the reference count of |dsa| and returns one. It does not mutate |dsa| for thread-safety purposes and may be used concurrently.
DSA_verify(int type, Pointer<Uint8> digest, int digest_len, Pointer<Uint8> sig, int sig_len, Pointer<DSA> dsa) → int
DSA_verify verifies that |sig| is a valid, ASN.1 signature, by the public key in |dsa|, of the hash in |digest|. It returns one if so, zero if invalid and -1 on error.
DSAparams_dup(Pointer<DSA> dsa) → Pointer<DSA>
DSAparams_dup returns a freshly allocated |DSA| that contains a copy of the parameters from |dsa|. It returns NULL on error.
EC_curve_nid2nist(int nid) → Pointer<Char>
EC_curve_nid2nist returns the NIST name of the elliptic curve specified by |nid|, or NULL if |nid| is not a NIST curve. For example, it returns "P-256" for |NID_X9_62_prime256v1|.
EC_curve_nist2nid(Pointer<Char> name) → int
EC_curve_nist2nid returns the NID of the elliptic curve specified by the NIST name |name|, or |NID_undef| if |name| is not a recognized name. For example, it returns |NID_X9_62_prime256v1| for "P-256".
EC_encode_to_curve_p256_xmd_sha256_sswu(Pointer<EC_GROUP> group, Pointer<EC_POINT> out, Pointer<Uint8> dst, int dst_len, Pointer<Uint8> msg, int msg_len) → int
EC_encode_to_curve_p256_xmd_sha256_sswu hashes |msg| to a point on |group| and writes the result to |out|, implementing the P256_XMD:SHA-256_SSWU_NU_ suite from RFC 9380. It returns one on success and zero on error.
EC_encode_to_curve_p384_xmd_sha384_sswu(Pointer<EC_GROUP> group, Pointer<EC_POINT> out, Pointer<Uint8> dst, int dst_len, Pointer<Uint8> msg, int msg_len) → int
EC_encode_to_curve_p384_xmd_sha384_sswu hashes |msg| to a point on |group| and writes the result to |out|, implementing the P384_XMD:SHA-384_SSWU_NU_ suite from RFC 9380. It returns one on success and zero on error.
EC_get_builtin_curves(Pointer<EC_builtin_curve> out_curves, int max_num_curves) → int
EC_get_builtin_curves writes at most |max_num_curves| elements to |out_curves| and returns the total number that it would have written, had |max_num_curves| been large enough.
EC_GROUP_cmp(Pointer<EC_GROUP> a, Pointer<EC_GROUP> b, Pointer<BN_CTX> ignored) → int
EC_GROUP_cmp returns zero if |a| and |b| are the same group and non-zero otherwise.
EC_GROUP_dup(Pointer<EC_GROUP> group) → Pointer<EC_GROUP>
EC_GROUP_dup increments |group|'s reference count and returns it, if |group| was created by |EC_GROUP_new_curve_GFp|. If |group| is static, it simply returns |group|.
EC_GROUP_free(Pointer<EC_GROUP> group) → void
EC_GROUP_free releases a reference to |group|, if |group| was created by |EC_GROUP_new_curve_GFp|. If |group| is static, it does nothing.
EC_GROUP_get0_generator(Pointer<EC_GROUP> group) → Pointer<EC_POINT>
EC_GROUP_get0_generator returns a pointer to the internal |EC_POINT| object in |group| that specifies the generator for the group.
EC_GROUP_get0_order(Pointer<EC_GROUP> group) → Pointer<BIGNUM>
EC_GROUP_get0_order returns a pointer to the internal |BIGNUM| object in |group| that specifies the order of the group.
EC_GROUP_get_asn1_flag(Pointer<EC_GROUP> group) → int
EC_GROUP_get_asn1_flag returns |OPENSSL_EC_NAMED_CURVE|.
EC_GROUP_get_cofactor(Pointer<EC_GROUP> group, Pointer<BIGNUM> cofactor, Pointer<BN_CTX> ctx) → int
EC_GROUP_get_cofactor sets |*cofactor| to the cofactor of |group|. It returns one on success and zero otherwise. |ctx| is ignored and may be NULL.
EC_GROUP_get_curve_GFp(Pointer<EC_GROUP> group, Pointer<BIGNUM> out_p, Pointer<BIGNUM> out_a, Pointer<BIGNUM> out_b, Pointer<BN_CTX> ctx) → int
EC_GROUP_get_curve_GFp gets various parameters about a group. It sets |*out_p| to the order of the coordinate field and |*out_a| and |*out_b| to the parameters of the curve when expressed as y² = x³ + ax + b. Any of the output parameters can be NULL. It returns one on success and zero on error. |ctx| is ignored and may be NULL.
EC_GROUP_get_curve_name(Pointer<EC_GROUP> group) → int
EC_GROUP_get_curve_name returns a NID that identifies |group|.
EC_GROUP_get_degree(Pointer<EC_GROUP> group) → int
EC_GROUP_get_degree returns the number of bits needed to represent an element of the field underlying |group|.
EC_GROUP_get_order(Pointer<EC_GROUP> group, Pointer<BIGNUM> order, Pointer<BN_CTX> ctx) → int
EC_GROUP_get_order sets |*order| to the order of |group|, if it's not NULL. It returns one on success and zero otherwise. |ctx| is ignored and may be NULL. Use |EC_GROUP_get0_order| instead.
EC_GROUP_method_of(Pointer<EC_GROUP> group) → Pointer<EC_METHOD>
EC_GROUP_method_of returns a dummy non-NULL pointer.
EC_GROUP_new_by_curve_name(int nid) → Pointer<EC_GROUP>
EC_GROUP_new_by_curve_name returns the |EC_GROUP| object for the elliptic curve specified by |nid|, or NULL on unsupported NID. For OpenSSL compatibility, this function returns a non-const pointer which may be passed to |EC_GROUP_free|. However, the resulting object is actually static and calling |EC_GROUP_free| is optional.
EC_GROUP_new_curve_GFp(Pointer<BIGNUM> p, Pointer<BIGNUM> a, Pointer<BIGNUM> b, Pointer<BN_CTX> ctx) → Pointer<EC_GROUP>
EC_GROUP_new_curve_GFp creates a new, arbitrary elliptic curve group based on the equation y² = x³ + a·x + b. It returns the new group or NULL on error. The lifetime of the resulting object must be managed with |EC_GROUP_dup| and |EC_GROUP_free|.
EC_GROUP_order_bits(Pointer<EC_GROUP> group) → int
EC_GROUP_order_bits returns the number of bits of the order of |group|.
EC_group_p224() → Pointer<EC_GROUP>
EC_group_p224 returns an |EC_GROUP| for P-224, also known as secp224r1.
EC_group_p256() → Pointer<EC_GROUP>
EC_group_p256 returns an |EC_GROUP| for P-256, also known as secp256r1 or prime256v1.
EC_group_p384() → Pointer<EC_GROUP>
EC_group_p384 returns an |EC_GROUP| for P-384, also known as secp384r1.
EC_group_p521() → Pointer<EC_GROUP>
EC_group_p521 returns an |EC_GROUP| for P-521, also known as secp521r1.
EC_GROUP_set_asn1_flag(Pointer<EC_GROUP> group, int flag) → void
EC_GROUP_set_asn1_flag does nothing.
EC_GROUP_set_generator(Pointer<EC_GROUP> group, Pointer<EC_POINT> generator, Pointer<BIGNUM> order, Pointer<BIGNUM> cofactor) → int
EC_GROUP_set_generator sets the generator for |group| to |generator|, which must have the given order and cofactor. It may only be used with |EC_GROUP| objects returned by |EC_GROUP_new_curve_GFp| and may only be used once on each group. |generator| must have been created using |group|.
EC_GROUP_set_point_conversion_form(Pointer<EC_GROUP> group, int form) → void
EC_GROUP_set_point_conversion_form aborts the process if |form| is not |POINT_CONVERSION_UNCOMPRESSED| and otherwise does nothing.
EC_hash_to_curve_p256_xmd_sha256_sswu(Pointer<EC_GROUP> group, Pointer<EC_POINT> out, Pointer<Uint8> dst, int dst_len, Pointer<Uint8> msg, int msg_len) → int
EC_hash_to_curve_p256_xmd_sha256_sswu hashes |msg| to a point on |group| and writes the result to |out|, implementing the P256_XMD:SHA-256_SSWU_RO_ suite from RFC 9380. It returns one on success and zero on error.
EC_hash_to_curve_p384_xmd_sha384_sswu(Pointer<EC_GROUP> group, Pointer<EC_POINT> out, Pointer<Uint8> dst, int dst_len, Pointer<Uint8> msg, int msg_len) → int
EC_hash_to_curve_p384_xmd_sha384_sswu hashes |msg| to a point on |group| and writes the result to |out|, implementing the P384_XMD:SHA-384_SSWU_RO_ suite from RFC 9380. It returns one on success and zero on error.
EC_KEY_check_fips(Pointer<EC_KEY> key) → int
EC_KEY_check_fips performs both a signing pairwise consistency test (FIPS 140-2 4.9.2) and the consistency test from SP 800-56Ar3 section 5.6.2.1.4. It returns one if it passes and zero otherwise.
EC_KEY_check_key(Pointer<EC_KEY> key) → int
EC_KEY_check_key performs several checks on |key| (possibly including an expensive check that the public key is in the primary subgroup). It returns one if all checks pass and zero otherwise. If it returns zero then detail about the problem can be found on the error stack.
EC_KEY_derive_from_secret(Pointer<EC_GROUP> group, Pointer<Uint8> secret, int secret_len) → Pointer<EC_KEY>
EC_KEY_derive_from_secret deterministically derives a private key for |group| from an input secret using HKDF-SHA256. It returns a newly-allocated |EC_KEY| on success or NULL on error. |secret| must not be used in any other algorithm. If using a base secret for multiple operations, derive separate values with a KDF such as HKDF first.
EC_KEY_dup(Pointer<EC_KEY> src) → Pointer<EC_KEY>
EC_KEY_dup returns a fresh copy of |src| or NULL on error.
EC_KEY_free(Pointer<EC_KEY> key) → void
EC_KEY_free frees all the data owned by |key| and |key| itself.
EC_KEY_generate_key(Pointer<EC_KEY> key) → int
EC_KEY_generate_key generates a random, private key, calculates the corresponding public key and stores both in |key|. It returns one on success or zero otherwise.
EC_KEY_generate_key_fips(Pointer<EC_KEY> key) → int
EC_KEY_generate_key_fips behaves like |EC_KEY_generate_key| but performs additional checks for FIPS compliance. This function is applicable when generating keys for either signing/verification or key agreement because both types of consistency check (PCT) are performed.
EC_KEY_get0_group(Pointer<EC_KEY> key) → Pointer<EC_GROUP>
EC_KEY_get0_group returns a pointer to the |EC_GROUP| object inside |key|.
EC_KEY_get0_private_key(Pointer<EC_KEY> key) → Pointer<BIGNUM>
EC_KEY_get0_private_key returns a pointer to the private key inside |key|.
EC_KEY_get0_public_key(Pointer<EC_KEY> key) → Pointer<EC_POINT>
EC_KEY_get0_public_key returns a pointer to the public key point inside |key|.
EC_KEY_get_conv_form(Pointer<EC_KEY> key) → int
EC_KEY_get_conv_form returns the conversation form that will be used by |key|.
EC_KEY_get_enc_flags(Pointer<EC_KEY> key) → int
EC_KEY_get_enc_flags returns the encoding flags for |key|, which is a bitwise-OR of |EC_PKEY_*| values.
EC_KEY_get_ex_data(Pointer<EC_KEY> r, int idx) → Pointer<Void>
EC_KEY_get_ex_new_index(int argl, Pointer<Void> argp, Pointer<Int> unused, Pointer<CRYPTO_EX_dup> dup_unused, Pointer<CRYPTO_EX_free> free_func) → int
ex_data functions.
EC_KEY_is_opaque(Pointer<EC_KEY> key) → int
EC_KEY_is_opaque returns one if |key| is opaque and doesn't expose its key material. Otherwise it return zero.
EC_KEY_key2buf(Pointer<EC_KEY> key, int form, Pointer<Pointer<Uint8>> out_buf, Pointer<BN_CTX> ctx) → int
EC_KEY_key2buf behaves like |EC_POINT_point2buf|, except it encodes the public key in |key|. |ctx| is ignored and may be NULL.
EC_KEY_marshal_curve_name(Pointer<CBB> cbb, Pointer<EC_GROUP> group) → int
EC_KEY_marshal_curve_name marshals |group| as a DER-encoded OBJECT IDENTIFIER and appends the result to |cbb|. It returns one on success and zero on failure.
EC_KEY_marshal_private_key(Pointer<CBB> cbb, Pointer<EC_KEY> key, int enc_flags) → int
EC_KEY_marshal_private_key marshals |key| as a DER-encoded ECPrivateKey structure (RFC 5915) and appends the result to |cbb|. It returns one on success and zero on failure. |enc_flags| is a combination of |EC_PKEY_*| values and controls whether corresponding fields are omitted.
EC_KEY_new() → Pointer<EC_KEY>
EC_KEY_new returns a fresh |EC_KEY| object or NULL on error.
EC_KEY_new_by_curve_name(int nid) → Pointer<EC_KEY>
EC_KEY_new_by_curve_name returns a fresh EC_KEY for group specified by |nid| or NULL on error.
EC_KEY_new_method(Pointer<ENGINE> engine) → Pointer<EC_KEY>
EC_KEY_new_method acts the same as |EC_KEY_new|, but takes an explicit |ENGINE|.
EC_KEY_oct2key(Pointer<EC_KEY> key, Pointer<Uint8> in$, int len, Pointer<BN_CTX> ctx) → int
EC_KEY_oct2key decodes |len| bytes from |in| as an EC public key in X9.62 form. |key| must already have a group configured. On success, it sets the public key in |key| to the result and returns one. Otherwise, it returns zero. |ctx| may be NULL.
EC_KEY_oct2priv(Pointer<EC_KEY> key, Pointer<Uint8> in$, int len) → int
EC_KEY_oct2priv decodes a big-endian, zero-padded integer from |len| bytes from |in| and sets |key|'s private key to the result. It returns one on success and zero on error. The input must be padded to the size of |key|'s group order.
EC_KEY_parse_curve_name(Pointer<CBS> cbs) → Pointer<EC_GROUP>
EC_KEY_parse_curve_name parses a DER-encoded OBJECT IDENTIFIER as a curve name from |cbs| and advances |cbs|. It returns the decoded |EC_GROUP| or NULL on error.
EC_KEY_parse_parameters(Pointer<CBS> cbs) → Pointer<EC_GROUP>
EC_KEY_parse_parameters parses a DER-encoded ECParameters structure (RFC 5480) from |cbs| and advances |cbs|. It returns the resulting |EC_GROUP| or NULL on error. It supports the namedCurve and specifiedCurve options, but use of specifiedCurve is deprecated. Use |EC_KEY_parse_curve_name| instead.
EC_KEY_parse_private_key(Pointer<CBS> cbs, Pointer<EC_GROUP> group) → Pointer<EC_KEY>
EC_KEY_parse_private_key parses a DER-encoded ECPrivateKey structure (RFC 5915) from |cbs| and advances |cbs|. It returns a newly-allocated |EC_KEY| or NULL on error. If |group| is non-null, the parameters field of the ECPrivateKey may be omitted (but must match |group| if present). Otherwise, the parameters field is required.
EC_KEY_priv2buf(Pointer<EC_KEY> key, Pointer<Pointer<Uint8>> out_buf) → int
EC_KEY_priv2buf behaves like |EC_KEY_priv2oct| but sets |*out_buf| to a newly-allocated buffer containing the result. It returns the size of the result on success and zero on error. The caller must release |*out_buf| with |OPENSSL_free| when done.
EC_KEY_priv2oct(Pointer<EC_KEY> key, Pointer<Uint8> out, int max_out) → int
EC_KEY_priv2oct serializes |key|'s private key as a big-endian integer, zero-padded to the size of |key|'s group order and writes the result to at most |max_out| bytes of |out|. It returns the number of bytes written on success and zero on error. If |out| is NULL, it returns the number of bytes needed without writing anything.
EC_KEY_set_asn1_flag(Pointer<EC_KEY> key, int flag) → void
EC_KEY_set_asn1_flag does nothing.
EC_KEY_set_conv_form(Pointer<EC_KEY> key, int cform) → void
EC_KEY_set_conv_form sets the conversion form to be used by |key|.
EC_KEY_set_enc_flags(Pointer<EC_KEY> key, int flags) → void
EC_KEY_set_enc_flags sets the encoding flags for |key|, which is a bitwise-OR of |EC_PKEY_*| values.
EC_KEY_set_ex_data(Pointer<EC_KEY> r, int idx, Pointer<Void> arg) → int
EC_KEY_set_group(Pointer<EC_KEY> key, Pointer<EC_GROUP> group) → int
EC_KEY_set_group sets the |EC_GROUP| object that |key| will use to |group|. It returns one on success and zero if |key| is already configured with a different group.
EC_KEY_set_private_key(Pointer<EC_KEY> key, Pointer<BIGNUM> priv) → int
EC_KEY_set_private_key sets the private key of |key| to |priv|. It returns one on success and zero otherwise. |key| must already have had a group configured (see |EC_KEY_set_group| and |EC_KEY_new_by_curve_name|).
EC_KEY_set_public_key(Pointer<EC_KEY> key, Pointer<EC_POINT> pub) → int
EC_KEY_set_public_key sets the public key of |key| to |pub|, by copying it. It returns one on success and zero otherwise. |key| must already have had a group configured (see |EC_KEY_set_group| and |EC_KEY_new_by_curve_name|), and |pub| must also belong to that group, and must not be the point at infinity.
EC_KEY_set_public_key_affine_coordinates(Pointer<EC_KEY> key, Pointer<BIGNUM> x, Pointer<BIGNUM> y) → int
EC_KEY_set_public_key_affine_coordinates sets the public key in |key| to (|x|, |y|). It returns one on success and zero on error. It's considered an error if |x| and |y| do not represent a point on |key|'s curve.
EC_KEY_up_ref(Pointer<EC_KEY> key) → int
EC_KEY_up_ref increases the reference count of |key| and returns one. It does not mutate |key| for thread-safety purposes and may be used concurrently.
EC_METHOD_get_field_type(Pointer<EC_METHOD> meth) → int
EC_METHOD_get_field_type returns NID_X9_62_prime_field.
EC_POINT_add(Pointer<EC_GROUP> group, Pointer<EC_POINT> r, Pointer<EC_POINT> a, Pointer<EC_POINT> b, Pointer<BN_CTX> ctx) → int
EC_POINT_add sets |r| equal to |a| plus |b|. It returns one on success and zero otherwise. |ctx| is ignored and may be NULL.
EC_POINT_clear_free(Pointer<EC_POINT> point) → void
EC_POINT_clear_free calls |EC_POINT_free|.
EC_POINT_cmp(Pointer<EC_GROUP> group, Pointer<EC_POINT> a, Pointer<EC_POINT> b, Pointer<BN_CTX> ctx) → int
EC_POINT_cmp returns zero if |a| is equal to |b|, greater than zero if not equal and -1 on error. |ctx| is ignored and may be NULL.
EC_POINT_copy(Pointer<EC_POINT> dest, Pointer<EC_POINT> src) → int
EC_POINT_copy sets |*dest| equal to |*src|. It returns one on success and zero otherwise.
EC_POINT_dbl(Pointer<EC_GROUP> group, Pointer<EC_POINT> r, Pointer<EC_POINT> a, Pointer<BN_CTX> ctx) → int
EC_POINT_dbl sets |r| equal to |a| plus |a|. It returns one on success and zero otherwise. |ctx| is ignored and may be NULL.
EC_POINT_dup(Pointer<EC_POINT> src, Pointer<EC_GROUP> group) → Pointer<EC_POINT>
EC_POINT_dup returns a fresh |EC_POINT| that contains the same values as |src|, or NULL on error.
EC_POINT_free(Pointer<EC_POINT> point) → void
EC_POINT_free frees |point| and the data that it points to.
EC_POINT_get_affine_coordinates(Pointer<EC_GROUP> group, Pointer<EC_POINT> point, Pointer<BIGNUM> x, Pointer<BIGNUM> y, Pointer<BN_CTX> ctx) → int
EC_POINT_get_affine_coordinates is an alias of |EC_POINT_get_affine_coordinates_GFp|.
EC_POINT_get_affine_coordinates_GFp(Pointer<EC_GROUP> group, Pointer<EC_POINT> point, Pointer<BIGNUM> x, Pointer<BIGNUM> y, Pointer<BN_CTX> ctx) → int
EC_POINT_get_affine_coordinates_GFp sets |x| and |y| to the affine value of |point|. It returns one on success and zero otherwise. |ctx| is ignored and may be NULL.
EC_POINT_invert(Pointer<EC_GROUP> group, Pointer<EC_POINT> a, Pointer<BN_CTX> ctx) → int
EC_POINT_invert sets |a| equal to minus |a|. It returns one on success and zero otherwise. |ctx| is ignored and may be NULL.
EC_POINT_is_at_infinity(Pointer<EC_GROUP> group, Pointer<EC_POINT> point) → int
EC_POINT_is_at_infinity returns one iff |point| is the point at infinity and zero otherwise.
EC_POINT_is_on_curve(Pointer<EC_GROUP> group, Pointer<EC_POINT> point, Pointer<BN_CTX> ctx) → int
EC_POINT_is_on_curve returns one if |point| is an element of |group| and and zero otherwise or when an error occurs. This is different from OpenSSL, which returns -1 on error. |ctx| is ignored and may be NULL.
EC_POINT_mul(Pointer<EC_GROUP> group, Pointer<EC_POINT> r, Pointer<BIGNUM> n, Pointer<EC_POINT> q, Pointer<BIGNUM> m, Pointer<BN_CTX> ctx) → int
EC_POINT_mul sets r = generatorn + qm. It returns one on success and zero otherwise. |ctx| may be NULL.
EC_POINT_new(Pointer<EC_GROUP> group) → Pointer<EC_POINT>
EC_POINT_new returns a fresh |EC_POINT| object in the given group, or NULL on error.
EC_POINT_oct2point(Pointer<EC_GROUP> group, Pointer<EC_POINT> point, Pointer<Uint8> buf, int len, Pointer<BN_CTX> ctx) → int
EC_POINT_oct2point sets |point| from |len| bytes of X9.62 format serialisation in |buf|. It returns one on success and zero on error. |ctx| may be NULL. It's considered an error if |buf| does not represent a point on the curve.
EC_POINT_point2buf(Pointer<EC_GROUP> group, Pointer<EC_POINT> point, int form, Pointer<Pointer<Uint8>> out_buf, Pointer<BN_CTX> ctx) → int
EC_POINT_point2buf serialises |point| into the X9.62 form given by |form| to a newly-allocated buffer and sets |*out_buf| to point to it. It returns the length of the result on success or zero on error. The caller must release |*out_buf| with |OPENSSL_free| when done. |ctx| is ignored and may be NULL.
EC_POINT_point2cbb(Pointer<CBB> out, Pointer<EC_GROUP> group, Pointer<EC_POINT> point, int form, Pointer<BN_CTX> ctx) → int
EC_POINT_point2cbb behaves like |EC_POINT_point2oct| but appends the serialised point to |cbb|. It returns one on success and zero on error. |ctx| is ignored and may be NULL.
EC_POINT_point2oct(Pointer<EC_GROUP> group, Pointer<EC_POINT> point, int form, Pointer<Uint8> buf, int max_out, Pointer<BN_CTX> ctx) → int
EC_POINT_point2oct serialises |point| into the X9.62 form given by |form| into, at most, |max_out| bytes at |buf|. It returns the number of bytes written or zero on error if |buf| is non-NULL, else the number of bytes needed. |ctx| is ignored and may be NULL.
EC_POINT_set_affine_coordinates(Pointer<EC_GROUP> group, Pointer<EC_POINT> point, Pointer<BIGNUM> x, Pointer<BIGNUM> y, Pointer<BN_CTX> ctx) → int
EC_POINT_set_affine_coordinates is an alias of |EC_POINT_set_affine_coordinates_GFp|.
EC_POINT_set_affine_coordinates_GFp(Pointer<EC_GROUP> group, Pointer<EC_POINT> point, Pointer<BIGNUM> x, Pointer<BIGNUM> y, Pointer<BN_CTX> ctx) → int
EC_POINT_set_affine_coordinates_GFp sets the value of |point| to be (|x|, |y|). |ctx| is ignored and may be NULL. It returns one on success or zero on error. It's considered an error if the point is not on the curve.
EC_POINT_set_compressed_coordinates_GFp(Pointer<EC_GROUP> group, Pointer<EC_POINT> point, Pointer<BIGNUM> x, int y_bit, Pointer<BN_CTX> ctx) → int
EC_POINT_set_compressed_coordinates_GFp sets |point| to equal the point with the given |x| coordinate and the y coordinate specified by |y_bit| (see X9.62). It returns one on success and zero otherwise. |ctx| may be NULL.
EC_POINT_set_to_infinity(Pointer<EC_GROUP> group, Pointer<EC_POINT> point) → int
EC_POINT_set_to_infinity sets |point| to be the "point at infinity" for the given group.
ECDH_compute_key(Pointer<Void> out, int outlen, Pointer<EC_POINT> pub_key, Pointer<EC_KEY> priv_key, Pointer<NativeFunction<Pointer<Void> Function(Pointer<Void> in$, Size inlen, Pointer<Void> out, Pointer<Size> outlen)>> kdf) → int
ECDH_compute_key calculates the shared key between |pub_key| and |priv_key|. If |kdf| is not NULL, then it is called with the bytes of the shared key and the parameter |out|. When |kdf| returns, the value of |*outlen| becomes the return value. Otherwise, as many bytes of the shared key as will fit are copied directly to, at most, |outlen| bytes at |out|. It returns the number of bytes written to |out|, or -1 on error.
ECDH_compute_key_fips(Pointer<Uint8> out, int out_len, Pointer<EC_POINT> pub_key, Pointer<EC_KEY> priv_key) → int
ECDH_compute_key_fips calculates the shared key between |pub_key| and |priv_key| and hashes it with the appropriate SHA function for |out_len|. The only value values for |out_len| are thus 24 (SHA-224), 32 (SHA-256), 48 (SHA-384), and 64 (SHA-512). It returns one on success and zero on error.
ECDSA_do_sign(Pointer<Uint8> digest, int digest_len, Pointer<EC_KEY> key) → Pointer<ECDSA_SIG>
ECDSA_do_sign signs |digest_len| bytes from |digest| with |key| and returns the resulting signature structure, or NULL on error.
ECDSA_do_verify(Pointer<Uint8> digest, int digest_len, Pointer<ECDSA_SIG> sig, Pointer<EC_KEY> key) → int
ECDSA_do_verify verifies that |sig| constitutes a valid signature by |key| of |digest|. It returns one on success or zero if the signature is invalid or on error.
ECDSA_SIG_free(Pointer<ECDSA_SIG> sig) → void
ECDSA_SIG_free frees |sig| its member |BIGNUM|s.
ECDSA_SIG_from_bytes(Pointer<Uint8> in$, int in_len) → Pointer<ECDSA_SIG>
ECDSA_SIG_from_bytes parses |in| as a DER-encoded ECDSA-Sig-Value structure. It returns a newly-allocated |ECDSA_SIG| structure or NULL on error.
ECDSA_SIG_get0(Pointer<ECDSA_SIG> sig, Pointer<Pointer<BIGNUM>> out_r, Pointer<Pointer<BIGNUM>> out_s) → void
ECDSA_SIG_get0 sets |*out_r| and |*out_s|, if non-NULL, to the two components of |sig|.
ECDSA_SIG_get0_r(Pointer<ECDSA_SIG> sig) → Pointer<BIGNUM>
ECDSA_SIG_get0_r returns the r component of |sig|.
ECDSA_SIG_get0_s(Pointer<ECDSA_SIG> sig) → Pointer<BIGNUM>
ECDSA_SIG_get0_s returns the s component of |sig|.
ECDSA_SIG_marshal(Pointer<CBB> cbb, Pointer<ECDSA_SIG> sig) → int
ECDSA_SIG_marshal marshals |sig| as a DER-encoded ECDSA-Sig-Value and appends the result to |cbb|. It returns one on success and zero on error.
ECDSA_SIG_max_len(int order_len) → int
ECDSA_SIG_max_len returns the maximum length of a DER-encoded ECDSA-Sig-Value structure for a group whose order is represented in |order_len| bytes, or zero on overflow.
ECDSA_SIG_new() → Pointer<ECDSA_SIG>
ECDSA_SIG_new returns a fresh |ECDSA_SIG| structure or NULL on error.
ECDSA_SIG_parse(Pointer<CBS> cbs) → Pointer<ECDSA_SIG>
ECDSA_SIG_parse parses a DER-encoded ECDSA-Sig-Value structure from |cbs| and advances |cbs|. It returns a newly-allocated |ECDSA_SIG| or NULL on error.
ECDSA_SIG_set0(Pointer<ECDSA_SIG> sig, Pointer<BIGNUM> r, Pointer<BIGNUM> s) → int
ECDSA_SIG_set0 sets |sig|'s components to |r| and |s|, neither of which may be NULL. On success, it takes ownership of each argument and returns one. Otherwise, it returns zero.
ECDSA_SIG_to_bytes(Pointer<Pointer<Uint8>> out_bytes, Pointer<Size> out_len, Pointer<ECDSA_SIG> sig) → int
ECDSA_SIG_to_bytes marshals |sig| as a DER-encoded ECDSA-Sig-Value and, on success, sets |*out_bytes| to a newly allocated buffer containing the result and returns one. Otherwise, it returns zero. The result should be freed with |OPENSSL_free|.
ECDSA_sign(int type, Pointer<Uint8> digest, int digest_len, Pointer<Uint8> sig, Pointer<UnsignedInt> sig_len, Pointer<EC_KEY> key) → int
ECDSA_sign signs |digest_len| bytes from |digest| with |key| and writes the resulting ASN.1-based signature to |sig|, which must have |ECDSA_size(key)| bytes of space. On successful exit, |*sig_len| is set to the actual number of bytes written. The |type| argument should be zero. It returns one on success and zero otherwise.
ECDSA_sign_p1363(Pointer<Uint8> digest, int digest_len, Pointer<Uint8> sig, Pointer<Size> out_sig_len, int max_sig_len, Pointer<EC_KEY> key) → int
ECDSA_sign_p1363 signs |digest_len| bytes from |digest| with |key| and writes the resulting P1363-based signature to |sig|, which must have |ECDSA_size_p1363(key)| bytes of space. On successful exit, |*out_sig_len| is set to the actual number of bytes written, which will always match |ECDSA_size_p1363(key)|. It returns one on success and zero otherwise.
ECDSA_sign_with_nonce_and_leak_private_key_for_testing(Pointer<Uint8> digest, int digest_len, Pointer<EC_KEY> eckey, Pointer<Uint8> nonce, int nonce_len) → Pointer<ECDSA_SIG>
ECDSA_sign_with_nonce_and_leak_private_key_for_testing behaves like |ECDSA_do_sign| but uses |nonce| for the ECDSA nonce 'k', instead of a random value. |nonce| is interpreted as a big-endian integer. It must be reduced modulo the group order and padded with zeros up to |BN_num_bytes(order)| bytes.
ECDSA_size(Pointer<EC_KEY> key) → int
ECDSA_size returns the maximum size of an ASN.1-based ECDSA signature using |key|. It returns zero if |key| is NULL or if it doesn't have a group set.
ECDSA_size_p1363(Pointer<EC_KEY> key) → int
ECDSA_size_p1363 returns the size of a P1363-based ECDSA signature using |key|. It returns zero if |key| is NULL or if it doesn't have a group set.
ECDSA_verify(int type, Pointer<Uint8> digest, int digest_len, Pointer<Uint8> sig, int sig_len, Pointer<EC_KEY> key) → int
ECDSA_verify verifies that |sig_len| bytes from |sig| constitute a valid ASN.1-based signature by |key| of |digest|. (The |type| argument should be zero.) It returns one on success or zero if the signature is invalid or an error occurred.
ECDSA_verify_p1363(Pointer<Uint8> digest, int digest_len, Pointer<Uint8> sig, int sig_len, Pointer<EC_KEY> key) → int
ECDSA_verify_p1363 verifies that |sig_len| bytes from |sig| constitute a valid P1363-based signature by |key| of |digest|. It returns one on success or zero if the signature is invalid or an error occurred.
ED25519_keypair(Pointer<Uint8> out_public_key, Pointer<Uint8> out_private_key) → void
ED25519_keypair sets |out_public_key| and |out_private_key| to a freshly generated, public–private key pair.
ED25519_keypair_from_seed(Pointer<Uint8> out_public_key, Pointer<Uint8> out_private_key, Pointer<Uint8> seed) → void
ED25519_keypair_from_seed calculates a public and private key from an Ed25519 “seed”. Seed values are not exposed by this API (although they happen to be the first 32 bytes of a private key) so this function is for interoperating with systems that may store just a seed instead of a full private key.
ED25519_sign(Pointer<Uint8> out_sig, Pointer<Uint8> message, int message_len, Pointer<Uint8> private_key) → int
ED25519_sign sets |out_sig| to be a signature of |message_len| bytes from |message| using |private_key|. It returns one on success or zero on allocation failure.
ED25519_verify(Pointer<Uint8> message, int message_len, Pointer<Uint8> signature, Pointer<Uint8> public_key) → int
ED25519_verify returns one iff |signature| is a valid signature, by |public_key| of |message_len| bytes from |message|. It returns zero otherwise.
EDIPARTYNAME_free(Pointer<EDIPARTYNAME> name) → void
EDIPARTYNAME_free releases memory associated with |name|. EDIPartyName is rarely used in practice, so callers are unlikely to need this function.
EDIPARTYNAME_new() → Pointer<EDIPARTYNAME>
EDIPARTYNAME_new returns a new, empty |EDIPARTYNAME|, or NULL on error. EDIPartyName is rarely used in practice, so callers are unlikely to need this function.
ENGINE_cleanup() → void
ENGINE_cleanup does nothing.
ENGINE_free(Pointer<ENGINE> engine) → int
ENGINE_free decrements the reference counts for all methods linked from |engine| and frees |engine| itself. It returns one.
ENGINE_get_ECDSA_method(Pointer<ENGINE> engine) → Pointer<ECDSA_METHOD>
ENGINE_get_RSA_method(Pointer<ENGINE> engine) → Pointer<RSA_METHOD>
ENGINE_load_builtin_engines() → void
ENGINE_load_builtin_engines does nothing.
ENGINE_new() → Pointer<ENGINE>
ENGINE_new returns an empty ENGINE that uses the default method for all algorithms.
ENGINE_register_all_complete() → int
ENGINE_register_all_complete returns one.
ENGINE_set_ECDSA_method(Pointer<ENGINE> engine, Pointer<ECDSA_METHOD> method, int method_size) → int
ENGINE_set_RSA_method(Pointer<ENGINE> engine, Pointer<RSA_METHOD> method, int method_size) → int
Method accessors.
ERR_add_error_data(int count) → void
ERR_add_error_data takes a variable number (|count|) of const char* pointers, concatenates them and sets the result as the data on the most recent error.
ERR_add_error_dataf(Pointer<Char> format) → void
ERR_add_error_dataf takes a printf-style format and arguments, and sets the result as the data on the most recent error.
ERR_clear_error() → void
ERR_clear_error clears the error queue for the current thread.
ERR_clear_system_error() → void
ERR_clear_system_error clears the system's error value (i.e. errno).
ERR_error_string(int packed_error, Pointer<Char> buf) → Pointer<Char>
ERR_error_string behaves like |ERR_error_string_n| but |len| is implicitly |ERR_ERROR_STRING_BUF_LEN|.
ERR_error_string_n(int packed_error, Pointer<Char> buf, int len) → Pointer<Char>
ERR_error_string_n generates a human-readable string representing |packed_error|, places it at |buf|, and returns |buf|. It writes at most |len| bytes (including the terminating NUL) and truncates the string if necessary. If |len| is greater than zero then |buf| is always NUL terminated.
ERR_free_strings() → void
ERR_free_strings does nothing.
ERR_func_error_string(int packed_error) → Pointer<Char>
ERR_func_error_string returns the string "OPENSSL_internal".
ERR_get_error() → int
ERR_get_error gets the packed error code for the least recent error and removes that error from the queue. If there are no errors in the queue then it returns zero.
ERR_get_error_line(Pointer<Pointer<Char>> file, Pointer<Int> line) → int
ERR_get_error_line acts like |ERR_get_error|, except that the file and line number of the call that added the error are also returned.
ERR_get_error_line_data(Pointer<Pointer<Char>> file, Pointer<Int> line, Pointer<Pointer<Char>> data, Pointer<Int> flags) → int
ERR_get_error_line_data acts like |ERR_get_error_line|, but also returns the error-specific data pointer and flags. The flags are a bitwise-OR of |ERR_FLAG_*| values. The error-specific data is owned by the error queue and the pointer becomes invalid after the next call that affects the same thread's error queue. If |*flags| contains |ERR_FLAG_STRING| then |*data| is human-readable.
ERR_GET_LIB(int packedError) → int
Returns the library code (ERR_LIB_*) for a packed BoringSSL error code.
ERR_get_next_error_library() → int
ERR_get_next_error_library returns a value suitable for passing as the |library| argument to |ERR_put_error|. This is intended for code that wishes to push its own, non-standard errors to the error queue.
ERR_GET_REASON(int packedError) → int
Returns the library-specific reason code (*_R_*) for a packed BoringSSL error code.
ERR_lib_error_string(int packed_error) → Pointer<Char>
ERR_lib_error_string returns a string representation of the library that generated |packed_error|, or a placeholder string is the library is unrecognized.
ERR_lib_symbol_name(int packed_error) → Pointer<Char>
ERR_lib_symbol_name returns the symbol name of library that generated |packed_error|, or NULL if unrecognized. For example, an error from |ERR_LIB_EVP| would return "EVP".
ERR_load_BIO_strings() → void
ERR_load_BIO_strings does nothing.
ERR_load_crypto_strings() → void
ERR_load_crypto_strings does nothing.
ERR_load_ERR_strings() → void
ERR_load_ERR_strings does nothing.
ERR_load_RAND_strings() → void
ERR_load_RAND_strings does nothing.
ERR_peek_error() → int
The "peek" functions act like the |ERR_get_error| functions, above, but they do not remove the error from the queue.
ERR_peek_error_line(Pointer<Pointer<Char>> file, Pointer<Int> line) → int
ERR_peek_error_line_data(Pointer<Pointer<Char>> file, Pointer<Int> line, Pointer<Pointer<Char>> data, Pointer<Int> flags) → int
ERR_peek_last_error() → int
The "peek last" functions act like the "peek" functions, above, except that they return the most recent error.
ERR_peek_last_error_line(Pointer<Pointer<Char>> file, Pointer<Int> line) → int
ERR_peek_last_error_line_data(Pointer<Pointer<Char>> file, Pointer<Int> line, Pointer<Pointer<Char>> data, Pointer<Int> flags) → int
ERR_pop_to_mark() → int
ERR_pop_to_mark removes errors from the most recent to the least recent until (and not including) a "marked" error. It returns zero if no marked error was found (and thus all errors were removed) and one otherwise. Errors are marked using |ERR_set_mark|.
ERR_print_errors(Pointer<BIO> bio) → void
ERR_print_errors prints the current contents of the error stack to |bio| using human readable strings where possible.
ERR_print_errors_cb(ERR_print_errors_callback_t callback, Pointer<Void> ctx) → void
ERR_print_errors_cb clears the current thread's error queue, calling |callback| with a string representation of each error, from the least recent to the most recent error.
ERR_print_errors_fp(Pointer<FILE> file) → void
ERR_print_errors_fp clears the current thread's error queue, printing each error to |file|. See |ERR_print_errors_cb| for the format.
ERR_put_error(int library, int unused, int reason, Pointer<Char> file, int line) → void
ERR_put_error adds an error to the error queue, dropping the least recent error if necessary for space reasons.
ERR_reason_error_string(int packed_error) → Pointer<Char>
ERR_reason_error_string returns a string representation of the reason for |packed_error|, or a placeholder string if the reason is unrecognized.
ERR_reason_symbol_name(int packed_error) → Pointer<Char>
ERR_reason_symbol_name returns the symbol name of the reason for |packed_error|, or NULL if unrecognized. For example, |ERR_R_INTERNAL_ERROR| would return "INTERNAL_ERROR".
ERR_remove_state(int pid) → void
ERR_remove_state calls |ERR_clear_error|.
ERR_remove_thread_state(Pointer<Int> tid) → void
ERR_remove_thread_state clears the error queue for the current thread if |tid| is NULL. Otherwise it calls |assert(0)|, because it's no longer possible to delete the error queue for other threads.
ERR_set_error_data(Pointer<Char> data, int flags) → void
ERR_set_error_data sets the data on the most recent error to |data|, which must be a NUL-terminated string. |flags| must contain |ERR_FLAG_STRING|. If |flags| contains |ERR_FLAG_MALLOCED|, this function takes ownership of |data|, which must have been allocated with |OPENSSL_malloc|. Otherwise, it saves a copy of |data|.
ERR_set_mark() → int
ERR_set_mark "marks" the most recent error for use with |ERR_pop_to_mark|. It returns one if an error was marked and zero if there are no errors.
EVP_add_cipher_alias(Pointer<Char> a, Pointer<Char> b) → int
EVP_add_cipher_alias does nothing and returns one.
EVP_add_digest(Pointer<EVP_MD> digest) → int
EVP_add_digest does nothing and returns one. It exists only for compatibility with OpenSSL.
EVP_aead_aes_128_cbc_sha1_tls() → Pointer<EVP_AEAD>
TLS-specific AEAD algorithms.
EVP_aead_aes_128_cbc_sha1_tls_implicit_iv() → Pointer<EVP_AEAD>
EVP_aead_aes_128_cbc_sha256_tls() → Pointer<EVP_AEAD>
EVP_aead_aes_128_ccm_bluetooth() → Pointer<EVP_AEAD>
EVP_aead_aes_128_ccm_bluetooth is AES-128-CCM with M=4 and L=2 (4-byte tags and 13-byte nonces), as described in the Bluetooth Core Specification v5.0, Volume 6, Part E, Section 1.
EVP_aead_aes_128_ccm_bluetooth_8() → Pointer<EVP_AEAD>
EVP_aead_aes_128_ccm_bluetooth_8 is AES-128-CCM with M=8 and L=2 (8-byte tags and 13-byte nonces), as used in the Bluetooth Mesh Networking Specification v1.0.
EVP_aead_aes_128_ccm_matter() → Pointer<EVP_AEAD>
EVP_aead_aes_128_ccm_matter is AES-128-CCM with M=16 and L=2 (16-byte tags and 13-byte nonces), as used in the Matter specification.
EVP_aead_aes_128_ctr_hmac_sha256() → Pointer<EVP_AEAD>
EVP_aead_aes_128_ctr_hmac_sha256 is AES-128 in CTR mode with HMAC-SHA256 for authentication. The nonce is 12 bytes; the bottom 32-bits are used as the block counter, thus the maximum plaintext size is 64GB.
EVP_aead_aes_128_eax() → Pointer<EVP_AEAD>
EVP_aead_aes_128_eax is AES-128 in EAX mode. Nonce size is either 12 or 16 bytes, tag length is 16 bytes. See https://doi.org/10.1007/978-3-540-25937-4_25.
EVP_aead_aes_128_gcm() → Pointer<EVP_AEAD>
EVP_aead_aes_128_gcm is AES-128 in Galois Counter Mode.
EVP_aead_aes_128_gcm_randnonce() → Pointer<EVP_AEAD>
EVP_aead_aes_128_gcm_randnonce is AES-128 in Galois Counter Mode with internal nonce generation. The 12-byte nonce is appended to the tag and is generated internally. The "tag", for the purpurses of the API, is thus 12 bytes larger. The nonce parameter when using this AEAD must be zero-length. Since the nonce is random, a single key should not be used for more than 2^32 seal operations.
EVP_aead_aes_128_gcm_siv() → Pointer<EVP_AEAD>
EVP_aead_aes_128_gcm_siv is AES-128 in GCM-SIV mode. See RFC 8452.
EVP_aead_aes_128_gcm_tls12() → Pointer<EVP_AEAD>
EVP_aead_aes_128_gcm_tls12 is AES-128 in Galois Counter Mode using the TLS 1.2 nonce construction.
EVP_aead_aes_128_gcm_tls13() → Pointer<EVP_AEAD>
EVP_aead_aes_128_gcm_tls13 is AES-128 in Galois Counter Mode using the TLS 1.3 nonce construction.
EVP_aead_aes_192_gcm() → Pointer<EVP_AEAD>
EVP_aead_aes_192_gcm is AES-192 in Galois Counter Mode.
EVP_aead_aes_256_cbc_sha1_tls() → Pointer<EVP_AEAD>
EVP_aead_aes_256_cbc_sha1_tls_implicit_iv() → Pointer<EVP_AEAD>
EVP_aead_aes_256_ctr_hmac_sha256() → Pointer<EVP_AEAD>
EVP_aead_aes_256_ctr_hmac_sha256 is AES-256 in CTR mode with HMAC-SHA256 for authentication. See |EVP_aead_aes_128_ctr_hmac_sha256| for details.
EVP_aead_aes_256_eax() → Pointer<EVP_AEAD>
EVP_aead_aes_256_eax is AES-256 in EAX mode. Nonce size is either 12 or 16 bytes, tag length is 16 bytes. See https://doi.org/10.1007/978-3-540-25937-4_25.
EVP_aead_aes_256_gcm() → Pointer<EVP_AEAD>
EVP_aead_aes_256_gcm is AES-256 in Galois Counter Mode.
EVP_aead_aes_256_gcm_randnonce() → Pointer<EVP_AEAD>
EVP_aead_aes_256_gcm_randnonce is AES-256 in Galois Counter Mode with internal nonce generation. The 12-byte nonce is appended to the tag and is generated internally. The "tag", for the purpurses of the API, is thus 12 bytes larger. The nonce parameter when using this AEAD must be zero-length. Since the nonce is random, a single key should not be used for more than 2^32 seal operations.
EVP_aead_aes_256_gcm_siv() → Pointer<EVP_AEAD>
EVP_aead_aes_256_gcm_siv is AES-256 in GCM-SIV mode. See RFC 8452.
EVP_aead_aes_256_gcm_tls12() → Pointer<EVP_AEAD>
EVP_aead_aes_256_gcm_tls12 is AES-256 in Galois Counter Mode using the TLS 1.2 nonce construction.
EVP_aead_aes_256_gcm_tls13() → Pointer<EVP_AEAD>
EVP_aead_aes_256_gcm_tls13 is AES-256 in Galois Counter Mode using the TLS 1.3 nonce construction.
EVP_aead_chacha20_poly1305() → Pointer<EVP_AEAD>
EVP_aead_chacha20_poly1305 is the AEAD built from ChaCha20 and Poly1305 as described in RFC 8439.
EVP_AEAD_CTX_aead(Pointer<EVP_AEAD_CTX> ctx) → Pointer<EVP_AEAD>
EVP_AEAD_CTX_aead returns the underlying AEAD for |ctx|, or NULL if one has not been set.
EVP_AEAD_CTX_cleanup(Pointer<EVP_AEAD_CTX> ctx) → void
EVP_AEAD_CTX_cleanup frees any data allocated by |ctx|. It is a no-op to call |EVP_AEAD_CTX_cleanup| on a |EVP_AEAD_CTX| that has been |memset| to all zeros.
EVP_AEAD_CTX_free(Pointer<EVP_AEAD_CTX> ctx) → void
EVP_AEAD_CTX_free calls |EVP_AEAD_CTX_cleanup| and |OPENSSL_free| on |ctx|.
EVP_AEAD_CTX_get_iv(Pointer<EVP_AEAD_CTX> ctx, Pointer<Pointer<Uint8>> out_iv, Pointer<Size> out_len) → int
EVP_AEAD_CTX_get_iv sets |*out_len| to the length of the IV for |ctx| and sets |*out_iv| to point to that many bytes of the current IV. This is only meaningful for AEADs with implicit IVs (i.e. CBC mode in TLS 1.0).
EVP_AEAD_CTX_init(Pointer<EVP_AEAD_CTX> ctx, Pointer<EVP_AEAD> aead, Pointer<Uint8> key, int key_len, int tag_len, Pointer<ENGINE> impl) → int
EVP_AEAD_CTX_init initializes |ctx| for the given AEAD algorithm. The |impl| argument is ignored and should be NULL. Authentication tags may be truncated by passing a size as |tag_len|. A |tag_len| of zero indicates the default tag length and this is defined as EVP_AEAD_DEFAULT_TAG_LENGTH for readability.
EVP_AEAD_CTX_init_with_direction(Pointer<EVP_AEAD_CTX> ctx, Pointer<EVP_AEAD> aead, Pointer<Uint8> key, int key_len, int tag_len, int dir) → int
EVP_AEAD_CTX_init_with_direction calls |EVP_AEAD_CTX_init| for normal AEADs. For TLS-specific and SSL3-specific AEADs, it initializes |ctx| for a given direction.
EVP_AEAD_CTX_new(Pointer<EVP_AEAD> aead, Pointer<Uint8> key, int key_len, int tag_len) → Pointer<EVP_AEAD_CTX>
EVP_AEAD_CTX_new allocates an |EVP_AEAD_CTX|, calls |EVP_AEAD_CTX_init| and returns the |EVP_AEAD_CTX|, or NULL on error.
EVP_AEAD_CTX_open(Pointer<EVP_AEAD_CTX> ctx, Pointer<Uint8> out, Pointer<Size> out_len, int max_out_len, Pointer<Uint8> nonce, int nonce_len, Pointer<Uint8> in$, int in_len, Pointer<Uint8> ad, int ad_len) → int
EVP_AEAD_CTX_open authenticates |in_len| bytes from |in| and |ad_len| bytes from |ad| and decrypts at most |in_len| bytes into |out|. It returns one on success and zero otherwise.
EVP_AEAD_CTX_open_gather(Pointer<EVP_AEAD_CTX> ctx, Pointer<Uint8> out, Pointer<Uint8> nonce, int nonce_len, Pointer<Uint8> in$, int in_len, Pointer<Uint8> in_tag, int in_tag_len, Pointer<Uint8> ad, int ad_len) → int
EVP_AEAD_CTX_open_gather decrypts and authenticates |in_len| bytes from |in| and authenticates |ad_len| bytes from |ad| using |in_tag_len| bytes of authentication tag from |in_tag|. If successful, it writes |in_len| bytes of plaintext to |out|. It returns one on success and zero otherwise.
EVP_AEAD_CTX_openv(Pointer<EVP_AEAD_CTX> ctx, Pointer<CRYPTO_IOVEC> iovec, int num_iovec, Pointer<Size> out_total_bytes, Pointer<Uint8> nonce, int nonce_len, Pointer<CRYPTO_IVEC> aadvec, int num_aadvec) → int
EVP_AEAD_CTX_openv authenticates the |in| bytes from |iovec| and |aadvec|, and decrypts the |in| bytes to the |out| pointers of |iovec|. It returns one on success and zero otherwise.
EVP_AEAD_CTX_openv_detached(Pointer<EVP_AEAD_CTX> ctx, Pointer<CRYPTO_IOVEC> iovec, int num_iovec, Pointer<Uint8> nonce, int nonce_len, Pointer<Uint8> in_tag, int in_tag_len, Pointer<CRYPTO_IVEC> aadvec, int num_aadvec) → int
EVP_AEAD_CTX_openv_detached authenticates the |in| bytes from |iovec| and |aadvec| using |in_tag_len| bytes of authentication tag from |in_tag|. If successful, it writes the plaintext of the |in| bytes to the |out| pointers of |iovec|. It returns one on success and zero otherwise.
EVP_AEAD_CTX_seal(Pointer<EVP_AEAD_CTX> ctx, Pointer<Uint8> out, Pointer<Size> out_len, int max_out_len, Pointer<Uint8> nonce, int nonce_len, Pointer<Uint8> in$, int in_len, Pointer<Uint8> ad, int ad_len) → int
EVP_AEAD_CTX_seal encrypts and authenticates |in_len| bytes from |in| and authenticates |ad_len| bytes from |ad| and writes the result to |out|. It returns one on success and zero otherwise.
EVP_AEAD_CTX_seal_scatter(Pointer<EVP_AEAD_CTX> ctx, Pointer<Uint8> out, Pointer<Uint8> out_tag, Pointer<Size> out_tag_len, int max_out_tag_len, Pointer<Uint8> nonce, int nonce_len, Pointer<Uint8> in$, int in_len, Pointer<Uint8> extra_in, int extra_in_len, Pointer<Uint8> ad, int ad_len) → int
EVP_AEAD_CTX_seal_scatter encrypts and authenticates |in_len| bytes from |in| and authenticates |ad_len| bytes from |ad|. It writes |in_len| bytes of ciphertext to |out| and the authentication tag to |out_tag|. It returns one on success and zero otherwise.
EVP_AEAD_CTX_sealv(Pointer<EVP_AEAD_CTX> ctx, Pointer<CRYPTO_IOVEC> iovec, int num_iovec, Pointer<Uint8> out_tag, Pointer<Size> out_tag_len, int max_out_tag_len, Pointer<Uint8> nonce, int nonce_len, Pointer<CRYPTO_IVEC> aadvec, int num_aadvec) → int
EVP_AEAD_CTX_sealv encrypts and authenticates the |in| bytes from |iovec| and authenticates the |aadvec| bytes. It writes the same amount of ciphertext to the |out| pointers of |iovec| and the authentication tag to |out_tag|. It returns one on success and zero otherwise.
EVP_AEAD_CTX_tag_len(Pointer<EVP_AEAD_CTX> ctx, Pointer<Size> out_tag_len, int in_len, int extra_in_len) → int
EVP_AEAD_CTX_tag_len computes the exact byte length of the tag written by |EVP_AEAD_CTX_seal_scatter| and writes it to |*out_tag_len|. It returns one on success or zero on error. |in_len| and |extra_in_len| must equal the arguments of the same names passed to |EVP_AEAD_CTX_seal_scatter|.
EVP_AEAD_CTX_zero(Pointer<EVP_AEAD_CTX> ctx) → void
EVP_AEAD_CTX_zero sets an uninitialized |ctx| to the zero state. It must be initialized with |EVP_AEAD_CTX_init| before use. It is safe, but not necessary, to call |EVP_AEAD_CTX_cleanup| in this state. This may be used for more uniform cleanup of |EVP_AEAD_CTX|.
EVP_aead_des_ede3_cbc_sha1_tls() → Pointer<EVP_AEAD>
EVP_aead_des_ede3_cbc_sha1_tls_implicit_iv() → Pointer<EVP_AEAD>
EVP_AEAD_key_length(Pointer<EVP_AEAD> aead) → int
EVP_AEAD_key_length returns the length, in bytes, of the keys used by |aead|.
EVP_AEAD_max_overhead(Pointer<EVP_AEAD> aead) → int
EVP_AEAD_max_overhead returns the maximum number of additional bytes added by the act of sealing data with |aead|.
EVP_AEAD_max_tag_len(Pointer<EVP_AEAD> aead) → int
EVP_AEAD_max_tag_len returns the maximum tag length when using |aead|. This is the largest value that can be passed as |tag_len| to |EVP_AEAD_CTX_init|.
EVP_AEAD_nonce_length(Pointer<EVP_AEAD> aead) → int
EVP_AEAD_nonce_length returns the length, in bytes, of the per-message nonce for |aead|.
EVP_aead_xchacha20_poly1305() → Pointer<EVP_AEAD>
EVP_aead_xchacha20_poly1305 is ChaCha20-Poly1305 with an extended nonce that makes random generation of nonces safe.
EVP_aes_128_cbc() → Pointer<EVP_CIPHER>
EVP_aes_128_ctr() → Pointer<EVP_CIPHER>
EVP_aes_128_ecb() → Pointer<EVP_CIPHER>
EVP_aes_128_gcm() → Pointer<EVP_CIPHER>
These AEADs are deprecated AES-GCM implementations that set |EVP_CIPH_FLAG_CUSTOM_CIPHER|. Use |EVP_aead_aes_128_gcm| and |EVP_aead_aes_256_gcm| instead.
EVP_aes_128_ofb() → Pointer<EVP_CIPHER>
EVP_aes_192_cbc() → Pointer<EVP_CIPHER>
EVP_aes_192_ctr() → Pointer<EVP_CIPHER>
EVP_aes_192_ecb() → Pointer<EVP_CIPHER>
These are deprecated, 192-bit version of AES.
EVP_aes_192_gcm() → Pointer<EVP_CIPHER>
EVP_aes_192_ofb() → Pointer<EVP_CIPHER>
EVP_aes_256_cbc() → Pointer<EVP_CIPHER>
EVP_aes_256_ctr() → Pointer<EVP_CIPHER>
EVP_aes_256_ecb() → Pointer<EVP_CIPHER>
EVP_aes_256_gcm() → Pointer<EVP_CIPHER>
EVP_aes_256_ofb() → Pointer<EVP_CIPHER>
EVP_blake2b256() → Pointer<EVP_MD>
EVP_BytesToKey(Pointer<EVP_CIPHER> type, Pointer<EVP_MD> md, Pointer<Uint8> salt, Pointer<Uint8> data, int data_len, int count, Pointer<Uint8> key, Pointer<Uint8> iv) → int
EVP_BytesToKey generates a key and IV for the cipher |type| by iterating |md| |count| times using |data| and an optional |salt|, writing the result to |key| and |iv|. If not NULL, the |key| and |iv| buffers must have enough space to hold a key and IV for |type|, as returned by |EVP_CIPHER_key_length| and |EVP_CIPHER_iv_length|. This function returns the length of the key (without the IV) on success or zero on error.
EVP_Cipher(Pointer<EVP_CIPHER_CTX> ctx, Pointer<Uint8> out, Pointer<Uint8> in$, int in_len) → int
EVP_Cipher historically exposed an internal implementation detail of |ctx| and should not be used. Use |EVP_CipherUpdate| and |EVP_CipherFinal_ex| instead.
EVP_CIPHER_block_size(Pointer<EVP_CIPHER> cipher) → int
EVP_CIPHER_block_size returns the block size, in bytes, for |cipher|, or one if |cipher| is a stream cipher.
EVP_CIPHER_CTX_block_size(Pointer<EVP_CIPHER_CTX> ctx) → int
EVP_CIPHER_CTX_block_size returns the block size, in bytes, of the cipher underlying |ctx|, or one if the cipher is a stream cipher. It will crash if no cipher has been configured.
EVP_CIPHER_CTX_cipher(Pointer<EVP_CIPHER_CTX> ctx) → Pointer<EVP_CIPHER>
EVP_CIPHER_CTX_cipher returns the |EVP_CIPHER| underlying |ctx|, or NULL if none has been set.
EVP_CIPHER_CTX_cleanup(Pointer<EVP_CIPHER_CTX> ctx) → int
EVP_CIPHER_CTX_cleanup frees any memory referenced by |ctx|. It returns one.
EVP_CIPHER_CTX_copy(Pointer<EVP_CIPHER_CTX> out, Pointer<EVP_CIPHER_CTX> in$) → int
EVP_CIPHER_CTX_copy sets |out| to be a duplicate of the current state of |in|. The |out| argument must have been previously initialised.
EVP_CIPHER_CTX_ctrl(Pointer<EVP_CIPHER_CTX> ctx, int command, int arg, Pointer<Void> ptr) → int
EVP_CIPHER_CTX_ctrl is an |ioctl| like function. The |command| argument should be one of the |EVP_CTRL_*| values. The |arg| and |ptr| arguments are specific to the command in question.
EVP_CIPHER_CTX_encrypting(Pointer<EVP_CIPHER_CTX> ctx) → int
EVP_CIPHER_CTX_encrypting returns one if |ctx| is configured for encryption and zero otherwise.
EVP_CIPHER_CTX_flags(Pointer<EVP_CIPHER_CTX> ctx) → int
EVP_CIPHER_CTX_flags returns a value which is the OR of zero or more |EVP_CIPH_*| flags. It will crash if no cipher has been configured.
EVP_CIPHER_CTX_free(Pointer<EVP_CIPHER_CTX> ctx) → void
EVP_CIPHER_CTX_free calls |EVP_CIPHER_CTX_cleanup| on |ctx| and then frees |ctx| itself.
EVP_CIPHER_CTX_get_app_data(Pointer<EVP_CIPHER_CTX> ctx) → Pointer<Void>
EVP_CIPHER_CTX_get_app_data returns the opaque, application data pointer for |ctx|, or NULL if none has been set.
EVP_CIPHER_CTX_init(Pointer<EVP_CIPHER_CTX> ctx) → void
EVP_CIPHER_CTX_init initialises an, already allocated, |EVP_CIPHER_CTX|.
EVP_CIPHER_CTX_iv_length(Pointer<EVP_CIPHER_CTX> ctx) → int
EVP_CIPHER_CTX_iv_length returns the IV size, in bytes, of the cipher underlying |ctx|. It will crash if no cipher has been configured.
EVP_CIPHER_CTX_key_length(Pointer<EVP_CIPHER_CTX> ctx) → int
EVP_CIPHER_CTX_key_length returns the key size, in bytes, of the cipher underlying |ctx| or zero if no cipher has been configured.
EVP_CIPHER_CTX_mode(Pointer<EVP_CIPHER_CTX> ctx) → int
EVP_CIPHER_CTX_mode returns one of the |EVP_CIPH_*| cipher mode values enumerated below. It will crash if no cipher has been configured.
EVP_CIPHER_CTX_new() → Pointer<EVP_CIPHER_CTX>
EVP_CIPHER_CTX_new allocates a fresh |EVP_CIPHER_CTX|, calls |EVP_CIPHER_CTX_init| and returns it, or NULL on allocation failure.
EVP_CIPHER_CTX_nid(Pointer<EVP_CIPHER_CTX> ctx) → int
EVP_CIPHER_CTX_nid returns a NID identifying the |EVP_CIPHER| underlying |ctx| (e.g. |NID_aes_128_gcm|). It will crash if no cipher has been configured.
EVP_CIPHER_CTX_reset(Pointer<EVP_CIPHER_CTX> ctx) → int
EVP_CIPHER_CTX_reset calls |EVP_CIPHER_CTX_cleanup| followed by |EVP_CIPHER_CTX_init| and returns one.
EVP_CIPHER_CTX_set_app_data(Pointer<EVP_CIPHER_CTX> ctx, Pointer<Void> data) → void
EVP_CIPHER_CTX_set_app_data sets the opaque, application data pointer for |ctx| to |data|.
EVP_CIPHER_CTX_set_flags(Pointer<EVP_CIPHER_CTX> ctx, int flags) → void
EVP_CIPHER_CTX_set_flags does nothing.
EVP_CIPHER_CTX_set_key_length(Pointer<EVP_CIPHER_CTX> ctx, int key_len) → int
EVP_CIPHER_CTX_set_key_length sets the key length for |ctx|. This is only valid for ciphers that can take a variable length key. It returns one on success and zero on error.
EVP_CIPHER_CTX_set_padding(Pointer<EVP_CIPHER_CTX> ctx, int pad) → int
EVP_CIPHER_CTX_set_padding sets whether padding is enabled for |ctx| and returns one. Pass a non-zero |pad| to enable padding (the default) or zero to disable.
EVP_CIPHER_flags(Pointer<EVP_CIPHER> cipher) → int
EVP_CIPHER_flags returns a value which is the OR of zero or more |EVP_CIPH_*| flags.
EVP_CIPHER_iv_length(Pointer<EVP_CIPHER> cipher) → int
EVP_CIPHER_iv_length returns the IV size, in bytes, of |cipher|, or zero if |cipher| doesn't take an IV.
EVP_CIPHER_key_length(Pointer<EVP_CIPHER> cipher) → int
EVP_CIPHER_key_length returns the key size, in bytes, for |cipher|. If |cipher| can take a variable key length then this function returns the default key length and |EVP_CIPHER_flags| will return a value with |EVP_CIPH_VARIABLE_LENGTH| set.
EVP_CIPHER_mode(Pointer<EVP_CIPHER> cipher) → int
EVP_CIPHER_mode returns one of the cipher mode values enumerated below.
EVP_CIPHER_nid(Pointer<EVP_CIPHER> cipher) → int
EVP_CIPHER_nid returns a NID identifying |cipher|. (For example, |NID_aes_128_gcm|.)
EVP_CipherFinal(Pointer<EVP_CIPHER_CTX> ctx, Pointer<Uint8> out, Pointer<Int> out_len) → int
EVP_CipherFinal calls |EVP_CipherFinal_ex|.
EVP_CipherFinal_ex(Pointer<EVP_CIPHER_CTX> ctx, Pointer<Uint8> out, Pointer<Int> out_len) → int
EVP_CipherFinal_ex does the same as |EVP_CipherFinal_ex2|, except that no output size is given and thus no bounds checking is performed.
EVP_CipherFinal_ex2(Pointer<EVP_CIPHER_CTX> ctx, Pointer<Uint8> out, Pointer<Size> out_len, int max_out_len) → int
EVP_CipherFinal_ex2 calls either |EVP_EncryptFinal_ex2| or |EVP_DecryptFinal_ex2| depending on how |ctx| has been setup.
EVP_CipherInit(Pointer<EVP_CIPHER_CTX> ctx, Pointer<EVP_CIPHER> cipher, Pointer<Uint8> key, Pointer<Uint8> iv, int enc) → int
EVP_CipherInit acts like EVP_CipherInit_ex except that |EVP_CIPHER_CTX_init| is called on |cipher| first, if |cipher| is not NULL.
EVP_CipherInit_ex(Pointer<EVP_CIPHER_CTX> ctx, Pointer<EVP_CIPHER> cipher, Pointer<ENGINE> engine, Pointer<Uint8> key, Pointer<Uint8> iv, int enc) → int
EVP_CipherInit_ex configures |ctx| for a fresh encryption (or decryption, if |enc| is zero) operation using |cipher|. If |ctx| has been previously configured with a cipher then |cipher|, |key| and |iv| may be |NULL| and |enc| may be -1 to reuse the previous values. The operation will use |key| as the key and |iv| as the IV (if any). These should have the correct lengths given by |EVP_CIPHER_key_length| and |EVP_CIPHER_iv_length|. It returns one on success and zero on error.
EVP_CipherUpdate(Pointer<EVP_CIPHER_CTX> ctx, Pointer<Uint8> out, Pointer<Int> out_len, Pointer<Uint8> in$, int in_len) → int
EVP_CipherUpdate does the same as |EVP_CipherUpdate_ex|, except that no output size is given and thus no bounds checking is performed.
EVP_CipherUpdate_ex(Pointer<EVP_CIPHER_CTX> ctx, Pointer<Uint8> out, Pointer<Size> out_len, int max_out_len, Pointer<Uint8> in$, int in_len) → int
EVP_CipherUpdate_ex calls either |EVP_EncryptUpdate_ex| or |EVP_DecryptUpdate_ex| depending on how |ctx| has been setup.
EVP_CipherUpdateAAD(Pointer<EVP_CIPHER_CTX> ctx, Pointer<Uint8> in$, int in_len) → int
EVP_CipherUpdateAAD adds |in_len| bytes from |in| to the AAD. The AAD must be fully specified in this way before any plaintext or ciphertext is supplied to the other functions. Please consider moving to the |EVP_AEAD| APIs instead.
EVP_cleanup() → void
EVP_cleanup does nothing.
EVP_DecodeBase64(Pointer<Uint8> out, Pointer<Size> out_len, int max_out, Pointer<Uint8> in$, int in_len) → int
EVP_DecodeBase64 decodes |in_len| bytes from base64 and writes |*out_len| bytes to |out|. |max_out| is the size of the output buffer. If it is not enough for the maximum output size, the operation fails. It returns one on success or zero on error.
EVP_DecodeBlock(Pointer<Uint8> dst, Pointer<Uint8> src, int src_len) → int
EVP_DecodeBlock encodes |src_len| bytes from |src| and writes the result to |dst|. It returns the number of bytes written or -1 on error.
EVP_DecodedLength(Pointer<Size> out_len, int len) → int
EVP_DecodedLength sets |*out_len| to the maximum number of bytes that will be needed to call |EVP_DecodeBase64| on an input of length |len|. It returns one on success or zero if |len| is not a valid length for a base64-encoded string.
EVP_DecodeFinal(Pointer<EVP_ENCODE_CTX> ctx, Pointer<Uint8> out, Pointer<Int> out_len) → int
EVP_DecodeFinal flushes any remaining output bytes from |ctx| to |out| and sets |*out_len| to the number of bytes written. It returns one on success and minus one on error.
EVP_DecodeInit(Pointer<EVP_ENCODE_CTX> ctx) → void
EVP_DecodeInit initialises |*ctx|, which is typically stack allocated, for a decoding operation.
EVP_DecodeUpdate(Pointer<EVP_ENCODE_CTX> ctx, Pointer<Uint8> out, Pointer<Int> out_len, Pointer<Uint8> in$, int in_len) → int
EVP_DecodeUpdate decodes |in_len| bytes from |in| and writes the decoded data to |out| and sets |*out_len| to the number of bytes written. Some state may be contained in |ctx| so |EVP_DecodeFinal| must be used to flush it before using the encoded data.
EVP_DecryptFinal(Pointer<EVP_CIPHER_CTX> ctx, Pointer<Uint8> out, Pointer<Int> out_len) → int
EVP_DecryptFinal calls |EVP_DecryptFinal_ex|.
EVP_DecryptFinal_ex(Pointer<EVP_CIPHER_CTX> ctx, Pointer<Uint8> out, Pointer<Int> out_len) → int
EVP_DecryptFinal_ex does the same as |EVP_DecryptFinal_ex2|, except that no output size is given and thus no bounds checking is performed.
EVP_DecryptFinal_ex2(Pointer<EVP_CIPHER_CTX> ctx, Pointer<Uint8> out, Pointer<Size> out_len, int max_out_len) → int
EVP_DecryptFinal_ex2 finishes a decryption operation and writes up to |max_out| bytes of output to out. On success, it sets |*out_len| to the number of bytes written and returns one. Otherwise, it returns zero.
EVP_DecryptInit(Pointer<EVP_CIPHER_CTX> ctx, Pointer<EVP_CIPHER> cipher, Pointer<Uint8> key, Pointer<Uint8> iv) → int
EVP_DecryptInit calls |EVP_CipherInit| with |enc| equal to zero.
EVP_DecryptInit_ex(Pointer<EVP_CIPHER_CTX> ctx, Pointer<EVP_CIPHER> cipher, Pointer<ENGINE> impl, Pointer<Uint8> key, Pointer<Uint8> iv) → int
EVP_DecryptInit_ex calls |EVP_CipherInit_ex| with |enc| equal to zero.
EVP_DecryptUpdate(Pointer<EVP_CIPHER_CTX> ctx, Pointer<Uint8> out, Pointer<Int> out_len, Pointer<Uint8> in$, int in_len) → int
EVP_DecryptUpdate does the same as |EVP_DecryptUpdate_ex|, except that no output size is given and thus no bounds checking is performed.
EVP_DecryptUpdate_ex(Pointer<EVP_CIPHER_CTX> ctx, Pointer<Uint8> out, Pointer<Size> out_len, int max_out_len, Pointer<Uint8> in$, int in_len) → int
EVP_DecryptUpdate_ex decrypts |in_len| bytes from |in| and writes up to |max_out| bytes of plaintext to |out|. On success, it sets |*out_len| to the number of output bytes and returns one. Otherwise, it returns zero.
EVP_default_properties_is_fips_enabled(Pointer<OSSL_LIB_CTX> libctx) → int
EVP_default_properties_is_fips_enabled calls |FIPS_mode|.
EVP_des_cbc() → Pointer<EVP_CIPHER>
EVP_des_ecb() → Pointer<EVP_CIPHER>
EVP_des_ede() → Pointer<EVP_CIPHER>
EVP_des_ede3() → Pointer<EVP_CIPHER>
EVP_des_ede3_cbc() → Pointer<EVP_CIPHER>
EVP_des_ede3_ecb() → Pointer<EVP_CIPHER>
EVP_des_ede3_ecb is an alias for |EVP_des_ede3|. Use the former instead.
EVP_des_ede_cbc() → Pointer<EVP_CIPHER>
EVP_Digest(Pointer<Void> data, int len, Pointer<Uint8> md_out, Pointer<UnsignedInt> md_out_size, Pointer<EVP_MD> type, Pointer<ENGINE> impl) → int
EVP_Digest performs a complete hashing operation in one call. It hashes |len| bytes from |data| and writes the digest to |md_out|. |EVP_MD_CTX_size| bytes are written, which is at most |EVP_MAX_MD_SIZE|. If |out_size| is not NULL then |*out_size| is set to the number of bytes written. It returns one on success and zero otherwise.
EVP_DigestFinal(Pointer<EVP_MD_CTX> ctx, Pointer<Uint8> md_out, Pointer<UnsignedInt> out_size) → int
EVP_DigestFinal acts like |EVP_DigestFinal_ex| except that |EVP_MD_CTX_cleanup| is called on |ctx| before returning.
EVP_DigestFinal_ex(Pointer<EVP_MD_CTX> ctx, Pointer<Uint8> md_out, Pointer<UnsignedInt> out_size) → int
EVP_DigestFinal_ex finishes the digest in |ctx| and writes the output to |md_out|. |EVP_MD_CTX_size| bytes are written, which is at most |EVP_MAX_MD_SIZE|. If |out_size| is not NULL then |*out_size| is set to the number of bytes written. It returns one. After this call, the hash cannot be updated or finished again until |EVP_DigestInit_ex| is called to start another hashing operation.
EVP_DigestFinalXOF(Pointer<EVP_MD_CTX> ctx, Pointer<Uint8> out, int len) → int
EVP_DigestFinalXOF returns zero and adds an error to the error queue. BoringSSL does not support any XOF digests.
EVP_DigestInit(Pointer<EVP_MD_CTX> ctx, Pointer<EVP_MD> type) → int
EVP_DigestInit acts like |EVP_DigestInit_ex| except that |ctx| is initialised before use.
EVP_DigestInit_ex(Pointer<EVP_MD_CTX> ctx, Pointer<EVP_MD> type, Pointer<ENGINE> engine) → int
EVP_DigestInit_ex configures |ctx|, which must already have been initialised, for a fresh hashing operation using |type|. It returns one on success and zero on allocation failure.
EVP_DigestSign(Pointer<EVP_MD_CTX> ctx, Pointer<Uint8> out_sig, Pointer<Size> out_sig_len, Pointer<Uint8> data, int data_len) → int
EVP_DigestSign signs |data_len| bytes from |data| using |ctx|. If |out_sig| is NULL then |*out_sig_len| is set to the maximum number of output bytes. Otherwise, on entry, |*out_sig_len| must contain the length of the |out_sig| buffer. If the call is successful, the signature is written to |out_sig| and |*out_sig_len| is set to its length.
EVP_DigestSignFinal(Pointer<EVP_MD_CTX> ctx, Pointer<Uint8> out_sig, Pointer<Size> out_sig_len) → int
EVP_DigestSignFinal signs the data that has been included by one or more calls to |EVP_DigestSignUpdate|. If |out_sig| is NULL then |*out_sig_len| is set to the maximum number of output bytes. Otherwise, on entry, |*out_sig_len| must contain the length of the |out_sig| buffer. If the call is successful, the signature is written to |out_sig| and |*out_sig_len| is set to its length.
EVP_DigestSignInit(Pointer<EVP_MD_CTX> ctx, Pointer<Pointer<EVP_PKEY_CTX>> pctx, Pointer<EVP_MD> type, Pointer<ENGINE> e, Pointer<EVP_PKEY> pkey) → int
EVP_DigestSignInit sets up |ctx| for a signing operation with |type| and |pkey|. The |ctx| argument must have been initialised with |EVP_MD_CTX_init|. If |pctx| is not NULL, the |EVP_PKEY_CTX| of the signing operation will be written to |*pctx|; this can be used to set alternative signing options.
EVP_DigestSignUpdate(Pointer<EVP_MD_CTX> ctx, Pointer<Void> data, int len) → int
EVP_DigestSignUpdate appends |len| bytes from |data| to the data which will be signed in |EVP_DigestSignFinal|. It returns one.
EVP_DigestUpdate(Pointer<EVP_MD_CTX> ctx, Pointer<Void> data, int len) → int
EVP_DigestUpdate hashes |len| bytes from |data| into the hashing operation in |ctx|. It returns one.
EVP_DigestVerify(Pointer<EVP_MD_CTX> ctx, Pointer<Uint8> sig, int sig_len, Pointer<Uint8> data, int len) → int
EVP_DigestVerify verifies that |sig_len| bytes from |sig| are a valid signature for |data|. It returns one on success or zero on error.
EVP_DigestVerifyFinal(Pointer<EVP_MD_CTX> ctx, Pointer<Uint8> sig, int sig_len) → int
EVP_DigestVerifyFinal verifies that |sig_len| bytes of |sig| are a valid signature for the data that has been included by one or more calls to |EVP_DigestVerifyUpdate|. It returns one on success and zero otherwise.
EVP_DigestVerifyInit(Pointer<EVP_MD_CTX> ctx, Pointer<Pointer<EVP_PKEY_CTX>> pctx, Pointer<EVP_MD> type, Pointer<ENGINE> e, Pointer<EVP_PKEY> pkey) → int
EVP_DigestVerifyInit sets up |ctx| for a signature verification operation with |type| and |pkey|. The |ctx| argument must have been initialised with |EVP_MD_CTX_init|. If |pctx| is not NULL, the |EVP_PKEY_CTX| of the signing operation will be written to |*pctx|; this can be used to set alternative signing options.
EVP_DigestVerifyUpdate(Pointer<EVP_MD_CTX> ctx, Pointer<Void> data, int len) → int
EVP_DigestVerifyUpdate appends |len| bytes from |data| to the data which will be verified by |EVP_DigestVerifyFinal|. It returns one.
EVP_enc_null() → Pointer<EVP_CIPHER>
EVP_enc_null returns a 'cipher' that passes plaintext through as ciphertext.
EVP_ENCODE_CTX_free(Pointer<EVP_ENCODE_CTX> ctx) → void
EVP_ENCODE_CTX_free releases memory associated with |ctx|.
EVP_ENCODE_CTX_new() → Pointer<EVP_ENCODE_CTX>
EVP_ENCODE_CTX_new returns a newly-allocated |EVP_ENCODE_CTX| or NULL on error. The caller must release the result with |EVP_ENCODE_CTX_free| when done.
EVP_EncodeBlock(Pointer<Uint8> dst, Pointer<Uint8> src, int src_len) → int
EVP_EncodeBlock encodes |src_len| bytes from |src| and writes the result to |dst| with a trailing NUL. It returns the number of bytes written, not including this trailing NUL.
EVP_EncodedLength(Pointer<Size> out_len, int len) → int
EVP_EncodedLength sets |*out_len| to the number of bytes that will be needed to call |EVP_EncodeBlock| on an input of length |len|. This includes the final NUL that |EVP_EncodeBlock| writes. It returns one on success or zero on error.
EVP_EncodeFinal(Pointer<EVP_ENCODE_CTX> ctx, Pointer<Uint8> out, Pointer<Int> out_len) → void
EVP_EncodeFinal flushes any remaining output bytes from |ctx| to |out| and sets |*out_len| to the number of bytes written.
EVP_EncodeInit(Pointer<EVP_ENCODE_CTX> ctx) → void
EVP_EncodeInit initialises |*ctx|, which is typically stack allocated, for an encoding operation.
EVP_EncodeUpdate(Pointer<EVP_ENCODE_CTX> ctx, Pointer<Uint8> out, Pointer<Int> out_len, Pointer<Uint8> in$, int in_len) → void
EVP_EncodeUpdate encodes |in_len| bytes from |in| and writes an encoded version of them to |out| and sets |*out_len| to the number of bytes written. Some state may be contained in |ctx| so |EVP_EncodeFinal| must be used to flush it before using the encoded data.
EVP_EncryptFinal(Pointer<EVP_CIPHER_CTX> ctx, Pointer<Uint8> out, Pointer<Int> out_len) → int
EVP_EncryptFinal calls |EVP_EncryptFinal_ex|.
EVP_EncryptFinal_ex(Pointer<EVP_CIPHER_CTX> ctx, Pointer<Uint8> out, Pointer<Int> out_len) → int
EVP_EncryptFinal_ex does the same as |EVP_EncryptFinal_ex2|, except that no output size is given and thus no bounds checking is performed.
EVP_EncryptFinal_ex2(Pointer<EVP_CIPHER_CTX> ctx, Pointer<Uint8> out, Pointer<Size> out_len, int max_out_len) → int
EVP_EncryptFinal_ex2 finishes an encryption operation and writes up to |max_out| bytes of output to out. On success, it sets |*out_len| to the number of bytes written and returns one. Otherwise, it returns zero.
EVP_EncryptInit(Pointer<EVP_CIPHER_CTX> ctx, Pointer<EVP_CIPHER> cipher, Pointer<Uint8> key, Pointer<Uint8> iv) → int
EVP_EncryptInit calls |EVP_CipherInit| with |enc| equal to one.
EVP_EncryptInit_ex(Pointer<EVP_CIPHER_CTX> ctx, Pointer<EVP_CIPHER> cipher, Pointer<ENGINE> impl, Pointer<Uint8> key, Pointer<Uint8> iv) → int
EVP_EncryptInit_ex calls |EVP_CipherInit_ex| with |enc| equal to one.
EVP_EncryptUpdate(Pointer<EVP_CIPHER_CTX> ctx, Pointer<Uint8> out, Pointer<Int> out_len, Pointer<Uint8> in$, int in_len) → int
EVP_EncryptUpdate does the same as |EVP_EncryptUpdate_ex|, except that no output size is given and thus no bounds checking is performed.
EVP_EncryptUpdate_ex(Pointer<EVP_CIPHER_CTX> ctx, Pointer<Uint8> out, Pointer<Size> out_len, int max_out_len, Pointer<Uint8> in$, int in_len) → int
EVP_EncryptUpdate_ex encrypts |in_len| bytes from |in| and writes up to |max_out| bytes of ciphertext to |out|. On success, it sets |*out_len| to the number of output bytes and returns one. Otherwise, it returns zero.
EVP_get_cipherbyname(Pointer<Char> name) → Pointer<EVP_CIPHER>
EVP_get_cipherbyname returns an |EVP_CIPHER| given a human readable name in |name|, or NULL if the name is unknown. Note using this function links almost every cipher implemented by BoringSSL into the binary, not just the ones the caller requests. Size-conscious callers, such as client software, should not use this function.
EVP_get_cipherbynid(int nid) → Pointer<EVP_CIPHER>
EVP_get_cipherbynid returns the cipher corresponding to the given NID, or NULL if no such cipher is known. Note using this function links almost every cipher implemented by BoringSSL into the binary, whether the caller uses them or not. Size-conscious callers, such as client software, should not use this function.
EVP_get_digestbyname(Pointer<Char> name) → Pointer<EVP_MD>
EVP_get_digestbyname returns an |EVP_MD| given a human readable name in |name|, or NULL if the name is unknown.
EVP_get_digestbynid(int nid) → Pointer<EVP_MD>
EVP_get_digestbynid returns an |EVP_MD| for the given NID, or NULL if no such digest is known.
EVP_get_digestbyobj(Pointer<ASN1_OBJECT> obj) → Pointer<EVP_MD>
EVP_get_digestbyobj returns an |EVP_MD| for the given |ASN1_OBJECT|, or NULL if no such digest is known.
EVP_has_aes_hardware() → int
EVP_has_aes_hardware returns one if we enable hardware support for fast and constant-time AES-GCM.
EVP_KEM_ciphertext_len(Pointer<EVP_KEM> kem) → int
EVP_KEM_ciphertext_len returns the fixed length, in bytes, of a ciphertext produced and consumed by |kem|.
EVP_KEM_decap(Pointer<EVP_KEM> kem, Pointer<Uint8> out_secret, int secret_len, Pointer<Uint8> ciphertext, int ciphertext_len, Pointer<EVP_PKEY> key) → int
EVP_KEM_decap uses |kem| to decapsulate a |ciphertext| of length |ciphertext_len|, using |key| as a decapsulation key. It outputs a shared secret of length |secret_len| into |*out_secret|. |key| must be a private key of the type expected by |kem|. |secret_len| must match the output of |EVP_KEM_secret_len| when called with |kem|. This function returns one on success or zero on failure. If |ciphertext| has been corrupted, the function may fail or it may output a shared secret that appears to be random. Any subsequent symmetric encryption using |*out_secret| must use an authenticated encryption scheme in order to discover the decapsulation failure.
EVP_KEM_encap(Pointer<EVP_KEM> kem, Pointer<Uint8> out_ciphertext, int ciphertext_len, Pointer<Uint8> out_secret, int secret_len, Pointer<EVP_PKEY> peer_key) → int
EVP_KEM_encap uses |kem| to encapsulate a |peer_key|. It outputs a ciphertext of length |ciphertext_len| into |*out_ciphertext| and outputs a shared secret of length |secret_len| into |*out_secret|. |peer_key| must be a public key of the type expected by |kem|. |ciphertext_len| and |secret_len| must match the output of |EVP_KEM_ciphertext_len| and |EVP_KEM_secret_len|, respectively, when called with |kem|. This function returns one on success or zero on failure.
EVP_kem_ml_kem_1024() → Pointer<EVP_KEM>
EVP_kem_ml_kem_768() → Pointer<EVP_KEM>
EVP_kem_ml_kem_* implement ML-KEM, defined in FIPS 203.
EVP_KEM_secret_len(Pointer<EVP_KEM> kem) → int
EVP_KEM_secret_len returns the fixed length, in bytes, of the shared secret produced and consumed by |kem|.
EVP_kem_xwing() → Pointer<EVP_KEM>
EVP_kem_xwing implements the hybrid KEM known as X-Wing or MLKEM768-X25519, defined in draft-irtf-cfrg-concrete-hybrid-kems.
EVP_marshal_digest_algorithm(Pointer<CBB> cbb, Pointer<EVP_MD> md) → int
EVP_marshal_digest_algorithm marshals |md| as an AlgorithmIdentifier structure and appends the result to |cbb|. It returns one on success and zero on error. It sets the parameters field to NULL. Use |EVP_marshal_digest_algorithm_no_params| to omit the parameters instead.
EVP_marshal_digest_algorithm_no_params(Pointer<CBB> cbb, Pointer<EVP_MD> md) → int
EVP_marshal_digest_algorithm_no_params behaves like |EVP_marshal_digest_algorithm| but omits the parameters field.
EVP_marshal_private_key(Pointer<CBB> cbb, Pointer<EVP_PKEY> key) → int
EVP_marshal_private_key marshals |key| as a DER-encoded PrivateKeyInfo structure (RFC 5208) and appends the result to |cbb|. It returns one on success and zero on error.
EVP_marshal_public_key(Pointer<CBB> cbb, Pointer<EVP_PKEY> key) → int
EVP_marshal_public_key marshals |key| as a DER-encoded SubjectPublicKeyInfo structure (RFC 5280) and appends the result to |cbb|. It returns one on success and zero on error.
EVP_md4() → Pointer<EVP_MD>
Hash algorithms.
EVP_md5() → Pointer<EVP_MD>
EVP_md5_sha1() → Pointer<EVP_MD>
EVP_md5_sha1 is a TLS-specific |EVP_MD| which computes the concatenation of MD5 and SHA-1, as used in TLS 1.1 and below.
EVP_MD_block_size(Pointer<EVP_MD> md) → int
EVP_MD_block_size returns the native block-size of |md|, in bytes.
EVP_MD_CTX_block_size(Pointer<EVP_MD_CTX> ctx) → int
EVP_MD_CTX_block_size returns the block size of the digest function used by |ctx|, in bytes. It will crash if a digest hasn't been set on |ctx|.
EVP_MD_CTX_cleanse(Pointer<EVP_MD_CTX> ctx) → void
EVP_MD_CTX_cleanse zeros the digest state in |ctx| and then performs the actions of |EVP_MD_CTX_cleanup|. Note that some |EVP_MD_CTX| objects contain more than just a digest (e.g. those resulting from |EVP_DigestSignInit|) but this function does not zero out more than just the digest state even in that case.
EVP_MD_CTX_cleanup(Pointer<EVP_MD_CTX> ctx) → int
EVP_MD_CTX_cleanup frees any resources owned by |ctx| and resets it to a freshly initialised state. It does not free |ctx| itself. It returns one.
EVP_MD_CTX_copy(Pointer<EVP_MD_CTX> out, Pointer<EVP_MD_CTX> in$) → int
EVP_MD_CTX_copy sets |out|, which must /not/ be initialised, to be a copy of |in|. It returns one on success and zero on error.
EVP_MD_CTX_copy_ex(Pointer<EVP_MD_CTX> out, Pointer<EVP_MD_CTX> in$) → int
EVP_MD_CTX_copy_ex sets |out|, which must already be initialised, to be a copy of |in|. It returns one on success and zero on allocation failure.
EVP_MD_CTX_create() → Pointer<EVP_MD_CTX>
EVP_MD_CTX_create calls |EVP_MD_CTX_new|.
EVP_MD_CTX_destroy(Pointer<EVP_MD_CTX> ctx) → void
EVP_MD_CTX_destroy calls |EVP_MD_CTX_free|.
EVP_MD_CTX_free(Pointer<EVP_MD_CTX> ctx) → void
EVP_MD_CTX_free calls |EVP_MD_CTX_cleanup| and then frees |ctx| itself.
EVP_MD_CTX_get0_md(Pointer<EVP_MD_CTX> ctx) → Pointer<EVP_MD>
EVP_MD_CTX_get0_md returns the underlying digest function, or NULL if one has not been set.
EVP_MD_CTX_init(Pointer<EVP_MD_CTX> ctx) → void
EVP_MD_CTX_init initialises an, already allocated, |EVP_MD_CTX|. This is the same as setting the structure to zero.
EVP_MD_CTX_md(Pointer<EVP_MD_CTX> ctx) → Pointer<EVP_MD>
EVP_MD_CTX_md returns the underlying digest function, or NULL if one has not been set. (This is the same as |EVP_MD_CTX_get0_md| but OpenSSL has deprecated this spelling.)
EVP_MD_CTX_move(Pointer<EVP_MD_CTX> out, Pointer<EVP_MD_CTX> in$) → void
EVP_MD_CTX_move sets |out|, which must already be initialised, to the hash state in |in|. |in| is mutated and left in an empty state.
EVP_MD_CTX_new() → Pointer<EVP_MD_CTX>
EVP_MD_CTX_new allocates and initialises a fresh |EVP_MD_CTX| and returns it, or NULL on allocation failure. The caller must use |EVP_MD_CTX_free| to release the resulting object.
EVP_MD_CTX_pkey_ctx(Pointer<EVP_MD_CTX> ctx) → Pointer<EVP_PKEY_CTX>
EVP_MD_CTX_pkey_ctx returns the |EVP_PKEY_CTX| used to configure additional parameters on |ctx| if |ctx| is used for a sign or verify operation with |EVP_DigestSignInit| or |EVP_DigestVerifyInit|. It returns NULL otherwise.
EVP_MD_CTX_reset(Pointer<EVP_MD_CTX> ctx) → int
EVP_MD_CTX_reset calls |EVP_MD_CTX_cleanup| followed by |EVP_MD_CTX_init|. It returns one.
EVP_MD_CTX_set_flags(Pointer<EVP_MD_CTX> ctx, int flags) → void
EVP_MD_CTX_set_flags does nothing.
EVP_MD_CTX_size(Pointer<EVP_MD_CTX> ctx) → int
EVP_MD_CTX_size returns the digest size of |ctx|, in bytes. It will crash if a digest hasn't been set on |ctx|.
EVP_MD_CTX_type(Pointer<EVP_MD_CTX> ctx) → int
EVP_MD_CTX_type returns a NID describing the digest function used by |ctx|. (For example, |NID_sha256|.) It will crash if a digest hasn't been set on |ctx|.
EVP_MD_fetch(Pointer<OSSL_LIB_CTX> libctx, Pointer<Char> name, Pointer<Char> propq) → Pointer<EVP_MD>
EVP_MD_fetch behaves like |EVP_get_digestbyname|. |libctx| and |propq| are ignored. Although it returns a non-const pointer, |EVP_MD|s in BoringSSL are static and do not need to be freed.
EVP_MD_flags(Pointer<EVP_MD> md) → int
EVP_MD_flags returns the flags for |md|, which is a set of |EVP_MD_FLAG_*| values, ORed together.
EVP_MD_free(Pointer<EVP_MD> md) → void
EVP_MD_free does nothing. |EVP_MD|s in BoringSSL are static.
EVP_MD_meth_get_flags(Pointer<EVP_MD> md) → int
EVP_MD_meth_get_flags calls |EVP_MD_flags|.
EVP_MD_nid(Pointer<EVP_MD> md) → int
EVP_MD_nid calls |EVP_MD_type|.
EVP_MD_size(Pointer<EVP_MD> md) → int
EVP_MD_size returns the digest size of |md|, in bytes.
EVP_MD_type(Pointer<EVP_MD> md) → int
EVP_MD_type returns a NID identifying |md|. (For example, |NID_sha256|.)
EVP_MD_up_ref(Pointer<EVP_MD> md) → int
EVP_MD_up_ref returns one. |EVP_MD|s in BoringSSL are static.
EVP_parse_digest_algorithm(Pointer<CBS> cbs) → Pointer<EVP_MD>
EVP_parse_digest_algorithm parses an AlgorithmIdentifier structure containing a hash function OID (for example, 2.16.840.1.101.3.4.2.1 is SHA-256) and advances |cbs|. The parameters field may either be omitted or a NULL. It returns the digest function or NULL on error.
EVP_parse_digest_algorithm_nid(Pointer<CBS> cbs) → int
EVP_parse_digest_algorithm_nid behaves like |EVP_parse_digest_algorithm| except it returns |NID_undef| on error and some other value on success. This may be used to avoid depending on every digest algorithm in the library.
EVP_parse_private_key(Pointer<CBS> cbs) → Pointer<EVP_PKEY>
EVP_parse_private_key decodes a DER-encoded PrivateKeyInfo structure (RFC 5208) from |cbs| and advances |cbs|. It returns a newly-allocated |EVP_PKEY| or NULL on error.
EVP_parse_public_key(Pointer<CBS> cbs) → Pointer<EVP_PKEY>
EVP_parse_public_key decodes a DER-encoded SubjectPublicKeyInfo structure (RFC 5280) from |cbs| and advances |cbs|. It returns a newly-allocated |EVP_PKEY| or NULL on error.
EVP_PBE_scrypt(Pointer<Char> password, int password_len, Pointer<Uint8> salt, int salt_len, int N, int r, int p, int max_mem, Pointer<Uint8> out_key, int key_len) → int
EVP_PBE_scrypt expands |password| into a secret key of length |key_len| using scrypt, as described in RFC 7914, and writes the result to |out_key|. It returns one on success and zero on allocation failure, if the memory required for the operation exceeds |max_mem|, or if any of the parameters are invalid as described below.
EVP_PKCS82PKEY(Pointer<PKCS8_PRIV_KEY_INFO> p8) → Pointer<EVP_PKEY>
EVP_PKCS82PKEY returns |p8| as a newly-allocated |EVP_PKEY|, or NULL if the key was unsupported or could not be decoded. The caller must release the result with |EVP_PKEY_free| when done.
EVP_PKEY2PKCS8(Pointer<EVP_PKEY> pkey) → Pointer<PKCS8_PRIV_KEY_INFO>
EVP_PKEY2PKCS8 encodes |pkey| as a PKCS#8 PrivateKeyInfo (RFC 5208), represented as a newly-allocated |PKCS8_PRIV_KEY_INFO|, or NULL on error. The caller must release the result with |PKCS8_PRIV_KEY_INFO_free| when done.
EVP_PKEY_assign(Pointer<EVP_PKEY> pkey, int type, Pointer<Void> key) → int
EVP_PKEY_assign sets the underlying key of |pkey| to |key|, which must be of the given type. If successful, it returns one. If the |type| argument is not one of |EVP_PKEY_RSA|, |EVP_PKEY_DSA|, or |EVP_PKEY_EC| values or if |key| is NULL, it returns zero. This function may not be used with other |EVP_PKEY_*| types.
EVP_PKEY_assign_DH(Pointer<EVP_PKEY> pkey, Pointer<DH> key) → int
EVP_PKEY_assign_DSA(Pointer<EVP_PKEY> pkey, Pointer<DSA> key) → int
EVP_PKEY_assign_EC_KEY(Pointer<EVP_PKEY> pkey, Pointer<EC_KEY> key) → int
EVP_PKEY_assign_RSA(Pointer<EVP_PKEY> pkey, Pointer<RSA> key) → int
EVP_PKEY_base_id(Pointer<EVP_PKEY> pkey) → int
EVP_PKEY_base_id calls |EVP_PKEY_id|.
EVP_PKEY_bits(Pointer<EVP_PKEY> pkey) → int
EVP_PKEY_bits returns the "size", in bits, of |pkey|. For an RSA key, this returns the bit length of the modulus. For an EC key, this returns the bit length of the group order.
EVP_PKEY_cmp(Pointer<EVP_PKEY> a, Pointer<EVP_PKEY> b) → int
EVP_PKEY_cmp calls |EVP_PKEY_eq|. It returns one if public keys are equal and zero otherwise.
EVP_PKEY_cmp_parameters(Pointer<EVP_PKEY> a, Pointer<EVP_PKEY> b) → int
EVP_PKEY_cmp_parameters calls |EVP_PKEY_parameters_eq|. It returns one if parameters are equal and zero otherwise.
EVP_PKEY_copy_parameters(Pointer<EVP_PKEY> to, Pointer<EVP_PKEY> from) → int
EVP_PKEY_copy_parameters sets the parameters of |to| to equal the parameters of |from|. It returns one on success and zero on error.
EVP_PKEY_copy_public(Pointer<EVP_PKEY> pkey) → Pointer<EVP_PKEY>
EVP_PKEY_copy_public returns a newly-allocated |EVP_PKEY| that contains only the public key of |pkey|, or NULL on error. Parameters, if relevant for the key type, are also copied.
EVP_PKEY_CTX_dup(Pointer<EVP_PKEY_CTX> ctx) → Pointer<EVP_PKEY_CTX>
EVP_PKEY_CTX_dup allocates a fresh |EVP_PKEY_CTX| and sets it equal to the state of |ctx|. It returns the fresh |EVP_PKEY_CTX| or NULL on error.
EVP_PKEY_CTX_free(Pointer<EVP_PKEY_CTX> ctx) → void
EVP_PKEY_CTX_free frees |ctx| and the data it owns.
EVP_PKEY_CTX_get0_pkey(Pointer<EVP_PKEY_CTX> ctx) → Pointer<EVP_PKEY>
EVP_PKEY_CTX_get0_pkey returns the |EVP_PKEY| associated with |ctx|.
EVP_PKEY_CTX_get0_rsa_oaep_label(Pointer<EVP_PKEY_CTX> ctx, Pointer<Pointer<Uint8>> out_label) → int
EVP_PKEY_CTX_get0_rsa_oaep_label sets |*out_label| to point to the internal buffer containing the OAEP label (which may be NULL) and returns the length of the label or a negative value on error.
EVP_PKEY_CTX_get_rsa_mgf1_md(Pointer<EVP_PKEY_CTX> ctx, Pointer<Pointer<EVP_MD>> out_md) → int
EVP_PKEY_CTX_get_rsa_mgf1_md sets |*out_md| to the digest function used in MGF1. Returns one on success or zero on error.
EVP_PKEY_CTX_get_rsa_oaep_md(Pointer<EVP_PKEY_CTX> ctx, Pointer<Pointer<EVP_MD>> out_md) → int
EVP_PKEY_CTX_get_rsa_oaep_md sets |*out_md| to the digest function used in OAEP padding. Returns one on success or zero on error.
EVP_PKEY_CTX_get_rsa_padding(Pointer<EVP_PKEY_CTX> ctx, Pointer<Int> out_padding) → int
EVP_PKEY_CTX_get_rsa_padding sets |out_padding| to the current padding value, which is one of the |RSA__PADDING| values. Returns one on success or zero on error.
EVP_PKEY_CTX_get_rsa_pss_saltlen(Pointer<EVP_PKEY_CTX> ctx, Pointer<Int> out_salt_len) → int
EVP_PKEY_CTX_get_rsa_pss_saltlen sets |*out_salt_len| to the salt length of a PSS-padded signature. See the documentation for |EVP_PKEY_CTX_set_rsa_pss_saltlen| for details of the special values that it can take.
EVP_PKEY_CTX_get_signature_md(Pointer<EVP_PKEY_CTX> ctx, Pointer<Pointer<EVP_MD>> out_md) → int
EVP_PKEY_CTX_get_signature_md sets |*out_md| to the digest to be used in a signature operation. It returns one on success or zero on error.
EVP_PKEY_CTX_new(Pointer<EVP_PKEY> pkey, Pointer<ENGINE> e) → Pointer<EVP_PKEY_CTX>
EVP_PKEY_CTX_new allocates a fresh |EVP_PKEY_CTX| for use with |pkey|. It returns the context or NULL on error.
EVP_PKEY_CTX_new_id(int id, Pointer<ENGINE> e) → Pointer<EVP_PKEY_CTX>
EVP_PKEY_CTX_new_id allocates a fresh |EVP_PKEY_CTX| for a key of type |id| (e.g. |EVP_PKEY_HMAC|). This can be used for key generation where |EVP_PKEY_CTX_new| can't be used because there isn't an |EVP_PKEY| to pass it. It returns the context or NULL on error.
EVP_PKEY_CTX_set0_rsa_oaep_label(Pointer<EVP_PKEY_CTX> ctx, Pointer<Uint8> label, int label_len) → int
EVP_PKEY_CTX_set0_rsa_oaep_label sets |label_len| bytes from |label| as the label used in OAEP. DANGER: On success, this call takes ownership of |label| and will call |OPENSSL_free| on it when |ctx| is destroyed.
EVP_PKEY_CTX_set1_signature_context_string(Pointer<EVP_PKEY_CTX> ctx, Pointer<Uint8> context, int context_len) → int
EVP_PKEY_CTX_set1_signature_context_string sets the context string for a signature or verification operation to |context|. It returns one success and zero on error. The context string is an additional input to some signature algorithms, such as ML-DSA, to separate different uses of the same key. This is known as domain separation. Section 8.3 of RFC 8032 provides some additional guidance on context strings.
EVP_PKEY_CTX_set_dh_pad(Pointer<EVP_PKEY_CTX> ctx, int pad) → int
EVP_PKEY_CTX_set_dh_pad configures configures whether |ctx|, which must be an |EVP_PKEY_derive| operation, configures the handling of leading zeros in the Diffie-Hellman shared secret. If |pad| is zero, leading zeros are removed from the secret. If |pad| is non-zero, the fixed-width shared secret is used unmodified, as in PKCS #3. If this function is not called, the default is to remove leading zeros.
EVP_PKEY_CTX_set_dsa_paramgen_bits(Pointer<EVP_PKEY_CTX> ctx, int nbits) → int
EVP_PKEY_CTX_set_dsa_paramgen_bits returns zero.
EVP_PKEY_CTX_set_dsa_paramgen_q_bits(Pointer<EVP_PKEY_CTX> ctx, int qbits) → int
EVP_PKEY_CTX_set_dsa_paramgen_q_bits returns zero.
EVP_PKEY_CTX_set_ec_param_enc(Pointer<EVP_PKEY_CTX> ctx, int encoding) → int
EVP_PKEY_CTX_set_ec_param_enc returns one if |encoding| is |OPENSSL_EC_NAMED_CURVE| or zero with an error otherwise.
EVP_PKEY_CTX_set_ec_paramgen_curve_nid(Pointer<EVP_PKEY_CTX> ctx, int nid) → int
EVP_PKEY_CTX_set_ec_paramgen_curve_nid sets the curve used for |EVP_PKEY_keygen| or |EVP_PKEY_paramgen| operations to |nid|. It returns one on success and zero on error.
EVP_PKEY_CTX_set_rsa_keygen_bits(Pointer<EVP_PKEY_CTX> ctx, int bits) → int
EVP_PKEY_CTX_set_rsa_keygen_bits sets the size of the desired RSA modulus, in bits, for key generation. Returns one on success or zero on error.
EVP_PKEY_CTX_set_rsa_keygen_pubexp(Pointer<EVP_PKEY_CTX> ctx, Pointer<BIGNUM> e) → int
EVP_PKEY_CTX_set_rsa_keygen_pubexp sets |e| as the public exponent for key generation. Returns one on success or zero on error. On success, |ctx| takes ownership of |e|. The library will then call |BN_free| on |e| when |ctx| is destroyed.
EVP_PKEY_CTX_set_rsa_mgf1_md(Pointer<EVP_PKEY_CTX> ctx, Pointer<EVP_MD> md) → int
EVP_PKEY_CTX_set_rsa_mgf1_md sets |md| as the digest used in MGF1. Returns one on success or zero on error.
EVP_PKEY_CTX_set_rsa_oaep_md(Pointer<EVP_PKEY_CTX> ctx, Pointer<EVP_MD> md) → int
EVP_PKEY_CTX_set_rsa_oaep_md sets |md| as the digest used in OAEP padding. Returns one on success or zero on error. If unset, the default is SHA-1. Callers are recommended to overwrite this default.
EVP_PKEY_CTX_set_rsa_padding(Pointer<EVP_PKEY_CTX> ctx, int padding) → int
EVP_PKEY_CTX_set_rsa_padding sets the padding type to use. It should be one of the |RSA_*_PADDING| values. Returns one on success or zero on error. By default, the padding is |RSA_PKCS1_PADDING|.
EVP_PKEY_CTX_set_rsa_pss_keygen_md(Pointer<EVP_PKEY_CTX> ctx, Pointer<EVP_MD> md) → int
EVP_PKEY_CTX_set_rsa_pss_keygen_md returns 0.
EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md(Pointer<EVP_PKEY_CTX> ctx, Pointer<EVP_MD> md) → int
EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md returns 0.
EVP_PKEY_CTX_set_rsa_pss_keygen_saltlen(Pointer<EVP_PKEY_CTX> ctx, int salt_len) → int
EVP_PKEY_CTX_set_rsa_pss_keygen_saltlen returns 0.
EVP_PKEY_CTX_set_rsa_pss_saltlen(Pointer<EVP_PKEY_CTX> ctx, int salt_len) → int
EVP_PKEY_CTX_set_rsa_pss_saltlen sets the length of the salt in a PSS-padded signature. A value of |RSA_PSS_SALTLEN_DIGEST| causes the salt to be the same length as the digest in the signature. A value of |RSA_PSS_SALTLEN_AUTO| causes the salt to be the maximum length that will fit when signing and recovered from the signature when verifying. Otherwise the value gives the size of the salt in bytes.
EVP_PKEY_CTX_set_signature_md(Pointer<EVP_PKEY_CTX> ctx, Pointer<EVP_MD> md) → int
EVP_PKEY_CTX_set_signature_md sets |md| as the digest to be used in a signature operation. It returns one on success or zero on error.
EVP_PKEY_decapsulate(Pointer<EVP_PKEY_CTX> ctx, Pointer<Uint8> out_secret, Pointer<Size> out_secret_len, Pointer<Uint8> ciphertext, int ciphertext_len) → int
EVP_PKEY_decapsulate implements private key decapsulation using |ctx|. |ciphertext| and |ciphertext_len| specify the ciphertext to be decapsulated. If |out_secret| is NULL, it writes the maximum size of the shared secret output to |*out_secret_len| and returns one. Otherwise, |*out_secret_len| must contain the number of bytes of space available at |out_secret|. If the space is insufficient, this function returns zero. If the space is sufficient, the decapsulated shared secret will be written to |out_secret| and the size of the output to |out_secret_len|, and this function will return one. If |ciphertext| has been corrupted, the function may fail or it may output a shared secret that appears to be random. Any subsequent symmetric encryption using |out_secret| must use an authenticated encryption scheme to discover the decapsulation failure.
EVP_PKEY_decapsulate_init(Pointer<EVP_PKEY_CTX> ctx, Pointer<OSSL_PARAM> params) → int
EVP_PKEY_decapsulate_init initialises an |EVP_PKEY_CTX| for a decapsulate operation. It should be called before |EVP_PKEY_decapsulate|. |params| is included for OpenSSL compatibility, but this parameter should be NULL or have |OSSL_PARAM_END| as its first element.
EVP_PKEY_decrypt(Pointer<EVP_PKEY_CTX> ctx, Pointer<Uint8> out, Pointer<Size> out_len, Pointer<Uint8> in$, int in_len) → int
EVP_PKEY_decrypt decrypts |in_len| bytes from |in|. If |out| is NULL, the maximum size of the plaintext is written to |out_len|. Otherwise, |*out_len| must contain the number of bytes of space available at |out|. If sufficient, the ciphertext will be written to |out| and |*out_len| updated with the true length.
EVP_PKEY_decrypt_init(Pointer<EVP_PKEY_CTX> ctx) → int
EVP_PKEY_decrypt_init initialises an |EVP_PKEY_CTX| for a decryption operation. It should be called before |EVP_PKEY_decrypt|.
EVP_PKEY_derive(Pointer<EVP_PKEY_CTX> ctx, Pointer<Uint8> key, Pointer<Size> out_key_len) → int
EVP_PKEY_derive derives a shared key from |ctx|. If |key| is non-NULL then, on entry, |out_key_len| must contain the amount of space at |key|. If sufficient then the shared key will be written to |key| and |*out_key_len| will be set to the length. If |key| is NULL then |out_key_len| will be set to the maximum length.
EVP_PKEY_derive_init(Pointer<EVP_PKEY_CTX> ctx) → int
EVP_PKEY_derive_init initialises an |EVP_PKEY_CTX| for a key derivation operation. It should be called before |EVP_PKEY_derive_set_peer| and |EVP_PKEY_derive|.
EVP_PKEY_derive_set_peer(Pointer<EVP_PKEY_CTX> ctx, Pointer<EVP_PKEY> peer) → int
EVP_PKEY_derive_set_peer sets the peer's key to be used for key derivation by |ctx| to |peer|. It should be called after |EVP_PKEY_derive_init|. (For example, this is used to set the peer's key in (EC)DH.) It returns one on success and zero on error.
EVP_pkey_dsa() → Pointer<EVP_PKEY_ALG>
EVP_pkey_dsa implements DSA keys, encoded as in RFC 3279, Section 2.3.2. The |EVP_PKEY_id| value is |EVP_PKEY_DSA|. This |EVP_PKEY_ALG| accepts all DSA parameters supported by BoringSSL.
EVP_PKEY_dup_ref(Pointer<EVP_PKEY> pkey) → Pointer<EVP_PKEY>
EVP_PKEY_dup_ref increments the reference count of |pkey| and returns |pkey|. The caller must call |EVP_PKEY_free| on the result to release the reference.
EVP_pkey_ec_p224() → Pointer<EVP_PKEY_ALG>
EVP_pkey_ec_* implement EC keys, encoded as id-ecPublicKey (RFC 5480, Section 2.1.1). The id-ecPublicKey encoding is confusingly named: it is also used for private keys (RFC 5915). The |EVP_PKEY_id| value is |EVP_PKEY_EC|.
EVP_pkey_ec_p256() → Pointer<EVP_PKEY_ALG>
EVP_pkey_ec_p384() → Pointer<EVP_PKEY_ALG>
EVP_pkey_ec_p521() → Pointer<EVP_PKEY_ALG>
EVP_pkey_ed25519() → Pointer<EVP_PKEY_ALG>
EVP_pkey_ed25519 implements Ed25519 keys (RFC 8032), encoded as in RFC 8410. The |EVP_PKEY_id| value is |EVP_PKEY_ED25519|.
EVP_PKEY_encapsulate(Pointer<EVP_PKEY_CTX> ctx, Pointer<Uint8> out_ciphertext, Pointer<Size> out_ciphertext_len, Pointer<Uint8> out_secret, Pointer<Size> out_secret_len) → int
EVP_PKEY_encapsulate implements public key encapsulation using |ctx|. It either performs the operation or returns the maximum output sizes, depending on whether |out_ciphertext| is NULL:
EVP_PKEY_encapsulate_init(Pointer<EVP_PKEY_CTX> ctx, Pointer<OSSL_PARAM> params) → int
EVP_PKEY_encapsulate_init initialises an |EVP_PKEY_CTX| for an encapsulate operation. It should be called before |EVP_PKEY_encapsulate|. |params| is included for OpenSSL compatibility, but this parameter should be NULL or have |OSSL_PARAM_END| as its first element.
EVP_PKEY_encrypt(Pointer<EVP_PKEY_CTX> ctx, Pointer<Uint8> out, Pointer<Size> out_len, Pointer<Uint8> in$, int in_len) → int
EVP_PKEY_encrypt encrypts |in_len| bytes from |in|. If |out| is NULL, the maximum size of the ciphertext is written to |out_len|. Otherwise, |*out_len| must contain the number of bytes of space available at |out|. If sufficient, the ciphertext will be written to |out| and |*out_len| updated with the true length.
EVP_PKEY_encrypt_init(Pointer<EVP_PKEY_CTX> ctx) → int
EVP_PKEY_encrypt_init initialises an |EVP_PKEY_CTX| for an encryption operation. It should be called before |EVP_PKEY_encrypt|.
EVP_PKEY_eq(Pointer<EVP_PKEY> a, Pointer<EVP_PKEY> b) → int
EVP_PKEY_eq compares |a| and |b| and returns one if their public keys are equal and zero otherwise.
EVP_PKEY_free(Pointer<EVP_PKEY> pkey) → void
EVP_PKEY_free decrements the reference count of |pkey| and frees it if the reference count drops to zero.
EVP_PKEY_from_private_key_info(Pointer<Uint8> in$, int len, Pointer<Pointer<EVP_PKEY_ALG>> algs, int num_algs) → Pointer<EVP_PKEY>
EVP_PKEY_from_private_key_info decodes a DER-encoded PrivateKeyInfo structure (RFC 5208) from |in|. It returns a newly-allocated |EVP_PKEY| or NULL on error. Only the |num_algs| algorithms in |algs| will be considered when parsing.
EVP_PKEY_from_private_seed(Pointer<EVP_PKEY_ALG> alg, Pointer<Uint8> in$, int len) → Pointer<EVP_PKEY>
EVP_PKEY_from_private_seed interprets |in| as a private seed of type |alg| and returns a newly-allocated |EVP_PKEY|, or nullptr on error.
EVP_PKEY_from_raw_private_key(Pointer<EVP_PKEY_ALG> alg, Pointer<Uint8> in$, int len) → Pointer<EVP_PKEY>
EVP_PKEY_from_raw_private_key interprets |in| as a raw private key of type |alg| and returns a newly-allocated |EVP_PKEY|, or nullptr on error.
EVP_PKEY_from_raw_public_key(Pointer<EVP_PKEY_ALG> alg, Pointer<Uint8> in$, int len) → Pointer<EVP_PKEY>
EVP_PKEY_from_raw_public_key interprets |in| as a raw public key of type |alg| and returns a newly-allocated |EVP_PKEY|, or nullptr on error.
EVP_PKEY_from_subject_public_key_info(Pointer<Uint8> in$, int len, Pointer<Pointer<EVP_PKEY_ALG>> algs, int num_algs) → Pointer<EVP_PKEY>
EVP_PKEY_from_subject_public_key_info decodes a DER-encoded SubjectPublicKeyInfo structure (RFC 5280) from |in|. It returns a newly-allocated |EVP_PKEY| or NULL on error. Only the |num_algs| algorithms in |algs| will be considered when parsing.
EVP_PKEY_generate_from_alg(Pointer<EVP_PKEY_ALG> alg) → Pointer<EVP_PKEY>
EVP_PKEY_generate_from_alg generates a new key of type |alg|. It returns a newly-allocated |EVP_PKEY| or nullptr on error.
EVP_PKEY_get0(Pointer<EVP_PKEY> pkey) → Pointer<Void>
EVP_PKEY_get0 returns NULL. This function is provided for compatibility with OpenSSL but does not return anything. Use the typed |EVP_PKEY_get0_*| functions instead.
EVP_PKEY_get0_DH(Pointer<EVP_PKEY> pkey) → Pointer<DH>
EVP_PKEY_get0_DSA(Pointer<EVP_PKEY> pkey) → Pointer<DSA>
EVP_PKEY_get0_EC_KEY(Pointer<EVP_PKEY> pkey) → Pointer<EC_KEY>
EVP_PKEY_get0_RSA(Pointer<EVP_PKEY> pkey) → Pointer<RSA>
EVP_PKEY_get1_DH(Pointer<EVP_PKEY> pkey) → Pointer<DH>
EVP_PKEY_get1_DSA(Pointer<EVP_PKEY> pkey) → Pointer<DSA>
EVP_PKEY_get1_EC_KEY(Pointer<EVP_PKEY> pkey) → Pointer<EC_KEY>
EVP_PKEY_get1_RSA(Pointer<EVP_PKEY> pkey) → Pointer<RSA>
EVP_PKEY_get1_tls_encodedpoint(Pointer<EVP_PKEY> pkey, Pointer<Pointer<Uint8>> out_ptr) → int
EVP_PKEY_get1_tls_encodedpoint sets |*out_ptr| to a newly-allocated buffer containing the raw encoded public key for |pkey|. The caller must call |OPENSSL_free| to release this buffer. The function returns the length of the buffer on success and zero on error.
EVP_PKEY_get_ec_curve_nid(Pointer<EVP_PKEY> pkey) → int
EVP_PKEY_get_ec_curve_nid returns |pkey|'s curve as a NID constant, such as |NID_X9_62_prime256v1|, or |NID_undef| if |pkey| is not an EC key.
EVP_PKEY_get_ec_point_conv_form(Pointer<EVP_PKEY> pkey) → int
EVP_PKEY_get_ec_point_conv_form returns |pkey|'s point conversion form as a |POINT_CONVERSION_*| constant, or zero if |pkey| is not an EC key.
EVP_PKEY_get_private_seed(Pointer<EVP_PKEY> pkey, Pointer<Uint8> out, Pointer<Size> out_len) → int
EVP_PKEY_get_private_seed outputs the private key for |pkey| as a private seed. If |out| is NULL, it sets |*out_len| to the size of the seed. Otherwise, it writes at most |*out_len| bytes to |out| and sets |*out_len| to the number of bytes written.
EVP_PKEY_get_raw_private_key(Pointer<EVP_PKEY> pkey, Pointer<Uint8> out, Pointer<Size> out_len) → int
EVP_PKEY_get_raw_private_key outputs the private key for |pkey| in raw form. If |out| is NULL, it sets |*out_len| to the size of the raw private key. Otherwise, it writes at most |*out_len| bytes to |out| and sets |*out_len| to the number of bytes written.
EVP_PKEY_get_raw_public_key(Pointer<EVP_PKEY> pkey, Pointer<Uint8> out, Pointer<Size> out_len) → int
EVP_PKEY_get_raw_public_key outputs the public key for |pkey| in raw form. If |out| is NULL, it sets |*out_len| to the size of the raw public key. Otherwise, it writes at most |*out_len| bytes to |out| and sets |*out_len| to the number of bytes written.
EVP_PKEY_has_private(Pointer<EVP_PKEY> pkey) → int
EVP_PKEY_has_private returns one if |pkey| has a private key, or zero otherwise.
EVP_PKEY_has_public(Pointer<EVP_PKEY> pkey) → int
EVP_PKEY_has_public returns one if |pkey| has a public key, or zero otherwise.
EVP_PKEY_id(Pointer<EVP_PKEY> pkey) → int
EVP_PKEY_id returns the type of |pkey|, which is one of the |EVP_PKEY_*| values above. These type values generally correspond to the algorithm OID, but not the parameters, of a SubjectPublicKeyInfo (RFC 5280) or PrivateKeyInfo (RFC 5208) AlgorithmIdentifier. Algorithm parameters can be inspected with algorithm-specific accessors, e.g. |EVP_PKEY_get_ec_curve_nid|.
EVP_PKEY_is_opaque(Pointer<EVP_PKEY> pkey) → int
EVP_PKEY_is_opaque returns one if |pkey| is opaque. Opaque keys are backed by custom implementations which do not expose key material and parameters. It is an error to attempt to duplicate, export, or compare an opaque key.
EVP_PKEY_keygen(Pointer<EVP_PKEY_CTX> ctx, Pointer<Pointer<EVP_PKEY>> out_pkey) → int
EVP_PKEY_keygen performs a key generation operation using the values from |ctx|. If |*out_pkey| is non-NULL, it overwrites |*out_pkey| with the resulting key. Otherwise, it sets |*out_pkey| to a newly-allocated |EVP_PKEY| containing the result. It returns one on success or zero on error.
EVP_PKEY_keygen_init(Pointer<EVP_PKEY_CTX> ctx) → int
EVP_PKEY_keygen_init initialises an |EVP_PKEY_CTX| for a key generation operation. It should be called before |EVP_PKEY_keygen|.
EVP_PKEY_missing_parameters(Pointer<EVP_PKEY> pkey) → int
EVP_PKEY_missing_parameters returns one if |pkey| is missing needed parameters or zero if not, or if the algorithm doesn't take parameters.
EVP_pkey_ml_dsa_44() → Pointer<EVP_PKEY_ALG>
EVP_pkey_ml_dsa_* implement ML-DSA keys, encoded as in draft-ietf-lamps-dilithium-certificates. The |EVP_PKEY_id| values are |EVP_PKEY_ML_DSA_*|. In the private key representation, only the "seed" form is serialized or parsed.
EVP_pkey_ml_dsa_65() → Pointer<EVP_PKEY_ALG>
EVP_pkey_ml_dsa_87() → Pointer<EVP_PKEY_ALG>
EVP_pkey_ml_kem_1024() → Pointer<EVP_PKEY_ALG>
EVP_pkey_ml_kem_768() → Pointer<EVP_PKEY_ALG>
EVP_pkey_ml_kem_* implement ML-KEM keys, encoded as in RFC 9935. The |EVP_PKEY_id| values are |EVP_PKEY_ML_KEM_*|. In the private key representation, only the "seed" form is serialized or parsed.
EVP_PKEY_new() → Pointer<EVP_PKEY>
EVP_PKEY_new creates a new, empty public-key object and returns it or NULL on allocation failure.
EVP_PKEY_new_raw_private_key(int type, Pointer<ENGINE> unused, Pointer<Uint8> in$, int len) → Pointer<EVP_PKEY>
EVP_PKEY_new_raw_private_key interprets |in| as a raw private key of type |type|, which must be an |EVP_PKEY_*| constant, such as |EVP_PKEY_X25519|, and returns a newly-allocated |EVP_PKEY|, or nullptr on error.
EVP_PKEY_new_raw_public_key(int type, Pointer<ENGINE> unused, Pointer<Uint8> in$, int len) → Pointer<EVP_PKEY>
EVP_PKEY_new_raw_public_key interprets |in| as a raw public key of type |type|, which must be an |EVP_PKEY_*| constant, such as |EVP_PKEY_X25519|, and returns a newly-allocated |EVP_PKEY|, or nullptr on error.
EVP_PKEY_parameters_eq(Pointer<EVP_PKEY> a, Pointer<EVP_PKEY> b) → int
EVP_PKEY_parameters_eq compares the parameters of |a| and |b|. It returns one if they match and zero otherwise. In algorithms that do not use parameters, this function returns one; null parameters are vacuously equal.
EVP_PKEY_paramgen(Pointer<EVP_PKEY_CTX> ctx, Pointer<Pointer<EVP_PKEY>> out_pkey) → int
EVP_PKEY_paramgen performs a parameter generation using the values from |ctx|. If |*out_pkey| is non-NULL, it overwrites |*out_pkey| with the resulting parameters, but no key. Otherwise, it sets |*out_pkey| to a newly-allocated |EVP_PKEY| containing the result. It returns one on success or zero on error.
EVP_PKEY_paramgen_init(Pointer<EVP_PKEY_CTX> ctx) → int
EVP_PKEY_paramgen_init initialises an |EVP_PKEY_CTX| for a parameter generation operation. It should be called before |EVP_PKEY_paramgen|.
EVP_PKEY_print_params(Pointer<BIO> out, Pointer<EVP_PKEY> pkey, int indent, Pointer<ASN1_PCTX> pctx) → int
EVP_PKEY_print_params prints a textual representation of the parameters in |pkey| to |out|. Returns one on success or zero otherwise.
EVP_PKEY_print_private(Pointer<BIO> out, Pointer<EVP_PKEY> pkey, int indent, Pointer<ASN1_PCTX> pctx) → int
EVP_PKEY_print_private prints a textual representation of the private key in |pkey| to |out|. Returns one on success or zero otherwise.
EVP_PKEY_print_public(Pointer<BIO> out, Pointer<EVP_PKEY> pkey, int indent, Pointer<ASN1_PCTX> pctx) → int
EVP_PKEY_print_public prints a textual representation of the public key in |pkey| to |out|. Returns one on success or zero otherwise.
EVP_pkey_rsa() → Pointer<EVP_PKEY_ALG>
EVP_pkey_rsa implements RSA keys (RFC 8017), encoded as rsaEncryption (RFC 3279, Section 2.3.1). The rsaEncryption encoding is confusingly named: these keys are used for all RSA operations, including signing. The |EVP_PKEY_id| value is |EVP_PKEY_RSA|.
EVP_pkey_rsa_pss_sha256() → Pointer<EVP_PKEY_ALG>
EVP_pkey_rsa_pss_* implements RSASSA-PSS keys, encoded as id-RSASSA-PSS (RFC 4055, Section 3.1). The |EVP_PKEY_id| value is |EVP_PKEY_RSA_PSS|. Each |EVP_PKEY_ALG| only accepts keys whose parameters specify:
EVP_pkey_rsa_pss_sha384() → Pointer<EVP_PKEY_ALG>
EVP_pkey_rsa_pss_sha512() → Pointer<EVP_PKEY_ALG>
EVP_PKEY_set1_DH(Pointer<EVP_PKEY> pkey, Pointer<DH> key) → int
EVP_PKEY_set1_DSA(Pointer<EVP_PKEY> pkey, Pointer<DSA> key) → int
EVP_PKEY_set1_EC_KEY(Pointer<EVP_PKEY> pkey, Pointer<EC_KEY> key) → int
EVP_PKEY_set1_RSA(Pointer<EVP_PKEY> pkey, Pointer<RSA> key) → int
Getting and setting concrete key types.
EVP_PKEY_set1_tls_encodedpoint(Pointer<EVP_PKEY> pkey, Pointer<Uint8> in$, int len) → int
EVP_PKEY_set1_tls_encodedpoint replaces |pkey| with a public key encoded by |in|. It returns one on success and zero on error.
EVP_PKEY_set_type(Pointer<EVP_PKEY> pkey, int type) → int
EVP_PKEY_set_type sets the type of |pkey| to |type|. It returns one if successful or zero if the |type| argument is not one of the |EVP_PKEY_*| values supported for use with this function. If |pkey| is NULL, it simply reports whether the type is known.
EVP_PKEY_sign(Pointer<EVP_PKEY_CTX> ctx, Pointer<Uint8> sig, Pointer<Size> sig_len, Pointer<Uint8> digest, int digest_len) → int
EVP_PKEY_sign signs |digest_len| bytes from |digest| using |ctx|. If |sig| is NULL, the maximum size of the signature is written to |out_sig_len|. Otherwise, |*sig_len| must contain the number of bytes of space available at |sig|. If sufficient, the signature will be written to |sig| and |*sig_len| updated with the true length. This function will fail for signature algorithms like Ed25519 that do not support signing pre-hashed inputs.
EVP_PKEY_sign_init(Pointer<EVP_PKEY_CTX> ctx) → int
EVP_PKEY_sign_init initialises an |EVP_PKEY_CTX| for a signing operation. It should be called before |EVP_PKEY_sign|.
EVP_PKEY_size(Pointer<EVP_PKEY> pkey) → int
EVP_PKEY_size returns the maximum size, in bytes, of a signature signed by |pkey|. For an RSA key, this returns the number of bytes needed to represent the modulus. For an EC key, this returns the maximum size of a DER-encoded ECDSA signature.
EVP_PKEY_type(int nid) → int
EVP_PKEY_type returns |nid|.
EVP_PKEY_up_ref(Pointer<EVP_PKEY> pkey) → int
EVP_PKEY_up_ref increments the reference count of |pkey| and returns one. It does not mutate |pkey| for thread-safety purposes and may be used concurrently.
EVP_PKEY_verify(Pointer<EVP_PKEY_CTX> ctx, Pointer<Uint8> sig, int sig_len, Pointer<Uint8> digest, int digest_len) → int
EVP_PKEY_verify verifies that |sig_len| bytes from |sig| are a valid signature for |digest|. This function will fail for signature algorithms like Ed25519 that do not support signing pre-hashed inputs.
EVP_PKEY_verify_init(Pointer<EVP_PKEY_CTX> ctx) → int
EVP_PKEY_verify_init initialises an |EVP_PKEY_CTX| for a signature verification operation. It should be called before |EVP_PKEY_verify|.
EVP_PKEY_verify_recover(Pointer<EVP_PKEY_CTX> ctx, Pointer<Uint8> out, Pointer<Size> out_len, Pointer<Uint8> sig, int siglen) → int
EVP_PKEY_verify_recover decrypts |sig_len| bytes from |sig|. If |out| is NULL, the maximum size of the plaintext is written to |out_len|. Otherwise, |*out_len| must contain the number of bytes of space available at |out|. If sufficient, the ciphertext will be written to |out| and |*out_len| updated with the true length.
EVP_PKEY_verify_recover_init(Pointer<EVP_PKEY_CTX> ctx) → int
EVP_PKEY_verify_recover_init initialises an |EVP_PKEY_CTX| for a public-key decryption operation. It should be called before |EVP_PKEY_verify_recover|.
EVP_pkey_x25519() → Pointer<EVP_PKEY_ALG>
EVP_pkey_x25519 implements X25519 keys (RFC 7748), encoded as in RFC 8410. The |EVP_PKEY_id| value is |EVP_PKEY_X25519|.
EVP_pkey_xwing() → Pointer<EVP_PKEY_ALG>
EVP_pkey_xwing implements the hybrid key encapsulation mechanism (KEM) known as X-Wing or MLKEM768-X25519, defined in draft-irtf-cfrg-concrete-hybrid-kems. Its private key representation is the "seed" form. It does not have public and private key encodings for X.509.
EVP_Q_digest(Pointer<OSSL_LIB_CTX> libctx, Pointer<Char> name, Pointer<Char> propq, Pointer<Void> in$, int in_len, Pointer<Uint8> out, Pointer<Size> out_len) → int
EVP_Q_digest behaves like |EVP_Digest| but specifies the digest by a string |name|. |libctx| and |propq| are ignored.
EVP_rc2_40_cbc() → Pointer<EVP_CIPHER>
EVP_rc2_40_cbc returns a cipher that implements 40-bit RC2 in CBC mode. This is obviously very, very weak and is included only in order to read PKCS#12 files, which often encrypt the certificate chain using this cipher. It is deliberately not exported.
EVP_rc2_cbc() → Pointer<EVP_CIPHER>
EVP_rc2_cbc returns a cipher that implements 128-bit RC2 in CBC mode.
EVP_rc4() → Pointer<EVP_CIPHER>
Cipher primitives.
EVP_RSA_gen(int bits) → Pointer<EVP_PKEY>
EVP_RSA_gen generates a new RSA key with the specified number of bits. It returns a newly-allocated |EVP_PKEY| or nullptr on error.
EVP_sha1() → Pointer<EVP_MD>
EVP_sha224() → Pointer<EVP_MD>
EVP_sha256() → Pointer<EVP_MD>
EVP_sha384() → Pointer<EVP_MD>
EVP_sha512() → Pointer<EVP_MD>
EVP_sha512_256() → Pointer<EVP_MD>
EVP_SignFinal(Pointer<EVP_MD_CTX> ctx, Pointer<Uint8> sig, Pointer<UnsignedInt> out_sig_len, Pointer<EVP_PKEY> pkey) → int
EVP_SignFinal signs the data that has been included by one or more calls to |EVP_SignUpdate|, using the key |pkey|, and writes it to |sig|. On entry, |sig| must point to at least |EVP_PKEY_size(pkey)| bytes of space. The actual size of the signature is written to |*out_sig_len|.
EVP_SignInit(Pointer<EVP_MD_CTX> ctx, Pointer<EVP_MD> type) → int
EVP_SignInit is a deprecated version of |EVP_SignInit_ex|.
EVP_SignInit_ex(Pointer<EVP_MD_CTX> ctx, Pointer<EVP_MD> type, Pointer<ENGINE> impl) → int
EVP_SignInit_ex configures |ctx|, which must already have been initialised, for a fresh signing operation using the hash function |type|. It returns one on success and zero otherwise.
EVP_SignUpdate(Pointer<EVP_MD_CTX> ctx, Pointer<Void> data, int len) → int
EVP_SignUpdate appends |len| bytes from |data| to the data which will be signed in |EVP_SignFinal|.
EVP_VerifyFinal(Pointer<EVP_MD_CTX> ctx, Pointer<Uint8> sig, int sig_len, Pointer<EVP_PKEY> pkey) → int
EVP_VerifyFinal verifies that |sig_len| bytes of |sig| are a valid signature, by |pkey|, for the data that has been included by one or more calls to |EVP_VerifyUpdate|.
EVP_VerifyInit(Pointer<EVP_MD_CTX> ctx, Pointer<EVP_MD> type) → int
EVP_VerifyInit is a deprecated version of |EVP_VerifyInit_ex|.
EVP_VerifyInit_ex(Pointer<EVP_MD_CTX> ctx, Pointer<EVP_MD> type, Pointer<ENGINE> impl) → int
EVP_VerifyInit_ex configures |ctx|, which must already have been initialised, for a fresh signature verification operation using the hash function |type|. It returns one on success and zero otherwise.
EVP_VerifyUpdate(Pointer<EVP_MD_CTX> ctx, Pointer<Void> data, int len) → int
EVP_VerifyUpdate appends |len| bytes from |data| to the data which will be signed in |EVP_VerifyFinal|.
EXTENDED_KEY_USAGE_free(Pointer<EXTENDED_KEY_USAGE> eku) → void
EXTENDED_KEY_USAGE_free releases memory associated with |eku|.
EXTENDED_KEY_USAGE_new() → Pointer<EXTENDED_KEY_USAGE>
EXTENDED_KEY_USAGE_new returns a newly-allocated, empty |EXTENDED_KEY_USAGE| object, or NULL on error.
extractBoringSslError() → String?
Formats the least recent (and most specific) error on the current thread's BoringSSL error queue, and clears the queue before returning.
FIPS_mode() → int
FIPS_mode returns zero unless BoringSSL is built with BORINGSSL_FIPS, in which case it returns one.
FIPS_mode_set(int on) → int
FIPS_mode_set returns one if |on| matches whether BoringSSL was built with |BORINGSSL_FIPS| and zero otherwise.
FIPS_module_name() → Pointer<Char>
FIPS_module_name returns the name of the FIPS module.
FIPS_query_algorithm_status(Pointer<Char> algorithm) → int
FIPS_query_algorithm_status returns one if |algorithm| is FIPS validated in the current BoringSSL and zero otherwise.
FIPS_read_counter(int counter) → int
FIPS_read_counter returns a counter of the number of times the specific function denoted by |counter| has been used. This always returns zero unless BoringSSL was built with BORINGSSL_FIPS_COUNTERS defined.
FIPS_version() → int
FIPS_version returns the version of the FIPS module, or zero if the build isn't exactly at a verified version. The version, expressed in base 10, will be a date in the form yyyymmdd.
GENERAL_NAME_dup(Pointer<GENERAL_NAME> gen) → Pointer<GENERAL_NAME>
GENERAL_NAME_dup returns a newly-allocated copy of |gen|, or NULL on error. This function works by serializing the structure, so it will fail if |gen| is empty.
GENERAL_NAME_free(Pointer<GENERAL_NAME> gen) → void
GENERAL_NAME_free releases memory associated with |gen|.
GENERAL_NAME_get0_otherName(Pointer<GENERAL_NAME> gen, Pointer<Pointer<ASN1_OBJECT>> out_oid, Pointer<Pointer<ASN1_TYPE>> out_value) → int
GENERAL_NAME_get0_otherName, if |gen| is an OtherName, sets |*out_oid| and |*out_value| to the OtherName's type-id and value, respectively, and returns one. If |gen| is not an OtherName, it returns zero and leaves |*out_oid| and |*out_value| unmodified. Either of |out_oid| or |out_value| may be NULL to ignore the value.
GENERAL_NAME_get0_value(Pointer<GENERAL_NAME> gen, Pointer<Int> out_type) → Pointer<Void>
GENERAL_NAME_get0_value returns the in-memory representation of |gen|'s contents and, |out_type| is not NULL, sets |out_type| to the type of |gen|, which will be a |GEN_| constant. If |gen| is incomplete, the return value will be NULL and the type will be -1.
GENERAL_NAME_new() → Pointer<GENERAL_NAME>
GENERAL_NAME_new returns a new, empty |GENERAL_NAME|, or NULL on error.
GENERAL_NAME_print(Pointer<BIO> out, Pointer<GENERAL_NAME> gen) → int
GENERAL_NAME_print prints a human-readable representation of |gen| to |out|. It returns one on success and zero on error.
GENERAL_NAME_set0_othername(Pointer<GENERAL_NAME> gen, Pointer<ASN1_OBJECT> oid, Pointer<ASN1_TYPE> value) → int
GENERAL_NAME_set0_othername sets |gen| to be an OtherName with type |oid| and value |value|. On success, it returns one and takes ownership of |oid| and |value|, which must be created in a way compatible with |ASN1_OBJECT_free| and |ASN1_TYPE_free|, respectively. On allocation failure, it returns zero. In the failure case, the caller retains ownership of |oid| and |value| and must release them when done.
GENERAL_NAME_set0_value(Pointer<GENERAL_NAME> gen, int type, Pointer<Void> value) → void
GENERAL_NAME_set0_value set |gen|'s type and value to |type| and |value|. |type| must be a |GEN_*| constant and |value| must be an object of the corresponding type. |gen| takes ownership of |value|, so |value| must have been an allocated object.
GENERAL_NAMES_free(Pointer<GENERAL_NAMES> gens) → void
GENERAL_NAMES_free releases memory associated with |gens|.
GENERAL_NAMES_new() → Pointer<GENERAL_NAMES>
GENERAL_NAMES_new returns a new, empty |GENERAL_NAMES|, or NULL on error.
GENERAL_SUBTREE_free(Pointer<GENERAL_SUBTREE> subtree) → void
GENERAL_SUBTREE_free releases memory associated with |subtree|.
GENERAL_SUBTREE_new() → Pointer<GENERAL_SUBTREE>
GENERAL_SUBTREE_new returns a newly-allocated, empty |GENERAL_SUBTREE| object, or NULL on error.
HKDF(Pointer<Uint8> out_key, int out_len, Pointer<EVP_MD> digest, Pointer<Uint8> secret, int secret_len, Pointer<Uint8> salt, int salt_len, Pointer<Uint8> info, int info_len) → int
HKDF computes HKDF (as specified by RFC 5869) of initial keying material |secret| with |salt| and |info| using |digest|, and outputs |out_len| bytes to |out_key|. It returns one on success and zero on error.
HKDF_expand(Pointer<Uint8> out_key, int out_len, Pointer<EVP_MD> digest, Pointer<Uint8> prk, int prk_len, Pointer<Uint8> info, int info_len) → int
HKDF_expand computes a HKDF OKM (as specified by RFC 5869) of length |out_len| from the PRK |prk| and info |info| using |digest|, and outputs the result to |out_key|. It returns one on success and zero on error.
HKDF_extract(Pointer<Uint8> out_key, Pointer<Size> out_len, Pointer<EVP_MD> digest, Pointer<Uint8> secret, int secret_len, Pointer<Uint8> salt, int salt_len) → int
HKDF_extract computes a HKDF PRK (as specified by RFC 5869) from initial keying material |secret| and salt |salt| using |digest|, and outputs |out_len| bytes to |out_key|. The maximum output size is |EVP_MAX_MD_SIZE|. It returns one on success and zero on error.
HMAC(Pointer<EVP_MD> evp_md, Pointer<Void> key, int key_len, Pointer<Uint8> data, int data_len, Pointer<Uint8> out, Pointer<UnsignedInt> out_len) → Pointer<Uint8>
HMAC calculates the HMAC of |data_len| bytes of |data|, using the given key and hash function, and writes the result to |out|. On entry, |out| must contain at least |EVP_MD_size| bytes of space. The actual length of the result is written to |*out_len|. An output size of |EVP_MAX_MD_SIZE| will always be large enough. It returns |out| or NULL on error.
HMAC_CTX_cleanse(Pointer<HMAC_CTX> ctx) → void
HMAC_CTX_cleanse zeros the digest state from |ctx| and then performs the actions of |HMAC_CTX_cleanup|.
HMAC_CTX_cleanup(Pointer<HMAC_CTX> ctx) → void
HMAC_CTX_cleanup frees data owned by |ctx|. It does not free |ctx| itself.
HMAC_CTX_copy(Pointer<HMAC_CTX> dest, Pointer<HMAC_CTX> src) → int
HMAC_CTX_copy calls |HMAC_CTX_init| on |dest| and then sets it equal to |src|. On entry, |dest| must /not/ be initialised for an operation with |HMAC_Init_ex|. It returns one on success and zero on error.
HMAC_CTX_copy_ex(Pointer<HMAC_CTX> dest, Pointer<HMAC_CTX> src) → int
HMAC_CTX_copy_ex sets |dest| equal to |src|. On entry, |dest| must have been initialised by calling |HMAC_CTX_init|. It returns one on success and zero on error.
HMAC_CTX_free(Pointer<HMAC_CTX> ctx) → void
HMAC_CTX_free calls |HMAC_CTX_cleanup| and then frees |ctx| itself.
HMAC_CTX_get_md(Pointer<HMAC_CTX> ctx) → Pointer<EVP_MD>
HMAC_CTX_get_md returns |ctx|'s hash function.
HMAC_CTX_init(Pointer<HMAC_CTX> ctx) → void
HMAC_CTX_init initialises |ctx| for use in an HMAC operation. It's assumed that HMAC_CTX objects will be allocated on the stack thus no allocation function is provided.
HMAC_CTX_new() → Pointer<HMAC_CTX>
HMAC_CTX_new allocates and initialises a new |HMAC_CTX| and returns it, or NULL on allocation failure. The caller must use |HMAC_CTX_free| to release the resulting object.
HMAC_CTX_reset(Pointer<HMAC_CTX> ctx) → void
HMAC_CTX_reset calls |HMAC_CTX_cleanup| followed by |HMAC_CTX_init|.
HMAC_Final(Pointer<HMAC_CTX> ctx, Pointer<Uint8> out, Pointer<UnsignedInt> out_len) → int
HMAC_Final completes the HMAC operation in |ctx| and writes the result to |out|. If |out_len| is not |NULL| then it writes the length of the result to |*out_len|. On entry, |out| must contain at least |HMAC_size| bytes of space. An output size of |EVP_MAX_MD_SIZE| will always be large enough. It returns one on success or zero on allocation failure.
HMAC_Init(Pointer<HMAC_CTX> ctx, Pointer<Void> key, int key_len, Pointer<EVP_MD> md) → int
Deprecated functions.
HMAC_Init_ex(Pointer<HMAC_CTX> ctx, Pointer<Void> key, int key_len, Pointer<EVP_MD> md, Pointer<ENGINE> impl) → int
HMAC_Init_ex sets up an initialised |HMAC_CTX| to use |md| as the hash function and |key| as the key. For a non-initial call, |md| may be NULL, in which case the previous hash function will be used. If the hash function has not changed and |key| is NULL, |ctx| reuses the previous key. It returns one on success or zero on allocation failure.
HMAC_size(Pointer<HMAC_CTX> ctx) → int
HMAC_size returns the size, in bytes, of the HMAC that will be produced by |ctx|. On entry, |ctx| must have been setup with |HMAC_Init_ex|.
HMAC_Update(Pointer<HMAC_CTX> ctx, Pointer<Uint8> data, int data_len) → int
HMAC_Update hashes |data_len| bytes from |data| into the current HMAC operation in |ctx|. It returns one.
i2a_ASN1_ENUMERATED(Pointer<BIO> bp, Pointer<ASN1_OCTET_STRING> a) → int
i2a_ASN1_ENUMERATED writes a human-readable representation of |a| to |bp|. It returns the number of bytes written on success, or a negative number on error. On error, this function may have written a partial output to |bp|.
i2a_ASN1_INTEGER(Pointer<BIO> bp, Pointer<ASN1_OCTET_STRING> a) → int
i2a_ASN1_INTEGER writes a human-readable representation of |a| to |bp|. It returns the number of bytes written on success, or a negative number on error. On error, this function may have written a partial output to |bp|.
i2a_ASN1_OBJECT(Pointer<BIO> bp, Pointer<ASN1_OBJECT> a) → int
i2a_ASN1_OBJECT writes a human-readable representation of |a| to |bp|. It returns the number of bytes written on success, or a negative number on error. On error, this function may have written a partial output to |bp|.
i2a_ASN1_STRING(Pointer<BIO> bp, Pointer<ASN1_OCTET_STRING> a, int type) → int
i2a_ASN1_STRING writes a text representation of |a|'s contents to |bp|. It returns the number of bytes written on success, or a negative number on error. On error, this function may have written a partial output to |bp|. |type| is ignored.
i2c_ASN1_BIT_STRING(Pointer<ASN1_OCTET_STRING> in$, Pointer<Pointer<Uint8>> outp) → int
i2c_ASN1_BIT_STRING encodes |in| as the contents of a DER-encoded BIT STRING, excluding the tag and length. If |outp| is non-NULL, it writes the result to |*outp|, advances |*outp| just past the output, and returns the number of bytes written. |*outp| must have space available for the result. If |outp| is NULL, it returns the number of bytes without writing anything. On error, it returns a value <= 0.
i2c_ASN1_INTEGER(Pointer<ASN1_OCTET_STRING> in$, Pointer<Pointer<Uint8>> outp) → int
i2c_ASN1_INTEGER encodes |in| as the contents of a DER-encoded INTEGER, excluding the tag and length. If |outp| is non-NULL, it writes the result to |*outp|, advances |*outp| just past the output, and returns the number of bytes written. |*outp| must have space available for the result. If |outp| is NULL, it returns the number of bytes without writing anything. On error, it returns a value <= 0.
i2d_ASN1_BIT_STRING(Pointer<ASN1_OCTET_STRING> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_ASN1_BIT_STRING marshals |in| as a DER-encoded ASN.1 BIT STRING, as described in |i2d_SAMPLE|.
i2d_ASN1_BMPSTRING(Pointer<ASN1_OCTET_STRING> in$, Pointer<Pointer<Uint8>> outp) → int
The following functions marshal |in| as a DER-encoded ASN.1 value of the corresponding type, as described in |i2d_SAMPLE|.
i2d_ASN1_BOOLEAN(int a, Pointer<Pointer<UnsignedChar>> outp) → int
i2d_ASN1_BOOLEAN marshals |a| as a DER-encoded ASN.1 BOOLEAN, as described in |i2d_SAMPLE|.
i2d_ASN1_ENUMERATED(Pointer<ASN1_OCTET_STRING> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_ASN1_ENUMERATED marshals |in| as a DER-encoded ASN.1 ENUMERATED, as described in |i2d_SAMPLE|.
i2d_ASN1_GENERALIZEDTIME(Pointer<ASN1_OCTET_STRING> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_ASN1_GENERALIZEDTIME marshals |in| as a DER-encoded ASN.1 GeneralizedTime, as described in |i2d_SAMPLE|.
i2d_ASN1_GENERALSTRING(Pointer<ASN1_OCTET_STRING> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_ASN1_IA5STRING(Pointer<ASN1_OCTET_STRING> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_ASN1_INTEGER(Pointer<ASN1_OCTET_STRING> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_ASN1_INTEGER marshals |in| as a DER-encoded ASN.1 INTEGER, as described in |i2d_SAMPLE|.
i2d_ASN1_NULL(Pointer<ASN1_NULL> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_ASN1_NULL marshals |in| as a DER-encoded ASN.1 NULL value, as described in |i2d_SAMPLE|.
i2d_ASN1_OBJECT(Pointer<ASN1_OBJECT> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_ASN1_OBJECT marshals |in| as a DER-encoded ASN.1 OBJECT IDENTIFIER, as described in |i2d_SAMPLE|.
i2d_ASN1_OCTET_STRING(Pointer<ASN1_OCTET_STRING> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_ASN1_PRINTABLESTRING(Pointer<ASN1_OCTET_STRING> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_ASN1_SEQUENCE_ANY(Pointer<ASN1_SEQUENCE_ANY> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_ASN1_SEQUENCE_ANY marshals |in| as a DER-encoded SEQUENCE OF ANY structure, as described in |i2d_SAMPLE|.
i2d_ASN1_SET_ANY(Pointer<ASN1_SEQUENCE_ANY> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_ASN1_SET_ANY marshals |in| as a DER-encoded SET OF ANY structure, as described in |i2d_SAMPLE|.
i2d_ASN1_T61STRING(Pointer<ASN1_OCTET_STRING> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_ASN1_TIME(Pointer<ASN1_OCTET_STRING> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_ASN1_TIME marshals |in| as a DER-encoded X.509 Time (RFC 5280), as described in |i2d_SAMPLE|.
i2d_ASN1_TYPE(Pointer<ASN1_TYPE> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_ASN1_TYPE marshals |in| as DER, as described in |i2d_SAMPLE|.
i2d_ASN1_UNIVERSALSTRING(Pointer<ASN1_OCTET_STRING> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_ASN1_UTCTIME(Pointer<ASN1_OCTET_STRING> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_ASN1_UTCTIME marshals |in| as a DER-encoded ASN.1 UTCTime, as described in |i2d_SAMPLE|.
i2d_ASN1_UTF8STRING(Pointer<ASN1_OCTET_STRING> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_ASN1_VISIBLESTRING(Pointer<ASN1_OCTET_STRING> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_AUTHORITY_INFO_ACCESS(Pointer<AUTHORITY_INFO_ACCESS> aia, Pointer<Pointer<Uint8>> outp) → int
i2d_AUTHORITY_INFO_ACCESS marshals |aia| as a DER-encoded AuthorityInfoAccessSyntax (RFC 5280), as described in |i2d_SAMPLE|.
i2d_AUTHORITY_KEYID(Pointer<AUTHORITY_KEYID> akid, Pointer<Pointer<Uint8>> outp) → int
i2d_AUTHORITY_KEYID marshals |akid| as a DER-encoded AuthorityKeyIdentifier (RFC 5280), as described in |i2d_SAMPLE|.
i2d_BASIC_CONSTRAINTS(Pointer<BASIC_CONSTRAINTS> bcons, Pointer<Pointer<Uint8>> outp) → int
i2d_BASIC_CONSTRAINTS marshals |bcons| as a DER-encoded BasicConstraints (RFC 5280), as described in |i2d_SAMPLE|.
i2d_CERTIFICATEPOLICIES(Pointer<CERTIFICATEPOLICIES> policies, Pointer<Pointer<Uint8>> outp) → int
i2d_CERTIFICATEPOLICIES marshals |policies| as a DER-encoded CertificatePolicies (RFC 5280), as described in |i2d_SAMPLE|.
i2d_CRL_DIST_POINTS(Pointer<CRL_DIST_POINTS> crldp, Pointer<Pointer<Uint8>> outp) → int
i2d_CRL_DIST_POINTS marshals |crldp| as a DER-encoded CRLDistributionPoints (RFC 5280), as described in |i2d_SAMPLE|.
i2d_DHparams(Pointer<DH> in$, Pointer<Pointer<UnsignedChar>> outp) → int
i2d_DHparams marshals |in| to a DER-encoded DHParameter structure (PKCS #3), as described in |i2d_SAMPLE|.
i2d_DHparams_bio(Pointer<BIO> bp, Pointer<DH> dh) → int
i2d_DIRECTORYSTRING(Pointer<ASN1_OCTET_STRING> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_DIRECTORYSTRING marshals |in| as a DER-encoded X.509 DirectoryString (RFC 5280), as described in |i2d_SAMPLE|.
i2d_DISPLAYTEXT(Pointer<ASN1_OCTET_STRING> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_DISPLAYTEXT marshals |in| as a DER-encoded X.509 DisplayText (RFC 5280), as described in |i2d_SAMPLE|.
i2d_DSA_PUBKEY(Pointer<DSA> dsa, Pointer<Pointer<Uint8>> outp) → int
i2d_DSA_PUBKEY marshals |dsa| as a DER-encoded SubjectPublicKeyInfo, as described in |i2d_SAMPLE|.
i2d_DSA_PUBKEY_bio(Pointer<BIO> bp, Pointer<DSA> dsa) → int
i2d_DSA_PUBKEY_fp(Pointer<FILE> fp, Pointer<DSA> dsa) → int
i2d_DSA_SIG(Pointer<DSA_SIG> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_DSA_SIG marshals |in| to a DER-encoded DSA-Sig-Value structure, as described in |i2d_SAMPLE|.
i2d_DSAparams(Pointer<DSA> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_DSAparams marshals |in|'s parameters as a DER-encoded Dss-Parms structure (RFC 3279), as described in |i2d_SAMPLE|.
i2d_DSAPrivateKey(Pointer<DSA> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_DSAPrivateKey marshals |in| as a DER-encoded DSA private key, as described in |i2d_SAMPLE|.
i2d_DSAPrivateKey_bio(Pointer<BIO> bp, Pointer<DSA> dsa) → int
i2d_DSAPrivateKey_fp(Pointer<FILE> fp, Pointer<DSA> dsa) → int
i2d_DSAPublicKey(Pointer<DSA> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_DSAPublicKey marshals |in| as a DER-encoded DSA public key, as described in |i2d_SAMPLE|.
i2d_EC_PUBKEY(Pointer<EC_KEY> ec_key, Pointer<Pointer<Uint8>> outp) → int
i2d_EC_PUBKEY marshals |ec_key| as a DER-encoded SubjectPublicKeyInfo, as described in |i2d_SAMPLE|.
i2d_EC_PUBKEY_bio(Pointer<BIO> bp, Pointer<EC_KEY> eckey) → int
i2d_EC_PUBKEY_fp(Pointer<FILE> fp, Pointer<EC_KEY> eckey) → int
i2d_ECDSA_SIG(Pointer<ECDSA_SIG> sig, Pointer<Pointer<Uint8>> outp) → int
i2d_ECDSA_SIG marshals |sig| as a DER-encoded ECDSA-Sig-Value, as described in |i2d_SAMPLE|.
i2d_ECParameters(Pointer<EC_KEY> key, Pointer<Pointer<Uint8>> outp) → int
i2d_ECParameters marshals |key|'s parameters as a DER-encoded OBJECT IDENTIFIER, as described in |i2d_SAMPLE|.
i2d_ECPKParameters(Pointer<EC_GROUP> group, Pointer<Pointer<Uint8>> outp) → int
i2d_ECPKParameters marshals |group| as a DER-encoded ECParameters structure (RFC 5480), as described in |i2d_SAMPLE|.
i2d_ECPrivateKey(Pointer<EC_KEY> key, Pointer<Pointer<Uint8>> outp) → int
i2d_ECPrivateKey marshals |key| as a DER-encoded ECPrivateKey structure (RFC 5915), as described in |i2d_SAMPLE|.
i2d_ECPrivateKey_bio(Pointer<BIO> bp, Pointer<EC_KEY> eckey) → int
i2d_ECPrivateKey_fp(Pointer<FILE> fp, Pointer<EC_KEY> eckey) → int
i2d_EXTENDED_KEY_USAGE(Pointer<EXTENDED_KEY_USAGE> eku, Pointer<Pointer<Uint8>> outp) → int
i2d_EXTENDED_KEY_USAGE marshals |eku| as a DER-encoded ExtKeyUsageSyntax (RFC 5280), as described in |i2d_SAMPLE|.
i2d_GENERAL_NAME(Pointer<GENERAL_NAME> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_GENERAL_NAME marshals |in| as a DER-encoded X.509 GeneralName (RFC 5280), as described in |i2d_SAMPLE|.
i2d_GENERAL_NAMES(Pointer<GENERAL_NAMES> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_GENERAL_NAMES marshals |in| as a DER-encoded SEQUENCE OF GeneralName, as described in |i2d_SAMPLE|.
i2d_ISSUING_DIST_POINT(Pointer<ISSUING_DIST_POINT> idp, Pointer<Pointer<Uint8>> outp) → int
i2d_ISSUING_DIST_POINT marshals |idp| as a DER-encoded IssuingDistributionPoint (RFC 5280), as described in |i2d_SAMPLE|.
i2d_NETSCAPE_SPKAC(Pointer<NETSCAPE_SPKAC> spkac, Pointer<Pointer<Uint8>> outp) → int
i2d_NETSCAPE_SPKAC marshals |spkac| as a DER-encoded PublicKeyAndChallenge structure, as described in |i2d_SAMPLE|.
i2d_NETSCAPE_SPKI(Pointer<NETSCAPE_SPKI> spki, Pointer<Pointer<Uint8>> outp) → int
i2d_NETSCAPE_SPKI marshals |spki| as a DER-encoded SignedPublicKeyAndChallenge structure, as described in |i2d_SAMPLE|.
i2d_PKCS7(Pointer<PKCS7> p7, Pointer<Pointer<Uint8>> out) → int
i2d_PKCS7 marshals |p7| as a DER-encoded PKCS#7 ContentInfo structure, as described in |i2d_SAMPLE|.
i2d_PKCS7_bio(Pointer<BIO> bio, Pointer<PKCS7> p7) → int
i2d_PKCS7_bio writes |p7| to |bio|. It returns one on success and zero on error.
i2d_PKCS8_bio(Pointer<BIO> bp, Pointer<X509_SIG> p8) → int
i2d_PKCS8_fp(Pointer<FILE> fp, Pointer<X509_SIG> p8) → int
i2d_PKCS8_PRIV_KEY_INFO(Pointer<PKCS8_PRIV_KEY_INFO> key, Pointer<Pointer<Uint8>> outp) → int
i2d_PKCS8_PRIV_KEY_INFO marshals |key| as a DER-encoded PrivateKeyInfo, as described in |i2d_SAMPLE|.
i2d_PKCS8_PRIV_KEY_INFO_bio(Pointer<BIO> bp, Pointer<PKCS8_PRIV_KEY_INFO> p8inf) → int
i2d_PKCS8_PRIV_KEY_INFO_fp(Pointer<FILE> fp, Pointer<PKCS8_PRIV_KEY_INFO> p8inf) → int
i2d_PKCS8PrivateKey_bio(Pointer<BIO> bp, Pointer<EVP_PKEY> x, Pointer<EVP_CIPHER> enc, Pointer<Char> pass, int pass_len, Pointer<pem_password_cb> cb, Pointer<Void> u) → int
i2d_PKCS8PrivateKey_fp(Pointer<FILE> fp, Pointer<EVP_PKEY> x, Pointer<EVP_CIPHER> enc, Pointer<Char> pass, int pass_len, Pointer<pem_password_cb> cb, Pointer<Void> u) → int
i2d_PKCS8PrivateKey_nid_bio(Pointer<BIO> bp, Pointer<EVP_PKEY> x, int nid, Pointer<Char> pass, int pass_len, Pointer<pem_password_cb> cb, Pointer<Void> u) → int
i2d_PKCS8PrivateKey_nid_fp(Pointer<FILE> fp, Pointer<EVP_PKEY> x, int nid, Pointer<Char> pass, int pass_len, Pointer<pem_password_cb> cb, Pointer<Void> u) → int
i2d_PKCS8PrivateKeyInfo_bio(Pointer<BIO> bp, Pointer<EVP_PKEY> key) → int
i2d_PKCS8PrivateKeyInfo_bio encodes |key| as a PKCS#8 PrivateKeyInfo structure (see |EVP_marshal_private_key|) and writes the result to |bp|. It returns one on success and zero on error.
i2d_PKCS8PrivateKeyInfo_fp(Pointer<FILE> fp, Pointer<EVP_PKEY> key) → int
i2d_PrivateKey(Pointer<EVP_PKEY> key, Pointer<Pointer<Uint8>> outp) → int
i2d_PrivateKey marshals a private key from |key| to type-specific format, as described in |i2d_SAMPLE|.
i2d_PrivateKey_bio(Pointer<BIO> bp, Pointer<EVP_PKEY> pkey) → int
i2d_PrivateKey_fp(Pointer<FILE> fp, Pointer<EVP_PKEY> pkey) → int
i2d_PUBKEY(Pointer<EVP_PKEY> pkey, Pointer<Pointer<Uint8>> outp) → int
i2d_PUBKEY marshals |pkey| as a DER-encoded SubjectPublicKeyInfo, as described in |i2d_SAMPLE|.
i2d_PUBKEY_bio(Pointer<BIO> bp, Pointer<EVP_PKEY> pkey) → int
i2d_PUBKEY_fp(Pointer<FILE> fp, Pointer<EVP_PKEY> pkey) → int
i2d_PublicKey(Pointer<EVP_PKEY> key, Pointer<Pointer<Uint8>> outp) → int
i2d_PublicKey marshals a public key from |key| to a type-specific format, as described in |i2d_SAMPLE|.
i2d_re_X509_CRL_tbs(Pointer<X509_CRL> crl, Pointer<Pointer<UnsignedChar>> outp) → int
i2d_re_X509_CRL_tbs serializes the TBSCertList portion of |crl|, as described in |i2d_SAMPLE|.
i2d_re_X509_REQ_tbs(Pointer<X509_REQ> req, Pointer<Pointer<Uint8>> outp) → int
i2d_re_X509_REQ_tbs serializes the CertificationRequestInfo (see RFC 2986) portion of |req|, as described in |i2d_SAMPLE|.
i2d_re_X509_tbs(Pointer<X509> x509, Pointer<Pointer<Uint8>> outp) → int
i2d_re_X509_tbs serializes the TBSCertificate portion of |x509|, as described in |i2d_SAMPLE|.
i2d_RSA_PSS_PARAMS(Pointer<RSA_PSS_PARAMS> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_RSA_PSS_PARAMS marshals |in| as a DER-encoded RSASSA-PSS-params (RFC 4055), as described in |i2d_SAMPLE|.
i2d_RSA_PUBKEY(Pointer<RSA> rsa, Pointer<Pointer<Uint8>> outp) → int
i2d_RSA_PUBKEY marshals |rsa| as a DER-encoded SubjectPublicKeyInfo structure, as described in |i2d_SAMPLE|.
i2d_RSA_PUBKEY_bio(Pointer<BIO> bp, Pointer<RSA> rsa) → int
i2d_RSA_PUBKEY_fp(Pointer<FILE> fp, Pointer<RSA> rsa) → int
i2d_RSAPrivateKey(Pointer<RSA> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_RSAPrivateKey marshals |in| to a DER-encoded RSAPrivateKey structure (RFC 8017), as described in |i2d_SAMPLE|.
i2d_RSAPrivateKey_bio(Pointer<BIO> bp, Pointer<RSA> rsa) → int
i2d_RSAPrivateKey_fp(Pointer<FILE> fp, Pointer<RSA> rsa) → int
i2d_RSAPublicKey(Pointer<RSA> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_RSAPublicKey marshals |in| to a DER-encoded RSAPublicKey structure (RFC 8017), as described in |i2d_SAMPLE|.
i2d_RSAPublicKey_bio(Pointer<BIO> bp, Pointer<RSA> rsa) → int
i2d_RSAPublicKey_fp(Pointer<FILE> fp, Pointer<RSA> rsa) → int
i2d_X509(Pointer<X509> x509, Pointer<Pointer<Uint8>> outp) → int
i2d_X509 marshals |x509| as a DER-encoded X.509 Certificate (RFC 5280), as described in |i2d_SAMPLE|.
i2d_X509_ALGOR(Pointer<X509_ALGOR> alg, Pointer<Pointer<Uint8>> outp) → int
i2d_X509_ALGOR marshals |alg| as a DER-encoded AlgorithmIdentifier, as described in |i2d_SAMPLE|.
i2d_X509_ATTRIBUTE(Pointer<X509_ATTRIBUTE> alg, Pointer<Pointer<Uint8>> outp) → int
i2d_X509_ATTRIBUTE marshals |alg| as a DER-encoded Attribute (RFC 2986), as described in |i2d_SAMPLE|.
i2d_X509_AUX(Pointer<X509> x509, Pointer<Pointer<Uint8>> outp) → int
i2d_X509_AUX marshals |x509| as a DER-encoded X.509 Certificate (RFC 5280), followed optionally by a separate, OpenSSL-specific structure with auxiliary properties. It behaves as described in |i2d_SAMPLE|.
i2d_X509_bio(Pointer<BIO> bp, Pointer<X509> x509) → int
The following functions behave like the corresponding unsuffixed |i2d_| functions, but write the result to |bp|. They return one on success and zero on error. Callers using them with memory |BIO|s to encode structures to memory should use |i2d_| directly instead.
i2d_X509_CRL(Pointer<X509_CRL> crl, Pointer<Pointer<Uint8>> outp) → int
i2d_X509_CRL marshals |crl| as a X.509 CertificateList (RFC 5280), as described in |i2d_SAMPLE|.
i2d_X509_CRL_bio(Pointer<BIO> bp, Pointer<X509_CRL> crl) → int
i2d_X509_CRL_fp(Pointer<FILE> fp, Pointer<X509_CRL> crl) → int
i2d_X509_CRL_tbs(Pointer<X509_CRL> crl, Pointer<Pointer<UnsignedChar>> outp) → int
i2d_X509_CRL_tbs serializes the TBSCertList portion of |crl|, as described in |i2d_SAMPLE|.
i2d_X509_EXTENSION(Pointer<X509_EXTENSION> ex, Pointer<Pointer<Uint8>> outp) → int
i2d_X509_EXTENSION marshals |ex| as a DER-encoded X.509 Extension (RFC 5280), as described in |i2d_SAMPLE|.
i2d_X509_EXTENSIONS(Pointer<X509_EXTENSIONS> alg, Pointer<Pointer<Uint8>> outp) → int
i2d_X509_EXTENSIONS marshals |alg| as a DER-encoded SEQUENCE OF Extension (RFC 5280), as described in |i2d_SAMPLE|.
i2d_X509_fp(Pointer<FILE> fp, Pointer<X509> x509) → int
The following functions behave like the corresponding |i2d_*_bio| functions, but write to |fp| instead.
i2d_X509_NAME(Pointer<X509_NAME> in$, Pointer<Pointer<Uint8>> outp) → int
i2d_X509_NAME marshals |in| as a DER-encoded X.509 Name (RFC 5280), as described in |i2d_SAMPLE|.
i2d_X509_PUBKEY(Pointer<X509_PUBKEY> key, Pointer<Pointer<Uint8>> outp) → int
i2d_X509_PUBKEY marshals |key| as a DER-encoded SubjectPublicKeyInfo, as described in |i2d_SAMPLE|.
i2d_X509_REQ(Pointer<X509_REQ> req, Pointer<Pointer<Uint8>> outp) → int
i2d_X509_REQ marshals |req| as a CertificateRequest (RFC 2986), as described in |i2d_SAMPLE|.
i2d_X509_REQ_bio(Pointer<BIO> bp, Pointer<X509_REQ> req) → int
i2d_X509_REQ_fp(Pointer<FILE> fp, Pointer<X509_REQ> req) → int
i2d_X509_REVOKED(Pointer<X509_REVOKED> alg, Pointer<Pointer<Uint8>> outp) → int
i2d_X509_REVOKED marshals |alg| as a DER-encoded X.509 CRL entry, as described in |i2d_SAMPLE|.
i2d_X509_SIG(Pointer<X509_SIG> sig, Pointer<Pointer<Uint8>> outp) → int
i2d_X509_SIG marshals |sig| as a DER-encoded algorithm and octet string pair, as described in |i2d_SAMPLE|.
i2d_X509_tbs(Pointer<X509> x509, Pointer<Pointer<Uint8>> outp) → int
i2d_X509_tbs serializes the TBSCertificate portion of |x509|, as described in |i2d_SAMPLE|.
i2o_ECPublicKey(Pointer<EC_KEY> key, Pointer<Pointer<UnsignedChar>> outp) → int
i2o_ECPublicKey marshals an EC point from |key|, as described in |i2d_SAMPLE|, except it returns zero on error instead of a negative value.
i2s_ASN1_ENUMERATED(Pointer<X509V3_EXT_METHOD> method, Pointer<ASN1_OCTET_STRING> aint) → Pointer<Char>
i2s_ASN1_ENUMERATED returns a human-readable representation of |aint| as a newly-allocated, NUL-terminated string, or NULL on error. |method| is ignored. The caller must release the result with |OPENSSL_free| when done.
i2s_ASN1_INTEGER(Pointer<X509V3_EXT_METHOD> method, Pointer<ASN1_OCTET_STRING> aint) → Pointer<Char>
i2s_ASN1_INTEGER returns a human-readable representation of |aint| as a newly-allocated, NUL-terminated string, or NULL on error. |method| is ignored. The caller must release the result with |OPENSSL_free| when done.
i2s_ASN1_OCTET_STRING(Pointer<X509V3_EXT_METHOD> method, Pointer<ASN1_OCTET_STRING> oct) → Pointer<Char>
i2s_ASN1_OCTET_STRING returns a human-readable representation of |oct| as a newly-allocated, NUL-terminated string, or NULL on error. |method| is ignored. The caller must release the result with |OPENSSL_free| when done.
i2t_ASN1_OBJECT(Pointer<Char> buf, int buf_len, Pointer<ASN1_OBJECT> a) → int
i2t_ASN1_OBJECT calls |OBJ_obj2txt| with |always_return_oid| set to zero.
i2v_GENERAL_NAME(Pointer<X509V3_EXT_METHOD> method, Pointer<GENERAL_NAME> gen, Pointer<stack_st_CONF_VALUE> ret) → Pointer<stack_st_CONF_VALUE>
i2v_GENERAL_NAME serializes |gen| as a |CONF_VALUE|. If |ret| is non-NULL, it appends the value to |ret| and returns |ret| on success or NULL on error. If it returns NULL, the caller is still responsible for freeing |ret|. If |ret| is NULL, it returns a newly-allocated |STACK_OF(CONF_VALUE)| containing the result. |method| is ignored. When done, the caller should release the result with |sk_CONF_VALUE_pop_free| and |X509V3_conf_free|.
i2v_GENERAL_NAMES(Pointer<X509V3_EXT_METHOD> method, Pointer<GENERAL_NAMES> gen, Pointer<stack_st_CONF_VALUE> extlist) → Pointer<stack_st_CONF_VALUE>
i2v_GENERAL_NAMES serializes |gen| as a list of |CONF_VALUE|s. If |ret| is non-NULL, it appends the values to |ret| and returns |ret| on success or NULL on error. If it returns NULL, the caller is still responsible for freeing |ret|. If |ret| is NULL, it returns a newly-allocated |STACK_OF(CONF_VALUE)| containing the results. |method| is ignored.
ISSUING_DIST_POINT_free(Pointer<ISSUING_DIST_POINT> idp) → void
ISSUING_DIST_POINT_free releases memory associated with |idp|.
ISSUING_DIST_POINT_new() → Pointer<ISSUING_DIST_POINT>
ISSUING_DIST_POINT_new returns a newly-allocated, empty |ISSUING_DIST_POINT| object, or NULL on error.
METHOD_ref(Pointer<Void> method) → void
METHOD_ref increments the reference count of |method|. This is a no-op for now because all methods are currently static.
METHOD_unref(Pointer<Void> method) → void
METHOD_unref decrements the reference count of |method| and frees it if the reference count drops to zero. This is a no-op for now because all methods are currently static.
NAME_CONSTRAINTS_check(Pointer<X509> x509, Pointer<NAME_CONSTRAINTS> nc) → int
NAME_CONSTRAINTS_check checks if |x509| satisfies name constraints in |nc|. It returns |X509_V_OK| on success and some |X509_V_ERR_*| constant on error.
NAME_CONSTRAINTS_free(Pointer<NAME_CONSTRAINTS> ncons) → void
NAME_CONSTRAINTS_free releases memory associated with |ncons|.
NAME_CONSTRAINTS_new() → Pointer<NAME_CONSTRAINTS>
NAME_CONSTRAINTS_new returns a newly-allocated, empty |NAME_CONSTRAINTS| object, or NULL on error.
NCONF_free(Pointer<CONF> conf) → void
NCONF_free frees all the data owned by |conf| and then |conf| itself.
NCONF_get_section(Pointer<CONF> conf, Pointer<Char> section) → Pointer<stack_st_CONF_VALUE>
NCONF_get_section returns a stack of values for a given section in |conf|. If |section| is NULL, the default section is returned. It returns NULL on error.
NCONF_get_string(Pointer<CONF> conf, Pointer<Char> section, Pointer<Char> name) → Pointer<Char>
NCONF_get_string returns the value of the key |name|, in section |section|. The |section| argument may be NULL to indicate the default section. It returns the value or NULL on error.
NCONF_load(Pointer<CONF> conf, Pointer<Char> filename, Pointer<Long> out_error_line) → int
NCONF_load parses the file named |filename| and adds the values found to |conf|. It returns one on success and zero on error. In the event of an error, if |out_error_line| is not NULL, |*out_error_line| is set to the number of the line that contained the error.
NCONF_load_bio(Pointer<CONF> conf, Pointer<BIO> bio, Pointer<Long> out_error_line) → int
NCONF_load_bio acts like |NCONF_load| but reads from |bio| rather than from a named file.
NCONF_new(Pointer<Void> method) → Pointer<CONF>
NCONF_new returns a fresh, empty |CONF|, or NULL on error. The |method| argument must be NULL.
NETSCAPE_SPKAC_free(Pointer<NETSCAPE_SPKAC> spkac) → void
NETSCAPE_SPKAC_free releases memory associated with |spkac|.
NETSCAPE_SPKAC_new() → Pointer<NETSCAPE_SPKAC>
NETSCAPE_SPKAC_new returns a newly-allocated, empty |NETSCAPE_SPKAC| object, or NULL on error.
NETSCAPE_SPKI_b64_decode(Pointer<Char> str, int len) → Pointer<NETSCAPE_SPKI>
NETSCAPE_SPKI_b64_decode decodes |len| bytes from |str| as a base64-encoded SignedPublicKeyAndChallenge structure. It returns a newly-allocated |NETSCAPE_SPKI| structure with the result, or NULL on error. If |len| is 0 or negative, the length is calculated with |strlen| and |str| must be a NUL-terminated C string.
NETSCAPE_SPKI_b64_encode(Pointer<NETSCAPE_SPKI> spki) → Pointer<Char>
NETSCAPE_SPKI_b64_encode encodes |spki| as a base64-encoded SignedPublicKeyAndChallenge structure. It returns a newly-allocated NUL-terminated C string with the result, or NULL on error. The caller must release the memory with |OPENSSL_free| when done.
NETSCAPE_SPKI_free(Pointer<NETSCAPE_SPKI> spki) → void
NETSCAPE_SPKI_free releases memory associated with |spki|.
NETSCAPE_SPKI_get_pubkey(Pointer<NETSCAPE_SPKI> spki) → Pointer<EVP_PKEY>
NETSCAPE_SPKI_get_pubkey decodes and returns the public key in |spki| as an |EVP_PKEY|, or NULL on error. The caller takes ownership of the resulting pointer and must call |EVP_PKEY_free| when done.
NETSCAPE_SPKI_new() → Pointer<NETSCAPE_SPKI>
NETSCAPE_SPKI_new returns a newly-allocated, empty |NETSCAPE_SPKI| object, or NULL on error.
NETSCAPE_SPKI_set_pubkey(Pointer<NETSCAPE_SPKI> spki, Pointer<EVP_PKEY> pkey) → int
NETSCAPE_SPKI_set_pubkey sets |spki|'s public key to |pkey|. It returns one on success or zero on error. This function does not take ownership of |pkey|, so the caller may continue to manage its lifetime independently of |spki|.
NETSCAPE_SPKI_sign(Pointer<NETSCAPE_SPKI> spki, Pointer<EVP_PKEY> pkey, Pointer<EVP_MD> md) → int
NETSCAPE_SPKI_sign signs |spki| with |pkey| and replaces the signature algorithm and signature fields. It returns the length of the signature on success and zero on error. This function uses digest algorithm |md|, or |pkey|'s default if NULL. Other signing parameters use |pkey|'s defaults.
NETSCAPE_SPKI_verify(Pointer<NETSCAPE_SPKI> spki, Pointer<EVP_PKEY> pkey) → int
NETSCAPE_SPKI_verify checks that |spki| has a valid signature by |pkey|. It returns one if the signature is valid and zero otherwise.
NOTICEREF_free(Pointer<NOTICEREF> ref) → void
NOTICEREF_free releases memory associated with |ref|.
NOTICEREF_new() → Pointer<NOTICEREF>
NOTICEREF_new returns a newly-allocated, empty |NOTICEREF| object, or NULL on error.
o2i_ECPublicKey(Pointer<Pointer<EC_KEY>> out_key, Pointer<Pointer<Uint8>> inp, int len) → Pointer<EC_KEY>
o2i_ECPublicKey parses an EC point from |len| bytes at |*inp| into |*out_key|. Note that this differs from the d2i format in that |*out_key| must be non-NULL with a group set. On successful exit, |*inp| is advanced by |len| bytes. It returns |*out_key| or NULL on error.
OBJ_cbs2nid(Pointer<CBS> cbs) → int
OBJ_cbs2nid returns the nid corresponding to the DER data in |cbs|, or |NID_undef| if no such object is known.
OBJ_cleanup() → void
OBJ_cleanup does nothing.
OBJ_cmp(Pointer<ASN1_OBJECT> a, Pointer<ASN1_OBJECT> b) → int
OBJ_cmp returns a value less than, equal to or greater than zero if |a| is less than, equal to or greater than |b|, respectively.
OBJ_create(Pointer<Char> oid, Pointer<Char> short_name, Pointer<Char> long_name) → int
OBJ_create adds a known object and returns the NID of the new object, or NID_undef on error.
OBJ_dup(Pointer<ASN1_OBJECT> obj) → Pointer<ASN1_OBJECT>
OBJ_dup returns a duplicate copy of |obj| or NULL on allocation failure. The caller must call |ASN1_OBJECT_free| on the result to release it.
OBJ_find_sigid_algs(int sign_nid, Pointer<Int> out_digest_nid, Pointer<Int> out_pkey_nid) → int
OBJ_find_sigid_algs finds the digest and public-key NIDs that correspond to the signing algorithm |sign_nid|. If successful, it sets |*out_digest_nid| and |*out_pkey_nid| and returns one. Otherwise it returns zero. Any of |out_digest_nid| or |out_pkey_nid| can be NULL if the caller doesn't need that output value.
OBJ_find_sigid_by_algs(Pointer<Int> out_sign_nid, int digest_nid, int pkey_nid) → int
OBJ_find_sigid_by_algs finds the signature NID that corresponds to the combination of |digest_nid| and |pkey_nid|. If success, it sets |*out_sign_nid| and returns one. Otherwise it returns zero. The |out_sign_nid| argument can be NULL if the caller only wishes to learn whether the combination is valid.
OBJ_get0_data(Pointer<ASN1_OBJECT> obj) → Pointer<Uint8>
OBJ_get0_data returns a pointer to the DER representation of |obj|. This is the contents of the DER-encoded identifier, not including the tag and length. If |obj| does not have an associated object identifier (i.e. it is a nid-only value), this value is the empty string.
OBJ_get_undef() → Pointer<ASN1_OBJECT>
OBJ_get_undef returns the object for |NID_undef|. Prefer this function over |OBJ_nid2obj| to avoid pulling in the full OID table.
OBJ_length(Pointer<ASN1_OBJECT> obj) → int
OBJ_length returns the length of the DER representation of |obj|. This is the contents of the DER-encoded identifier, not including the tag and length. If |obj| does not have an associated object identifier (i.e. it is a nid-only value), this value is the empty string.
OBJ_ln2nid(Pointer<Char> long_name) → int
OBJ_ln2nid returns the nid corresponding to |long_name|, or |NID_undef| if no such long name is known.
OBJ_nid2cbb(Pointer<CBB> out, int nid) → int
OBJ_nid2cbb writes |nid| as an ASN.1 OBJECT IDENTIFIER to |out|. It returns one on success or zero otherwise.
OBJ_nid2ln(int nid) → Pointer<Char>
OBJ_nid2ln returns the long name for |nid|, or NULL if |nid| is unknown.
OBJ_nid2obj(int nid) → Pointer<ASN1_OBJECT>
OBJ_nid2obj returns the |ASN1_OBJECT| corresponding to |nid|, or NULL if |nid| is unknown.
OBJ_nid2sn(int nid) → Pointer<Char>
OBJ_nid2sn returns the short name for |nid|, or NULL if |nid| is unknown.
OBJ_obj2nid(Pointer<ASN1_OBJECT> obj) → int
OBJ_obj2nid returns the nid corresponding to |obj|, or |NID_undef| if no such object is known.
OBJ_obj2txt(Pointer<Char> out, int out_len, Pointer<ASN1_OBJECT> obj, int always_return_oid) → int
OBJ_obj2txt converts |obj| to a textual representation. If |always_return_oid| is zero then |obj| will be matched against known objects and the long (preferably) or short name will be used if found. Otherwise |obj| will be converted into a dotted sequence of integers. If |out| is not NULL, then at most |out_len| bytes of the textual form will be written there. If |out_len| is at least one, then string written to |out| will always be NUL terminated. It returns the number of characters that could have been written, not including the final NUL, or -1 on error.
OBJ_sn2nid(Pointer<Char> short_name) → int
OBJ_sn2nid returns the nid corresponding to |short_name|, or |NID_undef| if no such short name is known.
OBJ_txt2nid(Pointer<Char> s) → int
OBJ_txt2nid returns the nid corresponding to |s|, which may be a short name, long name, or an ASCII string containing a dotted sequence of numbers. It returns the nid or NID_undef if unknown.
OBJ_txt2obj(Pointer<Char> s, int dont_search_names) → Pointer<ASN1_OBJECT>
OBJ_txt2obj returns an ASN1_OBJECT for the textual representation in |s|. If |dont_search_names| is zero, then |s| will be matched against the long and short names of a known objects to find a match. Otherwise |s| must contain an ASCII string with a dotted sequence of numbers. The resulting object need not be previously known. It returns a freshly allocated |ASN1_OBJECT| or NULL on error.
OpenSSL_add_all_algorithms() → void
OpenSSL_add_all_algorithms does nothing.
OPENSSL_add_all_algorithms_conf() → void
OPENSSL_add_all_algorithms_conf does nothing.
OpenSSL_add_all_ciphers() → void
OpenSSL_add_all_ciphers does nothing.
OpenSSL_add_all_digests() → void
OpenSSL_add_all_digests does nothing.
OPENSSL_asprintf(Pointer<Pointer<Char>> str, Pointer<Char> format) → int
OPENSSL_asprintf has the same behavior as asprintf(3), except that memory allocated in a returned string must be freed with |OPENSSL_free|.
OPENSSL_calloc(int num, int size) → Pointer<Void>
OPENSSL_calloc is similar to a regular |calloc|, but allocates data with |OPENSSL_malloc|. On overflow, it will push |ERR_R_OVERFLOW| onto the error queue.
OPENSSL_cleanse(Pointer<Void> ptr, int len) → void
OPENSSL_cleanse zeros out |len| bytes of memory at |ptr|. This is similar to |memset_s| from C11.
OPENSSL_cleanup() → void
OPENSSL_cleanup does nothing.
OPENSSL_clear_free(Pointer<Void> ptr, int len) → void
OPENSSL_clear_free calls |OPENSSL_free|. BoringSSL automatically clears all allocations on free, but we define |OPENSSL_clear_free| for compatibility.
OPENSSL_config(Pointer<Char> config_name) → void
OPENSSL_config does nothing.
OPENSSL_free(Pointer<Void> ptr) → void
OPENSSL_free does nothing if |ptr| is NULL. Otherwise it zeros out the memory allocated at |ptr| and frees it along with the private data. It must only be used on on |ptr| values obtained from |OPENSSL_malloc|
OPENSSL_fromxdigit(Pointer<Uint8> out, int c) → int
OPENSSL_fromxdigit returns one if |c| is a hexadecimal digit as recognized by OPENSSL_isxdigit, and sets |out| to the corresponding value. Otherwise zero is returned.
OPENSSL_hash32(Pointer<Void> ptr, int len) → int
OPENSSL_hash32 implements the 32 bit, FNV-1a hash.
OPENSSL_init_crypto(int opts, Pointer<OPENSSL_INIT_SETTINGS> settings) → int
OPENSSL_init_crypto returns one.
OPENSSL_isalnum(int c) → int
OPENSSL_isalnum is a locale-independent, ASCII-only version of isalnum(3), It only recognizes what |OPENSSL_isalpha| and |OPENSSL_isdigit| recognize.
OPENSSL_isalpha(int c) → int
OPENSSL_isalpha is a locale-independent, ASCII-only version of isalpha(3), It only recognizes 'a' through 'z' and 'A' through 'Z' as alphabetic.
OPENSSL_isdigit(int c) → int
OPENSSL_isdigit is a locale-independent, ASCII-only version of isdigit(3), It only recognizes '0' through '9' as digits.
OPENSSL_isspace(int c) → int
OPENSSL_isspace is a locale-independent, ASCII-only version of isspace(3). It only recognizes '\t', '\n', '\v', '\f', '\r', and ' '.
OPENSSL_isxdigit(int c) → int
OPENSSL_isxdigit is a locale-independent, ASCII-only version of isxdigit(3), It only recognizes '0' through '9', 'a' through 'f', and 'A through 'F' as digits.
OPENSSL_load_builtin_modules() → void
OPENSSL_load_builtin_modules does nothing.
OPENSSL_malloc(int size) → Pointer<Void>
OPENSSL_malloc is similar to a regular |malloc|, but allocates additional private data. The resulting pointer must be freed with |OPENSSL_free|. In the case of a malloc failure, prior to returning NULL |OPENSSL_malloc| will push |ERR_R_MALLOC_FAILURE| onto the openssl error stack.
OPENSSL_malloc_init() → int
OPENSSL_malloc_init returns one.
OPENSSL_memdup(Pointer<Void> data, int size) → Pointer<Void>
OPENSSL_memdup returns an allocated, duplicate of |size| bytes from |data| or NULL on allocation failure. The memory allocated must be freed with |OPENSSL_free|.
OPENSSL_no_config() → void
OPENSSL_no_config does nothing.
OPENSSL_realloc(Pointer<Void> ptr, int new_size) → Pointer<Void>
OPENSSL_realloc returns a pointer to a buffer of |new_size| bytes that contains the contents of |ptr|. Unlike |realloc|, a new buffer is always allocated and the data at |ptr| is always wiped and freed. Memory is allocated with |OPENSSL_malloc| and must be freed with |OPENSSL_free|.
OPENSSL_secure_clear_free(Pointer<Void> ptr, int len) → void
OPENSSL_secure_clear_free calls |OPENSSL_clear_free|.
OPENSSL_secure_malloc(int size) → Pointer<Void>
OPENSSL_secure_malloc calls |OPENSSL_malloc|.
OPENSSL_sk_deep_copy(Pointer<OPENSSL_STACK> sk, OPENSSL_sk_call_copy_func call_copy_func, OPENSSL_sk_copy_func copy_func, OPENSSL_sk_call_free_func call_free_func, OPENSSL_sk_free_func free_func) → Pointer<OPENSSL_STACK>
OPENSSL_sk_delete(Pointer<OPENSSL_STACK> sk, int where) → Pointer<Void>
OPENSSL_sk_delete_if(Pointer<OPENSSL_STACK> sk, OPENSSL_sk_call_delete_if_func call_func, OPENSSL_sk_delete_if_func func, Pointer<Void> data) → void
OPENSSL_sk_delete_ptr(Pointer<OPENSSL_STACK> sk, Pointer<Void> p) → Pointer<Void>
OPENSSL_sk_dup(Pointer<OPENSSL_STACK> sk) → Pointer<OPENSSL_STACK>
OPENSSL_sk_find(Pointer<OPENSSL_STACK> sk, Pointer<Size> out_index, Pointer<Void> p, OPENSSL_sk_call_cmp_func call_cmp_func) → int
OPENSSL_sk_free(Pointer<OPENSSL_STACK> sk) → void
OPENSSL_sk_insert(Pointer<OPENSSL_STACK> sk, Pointer<Void> p, int where) → int
OPENSSL_sk_is_sorted(Pointer<OPENSSL_STACK> sk) → int
OPENSSL_sk_new(OPENSSL_sk_cmp_func comp) → Pointer<OPENSSL_STACK>
The following are raw stack functions. They implement the corresponding typed |sk_SAMPLE_*| functions generated by |DEFINE_STACK_OF|. Callers shouldn't be using them. Rather, callers should use the typed functions.
OPENSSL_sk_new_null() → Pointer<OPENSSL_STACK>
OPENSSL_sk_num(Pointer<OPENSSL_STACK> sk) → int
OPENSSL_sk_pop(Pointer<OPENSSL_STACK> sk) → Pointer<Void>
OPENSSL_sk_pop_free_ex(Pointer<OPENSSL_STACK> sk, OPENSSL_sk_call_free_func call_free_func, OPENSSL_sk_free_func free_func) → void
OPENSSL_sk_push(Pointer<OPENSSL_STACK> sk, Pointer<Void> p) → int
OPENSSL_sk_set(Pointer<OPENSSL_STACK> sk, int i, Pointer<Void> p) → Pointer<Void>
OPENSSL_sk_set_cmp_func(Pointer<OPENSSL_STACK> sk, OPENSSL_sk_cmp_func comp) → OPENSSL_sk_cmp_func
OPENSSL_sk_shift(Pointer<OPENSSL_STACK> sk) → Pointer<Void>
OPENSSL_sk_sort(Pointer<OPENSSL_STACK> sk, OPENSSL_sk_call_cmp_func call_cmp_func) → void
OPENSSL_sk_sort_and_dedup(Pointer<OPENSSL_STACK> sk, OPENSSL_sk_call_cmp_func call_cmp_func, OPENSSL_sk_call_free_func call_free_func, OPENSSL_sk_free_func free_func) → void
OPENSSL_sk_value(Pointer<OPENSSL_STACK> sk, int i) → Pointer<Void>
OPENSSL_sk_zero(Pointer<OPENSSL_STACK> sk) → void
OPENSSL_strcasecmp(Pointer<Char> a, Pointer<Char> b) → int
OPENSSL_strcasecmp is a locale-independent, ASCII-only version of strcasecmp(3).
OPENSSL_strdup(Pointer<Char> s) → Pointer<Char>
OPENSSL_strdup has the same behaviour as strdup(3).
OPENSSL_strhash(Pointer<Char> s) → int
OPENSSL_strhash calls |OPENSSL_hash32| on the NUL-terminated string |s|.
OPENSSL_strlcat(Pointer<Char> dst, Pointer<Char> src, int dst_size) → int
OPENSSL_strlcat acts like strlcat(3).
OPENSSL_strlcpy(Pointer<Char> dst, Pointer<Char> src, int dst_size) → int
OPENSSL_strlcpy acts like strlcpy(3).
OPENSSL_strncasecmp(Pointer<Char> a, Pointer<Char> b, int n) → int
OPENSSL_strncasecmp is a locale-independent, ASCII-only version of strncasecmp(3).
OPENSSL_strndup(Pointer<Char> str, int size) → Pointer<Char>
OPENSSL_strndup returns an allocated, duplicate of |str|, which is, at most, |size| bytes. The result is always NUL terminated. The memory allocated must be freed with |OPENSSL_free|.
OPENSSL_strnlen(Pointer<Char> s, int len) → int
OPENSSL_strnlen has the same behaviour as strnlen(3).
OPENSSL_tolower(int c) → int
OPENSSL_tolower is a locale-independent, ASCII-only version of tolower(3). It only lowercases ASCII values. Other values are returned as-is.
OPENSSL_vasprintf(Pointer<Pointer<Char>> str, Pointer<Char> format, Pointer<__va_list_tag> args) → int
OPENSSL_vasprintf has the same behavior as vasprintf(3), except that memory allocated in a returned string must be freed with |OPENSSL_free|.
OpenSSL_version(int which) → Pointer<Char>
OpenSSL_version is a compatibility function that returns the string "BoringSSL" if |which| is |OPENSSL_VERSION| and placeholder strings otherwise.
OpenSSL_version_num() → int
OpenSSL_version_num is a compatibility function that returns OPENSSL_VERSION_NUMBER from base.h.
OPENSSL_zalloc(int size) → Pointer<Void>
OPENSSL_zalloc behaves like |OPENSSL_malloc| except it also initializes the resulting memory to zero.
OTHERNAME_free(Pointer<OTHERNAME> name) → void
OTHERNAME_free releases memory associated with |name|.
OTHERNAME_new() → Pointer<OTHERNAME>
OTHERNAME_new returns a new, empty |OTHERNAME|, or NULL on error.
PEM_ASN1_read(Pointer<d2i_of_void> d2i, Pointer<Char> name, Pointer<FILE> fp, Pointer<Pointer<Void>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<Void>
PEM_ASN1_read_bio(Pointer<d2i_of_void> d2i, Pointer<Char> name, Pointer<BIO> bp, Pointer<Pointer<Void>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<Void>
PEM_ASN1_write(Pointer<i2d_of_void> i2d, Pointer<Char> name, Pointer<FILE> fp, Pointer<Void> x, Pointer<EVP_CIPHER> enc, Pointer<UnsignedChar> pass, int pass_len, Pointer<pem_password_cb> callback, Pointer<Void> u) → int
PEM_ASN1_write_bio(Pointer<i2d_of_void> i2d, Pointer<Char> name, Pointer<BIO> bp, Pointer<Void> x, Pointer<EVP_CIPHER> enc, Pointer<UnsignedChar> pass, int pass_len, Pointer<pem_password_cb> cb, Pointer<Void> u) → int
PEM_bytes_read_bio(Pointer<Pointer<UnsignedChar>> pdata, Pointer<Long> plen, Pointer<Pointer<Char>> pnm, Pointer<Char> name, Pointer<BIO> bp, Pointer<pem_password_cb> cb, Pointer<Void> u) → int
PEM_def_callback(Pointer<Char> buf, int size, int rwflag, Pointer<Void> userdata) → int
PEM_def_callback treats |userdata| as a string and copies it into |buf|, assuming its |size| is sufficient. Returns the length of the string, or -1 on error. Error cases the buffer being too small, or |buf| and |userdata| being NULL. Note that this is different from OpenSSL, which prompts for a password.
PEM_read(Pointer<FILE> fp, Pointer<Pointer<Char>> name, Pointer<Pointer<Char>> header, Pointer<Pointer<UnsignedChar>> data, Pointer<Long> len) → int
PEM_read_bio(Pointer<BIO> bp, Pointer<Pointer<Char>> name, Pointer<Pointer<Char>> header, Pointer<Pointer<UnsignedChar>> data, Pointer<Long> len) → int
PEM_read_bio reads from |bp|, until the next PEM block. If one is found, it returns one and sets |*name|, |*header|, and |*data| to newly-allocated buffers containing the PEM type, the header block, and the decoded data, respectively. |*name| and |*header| are NUL-terminated C strings, while |*data| has |*len| bytes. The caller must release each of |*name|, |*header|, and |*data| with |OPENSSL_free| when done. If no PEM block is found, this function returns zero and pushes |PEM_R_NO_START_LINE| to the error queue. If one is found, but there is an error decoding it, it returns zero and pushes some other error to the error queue.
PEM_read_bio_DHparams(Pointer<BIO> bp, Pointer<Pointer<DH>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<DH>
PEM_read_bio_DSA_PUBKEY(Pointer<BIO> bp, Pointer<Pointer<DSA>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<DSA>
PEM_read_bio_DSAparams(Pointer<BIO> bp, Pointer<Pointer<DSA>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<DSA>
PEM_read_bio_DSAPrivateKey(Pointer<BIO> bp, Pointer<Pointer<DSA>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<DSA>
PEM_read_bio_EC_PUBKEY(Pointer<BIO> bp, Pointer<Pointer<EC_KEY>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<EC_KEY>
PEM_read_bio_ECPrivateKey(Pointer<BIO> bp, Pointer<Pointer<EC_KEY>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<EC_KEY>
PEM_read_bio_PKCS7(Pointer<BIO> bp, Pointer<Pointer<PKCS7>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<PKCS7>
PEM_read_bio_PKCS8(Pointer<BIO> bp, Pointer<Pointer<X509_SIG>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<X509_SIG>
PEM_read_bio_PKCS8_PRIV_KEY_INFO(Pointer<BIO> bp, Pointer<Pointer<PKCS8_PRIV_KEY_INFO>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<PKCS8_PRIV_KEY_INFO>
PEM_read_bio_PrivateKey(Pointer<BIO> bp, Pointer<Pointer<EVP_PKEY>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<EVP_PKEY>
PEM_read_bio_PUBKEY(Pointer<BIO> bp, Pointer<Pointer<EVP_PKEY>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<EVP_PKEY>
PEM_read_bio_RSA_PUBKEY(Pointer<BIO> bp, Pointer<Pointer<RSA>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<RSA>
PEM_read_bio_RSAPrivateKey(Pointer<BIO> bp, Pointer<Pointer<RSA>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<RSA>
PEM_read_bio_RSAPublicKey(Pointer<BIO> bp, Pointer<Pointer<RSA>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<RSA>
PEM_read_bio_X509(Pointer<BIO> bp, Pointer<Pointer<X509>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<X509>
PEM_read_bio_X509_AUX(Pointer<BIO> bp, Pointer<Pointer<X509>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<X509>
TODO(crbug.com/boringssl/426): When documenting these, copy the warning about auxiliary properties from |PEM_X509_INFO_read_bio|.
PEM_read_bio_X509_CRL(Pointer<BIO> bp, Pointer<Pointer<X509_CRL>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<X509_CRL>
PEM_read_bio_X509_REQ(Pointer<BIO> bp, Pointer<Pointer<X509_REQ>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<X509_REQ>
PEM_read_DHparams(Pointer<FILE> fp, Pointer<Pointer<DH>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<DH>
PEM_read_DSA_PUBKEY(Pointer<FILE> fp, Pointer<Pointer<DSA>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<DSA>
PEM_read_DSAparams(Pointer<FILE> fp, Pointer<Pointer<DSA>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<DSA>
PEM_read_DSAPrivateKey(Pointer<FILE> fp, Pointer<Pointer<DSA>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<DSA>
PEM_read_EC_PUBKEY(Pointer<FILE> fp, Pointer<Pointer<EC_KEY>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<EC_KEY>
PEM_read_ECPrivateKey(Pointer<FILE> fp, Pointer<Pointer<EC_KEY>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<EC_KEY>
PEM_read_PKCS7(Pointer<FILE> fp, Pointer<Pointer<PKCS7>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<PKCS7>
PEM_read_PKCS8(Pointer<FILE> fp, Pointer<Pointer<X509_SIG>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<X509_SIG>
PEM_read_PKCS8_PRIV_KEY_INFO(Pointer<FILE> fp, Pointer<Pointer<PKCS8_PRIV_KEY_INFO>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<PKCS8_PRIV_KEY_INFO>
PEM_read_PrivateKey(Pointer<FILE> fp, Pointer<Pointer<EVP_PKEY>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<EVP_PKEY>
PEM_read_PUBKEY(Pointer<FILE> fp, Pointer<Pointer<EVP_PKEY>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<EVP_PKEY>
PEM_read_RSA_PUBKEY(Pointer<FILE> fp, Pointer<Pointer<RSA>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<RSA>
PEM_read_RSAPrivateKey(Pointer<FILE> fp, Pointer<Pointer<RSA>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<RSA>
PEM_read_RSAPublicKey(Pointer<FILE> fp, Pointer<Pointer<RSA>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<RSA>
PEM_read_X509(Pointer<FILE> fp, Pointer<Pointer<X509>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<X509>
PEM_read_X509_AUX(Pointer<FILE> fp, Pointer<Pointer<X509>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<X509>
PEM_read_X509_CRL(Pointer<FILE> fp, Pointer<Pointer<X509_CRL>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<X509_CRL>
PEM_read_X509_REQ(Pointer<FILE> fp, Pointer<Pointer<X509_REQ>> x, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<X509_REQ>
PEM_write(Pointer<FILE> fp, Pointer<Char> name, Pointer<Char> hdr, Pointer<UnsignedChar> data, int len) → int
PEM_write_bio(Pointer<BIO> bp, Pointer<Char> name, Pointer<Char> hdr, Pointer<UnsignedChar> data, int len) → int
PEM_write_bio writes a PEM block to |bp|, containing |len| bytes from |data| as data. |name| and |hdr| are NUL-terminated C strings containing the PEM type and header block, respectively. This function returns zero on error and the number of bytes written on success.
PEM_write_bio_DHparams(Pointer<BIO> bp, Pointer<DH> x) → int
PEM_write_bio_DSA_PUBKEY(Pointer<BIO> bp, Pointer<DSA> x) → int
PEM_write_bio_DSAparams(Pointer<BIO> bp, Pointer<DSA> x) → int
PEM_write_bio_DSAPrivateKey(Pointer<BIO> bp, Pointer<DSA> x, Pointer<EVP_CIPHER> enc, Pointer<UnsignedChar> pass, int pass_len, Pointer<pem_password_cb> cb, Pointer<Void> u) → int
PEM_write_bio_EC_PUBKEY(Pointer<BIO> bp, Pointer<EC_KEY> x) → int
PEM_write_bio_ECPrivateKey(Pointer<BIO> bp, Pointer<EC_KEY> x, Pointer<EVP_CIPHER> enc, Pointer<UnsignedChar> pass, int pass_len, Pointer<pem_password_cb> cb, Pointer<Void> u) → int
PEM_write_bio_PKCS7(Pointer<BIO> bp, Pointer<PKCS7> x) → int
PEM_write_bio_PKCS8(Pointer<BIO> bp, Pointer<X509_SIG> x) → int
PEM_write_bio_PKCS8_PRIV_KEY_INFO(Pointer<BIO> bp, Pointer<PKCS8_PRIV_KEY_INFO> x) → int
PEM_write_bio_PKCS8PrivateKey(Pointer<BIO> bp, Pointer<EVP_PKEY> x, Pointer<EVP_CIPHER> enc, Pointer<Char> pass, int pass_len, Pointer<pem_password_cb> cb, Pointer<Void> u) → int
PEM_write_bio_PKCS8PrivateKey_nid(Pointer<BIO> bp, Pointer<EVP_PKEY> x, int nid, Pointer<Char> pass, int pass_len, Pointer<pem_password_cb> cb, Pointer<Void> u) → int
PEM_write_bio_PrivateKey(Pointer<BIO> bp, Pointer<EVP_PKEY> x, Pointer<EVP_CIPHER> enc, Pointer<UnsignedChar> pass, int pass_len, Pointer<pem_password_cb> cb, Pointer<Void> u) → int
PEM_write_bio_PUBKEY(Pointer<BIO> bp, Pointer<EVP_PKEY> x) → int
PEM_write_bio_RSA_PUBKEY(Pointer<BIO> bp, Pointer<RSA> x) → int
PEM_write_bio_RSAPrivateKey(Pointer<BIO> bp, Pointer<RSA> x, Pointer<EVP_CIPHER> enc, Pointer<UnsignedChar> pass, int pass_len, Pointer<pem_password_cb> cb, Pointer<Void> u) → int
PEM_write_bio_RSAPublicKey(Pointer<BIO> bp, Pointer<RSA> x) → int
PEM_write_bio_X509(Pointer<BIO> bp, Pointer<X509> x) → int
PEM_write_bio_X509_AUX(Pointer<BIO> bp, Pointer<X509> x) → int
PEM_write_bio_X509_CRL(Pointer<BIO> bp, Pointer<X509_CRL> x) → int
PEM_write_bio_X509_REQ(Pointer<BIO> bp, Pointer<X509_REQ> x) → int
PEM_write_bio_X509_REQ_NEW(Pointer<BIO> bp, Pointer<X509_REQ> x) → int
PEM_write_DHparams(Pointer<FILE> fp, Pointer<DH> x) → int
PEM_write_DSA_PUBKEY(Pointer<FILE> fp, Pointer<DSA> x) → int
PEM_write_DSAparams(Pointer<FILE> fp, Pointer<DSA> x) → int
PEM_write_DSAPrivateKey(Pointer<FILE> fp, Pointer<DSA> x, Pointer<EVP_CIPHER> enc, Pointer<UnsignedChar> pass, int pass_len, Pointer<pem_password_cb> cb, Pointer<Void> u) → int
PEM_write_EC_PUBKEY(Pointer<FILE> fp, Pointer<EC_KEY> x) → int
PEM_write_ECPrivateKey(Pointer<FILE> fp, Pointer<EC_KEY> x, Pointer<EVP_CIPHER> enc, Pointer<UnsignedChar> pass, int pass_len, Pointer<pem_password_cb> cb, Pointer<Void> u) → int
PEM_write_PKCS7(Pointer<FILE> fp, Pointer<PKCS7> x) → int
PEM_write_PKCS8(Pointer<FILE> fp, Pointer<X509_SIG> x) → int
PEM_write_PKCS8_PRIV_KEY_INFO(Pointer<FILE> fp, Pointer<PKCS8_PRIV_KEY_INFO> x) → int
PEM_write_PKCS8PrivateKey(Pointer<FILE> fp, Pointer<EVP_PKEY> x, Pointer<EVP_CIPHER> enc, Pointer<Char> pass, int pass_len, Pointer<pem_password_cb> cd, Pointer<Void> u) → int
PEM_write_PKCS8PrivateKey_nid(Pointer<FILE> fp, Pointer<EVP_PKEY> x, int nid, Pointer<Char> pass, int pass_len, Pointer<pem_password_cb> cb, Pointer<Void> u) → int
PEM_write_PrivateKey(Pointer<FILE> fp, Pointer<EVP_PKEY> x, Pointer<EVP_CIPHER> enc, Pointer<UnsignedChar> pass, int pass_len, Pointer<pem_password_cb> cb, Pointer<Void> u) → int
PEM_write_PUBKEY(Pointer<FILE> fp, Pointer<EVP_PKEY> x) → int
PEM_write_RSA_PUBKEY(Pointer<FILE> fp, Pointer<RSA> x) → int
PEM_write_RSAPrivateKey(Pointer<FILE> fp, Pointer<RSA> x, Pointer<EVP_CIPHER> enc, Pointer<UnsignedChar> pass, int pass_len, Pointer<pem_password_cb> cb, Pointer<Void> u) → int
PEM_write_RSAPublicKey(Pointer<FILE> fp, Pointer<RSA> x) → int
PEM_write_X509(Pointer<FILE> fp, Pointer<X509> x) → int
PEM_write_X509_AUX(Pointer<FILE> fp, Pointer<X509> x) → int
PEM_write_X509_CRL(Pointer<FILE> fp, Pointer<X509_CRL> x) → int
PEM_write_X509_REQ(Pointer<FILE> fp, Pointer<X509_REQ> x) → int
PEM_write_X509_REQ_NEW(Pointer<FILE> fp, Pointer<X509_REQ> x) → int
PEM_X509_INFO_read(Pointer<FILE> fp, Pointer<stack_st_X509_INFO> sk, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<stack_st_X509_INFO>
PEM_X509_INFO_read behaves like |PEM_X509_INFO_read_bio| but reads from a |FILE|.
PEM_X509_INFO_read_bio(Pointer<BIO> bp, Pointer<stack_st_X509_INFO> sk, Pointer<pem_password_cb> cb, Pointer<Void> u) → Pointer<stack_st_X509_INFO>
PEM_X509_INFO_read_bio reads PEM blocks from |bp| and decodes any certificates, CRLs, and private keys found. It returns a |STACK_OF(X509_INFO)| structure containing the results, or NULL on error.
PKCS5_PBKDF2_HMAC(Pointer<Char> password, int password_len, Pointer<Uint8> salt, int salt_len, int iterations, Pointer<EVP_MD> digest, int key_len, Pointer<Uint8> out_key) → int
PKCS5_PBKDF2_HMAC computes |iterations| iterations of PBKDF2 of |password| and |salt|, using |digest|, and outputs |key_len| bytes to |out_key|. It returns one on success and zero on allocation failure or if iterations is 0.
PKCS5_PBKDF2_HMAC_SHA1(Pointer<Char> password, int password_len, Pointer<Uint8> salt, int salt_len, int iterations, int key_len, Pointer<Uint8> out_key) → int
PKCS5_PBKDF2_HMAC_SHA1 is the same as PKCS5_PBKDF2_HMAC, but with |digest| fixed to |EVP_sha1|.
PKCS7_bundle_certificates(Pointer<CBB> out, Pointer<stack_st_X509> certs) → int
PKCS7_bundle_certificates behaves like |PKCS7_bundle_raw_certificates| but takes |X509| objects as input.
PKCS7_bundle_CRLs(Pointer<CBB> out, Pointer<stack_st_X509_CRL> crls) → int
PKCS7_bundle_CRLs appends a PKCS#7, SignedData structure containing |crls| to |out|. It returns one on success and zero on error. Note that CRLs in SignedData structures are unordered. The order in |crls| will not be preserved.
PKCS7_bundle_raw_certificates(Pointer<CBB> out, Pointer<stack_st_CRYPTO_BUFFER> certs) → int
PKCS7_bundle_raw_certificates appends a PKCS#7, SignedData structure containing |certs| to |out|. It returns one on success and zero on error. Note that certificates in SignedData structures are unordered. The order in |certs| will not be preserved.
PKCS7_free(Pointer<PKCS7> p7) → void
PKCS7_free releases memory associated with |p7|.
PKCS7_get_certificates(Pointer<stack_st_X509> out_certs, Pointer<CBS> cbs) → int
PKCS7_get_certificates behaves like |PKCS7_get_raw_certificates| but parses them into |X509| objects.
PKCS7_get_CRLs(Pointer<stack_st_X509_CRL> out_crls, Pointer<CBS> cbs) → int
PKCS7_get_CRLs parses a PKCS#7, SignedData structure from |cbs| and appends the included CRLs to |out_crls|. It returns one on success and zero on error. |cbs| is advanced passed the structure.
PKCS7_get_PEM_certificates(Pointer<stack_st_X509> out_certs, Pointer<BIO> pem_bio) → int
PKCS7_get_PEM_certificates reads a PEM-encoded, PKCS#7, SignedData structure from |pem_bio| and appends the included certificates to |out_certs|. It returns one on success and zero on error.
PKCS7_get_PEM_CRLs(Pointer<stack_st_X509_CRL> out_crls, Pointer<BIO> pem_bio) → int
PKCS7_get_PEM_CRLs reads a PEM-encoded, PKCS#7, SignedData structure from |pem_bio| and appends the included CRLs to |out_crls|. It returns one on success and zero on error.
PKCS7_get_raw_certificates(Pointer<stack_st_CRYPTO_BUFFER> out_certs, Pointer<CBS> cbs, Pointer<CRYPTO_BUFFER_POOL> pool) → int
PKCS7_get_raw_certificates parses a PKCS#7, SignedData structure from |cbs| and appends the included certificates to |out_certs|. It returns one on success and zero on error. |cbs| is advanced passed the structure.
PKCS7_sign(Pointer<X509> sign_cert, Pointer<EVP_PKEY> pkey, Pointer<stack_st_X509> certs, Pointer<BIO> data, int flags) → Pointer<PKCS7>
PKCS7_sign can operate in two modes to provide some backwards compatibility:
PKCS7_type_is_data(Pointer<PKCS7> p7) → int
PKCS7_type_is_data returns zero.
PKCS7_type_is_digest(Pointer<PKCS7> p7) → int
PKCS7_type_is_digest returns zero.
PKCS7_type_is_encrypted(Pointer<PKCS7> p7) → int
PKCS7_type_is_encrypted returns zero.
PKCS7_type_is_enveloped(Pointer<PKCS7> p7) → int
PKCS7_type_is_enveloped returns zero.
PKCS7_type_is_signed(Pointer<PKCS7> p7) → int
PKCS7_type_is_signed returns one. (We only support signed data ContentInfos.)
PKCS7_type_is_signedAndEnveloped(Pointer<PKCS7> p7) → int
PKCS7_type_is_signedAndEnveloped returns zero.
PKCS8_PRIV_KEY_INFO_free(Pointer<PKCS8_PRIV_KEY_INFO> key) → void
PKCS8_PRIV_KEY_INFO_free releases memory associated with |key|.
PKCS8_PRIV_KEY_INFO_new() → Pointer<PKCS8_PRIV_KEY_INFO>
PKCS8_PRIV_KEY_INFO_new returns a newly-allocated, empty |PKCS8_PRIV_KEY_INFO| object, or NULL on error.
POLICY_CONSTRAINTS_free(Pointer<POLICY_CONSTRAINTS> pcons) → void
POLICY_CONSTRAINTS_free releases memory associated with |pcons|.
POLICY_CONSTRAINTS_new() → Pointer<POLICY_CONSTRAINTS>
POLICY_CONSTRAINTS_new returns a newly-allocated, empty |POLICY_CONSTRAINTS| object, or NULL on error.
POLICY_MAPPING_free(Pointer<POLICY_MAPPING> mapping) → void
POLICY_MAPPING_free releases memory associated with |mapping|.
POLICY_MAPPING_new() → Pointer<POLICY_MAPPING>
POLICY_MAPPING_new returns a newly-allocated, empty |POLICY_MAPPING| object, or NULL on error.
POLICYINFO_free(Pointer<POLICYINFO> info) → void
POLICYINFO_free releases memory associated with |info|.
POLICYINFO_new() → Pointer<POLICYINFO>
POLICYINFO_new returns a newly-allocated, empty |POLICYINFO| object, or NULL on error.
POLICYQUALINFO_free(Pointer<POLICYQUALINFO> info) → void
POLICYQUALINFO_free releases memory associated with |info|.
POLICYQUALINFO_new() → Pointer<POLICYQUALINFO>
POLICYQUALINFO_new returns a newly-allocated, empty |POLICYQUALINFO| object, or NULL on error.
RAND_add(Pointer<Void> buf, int num, double entropy) → void
RAND_add does nothing.
RAND_bytes(Pointer<Uint8> buf, int len) → int
RAND_bytes writes |len| bytes of random data to |buf| and returns one. In the event that sufficient random data can not be obtained, |abort| is called.
RAND_cleanup() → void
RAND_cleanup does nothing.
RAND_disable_fork_unsafe_buffering() → void
RAND_disable_fork_unsafe_buffering restores BoringSSL's default fork-safety protections. See also |RAND_enable_fork_unsafe_buffering|.
RAND_egd(Pointer<Char> arg0) → int
RAND_egd returns 255.
RAND_enable_fork_unsafe_buffering(int fd) → void
RAND_enable_fork_unsafe_buffering indicates that clones of the address space, e.g. via |fork|, will never call into BoringSSL. It may be used to disable BoringSSL's more expensive fork-safety measures. However, calling this function and then using BoringSSL across |fork| calls will leak secret keys. |fd| must be -1.
RAND_file_name(Pointer<Char> buf, int num) → Pointer<Char>
RAND_file_name returns NULL.
RAND_get_rand_method() → Pointer<RAND_METHOD>
RAND_get_rand_method returns |RAND_SSLeay()|.
RAND_get_system_entropy_for_custom_prng(Pointer<Uint8> buf, int len) → void
RAND_get_system_entropy_for_custom_prng writes |len| bytes of random data from a system entropy source to |buf|. The maximum length of entropy which may be requested is 256 bytes. If more than 256 bytes of data is requested, or if sufficient random data can not be obtained, |abort| is called. |RAND_bytes| should normally be used instead of this function. This function should only be used for seed values or where |malloc| should not be called from BoringSSL. This function is not FIPS compliant.
RAND_load_file(Pointer<Char> path, int num) → int
RAND_load_file returns a nonnegative number.
RAND_maybe_reseed() → int
RAND_maybe_reseed might reseed the PRNG if it's getting close to the reseed limit. If it does so, it may briefly block other threads that are concurrently calling RAND_bytes, but only for ~microseconds. Applications may wish to periodically call this function to avoid hitting a reseed while servicing a RAND_bytes call, which could happen from anywhere and take milliseconds or more in FIPS configurations. Most applications, however, should ignore this and it only makes a difference in FIPS builds.
RAND_OpenSSL() → Pointer<RAND_METHOD>
RAND_OpenSSL returns a pointer to a dummy |RAND_METHOD|.
RAND_poll() → int
RAND_poll returns one.
RAND_pseudo_bytes(Pointer<Uint8> buf, int len) → int
RAND_pseudo_bytes is a wrapper around |RAND_bytes|.
RAND_seed(Pointer<Void> buf, int num) → void
RAND_seed reads a single byte of random data to ensure that any file descriptors etc are opened.
RAND_set_rand_method(Pointer<RAND_METHOD> arg0) → int
RAND_set_rand_method returns one.
RAND_SSLeay() → Pointer<RAND_METHOD>
RAND_SSLeay returns a pointer to a dummy |RAND_METHOD|.
RAND_status() → int
RAND_status returns one.
RSA_add_pkcs1_prefix(Pointer<Pointer<Uint8>> out_msg, Pointer<Size> out_msg_len, Pointer<Int> is_alloced, int hash_nid, Pointer<Uint8> digest, int digest_len) → int
RSA_add_pkcs1_prefix builds a version of |digest| prefixed with the DigestInfo header for the given hash function and sets |out_msg| to point to it. On successful return, if |*is_alloced| is one, the caller must release |*out_msg| with |OPENSSL_free|.
RSA_bits(Pointer<RSA> rsa) → int
RSA_bits returns the size of |rsa|, in bits.
RSA_blinding_off(Pointer<RSA> rsa) → void
RSA_blinding_off does nothing.
RSA_blinding_on(Pointer<RSA> rsa, Pointer<BN_CTX> ctx) → int
RSA_blinding_on returns one.
RSA_check_fips(Pointer<RSA> key) → int
RSA_check_fips performs public key validity tests on |key|. It returns one if they pass and zero otherwise. Opaque keys always fail. This function does not mutate |rsa| for thread-safety purposes and may be used concurrently.
RSA_check_key(Pointer<RSA> rsa) → int
RSA_check_key performs basic validity tests on |rsa|. It returns one if they pass and zero otherwise. Opaque keys and public keys always pass. If it returns zero then a more detailed error is available on the error queue.
RSA_decrypt(Pointer<RSA> rsa, Pointer<Size> out_len, Pointer<Uint8> out, int max_out, Pointer<Uint8> in$, int in_len, int padding) → int
RSA_decrypt decrypts |in_len| bytes from |in| with the private key from |rsa| and writes, at most, |max_out| bytes of plaintext to |out|. The |max_out| argument must be, at least, |RSA_size| in order to ensure success.
RSA_encrypt(Pointer<RSA> rsa, Pointer<Size> out_len, Pointer<Uint8> out, int max_out, Pointer<Uint8> in$, int in_len, int padding) → int
RSA_encrypt encrypts |in_len| bytes from |in| to the public key from |rsa| and writes, at most, |max_out| bytes of encrypted data to |out|. The |max_out| argument must be, at least, |RSA_size| in order to ensure success.
RSA_flags(Pointer<RSA> rsa) → int
RSA_flags returns the flags for |rsa|. These are a bitwise OR of |RSA_FLAG_*| constants.
RSA_free(Pointer<RSA> rsa) → void
RSA_free decrements the reference count of |rsa| and frees it if the reference count drops to zero.
RSA_generate_key_ex(Pointer<RSA> rsa, int bits, Pointer<BIGNUM> e, Pointer<BN_GENCB> cb) → int
RSA_generate_key_ex generates a new RSA key where the modulus has size |bits| and the public exponent is |e|. If unsure, |RSA_F4| is a good value for |e|. If |cb| is not NULL then it is called during the key generation process. In addition to the calls documented for |BN_generate_prime_ex|, it is called with event=2 when the n'th prime is rejected as unsuitable and with event=3 when a suitable value for |p| is found.
RSA_generate_key_fips(Pointer<RSA> rsa, int bits, Pointer<BN_GENCB> cb) → int
RSA_generate_key_fips behaves like |RSA_generate_key_ex| but performs additional checks for FIPS compliance. The public exponent is always 65537 and |bits| must be either 2048 or 3072.
RSA_get0_crt_params(Pointer<RSA> rsa, Pointer<Pointer<BIGNUM>> out_dmp1, Pointer<Pointer<BIGNUM>> out_dmq1, Pointer<Pointer<BIGNUM>> out_iqmp) → void
RSA_get0_crt_params sets |*out_dmp1|, |*out_dmq1|, and |*out_iqmp|, if non-NULL, to |rsa|'s CRT parameters. These are d (mod p-1), d (mod q-1) and q^-1 (mod p), respectively. If |rsa| is a public key, each parameter will be set to NULL.
RSA_get0_d(Pointer<RSA> rsa) → Pointer<BIGNUM>
RSA_get0_d returns |rsa|'s private exponent. If |rsa| is a public key, this value will be NULL.
RSA_get0_dmp1(Pointer<RSA> rsa) → Pointer<BIGNUM>
RSA_get0_dmp1 returns d (mod p-1) for |rsa|. If |rsa| is a public key or lacks CRT parameters, this value will be NULL.
RSA_get0_dmq1(Pointer<RSA> rsa) → Pointer<BIGNUM>
RSA_get0_dmq1 returns d (mod q-1) for |rsa|. If |rsa| is a public key or lacks CRT parameters, this value will be NULL.
RSA_get0_e(Pointer<RSA> rsa) → Pointer<BIGNUM>
RSA_get0_e returns |rsa|'s public exponent.
RSA_get0_factors(Pointer<RSA> rsa, Pointer<Pointer<BIGNUM>> out_p, Pointer<Pointer<BIGNUM>> out_q) → void
RSA_get0_factors sets |*out_p| and |*out_q|, if non-NULL, to |rsa|'s prime factors. If |rsa| is a public key, they will be set to NULL.
RSA_get0_iqmp(Pointer<RSA> rsa) → Pointer<BIGNUM>
RSA_get0_iqmp returns q^-1 (mod p). If |rsa| is a public key or lacks CRT parameters, this value will be NULL.
RSA_get0_key(Pointer<RSA> rsa, Pointer<Pointer<BIGNUM>> out_n, Pointer<Pointer<BIGNUM>> out_e, Pointer<Pointer<BIGNUM>> out_d) → void
RSA_get0_key sets |*out_n|, |*out_e|, and |*out_d|, if non-NULL, to |rsa|'s modulus, public exponent, and private exponent, respectively. If |rsa| is a public key, the private exponent will be set to NULL.
RSA_get0_n(Pointer<RSA> rsa) → Pointer<BIGNUM>
RSA_get0_n returns |rsa|'s public modulus.
RSA_get0_p(Pointer<RSA> rsa) → Pointer<BIGNUM>
RSA_get0_p returns |rsa|'s first private prime factor. If |rsa| is a public key or lacks its prime factors, this value will be NULL.
RSA_get0_pss_params(Pointer<RSA> rsa) → Pointer<RSA_PSS_PARAMS>
RSA_get0_pss_params returns NULL. In OpenSSL, this function retries RSA-PSS parameters associated with |RSA| objects, but BoringSSL does not enable the id-RSASSA-PSS key encoding by default.
RSA_get0_q(Pointer<RSA> rsa) → Pointer<BIGNUM>
RSA_get0_q returns |rsa|'s second private prime factor. If |rsa| is a public key or lacks its prime factors, this value will be NULL.
RSA_get_ex_data(Pointer<RSA> rsa, int idx) → Pointer<Void>
RSA_get_ex_new_index(int argl, Pointer<Void> argp, Pointer<Int> unused, Pointer<CRYPTO_EX_dup> dup_unused, Pointer<CRYPTO_EX_free> free_func) → int
ex_data functions.
RSA_is_opaque(Pointer<RSA> rsa) → int
RSA_is_opaque returns one if |rsa| is opaque and doesn't expose its key material. Otherwise it returns zero.
RSA_marshal_private_key(Pointer<CBB> cbb, Pointer<RSA> rsa) → int
RSA_marshal_private_key marshals |rsa| as a DER-encoded RSAPrivateKey structure (RFC 8017) and appends the result to |cbb|. It returns one on success and zero on failure.
RSA_marshal_public_key(Pointer<CBB> cbb, Pointer<RSA> rsa) → int
RSA_marshal_public_key marshals |rsa| as a DER-encoded RSAPublicKey structure (RFC 8017) and appends the result to |cbb|. It returns one on success and zero on failure.
RSA_new() → Pointer<RSA>
RSA_new returns a new, empty |RSA| object or NULL on error. Prefer using |RSA_new_public_key| or |RSA_new_private_key| to import an RSA key.
RSA_new_method(Pointer<ENGINE> engine) → Pointer<RSA>
RSA_new_method acts the same as |RSA_new| but takes an explicit |ENGINE|.
RSA_new_method_no_e(Pointer<ENGINE> engine, Pointer<BIGNUM> n) → Pointer<RSA>
RSA_new_method_no_e returns a newly-allocated |RSA| object backed by |engine|, with a public modulus of |n| and no known public exponent.
RSA_new_private_key(Pointer<BIGNUM> n, Pointer<BIGNUM> e, Pointer<BIGNUM> d, Pointer<BIGNUM> p, Pointer<BIGNUM> q, Pointer<BIGNUM> dmp1, Pointer<BIGNUM> dmq1, Pointer<BIGNUM> iqmp) → Pointer<RSA>
RSA_new_private_key returns a new |RSA| object containing a private key with the specified parameters, or NULL on error or invalid input. All parameters are mandatory and may not be NULL.
RSA_new_private_key_large_e(Pointer<BIGNUM> n, Pointer<BIGNUM> e, Pointer<BIGNUM> d, Pointer<BIGNUM> p, Pointer<BIGNUM> q, Pointer<BIGNUM> dmp1, Pointer<BIGNUM> dmq1, Pointer<BIGNUM> iqmp) → Pointer<RSA>
RSA_new_private_key_large_e behaves like |RSA_new_private_key| but allows any |e| up to |n|.
RSA_new_private_key_no_crt(Pointer<BIGNUM> n, Pointer<BIGNUM> e, Pointer<BIGNUM> d) → Pointer<RSA>
RSA_new_private_key_no_crt behaves like |RSA_new_private_key| but constructs an RSA key without CRT coefficients.
RSA_new_private_key_no_e(Pointer<BIGNUM> n, Pointer<BIGNUM> d) → Pointer<RSA>
RSA_new_private_key_no_e behaves like |RSA_new_private_key| but constructs an RSA key without CRT parameters or public exponent.
RSA_new_public_key(Pointer<BIGNUM> n, Pointer<BIGNUM> e) → Pointer<RSA>
RSA_new_public_key returns a new |RSA| object containing a public key with the specified parameters, or NULL on error or invalid input.
RSA_new_public_key_large_e(Pointer<BIGNUM> n, Pointer<BIGNUM> e) → Pointer<RSA>
RSA_new_public_key_large_e behaves like |RSA_new_public_key| but allows any |e| up to |n|.
RSA_padding_add_PKCS1_OAEP_mgf1(Pointer<Uint8> to, int to_len, Pointer<Uint8> from, int from_len, Pointer<Uint8> param, int param_len, Pointer<EVP_MD> md, Pointer<EVP_MD> mgf1md) → int
RSA_padding_add_PKCS1_OAEP_mgf1 writes an OAEP padding of |from| to |to| with the given parameters and hash functions. If |md| is NULL then SHA-1 is used. If |mgf1md| is NULL then the value of |md| is used (which means SHA-1 if that, in turn, is NULL).
RSA_padding_add_PKCS1_PSS_mgf1(Pointer<RSA> rsa, Pointer<Uint8> EM, Pointer<Uint8> mHash, Pointer<EVP_MD> Hash, Pointer<EVP_MD> mgf1Hash, int sLen) → int
RSA_padding_add_PKCS1_PSS_mgf1 writes a PSS padding of |mHash| to |EM|, where |mHash| is a digest produced by |Hash|. |RSA_size(rsa)| bytes of output will be written to |EM|. The |mgf1Hash| argument specifies the hash function for generating the mask. If NULL, |Hash| is used. The |sLen| argument specifies the expected salt length in bytes. If |sLen| is -1 then the salt length is the same as the hash length. If -2, then the salt length is maximal given the space in |EM|.
RSA_parse_private_key(Pointer<CBS> cbs) → Pointer<RSA>
RSA_parse_private_key parses a DER-encoded RSAPrivateKey structure (RFC 8017) from |cbs| and advances |cbs|. It returns a newly-allocated |RSA| or NULL on error.
RSA_parse_public_key(Pointer<CBS> cbs) → Pointer<RSA>
RSA_parse_public_key parses a DER-encoded RSAPublicKey structure (RFC 8017) from |cbs| and advances |cbs|. It returns a newly-allocated |RSA| or NULL on error.
RSA_print(Pointer<BIO> bio, Pointer<RSA> rsa, int indent) → int
RSA_print prints a textual representation of |rsa| to |bio|. It returns one on success or zero otherwise.
RSA_private_decrypt(int flen, Pointer<Uint8> from, Pointer<Uint8> to, Pointer<RSA> rsa, int padding) → int
RSA_private_decrypt decrypts |flen| bytes from |from| with the public key in |rsa| and writes the plaintext to |to|. The |to| buffer must have at least |RSA_size| bytes of space. It returns the number of bytes written, or -1 on error. The |padding| argument must be one of the |RSA_*_PADDING| values. If in doubt, use |RSA_PKCS1_OAEP_PADDING| for new protocols. Passing |RSA_PKCS1_PADDING| into this function is deprecated and insecure. See |RSA_decrypt|.
RSA_private_encrypt(int flen, Pointer<Uint8> from, Pointer<Uint8> to, Pointer<RSA> rsa, int padding) → int
RSA_private_encrypt performs the private key portion of computing a signature with |rsa|. It takes |flen| bytes from |from| as input and writes the result to |to|. The |to| buffer must have at least |RSA_size| bytes of space. It returns the number of bytes written, or -1 on error.
RSA_private_key_from_bytes(Pointer<Uint8> in$, int in_len) → Pointer<RSA>
RSA_private_key_from_bytes parses |in| as a DER-encoded RSAPrivateKey structure (RFC 8017). It returns a newly-allocated |RSA| or NULL on error.
RSA_private_key_to_bytes(Pointer<Pointer<Uint8>> out_bytes, Pointer<Size> out_len, Pointer<RSA> rsa) → int
RSA_private_key_to_bytes marshals |rsa| as a DER-encoded RSAPrivateKey structure (RFC 8017) and, on success, sets |*out_bytes| to a newly allocated buffer containing the result and returns one. Otherwise, it returns zero. The result should be freed with |OPENSSL_free|.
RSA_PSS_PARAMS_free(Pointer<RSA_PSS_PARAMS> params) → void
RSA_PSS_PARAMS_free releases memory associated with |params|.
RSA_PSS_PARAMS_new() → Pointer<RSA_PSS_PARAMS>
RSA_PSS_PARAMS_new returns a new, empty |RSA_PSS_PARAMS|, or NULL on error.
RSA_public_decrypt(int flen, Pointer<Uint8> from, Pointer<Uint8> to, Pointer<RSA> rsa, int padding) → int
RSA_public_decrypt performs the public key portion of verifying |flen| bytes of signature from |from| using the public key from |rsa|. It writes the result to |to|, which must have at least |RSA_size| bytes of space. It returns the number of bytes written, or -1 on error.
RSA_public_encrypt(int flen, Pointer<Uint8> from, Pointer<Uint8> to, Pointer<RSA> rsa, int padding) → int
RSA_public_encrypt encrypts |flen| bytes from |from| to the public key in |rsa| and writes the encrypted data to |to|. The |to| buffer must have at least |RSA_size| bytes of space. It returns the number of bytes written, or -1 on error. The |padding| argument must be one of the |RSA_*_PADDING| values. If in doubt, use |RSA_PKCS1_OAEP_PADDING| for new protocols.
RSA_public_key_from_bytes(Pointer<Uint8> in$, int in_len) → Pointer<RSA>
RSA_public_key_from_bytes parses |in| as a DER-encoded RSAPublicKey structure (RFC 8017). It returns a newly-allocated |RSA| or NULL on error.
RSA_public_key_to_bytes(Pointer<Pointer<Uint8>> out_bytes, Pointer<Size> out_len, Pointer<RSA> rsa) → int
RSA_public_key_to_bytes marshals |rsa| as a DER-encoded RSAPublicKey structure (RFC 8017) and, on success, sets |*out_bytes| to a newly allocated buffer containing the result and returns one. Otherwise, it returns zero. The result should be freed with |OPENSSL_free|.
RSA_set0_crt_params(Pointer<RSA> rsa, Pointer<BIGNUM> dmp1, Pointer<BIGNUM> dmq1, Pointer<BIGNUM> iqmp) → int
RSA_set0_crt_params sets |rsa|'s CRT parameters to |dmp1|, |dmq1|, and |iqmp|, if non-NULL, and takes ownership of them. On success, it takes ownership of its parameters and returns one. Otherwise, it returns zero.
RSA_set0_factors(Pointer<RSA> rsa, Pointer<BIGNUM> p, Pointer<BIGNUM> q) → int
RSA_set0_factors sets |rsa|'s prime factors to |p| and |q|, if non-NULL, and takes ownership of them. On success, it takes ownership of each argument and returns one. Otherwise, it returns zero.
RSA_set0_key(Pointer<RSA> rsa, Pointer<BIGNUM> n, Pointer<BIGNUM> e, Pointer<BIGNUM> d) → int
RSA_set0_key sets |rsa|'s modulus, public exponent, and private exponent to |n|, |e|, and |d| respectively, if non-NULL. On success, it takes ownership of each argument and returns one. Otherwise, it returns zero.
RSA_set_ex_data(Pointer<RSA> rsa, int idx, Pointer<Void> arg) → int
RSA_sign(int hash_nid, Pointer<Uint8> digest, int digest_len, Pointer<Uint8> out, Pointer<UnsignedInt> out_len, Pointer<RSA> rsa) → int
RSA_sign signs |digest_len| bytes of digest from |digest| with |rsa| using RSASSA-PKCS1-v1_5. It writes, at most, |RSA_size(rsa)| bytes to |out|. On successful return, the actual number of bytes written is written to |*out_len|.
RSA_sign_pss_mgf1(Pointer<RSA> rsa, Pointer<Size> out_len, Pointer<Uint8> out, int max_out, Pointer<Uint8> digest, int digest_len, Pointer<EVP_MD> md, Pointer<EVP_MD> mgf1_md, int salt_len) → int
RSA_sign_pss_mgf1 signs |digest_len| bytes from |digest| with the public key from |rsa| using RSASSA-PSS with MGF1 as the mask generation function. It writes, at most, |max_out| bytes of signature data to |out|. The |max_out| argument must be, at least, |RSA_size| in order to ensure success. It returns 1 on success or zero on error.
RSA_sign_raw(Pointer<RSA> rsa, Pointer<Size> out_len, Pointer<Uint8> out, int max_out, Pointer<Uint8> in$, int in_len, int padding) → int
RSA_sign_raw performs the private key portion of computing a signature with |rsa|. It writes, at most, |max_out| bytes of signature data to |out|. The |max_out| argument must be, at least, |RSA_size| in order to ensure the output fits. It returns 1 on success or zero on error.
RSA_size(Pointer<RSA> rsa) → int
RSA_size returns the number of bytes in the modulus, which is also the size of a signature or encrypted value using |rsa|.
RSA_test_flags(Pointer<RSA> rsa, int flags) → int
RSA_test_flags returns the subset of flags in |flags| which are set in |rsa|.
RSA_up_ref(Pointer<RSA> rsa) → int
RSA_up_ref increments the reference count of |rsa| and returns one. It does not mutate |rsa| for thread-safety purposes and may be used concurrently.
RSA_verify(int hash_nid, Pointer<Uint8> digest, int digest_len, Pointer<Uint8> sig, int sig_len, Pointer<RSA> rsa) → int
RSA_verify verifies that |sig_len| bytes from |sig| are a valid, RSASSA-PKCS1-v1_5 signature of |digest_len| bytes at |digest| by |rsa|.
RSA_verify_PKCS1_PSS_mgf1(Pointer<RSA> rsa, Pointer<Uint8> mHash, Pointer<EVP_MD> Hash, Pointer<EVP_MD> mgf1Hash, Pointer<Uint8> EM, int sLen) → int
RSA_verify_PKCS1_PSS_mgf1 verifies that |EM| is a correct PSS padding of |mHash|, where |mHash| is a digest produced by |Hash|. |EM| must point to exactly |RSA_size(rsa)| bytes of data. The |mgf1Hash| argument specifies the hash function for generating the mask. If NULL, |Hash| is used. The |sLen| argument specifies the expected salt length in bytes. If |sLen| is -1 then the salt length is the same as the hash length. If -2, then the salt length is recovered and all values accepted.
RSA_verify_pss_mgf1(Pointer<RSA> rsa, Pointer<Uint8> digest, int digest_len, Pointer<EVP_MD> md, Pointer<EVP_MD> mgf1_md, int salt_len, Pointer<Uint8> sig, int sig_len) → int
RSA_verify_pss_mgf1 verifies that |sig_len| bytes from |sig| are a valid, RSASSA-PSS signature of |digest_len| bytes at |digest| by |rsa|. It returns one if the signature is valid and zero otherwise. MGF1 is used as the mask generation function.
RSA_verify_raw(Pointer<RSA> rsa, Pointer<Size> out_len, Pointer<Uint8> out, int max_out, Pointer<Uint8> in$, int in_len, int padding) → int
RSA_verify_raw performs the public key portion of verifying |in_len| bytes of signature from |in| using the public key from |rsa|. On success, it returns one and writes, at most, |max_out| bytes of output to |out|. The |max_out| argument must be, at least, |RSA_size| in order to ensure the output fits. On failure or invalid input, it returns zero.
RSAPrivateKey_dup(Pointer<RSA> rsa) → Pointer<RSA>
RSAPrivateKey_dup allocates a fresh |RSA| and copies the private key from |rsa| into it. It returns the fresh |RSA| object, or NULL on error.
RSAPublicKey_dup(Pointer<RSA> rsa) → Pointer<RSA>
RSAPublicKey_dup allocates a fresh |RSA| and copies the public key from |rsa| into it. It returns the fresh |RSA| object, or NULL on error.
s2i_ASN1_INTEGER(Pointer<X509V3_EXT_METHOD> method, Pointer<Char> value) → Pointer<ASN1_OCTET_STRING>
s2i_ASN1_INTEGER decodes |value| as the ASCII representation of an integer, and returns a newly-allocated |ASN1_INTEGER| containing the result, or NULL on error. |method| is ignored. If |value| begins with "0x" or "0X", the input is decoded in hexadecimal, otherwise decimal.
s2i_ASN1_OCTET_STRING(Pointer<X509V3_EXT_METHOD> method, Pointer<X509V3_CTX> ctx, Pointer<Char> str) → Pointer<ASN1_OCTET_STRING>
s2i_ASN1_OCTET_STRING decodes |str| as a hexadecimal byte string, with optional colon separators between bytes. It returns a newly-allocated |ASN1_OCTET_STRING| with the result on success, or NULL on error. |method| and |ctx| are ignored.
SHA1(Pointer<Uint8> data, int len, Pointer<Uint8> out) → Pointer<Uint8>
SHA1 writes the digest of |len| bytes from |data| to |out| and returns |out|. There must be at least |SHA_DIGEST_LENGTH| bytes of space in |out|.
SHA1_Final(Pointer<Uint8> out, Pointer<SHA_CTX> sha) → int
SHA1_Final adds the final padding to |sha| and writes the resulting digest to |out|, which must have at least |SHA_DIGEST_LENGTH| bytes of space. It returns one.
SHA1_Init(Pointer<SHA_CTX> sha) → int
SHA1_Init initialises |sha| and returns one.
SHA1_Transform(Pointer<SHA_CTX> sha, Pointer<Uint8> block) → void
SHA1_Transform is a low-level function that performs a single, SHA-1 block transformation using the state from |sha| and |SHA_CBLOCK| bytes from |block|.
SHA1_Update(Pointer<SHA_CTX> sha, Pointer<Void> data, int len) → int
SHA1_Update adds |len| bytes from |data| to |sha| and returns one.
SHA224(Pointer<Uint8> data, int len, Pointer<Uint8> out) → Pointer<Uint8>
SHA224 writes the digest of |len| bytes from |data| to |out| and returns |out|. There must be at least |SHA224_DIGEST_LENGTH| bytes of space in |out|.
SHA224_Final(Pointer<Uint8> out, Pointer<SHA256_CTX> sha) → int
SHA224_Final adds the final padding to |sha| and writes the resulting digest to |out|, which must have at least |SHA224_DIGEST_LENGTH| bytes of space. It returns 1.
SHA224_Init(Pointer<SHA256_CTX> sha) → int
SHA224_Init initialises |sha| and returns 1.
SHA224_Update(Pointer<SHA256_CTX> sha, Pointer<Void> data, int len) → int
SHA224_Update adds |len| bytes from |data| to |sha| and returns 1.
SHA256(Pointer<Uint8> data, int len, Pointer<Uint8> out) → Pointer<Uint8>
SHA256 writes the digest of |len| bytes from |data| to |out| and returns |out|. There must be at least |SHA256_DIGEST_LENGTH| bytes of space in |out|.
SHA256_Final(Pointer<Uint8> out, Pointer<SHA256_CTX> sha) → int
SHA256_Final adds the final padding to |sha| and writes the resulting digest to |out|, which must have at least |SHA256_DIGEST_LENGTH| bytes of space. It returns one on success and zero on programmer error.
SHA256_Init(Pointer<SHA256_CTX> sha) → int
SHA256_Init initialises |sha| and returns 1.
SHA256_Transform(Pointer<SHA256_CTX> sha, Pointer<Uint8> block) → void
SHA256_Transform is a low-level function that performs a single, SHA-256 block transformation using the state from |sha| and |SHA256_CBLOCK| bytes from |block|.
SHA256_TransformBlocks(Pointer<CBS_ASN1_TAG> state, Pointer<Uint8> data, int num_blocks) → void
SHA256_TransformBlocks is a low-level function that takes |num_blocks| * |SHA256_CBLOCK| bytes of data and performs SHA-256 transforms on it to update |state|. You should not use this function unless you are implementing a derivative of SHA-256.
SHA256_Update(Pointer<SHA256_CTX> sha, Pointer<Void> data, int len) → int
SHA256_Update adds |len| bytes from |data| to |sha| and returns 1.
SHA384(Pointer<Uint8> data, int len, Pointer<Uint8> out) → Pointer<Uint8>
SHA384 writes the digest of |len| bytes from |data| to |out| and returns |out|. There must be at least |SHA384_DIGEST_LENGTH| bytes of space in |out|.
SHA384_Final(Pointer<Uint8> out, Pointer<SHA512_CTX> sha) → int
SHA384_Final adds the final padding to |sha| and writes the resulting digest to |out|, which must have at least |SHA384_DIGEST_LENGTH| bytes of space. It returns one on success and zero on programmer error.
SHA384_Init(Pointer<SHA512_CTX> sha) → int
SHA384_Init initialises |sha| and returns 1.
SHA384_Update(Pointer<SHA512_CTX> sha, Pointer<Void> data, int len) → int
SHA384_Update adds |len| bytes from |data| to |sha| and returns 1.
SHA512(Pointer<Uint8> data, int len, Pointer<Uint8> out) → Pointer<Uint8>
SHA512 writes the digest of |len| bytes from |data| to |out| and returns |out|. There must be at least |SHA512_DIGEST_LENGTH| bytes of space in |out|.
SHA512_256(Pointer<Uint8> data, int len, Pointer<Uint8> out) → Pointer<Uint8>
SHA512_256 writes the digest of |len| bytes from |data| to |out| and returns |out|. There must be at least |SHA512_256_DIGEST_LENGTH| bytes of space in |out|.
SHA512_256_Final(Pointer<Uint8> out, Pointer<SHA512_CTX> sha) → int
SHA512_256_Final adds the final padding to |sha| and writes the resulting digest to |out|, which must have at least |SHA512_256_DIGEST_LENGTH| bytes of space. It returns one on success and zero on programmer error.
SHA512_256_Init(Pointer<SHA512_CTX> sha) → int
SHA512_256_Init initialises |sha| and returns 1.
SHA512_256_Update(Pointer<SHA512_CTX> sha, Pointer<Void> data, int len) → int
SHA512_256_Update adds |len| bytes from |data| to |sha| and returns 1.
SHA512_Final(Pointer<Uint8> out, Pointer<SHA512_CTX> sha) → int
SHA512_Final adds the final padding to |sha| and writes the resulting digest to |out|, which must have at least |SHA512_DIGEST_LENGTH| bytes of space. It returns one on success and zero on programmer error.
SHA512_Init(Pointer<SHA512_CTX> sha) → int
SHA512_Init initialises |sha| and returns 1.
SHA512_Transform(Pointer<SHA512_CTX> sha, Pointer<Uint8> block) → void
SHA512_Transform is a low-level function that performs a single, SHA-512 block transformation using the state from |sha| and |SHA512_CBLOCK| bytes from |block|.
SHA512_Update(Pointer<SHA512_CTX> sha, Pointer<Void> data, int len) → int
SHA512_Update adds |len| bytes from |data| to |sha| and returns 1.
sk_free(Pointer<OPENSSL_STACK> sk) → void
sk_new_null() → Pointer<OPENSSL_STACK>
The following functions call the corresponding |OPENSSL_sk_*| function.
sk_num(Pointer<OPENSSL_STACK> sk) → int
sk_pop(Pointer<OPENSSL_STACK> sk) → Pointer<Void>
sk_pop_free(Pointer<OPENSSL_STACK> sk, OPENSSL_sk_free_func free_func) → void
sk_pop_free behaves like |OPENSSL_sk_pop_free_ex| but performs an invalid function pointer cast. It exists because some existing callers called |sk_pop_free| directly.
sk_pop_free_ex(Pointer<OPENSSL_STACK> sk, OPENSSL_sk_call_free_func call_free_func, OPENSSL_sk_free_func free_func) → void
sk_pop_free_ex calls |OPENSSL_sk_pop_free_ex|.
sk_push(Pointer<OPENSSL_STACK> sk, Pointer<Void> p) → int
sk_value(Pointer<OPENSSL_STACK> sk, int i) → Pointer<Void>
SPAKE2_CTX_free(Pointer<SPAKE2_CTX> ctx) → void
SPAKE2_CTX_free frees |ctx| and all the resources that it has allocated.
SPAKE2_CTX_new(int my_role, Pointer<Uint8> my_name, int my_name_len, Pointer<Uint8> their_name, int their_name_len) → Pointer<SPAKE2_CTX>
SPAKE2_CTX_new creates a new |SPAKE2_CTX| (which can only be used for a single execution of the protocol). SPAKE2 requires the symmetry of the two parties to be broken which is indicated via |my_role| – each party must pass a different value for this argument.
SPAKE2_generate_msg(Pointer<SPAKE2_CTX> ctx, Pointer<Uint8> out, Pointer<Size> out_len, int max_out_len, Pointer<Uint8> password, int password_len) → int
SPAKE2_generate_msg generates a SPAKE2 message given |password|, writes it to |out| and sets |*out_len| to the number of bytes written.
SPAKE2_process_msg(Pointer<SPAKE2_CTX> ctx, Pointer<Uint8> out_key, Pointer<Size> out_key_len, int max_out_key_len, Pointer<Uint8> their_msg, int their_msg_len) → int
SPAKE2_process_msg completes the SPAKE2 exchange given the peer's message in |their_msg|, writes at most |max_out_key_len| bytes to |out_key| and sets |*out_key_len| to the number of bytes written.
SSLeay() → int
SSLeay is a compatibility function that returns OPENSSL_VERSION_NUMBER from base.h.
SSLeay_version(int which) → Pointer<Char>
SSLeay_version calls |OpenSSL_version|.
USERNOTICE_free(Pointer<USERNOTICE> notice) → void
USERNOTICE_free releases memory associated with |notice|.
USERNOTICE_new() → Pointer<USERNOTICE>
USERNOTICE_new returns a newly-allocated, empty |USERNOTICE| object, or NULL on error.
X25519(Pointer<Uint8> out_shared_key, Pointer<Uint8> private_key, Pointer<Uint8> peer_public_value) → int
X25519 writes a shared key to |out_shared_key| that is calculated from the given private key and the peer's public value. It returns one on success and zero on error.
X25519_keypair(Pointer<Uint8> out_public_value, Pointer<Uint8> out_private_key) → void
X25519_keypair sets |out_public_value| and |out_private_key| to a freshly generated, public–private key pair.
X25519_public_from_private(Pointer<Uint8> out_public_value, Pointer<Uint8> private_key) → void
X25519_public_from_private calculates a Diffie-Hellman public value from the given private key and writes it to |out_public_value|.
X509_add1_ext_i2d(Pointer<X509> x, int nid, Pointer<Void> value, int crit, int flags) → int
X509_add1_ext_i2d behaves like |X509V3_add1_i2d| but adds the extension to |x|'s extension list.
X509_add1_reject_object(Pointer<X509> x509, Pointer<ASN1_OBJECT> obj) → int
X509_add1_reject_object configures |x509| as distrusted for |obj|. It returns one on success and zero on error. |obj| should be a certificate usage OID associated with an |X509_TRUST_*| constant.
X509_add1_trust_object(Pointer<X509> x509, Pointer<ASN1_OBJECT> obj) → int
X509_add1_trust_object configures |x509| as a valid trust anchor for |obj|. It returns one on success and zero on error. |obj| should be a certificate usage OID associated with an |X509_TRUST_*| constant.
X509_add_ext(Pointer<X509> x, Pointer<X509_EXTENSION> ex, int loc) → int
X509_add_ext adds a copy of |ex| to |x|. It returns one on success and zero on failure. The caller retains ownership of |ex| and can release it independently of |x|.
X509_ALGOR_cmp(Pointer<X509_ALGOR> a, Pointer<X509_ALGOR> b) → int
X509_ALGOR_cmp returns zero if |a| and |b| are equal, and some non-zero value otherwise. Note this function can only be used for equality checks, not an ordering.
X509_ALGOR_copy(Pointer<X509_ALGOR> dst, Pointer<X509_ALGOR> src) → int
X509_ALGOR_copy sets |dst| to a copy of the contents of |src|. It returns one on success and zero on error.
X509_ALGOR_dup(Pointer<X509_ALGOR> alg) → Pointer<X509_ALGOR>
X509_ALGOR_dup returns a newly-allocated copy of |alg|, or NULL on error. This function works by serializing the structure, so if |alg| is incomplete, it may fail.
X509_ALGOR_free(Pointer<X509_ALGOR> alg) → void
X509_ALGOR_free releases memory associated with |alg|.
X509_ALGOR_get0(Pointer<Pointer<ASN1_OBJECT>> out_obj, Pointer<Int> out_param_type, Pointer<Pointer<Void>> out_param_value, Pointer<X509_ALGOR> alg) → void
X509_ALGOR_get0 sets |*out_obj| to the |alg|'s algorithm. If |alg|'s parameter is omitted, it sets |*out_param_type| and |*out_param_value| to |V_ASN1_UNDEF| and NULL. Otherwise, it sets |*out_param_type| and |*out_param_value| to the parameter, using the same representation as |ASN1_TYPE_set0|. See |ASN1_TYPE_set0| and |ASN1_TYPE| for details.
X509_ALGOR_new() → Pointer<X509_ALGOR>
X509_ALGOR_new returns a newly-allocated, empty |X509_ALGOR| object, or NULL on error.
X509_ALGOR_set0(Pointer<X509_ALGOR> alg, Pointer<ASN1_OBJECT> obj, int param_type, Pointer<Void> param_value) → int
X509_ALGOR_set0 sets |alg| to an AlgorithmIdentifier with algorithm |obj| and parameter determined by |param_type| and |param_value|. It returns one on success and zero on error. This function takes ownership of |obj| and |param_value| on success.
X509_ALGOR_set_md(Pointer<X509_ALGOR> alg, Pointer<EVP_MD> md) → int
X509_ALGOR_set_md sets |alg| to the hash function |md|. Note this AlgorithmIdentifier represents the hash function itself, not a signature algorithm that uses |md|. It returns one on success and zero on error.
X509_alias_get0(Pointer<X509> x509, Pointer<Int> out_len) → Pointer<Uint8>
X509_alias_get0 looks up |x509|'s alias. If found, it sets |*out_len| to the alias's length and returns a pointer to a buffer containing the contents. If not found, it outputs the empty string by returning NULL and setting |*out_len| to zero.
X509_alias_set1(Pointer<X509> x509, Pointer<Uint8> name, int len) → int
X509_alias_set1 sets |x509|'s alias to |len| bytes from |name|. If |name| is NULL, the alias is cleared instead. Aliases are not part of the certificate itself and will not be serialized by |i2d_X509|. If |x509| is serialized in a PKCS#12 structure, the friendlyName attribute (RFC 2985) will contain this alias.
X509_ATTRIBUTE_count(Pointer<X509_ATTRIBUTE> attr) → int
X509_ATTRIBUTE_count returns the number of values in |attr|.
X509_ATTRIBUTE_create(int nid, int attrtype, Pointer<Void> value) → Pointer<X509_ATTRIBUTE>
X509_ATTRIBUTE_create returns a newly-allocated |X509_ATTRIBUTE|, or NULL on error. The attribute has type |nid| and contains a single value determined by |attrtype| and |value|, which are interpreted as in |ASN1_TYPE_set|. Note this function takes ownership of |value|.
X509_ATTRIBUTE_create_by_NID(Pointer<Pointer<X509_ATTRIBUTE>> attr, int nid, int attrtype, Pointer<Void> data, int len) → Pointer<X509_ATTRIBUTE>
X509_ATTRIBUTE_create_by_NID returns a newly-allocated |X509_ATTRIBUTE| of type |nid|, or NULL on error. The value is determined as in |X509_ATTRIBUTE_set1_data|.
X509_ATTRIBUTE_create_by_OBJ(Pointer<Pointer<X509_ATTRIBUTE>> attr, Pointer<ASN1_OBJECT> obj, int attrtype, Pointer<Void> data, int len) → Pointer<X509_ATTRIBUTE>
X509_ATTRIBUTE_create_by_OBJ behaves like |X509_ATTRIBUTE_create_by_NID| except the attribute's type is determined by |obj|.
X509_ATTRIBUTE_create_by_txt(Pointer<Pointer<X509_ATTRIBUTE>> attr, Pointer<Char> attrname, int type, Pointer<UnsignedChar> bytes, int len) → Pointer<X509_ATTRIBUTE>
X509_ATTRIBUTE_create_by_txt behaves like |X509_ATTRIBUTE_create_by_NID| except the attribute's type is determined by calling |OBJ_txt2obj| with |attrname|.
X509_ATTRIBUTE_dup(Pointer<X509_ATTRIBUTE> attr) → Pointer<X509_ATTRIBUTE>
X509_ATTRIBUTE_dup returns a newly-allocated copy of |attr|, or NULL on error. This function works by serializing the structure, so if |attr| is incomplete, it may fail.
X509_ATTRIBUTE_free(Pointer<X509_ATTRIBUTE> attr) → void
X509_ATTRIBUTE_free releases memory associated with |attr|.
X509_ATTRIBUTE_get0_data(Pointer<X509_ATTRIBUTE> attr, int idx, int attrtype, Pointer<Void> unused) → Pointer<Void>
X509_ATTRIBUTE_get0_data returns the |idx|th value of |attr| in a type-specific representation to |attrtype|, or NULL if out of bounds or the type does not match. |attrtype| is one of the type values in |ASN1_TYPE|. On match, the return value uses the same representation as |ASN1_TYPE_set0|. See |ASN1_TYPE| for details.
X509_ATTRIBUTE_get0_object(Pointer<X509_ATTRIBUTE> attr) → Pointer<ASN1_OBJECT>
X509_ATTRIBUTE_get0_object returns the type of |attr|.
X509_ATTRIBUTE_get0_type(Pointer<X509_ATTRIBUTE> attr, int idx) → Pointer<ASN1_TYPE>
X509_ATTRIBUTE_get0_type returns the |idx|th value in |attr|, or NULL if out of bounds. Note this function returns one of |attr|'s values, not the type.
X509_ATTRIBUTE_new() → Pointer<X509_ATTRIBUTE>
X509_ATTRIBUTE_new returns a newly-allocated, empty |X509_ATTRIBUTE| object, or NULL on error. |X509_ATTRIBUTE_set1_*| may be used to finish initializing it.
X509_ATTRIBUTE_set1_data(Pointer<X509_ATTRIBUTE> attr, int attrtype, Pointer<Void> data, int len) → int
X509_ATTRIBUTE_set1_data appends a value to |attr|'s value set and returns one on success or zero on error. The value is determined as follows:
X509_ATTRIBUTE_set1_object(Pointer<X509_ATTRIBUTE> attr, Pointer<ASN1_OBJECT> obj) → int
X509_ATTRIBUTE_set1_object sets |attr|'s type to |obj|. It returns one on success and zero on error.
X509_chain_up_ref(Pointer<stack_st_X509> chain) → Pointer<stack_st_X509>
X509_chain_up_ref returns a newly-allocated |STACK_OF(X509)| containing a shallow copy of |chain|, or NULL on error. That is, the return value has the same contents as |chain|, and each |X509|'s reference count is incremented by one.
X509_check_ca(Pointer<X509> x509) → int
X509_check_ca returns one if |x509| may be considered a CA certificate, according to basic constraints and key usage extensions. Otherwise, it returns zero. If |x509| is an X509v1 certificate, and thus has no extensions, it is considered eligible.
X509_check_email(Pointer<X509> x509, Pointer<Char> chk, int chklen, int flags) → int
X509_check_email checks if |x509| matches the email address |chk|. It returns one on match, zero on mismatch, or a negative number on error. |flags| should be some combination of |X509_CHECK_FLAG_*| and modifies the behavior.
X509_check_host(Pointer<X509> x509, Pointer<Char> chk, int chklen, int flags, Pointer<Pointer<Char>> out_peername) → int
X509_check_host checks if |x509| matches the DNS name |chk|. It returns one on match, zero on mismatch, or a negative number on error. |flags| should be some combination of |X509_CHECK_FLAG_*| and modifies the behavior. On match, if |out_peername| is non-NULL, it additionally sets |*out_peername| to a newly-allocated, NUL-terminated string containing the DNS name or wildcard in the certificate which matched. The caller must then free |*out_peername| with |OPENSSL_free| when done.
X509_check_ip(Pointer<X509> x509, Pointer<Uint8> chk, int chklen, int flags) → int
X509_check_ip checks if |x509| matches the IP address |chk|. The IP address is represented in byte form and should be 4 bytes for an IPv4 address and 16 bytes for an IPv6 address. It returns one on match, zero on mismatch, or a negative number on error. |flags| should be some combination of |X509_CHECK_FLAG_*| and modifies the behavior.
X509_check_ip_asc(Pointer<X509> x509, Pointer<Char> ipasc, int flags) → int
X509_check_ip_asc behaves like |X509_check_ip| except the IP address is specified in textual form in |ipasc|.
X509_check_issued(Pointer<X509> issuer, Pointer<X509> subject) → int
X509_check_issued checks if |issuer| and |subject|'s name, authority key identifier, and key usage fields allow |issuer| to have issued |subject|. It returns |X509_V_OK| on success and an |X509_V_ERR_*| value otherwise.
X509_check_private_key(Pointer<X509> x509, Pointer<EVP_PKEY> pkey) → int
X509_check_private_key returns one if |x509|'s public key matches |pkey| and zero otherwise.
X509_check_purpose(Pointer<X509> x509, int purpose, int ca) → int
X509_check_purpose performs checks if |x509|'s basic constraints, key usage, and extended key usage extensions for the specified purpose. |purpose| should be one of |X509_PURPOSE_*| constants. See |X509_VERIFY_PARAM_set_purpose| for details. It returns one if |x509|'s extensions are consistent with |purpose| and zero otherwise. If |ca| is non-zero, |x509| is checked as a CA certificate. Otherwise, it is checked as an end-entity certificate.
X509_check_trust(Pointer<X509> x509, int id, int flags) → int
X509_check_trust checks if |x509| is a valid trust anchor for trust type |id|. See |X509_VERIFY_PARAM_set_trust| for details. It returns |X509_TRUST_TRUSTED| if |x509| is a trust anchor, |X509_TRUST_REJECTED| if it was distrusted, and |X509_TRUST_UNTRUSTED| otherwise. |id| should be one of the |X509_TRUST_*| constants, or zero to indicate the default behavior. |flags| should be zero and is ignored.
X509_cmp(Pointer<X509> a, Pointer<X509> b) → int
X509_cmp compares |a| and |b| and returns zero if they are equal, a negative number if |b| sorts after |a| and a negative number if |a| sorts after |b|. The sort order implemented by this function is arbitrary and does not reflect properties of the certificate such as expiry. Applications should not rely on the order itself.
X509_cmp_current_time(Pointer<ASN1_OCTET_STRING> s) → int
X509_cmp_current_time behaves like |X509_cmp_time| but compares |s| against the current time.
X509_cmp_time(Pointer<ASN1_OCTET_STRING> s, Pointer<Long> t) → int
X509_cmp_time compares |s| against |*t|. On success, it returns a negative number if |s| <= |*t| and a positive number if |s| > |*t|. On error, it returns zero. If |t| is NULL, it uses the current time instead of |*t|.
X509_cmp_time_posix(Pointer<ASN1_OCTET_STRING> s, int t) → int
X509_cmp_time_posix compares |s| against |t|. On success, it returns a negative number if |s| <= |t| and a positive number if |s| > |t|. On error, it returns zero.
X509_CRL_add0_revoked(Pointer<X509_CRL> crl, Pointer<X509_REVOKED> rev) → int
X509_CRL_add0_revoked adds |rev| to |crl|. On success, it takes ownership of |rev| and returns one. On error, it returns zero. If this function fails, the caller retains ownership of |rev| and must release it when done.
X509_CRL_add1_ext_i2d(Pointer<X509_CRL> x, int nid, Pointer<Void> value, int crit, int flags) → int
X509_CRL_add1_ext_i2d behaves like |X509V3_add1_i2d| but adds the extension to |x|'s extension list.
X509_CRL_add_ext(Pointer<X509_CRL> x, Pointer<X509_EXTENSION> ex, int loc) → int
X509_CRL_add_ext adds a copy of |ex| to |x|. It returns one on success and zero on failure. The caller retains ownership of |ex| and can release it independently of |x|.
X509_CRL_cmp(Pointer<X509_CRL> a, Pointer<X509_CRL> b) → int
X509_CRL_cmp behaves like |X509_NAME_cmp|, but compares |a| and |b|'s issuer names.
X509_CRL_delete_ext(Pointer<X509_CRL> x, int loc) → Pointer<X509_EXTENSION>
X509_CRL_delete_ext removes the extension in |x| at index |loc| and returns the removed extension, or NULL if |loc| was out of bounds. If non-NULL, the caller must release the result with |X509_EXTENSION_free|.
X509_CRL_digest(Pointer<X509_CRL> crl, Pointer<EVP_MD> md, Pointer<Uint8> out, Pointer<UnsignedInt> out_len) → int
X509_CRL_digest hashes |crl|'s DER encoding with |md| and writes the result to |out|. |EVP_MD_CTX_size| bytes are written, which is at most |EVP_MAX_MD_SIZE|. If |out_len| is not NULL, |*out_len| is set to the number of bytes written. This function returns one on success and zero on error. Note this digest covers the entire CRL, not just the signed portion.
X509_CRL_dup(Pointer<X509_CRL> crl) → Pointer<X509_CRL>
X509_CRL_dup returns a newly-allocated copy of |crl|, or NULL on error. This function works by serializing the structure, so if |crl| is incomplete, it may fail.
X509_CRL_free(Pointer<X509_CRL> crl) → void
X509_CRL_free decrements |crl|'s reference count and, if zero, releases memory associated with |crl|.
X509_CRL_get0_by_cert(Pointer<X509_CRL> crl, Pointer<Pointer<X509_REVOKED>> out, Pointer<X509> x509) → int
X509_CRL_get0_by_cert behaves like |X509_CRL_get0_by_serial|, except it looks for the entry that matches |x509|.
X509_CRL_get0_by_serial(Pointer<X509_CRL> crl, Pointer<Pointer<X509_REVOKED>> out, Pointer<ASN1_OCTET_STRING> serial) → int
X509_CRL_get0_by_serial finds the entry in |crl| whose serial number is |serial|. If found, it sets |*out| to the entry and returns one. If not found, it returns zero.
X509_CRL_get0_extensions(Pointer<X509_CRL> crl) → Pointer<X509_EXTENSIONS>
X509_CRL_get0_extensions returns |crl|'s extension list, or NULL if |crl| omits it. A CRL can have extensions on individual entries, which is |X509_REVOKED_get0_extensions|, or on the overall CRL, which is this function.
X509_CRL_get0_lastUpdate(Pointer<X509_CRL> crl) → Pointer<ASN1_OCTET_STRING>
X509_CRL_get0_lastUpdate returns |crl|'s thisUpdate time. The OpenSSL API refers to this field as lastUpdate.
X509_CRL_get0_nextUpdate(Pointer<X509_CRL> crl) → Pointer<ASN1_OCTET_STRING>
X509_CRL_get0_nextUpdate returns |crl|'s nextUpdate time, or NULL if |crl| has none.
X509_CRL_get0_signature(Pointer<X509_CRL> crl, Pointer<Pointer<ASN1_OCTET_STRING>> out_sig, Pointer<Pointer<X509_ALGOR>> out_alg) → void
X509_CRL_get0_signature sets |*out_sig| and |*out_alg| to the signature and signature algorithm of |crl|, respectively. Either output pointer may be NULL to ignore the value.
X509_CRL_get_ext(Pointer<X509_CRL> x, int loc) → Pointer<X509_EXTENSION>
X509_CRL_get_ext returns the extension in |x| at index |loc|, or NULL if |loc| is out of bounds. This function returns a non-const pointer for OpenSSL compatibility, but callers should not mutate the result.
X509_CRL_get_ext_by_critical(Pointer<X509_CRL> x, int crit, int lastpos) → int
X509_CRL_get_ext_by_critical behaves like |X509v3_get_ext_by_critical| but searches for extensions in |x|.
X509_CRL_get_ext_by_NID(Pointer<X509_CRL> x, int nid, int lastpos) → int
X509_CRL_get_ext_by_NID behaves like |X509v3_get_ext_by_NID| but searches for extensions in |x|.
X509_CRL_get_ext_by_OBJ(Pointer<X509_CRL> x, Pointer<ASN1_OBJECT> obj, int lastpos) → int
X509_CRL_get_ext_by_OBJ behaves like |X509v3_get_ext_by_OBJ| but searches for extensions in |x|.
X509_CRL_get_ext_count(Pointer<X509_CRL> x) → int
X509_CRL_get_ext_count returns the number of extensions in |x|.
X509_CRL_get_ext_d2i(Pointer<X509_CRL> crl, int nid, Pointer<Int> out_critical, Pointer<Int> out_idx) → Pointer<Void>
X509_CRL_get_ext_d2i behaves like |X509V3_get_d2i| but looks for the extension in |crl|'s extension list.
X509_CRL_get_issuer(Pointer<X509_CRL> crl) → Pointer<X509_NAME>
X509_CRL_get_issuer returns |crl|'s issuer name. Note this function is not const-correct for legacy reasons.
X509_CRL_get_lastUpdate(Pointer<X509_CRL> crl) → Pointer<ASN1_OCTET_STRING>
X509_CRL_get_lastUpdate returns a mutable pointer to |crl|'s thisUpdate time. The OpenSSL API refers to this field as lastUpdate.
X509_CRL_get_nextUpdate(Pointer<X509_CRL> crl) → Pointer<ASN1_OCTET_STRING>
X509_CRL_get_nextUpdate returns a mutable pointer to |crl|'s nextUpdate time, or NULL if |crl| has none. Use |X509_CRL_get0_nextUpdate| or |X509_CRL_set1_nextUpdate| instead.
X509_CRL_get_REVOKED(Pointer<X509_CRL> crl) → Pointer<stack_st_X509_REVOKED>
X509_CRL_get_REVOKED returns the list of revoked certificates in |crl|, or NULL if |crl| omits it.
X509_CRL_get_signature_nid(Pointer<X509_CRL> crl) → int
X509_CRL_get_signature_nid returns the NID corresponding to |crl|'s signature algorithm, or |NID_undef| if the signature algorithm does not correspond to a known NID.
X509_CRL_get_version(Pointer<X509_CRL> crl) → int
X509_CRL_get_version returns the numerical value of |crl|'s version, which will be one of the |X509_CRL_VERSION_*| constants.
X509_CRL_match(Pointer<X509_CRL> a, Pointer<X509_CRL> b) → int
X509_CRL_match compares |a| and |b| and returns zero if they are equal, a negative number if |b| sorts after |a| and a negative number if |a| sorts after |b|. The sort order implemented by this function is arbitrary and does not reflect properties of the CRL such as expiry. Applications should not rely on the order itself.
X509_CRL_new() → Pointer<X509_CRL>
X509_CRL_new returns a newly-allocated, empty |X509_CRL| object, or NULL on error. This object may be filled in and then signed to construct a CRL.
X509_CRL_print(Pointer<BIO> bp, Pointer<X509_CRL> x) → int
X509_CRL_print writes a human-readable representation of |x| to |bp|. It returns one on success and zero on error.
X509_CRL_print_fp(Pointer<FILE> fp, Pointer<X509_CRL> x) → int
X509_CRL_print_fp behaves like |X509_CRL_print| but writes to |fp|.
X509_CRL_set1_lastUpdate(Pointer<X509_CRL> crl, Pointer<ASN1_OCTET_STRING> tm$1) → int
X509_CRL_set1_lastUpdate sets |crl|'s thisUpdate time to |tm|. It returns one on success and zero on error. The OpenSSL API refers to this field as lastUpdate.
X509_CRL_set1_nextUpdate(Pointer<X509_CRL> crl, Pointer<ASN1_OCTET_STRING> tm$1) → int
X509_CRL_set1_nextUpdate sets |crl|'s nextUpdate time to |tm|. It returns one on success and zero on error.
X509_CRL_set1_signature_algo(Pointer<X509_CRL> crl, Pointer<X509_ALGOR> algo) → int
X509_CRL_set1_signature_algo sets |crl|'s signature algorithm to |algo| and returns one on success or zero on error. It updates both the signature field of the TBSCertList structure, and the signatureAlgorithm field of the CRL.
X509_CRL_set1_signature_value(Pointer<X509_CRL> crl, Pointer<Uint8> sig, int sig_len) → int
X509_CRL_set1_signature_value sets |crl|'s signature to a copy of the |sig_len| bytes pointed by |sig|. It returns one on success and zero on error.
X509_CRL_set_issuer_name(Pointer<X509_CRL> crl, Pointer<X509_NAME> name) → int
X509_CRL_set_issuer_name sets |crl|'s issuer to a copy of |name|. It returns one on success and zero on error.
X509_CRL_set_version(Pointer<X509_CRL> crl, int version) → int
X509_CRL_set_version sets |crl|'s version to |version|, which should be one of the |X509_CRL_VERSION_*| constants. It returns one on success and zero on error.
X509_CRL_sign(Pointer<X509_CRL> crl, Pointer<EVP_PKEY> pkey, Pointer<EVP_MD> md) → int
X509_CRL_sign signs |crl| with |pkey| and replaces the signature algorithm and signature fields. It returns the length of the signature on success and zero on error. This function uses digest algorithm |md|, or |pkey|'s default if NULL. Other signing parameters use |pkey|'s defaults. To customize them, use |X509_CRL_sign_ctx|.
X509_CRL_sign_ctx(Pointer<X509_CRL> crl, Pointer<EVP_MD_CTX> ctx) → int
X509_CRL_sign_ctx signs |crl| with |ctx| and replaces the signature algorithm and signature fields. It returns the length of the signature on success and zero on error. The signature algorithm and parameters come from |ctx|, which must have been initialized with |EVP_DigestSignInit|. The caller should configure the corresponding |EVP_PKEY_CTX| before calling this function.
X509_CRL_sort(Pointer<X509_CRL> crl) → int
X509_CRL_sort sorts the entries in |crl| by serial number. It returns one on success and zero on error.
X509_CRL_up_ref(Pointer<X509_CRL> crl) → int
X509_CRL_up_ref adds one to the reference count of |crl| and returns one.
X509_CRL_verify(Pointer<X509_CRL> crl, Pointer<EVP_PKEY> pkey) → int
X509_CRL_verify checks that |crl| has a valid signature by |pkey|. It returns one if the signature is valid and zero otherwise.
X509_delete_ext(Pointer<X509> x, int loc) → Pointer<X509_EXTENSION>
X509_delete_ext removes the extension in |x| at index |loc| and returns the removed extension, or NULL if |loc| was out of bounds. If non-NULL, the caller must release the result with |X509_EXTENSION_free|.
X509_digest(Pointer<X509> x509, Pointer<EVP_MD> md, Pointer<Uint8> out, Pointer<UnsignedInt> out_len) → int
X509_digest hashes |x509|'s DER encoding with |md| and writes the result to |out|. |EVP_MD_CTX_size| bytes are written, which is at most |EVP_MAX_MD_SIZE|. If |out_len| is not NULL, |*out_len| is set to the number of bytes written. This function returns one on success and zero on error. Note this digest covers the entire certificate, not just the signed portion.
X509_dup(Pointer<X509> x509) → Pointer<X509>
X509_dup returns a newly-allocated copy of |x509|, or NULL on error. This function works by serializing the structure, so auxiliary properties (see |i2d_X509_AUX|) are not preserved. Additionally, if |x509| is incomplete, this function may fail.
X509_dup_ref(Pointer<X509> x509) → Pointer<X509>
X509_dup_ref increments the reference count of |x509| and returns |x509|. The caller must call |X509_free| on the result to release the reference.
X509_email_free(Pointer<stack_st_OPENSSL_STRING> sk) → void
X509_email_free releases memory associated with |sk|, including |sk| itself. Each |OPENSSL_STRING| in |sk| must be a NUL-terminated string allocated with |OPENSSL_malloc|. If |sk| is NULL, no action is taken.
X509_EXTENSION_create_by_NID(Pointer<Pointer<X509_EXTENSION>> ex, int nid, int crit, Pointer<ASN1_OCTET_STRING> data) → Pointer<X509_EXTENSION>
X509_EXTENSION_create_by_NID creates a new |X509_EXTENSION| with type |nid|, value |data|, and critical bit |crit|. It returns an |X509_EXTENSION| on success, and NULL on error. |nid| should be a |NID_*| constant.
X509_EXTENSION_create_by_OBJ(Pointer<Pointer<X509_EXTENSION>> ex, Pointer<ASN1_OBJECT> obj, int crit, Pointer<ASN1_OCTET_STRING> data) → Pointer<X509_EXTENSION>
X509_EXTENSION_create_by_OBJ behaves like |X509_EXTENSION_create_by_NID|, but the extension type is determined by an |ASN1_OBJECT|.
X509_EXTENSION_dup(Pointer<X509_EXTENSION> ex) → Pointer<X509_EXTENSION>
X509_EXTENSION_dup returns a newly-allocated copy of |ex|, or NULL on error. This function works by serializing the structure, so if |ex| is incomplete, it may fail.
X509_EXTENSION_free(Pointer<X509_EXTENSION> ex) → void
X509_EXTENSION_free releases memory associated with |ex|.
X509_EXTENSION_get_critical(Pointer<X509_EXTENSION> ex) → int
X509_EXTENSION_get_critical returns one if |ex| is critical and zero otherwise.
X509_EXTENSION_get_data(Pointer<X509_EXTENSION> ne) → Pointer<ASN1_OCTET_STRING>
X509_EXTENSION_get_data returns |ne|'s extension value. This function returns a non-const pointer for OpenSSL compatibility, but callers should not mutate the result.
X509_EXTENSION_get_object(Pointer<X509_EXTENSION> ex) → Pointer<ASN1_OBJECT>
X509_EXTENSION_get_object returns |ex|'s extension type. This function returns a non-const pointer for OpenSSL compatibility, but callers should not mutate the result.
X509_EXTENSION_new() → Pointer<X509_EXTENSION>
X509_EXTENSION_new returns a newly-allocated, empty |X509_EXTENSION| object or NULL on error.
X509_EXTENSION_set_critical(Pointer<X509_EXTENSION> ex, int crit) → int
X509_EXTENSION_set_critical sets |ex| to critical if |crit| is non-zero and to non-critical if |crit| is zero.
X509_EXTENSION_set_data(Pointer<X509_EXTENSION> ex, Pointer<ASN1_OCTET_STRING> data) → int
X509_EXTENSION_set_data set's |ex|'s extension value to a copy of |data|. It returns one on success and zero on error.
X509_EXTENSION_set_object(Pointer<X509_EXTENSION> ex, Pointer<ASN1_OBJECT> obj) → int
X509_EXTENSION_set_object sets |ex|'s extension type to |obj|. It returns one on success and zero on error.
X509_find_by_issuer_and_serial(Pointer<stack_st_X509> sk, Pointer<X509_NAME> name, Pointer<ASN1_OCTET_STRING> serial) → Pointer<X509>
X509_find_by_issuer_and_serial returns the first |X509| in |sk| whose issuer and serial are |name| and |serial|, respectively. If no match is found, it returns NULL.
X509_find_by_subject(Pointer<stack_st_X509> sk, Pointer<X509_NAME> name) → Pointer<X509>
X509_find_by_subject returns the first |X509| in |sk| whose subject is |name|. If no match is found, it returns NULL.
X509_free(Pointer<X509> x509) → void
X509_free decrements |x509|'s reference count and, if zero, releases memory associated with |x509|.
X509_get0_authority_issuer(Pointer<X509> x509) → Pointer<GENERAL_NAMES>
X509_get0_authority_issuer returns the authorityCertIssuer of |x509|'s authority key identifier, if the extension and field are present. (See RFC 5280, section 4.2.1.1.) It returns NULL if the extension is not present, if it is present but lacks a authorityCertIssuer field, or if some extension in |x509| was invalid.
X509_get0_authority_key_id(Pointer<X509> x509) → Pointer<ASN1_OCTET_STRING>
X509_get0_authority_key_id returns keyIdentifier of |x509|'s authority key identifier, if the extension and field are present. (See RFC 5280, section 4.2.1.1.) It returns NULL if the extension is not present, if it is present but lacks a keyIdentifier field, or if some extension in |x509| was invalid.
X509_get0_authority_serial(Pointer<X509> x509) → Pointer<ASN1_OCTET_STRING>
X509_get0_authority_serial returns the authorityCertSerialNumber of |x509|'s authority key identifier, if the extension and field are present. (See RFC 5280, section 4.2.1.1.) It returns NULL if the extension is not present, if it is present but lacks a authorityCertSerialNumber field, or if some extension in |x509| was invalid.
X509_get0_extensions(Pointer<X509> x509) → Pointer<X509_EXTENSIONS>
X509_get0_extensions returns |x509|'s extension list, or NULL if |x509| omits it.
X509_get0_notAfter(Pointer<X509> x509) → Pointer<ASN1_OCTET_STRING>
X509_get0_notAfter returns |x509|'s notAfter time.
X509_get0_notBefore(Pointer<X509> x509) → Pointer<ASN1_OCTET_STRING>
X509_get0_notBefore returns |x509|'s notBefore time.
X509_get0_pubkey(Pointer<X509> x509) → Pointer<EVP_PKEY>
X509_get0_pubkey returns |x509|'s public key as an |EVP_PKEY|, or NULL if the public key was unsupported or could not be decoded. The |EVP_PKEY| is cached in |x509|, so callers must not mutate the result.
X509_get0_pubkey_bitstr(Pointer<X509> x509) → Pointer<ASN1_OCTET_STRING>
X509_get0_pubkey_bitstr returns the BIT STRING portion of |x509|'s public key. Note this does not contain the AlgorithmIdentifier portion.
X509_get0_serialNumber(Pointer<X509> x509) → Pointer<ASN1_OCTET_STRING>
X509_get0_serialNumber returns |x509|'s serial number.
X509_get0_signature(Pointer<Pointer<ASN1_OCTET_STRING>> out_sig, Pointer<Pointer<X509_ALGOR>> out_alg, Pointer<X509> x509) → void
X509_get0_signature sets |*out_sig| and |*out_alg| to the signature and signature algorithm of |x509|, respectively. Either output pointer may be NULL to ignore the value.
X509_get0_subject_key_id(Pointer<X509> x509) → Pointer<ASN1_OCTET_STRING>
X509_get0_subject_key_id returns |x509|'s subject key identifier, if present. (See RFC 5280, section 4.2.1.2.) It returns NULL if the extension is not present or if some extension in |x509| was invalid.
X509_get0_tbs_sigalg(Pointer<X509> x509) → Pointer<X509_ALGOR>
X509_get0_tbs_sigalg returns the signature algorithm in |x509|'s TBSCertificate. For the outer signature algorithm, see |X509_get0_signature|.
X509_get0_uids(Pointer<X509> x509, Pointer<Pointer<ASN1_OCTET_STRING>> out_issuer_uid, Pointer<Pointer<ASN1_OCTET_STRING>> out_subject_uid) → void
X509_get0_uids sets |*out_issuer_uid| to a non-owning pointer to the issuerUID field of |x509|, or NULL if |x509| has no issuerUID. It similarly outputs |x509|'s subjectUID field to |*out_subject_uid|.
X509_get1_email(Pointer<X509> x509) → Pointer<stack_st_OPENSSL_STRING>
X509_get1_email returns a newly-allocated list of NUL-terminated strings containing all email addresses in |x509|'s subject and all rfc822name names in |x509|'s subject alternative names. Email addresses which contain embedded NUL bytes are skipped. The results are returned in an arbitrary order.
X509_get1_ocsp(Pointer<X509> x509) → Pointer<stack_st_OPENSSL_STRING>
X509_get1_ocsp returns a newly-allocated list of NUL-terminated strings containing all OCSP URIs in |x509|. That is, it collects all URI AccessDescriptions with an accessMethod of id-ad-ocsp in |x509|'s authority information access extension. URIs which contain embedded NUL bytes are skipped. The results are returned in an arbitrary order.
X509_get_default_cert_area() → Pointer<Char>
The following functions return filesystem paths used to determine the above "default" paths, when the corresponding environment variables are not set.
X509_get_default_cert_dir() → Pointer<Char>
X509_get_default_cert_dir_env() → Pointer<Char>
X509_get_default_cert_dir_env returns "SSL_CERT_DIR", an environment variable used to determine the above "default" paths.
X509_get_default_cert_file() → Pointer<Char>
X509_get_default_cert_file_env() → Pointer<Char>
X509_get_default_cert_file_env returns "SSL_CERT_FILE", an environment variable used to determine the above "default" paths.
X509_get_default_private_dir() → Pointer<Char>
X509_get_ex_data(Pointer<X509> r, int idx) → Pointer<Void>
X509_get_ex_new_index(int argl, Pointer<Void> argp, Pointer<Int> unused, Pointer<CRYPTO_EX_dup> dup_unused, Pointer<CRYPTO_EX_free> free_func) → int
ex_data functions.
X509_get_ext(Pointer<X509> x, int loc) → Pointer<X509_EXTENSION>
X509_get_ext returns the extension in |x| at index |loc|, or NULL if |loc| is out of bounds. This function returns a non-const pointer for OpenSSL compatibility, but callers should not mutate the result.
X509_get_ext_by_critical(Pointer<X509> x, int crit, int lastpos) → int
X509_get_ext_by_critical behaves like |X509v3_get_ext_by_critical| but searches for extensions in |x|.
X509_get_ext_by_NID(Pointer<X509> x, int nid, int lastpos) → int
X509_get_ext_by_NID behaves like |X509v3_get_ext_by_NID| but searches for extensions in |x|.
X509_get_ext_by_OBJ(Pointer<X509> x, Pointer<ASN1_OBJECT> obj, int lastpos) → int
X509_get_ext_by_OBJ behaves like |X509v3_get_ext_by_OBJ| but searches for extensions in |x|.
X509_get_ext_count(Pointer<X509> x) → int
X509_get_ext_count returns the number of extensions in |x|.
X509_get_ext_d2i(Pointer<X509> x509, int nid, Pointer<Int> out_critical, Pointer<Int> out_idx) → Pointer<Void>
X509_get_ext_d2i behaves like |X509V3_get_d2i| but looks for the extension in |x509|'s extension list.
X509_get_extended_key_usage(Pointer<X509> x509) → int
X509_get_extended_key_usage returns a bitmask of extended key usages (see Section 4.2.1.12 of RFC 5280) which |x509| is valid for. The result will be a combination of |XKU_*| constants. If checking an extended key usage not defined above, callers should extract the extended key usage extension separately, e.g. via |X509_get_ext_d2i|.
X509_get_extension_flags(Pointer<X509> x509) → int
X509_get_extension_flags decodes a set of extensions from |x509| and returns a collection of |EXFLAG_*| bits which reflect |x509|. If there was an error in computing this bitmask, the result will include the |EXFLAG_INVALID| bit.
X509_get_issuer_name(Pointer<X509> x509) → Pointer<X509_NAME>
X509_get_issuer_name returns |x509|'s issuer.
X509_get_key_usage(Pointer<X509> x509) → int
X509_get_key_usage returns a bitmask of key usages (see Section 4.2.1.3 of RFC 5280) which |x509| is valid for. This function only reports the first 16 bits, in a little-endian byte order, but big-endian bit order. That is, bits 0 though 7 are reported at 1<<7 through 1<<0, and bits 8 through 15 are reported at 1<<15 through 1<<8.
X509_get_notAfter(Pointer<X509> x509) → Pointer<ASN1_OCTET_STRING>
X509_get_notAfter returns |x509|'s notAfter time. Note this function is not const-correct for legacy reasons. Use |X509_get0_notAfter| or |X509_getm_notAfter| instead.
X509_get_notBefore(Pointer<X509> x509) → Pointer<ASN1_OCTET_STRING>
X509_get_notBefore returns |x509|'s notBefore time. Note this function is not const-correct for legacy reasons. Use |X509_get0_notBefore| or |X509_getm_notBefore| instead.
X509_get_pathlen(Pointer<X509> x509) → int
X509_get_pathlen returns path length constraint from the basic constraints extension in |x509|. (See RFC 5280, section 4.2.1.9.) It returns -1 if the constraint is not present, or if some extension in |x509| was invalid.
X509_get_pubkey(Pointer<X509> x509) → Pointer<EVP_PKEY>
X509_get_pubkey behaves like |X509_get0_pubkey| but increments the reference count on the |EVP_PKEY|. The caller must release the result with |EVP_PKEY_free| when done. The |EVP_PKEY| is cached in |x509|, so callers must not mutate the result.
X509_get_serialNumber(Pointer<X509> x509) → Pointer<ASN1_OCTET_STRING>
X509_get_serialNumber returns a mutable pointer to |x509|'s serial number. Prefer |X509_get0_serialNumber|.
X509_get_signature_nid(Pointer<X509> x509) → int
X509_get_signature_nid returns the NID corresponding to |x509|'s signature algorithm, or |NID_undef| if the signature algorithm does not correspond to a known NID.
X509_get_subject_name(Pointer<X509> x509) → Pointer<X509_NAME>
X509_get_subject_name returns |x509|'s subject.
X509_get_version(Pointer<X509> x509) → int
X509_get_version returns the numerical value of |x509|'s version, which will be one of the |X509_VERSION_*| constants.
X509_get_X509_PUBKEY(Pointer<X509> x509) → Pointer<X509_PUBKEY>
X509_get_X509_PUBKEY returns the public key of |x509|. Note this function is not const-correct for legacy reasons. Callers should not modify the returned object.
X509_getm_notAfter(Pointer<X509> x) → Pointer<ASN1_OCTET_STRING>
X509_getm_notAfter returns a mutable pointer to |x509|'s notAfter time.
X509_getm_notBefore(Pointer<X509> x509) → Pointer<ASN1_OCTET_STRING>
X509_getm_notBefore returns a mutable pointer to |x509|'s notBefore time.
X509_gmtime_adj(Pointer<ASN1_OCTET_STRING> s, int offset_sec) → Pointer<ASN1_OCTET_STRING>
X509_gmtime_adj behaves like |X509_time_adj_ex| but adds |offset_sec| to the current time.
X509_INFO_free(Pointer<X509_INFO> info) → void
X509_INFO_free releases memory associated with |info|.
X509_issuer_name_cmp(Pointer<X509> a, Pointer<X509> b) → int
X509_issuer_name_cmp behaves like |X509_NAME_cmp|, but compares |a| and |b|'s issuer names.
X509_issuer_name_hash(Pointer<X509> x509) → int
X509_issuer_name_hash returns the hash of |x509|'s issuer name with |X509_NAME_hash|.
X509_issuer_name_hash_old(Pointer<X509> x509) → int
X509_issuer_name_hash_old returns the hash of |x509|'s issuer name with |X509_NAME_hash_old|.
X509_keyid_get0(Pointer<X509> x509, Pointer<Int> out_len) → Pointer<Uint8>
X509_keyid_get0 looks up |x509|'s key ID. If found, it sets |*out_len| to the key ID's length and returns a pointer to a buffer containing the contents. If not found, it outputs the empty string by returning NULL and setting |*out_len| to zero.
X509_keyid_set1(Pointer<X509> x509, Pointer<Uint8> id, int len) → int
X509_keyid_set1 sets |x509|'s key ID to |len| bytes from |id|. If |id| is NULL, the key ID is cleared instead. Key IDs are not part of the certificate itself and will not be serialized by |i2d_X509|.
X509_load_cert_crl_file(Pointer<X509_LOOKUP> lookup, Pointer<Char> file, int type) → int
X509_load_cert_crl_file loads CRLs and trusted certificates from |file| and adds them to |lookup|'s |X509_STORE|. It returns one on success and zero on error.
X509_load_cert_file(Pointer<X509_LOOKUP> lookup, Pointer<Char> file, int type) → int
X509_load_cert_file loads trusted certificates from |file| and adds them to |lookup|'s |X509_STORE|. It returns one on success and zero on error.
X509_load_crl_file(Pointer<X509_LOOKUP> lookup, Pointer<Char> file, int type) → int
X509_load_crl_file loads CRLs from |file| and add them it to |lookup|'s |X509_STORE|. It returns one on success and zero on error.
X509_LOOKUP_add_dir(Pointer<X509_LOOKUP> lookup, Pointer<Char> path, int type) → int
X509_LOOKUP_add_dir configures |lookup| to load CRLs and trusted certificates from the directories in |path|. It returns one on success and zero on error. |lookup| must have been constructed with |X509_LOOKUP_hash_dir|.
X509_LOOKUP_ctrl(Pointer<X509_LOOKUP> lookup, int cmd, Pointer<Char> argc, int argl, Pointer<Pointer<Char>> ret) → int
X509_LOOKUP_ctrl implements commands on |lookup|. |cmd| specifies the command. The other arguments specify the operation in a command-specific way. Use |X509_LOOKUP_load_file| or |X509_LOOKUP_add_dir| instead.
X509_LOOKUP_file() → Pointer<X509_LOOKUP_METHOD>
X509_LOOKUP_file creates |X509_LOOKUP|s that may be used with |X509_LOOKUP_load_file|.
X509_LOOKUP_free(Pointer<X509_LOOKUP> ctx) → void
X509_LOOKUP_free releases memory associated with |ctx|. This function should never be used outside the library. No function in the public API hands ownership of an |X509_LOOKUP| to the caller.
X509_LOOKUP_hash_dir() → Pointer<X509_LOOKUP_METHOD>
X509_LOOKUP_hash_dir creates |X509_LOOKUP|s that may be used with |X509_LOOKUP_add_dir|.
X509_LOOKUP_load_file(Pointer<X509_LOOKUP> lookup, Pointer<Char> file, int type) → int
X509_LOOKUP_load_file calls |X509_load_cert_crl_file|. |lookup| must have been constructed with |X509_LOOKUP_file|.
X509_NAME_add_entry(Pointer<X509_NAME> name, Pointer<X509_NAME_ENTRY> entry, int loc, int set) → int
X509_NAME_add_entry adds a copy of |entry| to |name| and returns one on success or zero on error. If |loc| is -1, the entry is appended to |name|. Otherwise, it is inserted at index |loc|. If |set| is -1, the entry is added to the previous entry's RDN. If it is 0, the entry becomes a singleton RDN. If 1, it is added to next entry's RDN.
X509_NAME_add_entry_by_NID(Pointer<X509_NAME> name, int nid, int type, Pointer<Uint8> bytes, int len, int loc, int set) → int
X509_NAME_add_entry_by_NID behaves like |X509_NAME_add_entry_by_OBJ| but sets the entry's attribute type to |nid|, which should be one of the |NID_*| constants.
X509_NAME_add_entry_by_OBJ(Pointer<X509_NAME> name, Pointer<ASN1_OBJECT> obj, int type, Pointer<Uint8> bytes, int len, int loc, int set) → int
X509_NAME_add_entry_by_OBJ adds a new entry to |name| and returns one on success or zero on error. The entry's attribute type is |obj|. The entry's attribute value is determined by |type|, |bytes|, and |len|, as in |X509_NAME_ENTRY_set_data|. The entry's position is determined by |loc| and |set| as in |X509_NAME_add_entry|.
X509_NAME_add_entry_by_txt(Pointer<X509_NAME> name, Pointer<Char> field, int type, Pointer<Uint8> bytes, int len, int loc, int set) → int
X509_NAME_add_entry_by_txt behaves like |X509_NAME_add_entry_by_OBJ| but sets the entry's attribute type to |field|, which is passed to |OBJ_txt2obj|.
X509_NAME_cmp(Pointer<X509_NAME> a, Pointer<X509_NAME> b) → int
X509_NAME_cmp compares |a| and |b|'s canonicalized forms. It returns zero if they are equal, one if |a| sorts after |b|, -1 if |b| sorts after |a|, and -2 on error.
X509_NAME_delete_entry(Pointer<X509_NAME> name, int loc) → Pointer<X509_NAME_ENTRY>
X509_NAME_delete_entry removes and returns the attribute in |name| at index |loc|, or NULL if |loc| is out of range. |loc| is interpreted using |X509_NAME|'s flattened representation. If the attribute is found, the caller is responsible for releasing the result with |X509_NAME_ENTRY_free|.
X509_NAME_digest(Pointer<X509_NAME> name, Pointer<EVP_MD> md, Pointer<Uint8> out, Pointer<UnsignedInt> out_len) → int
X509_NAME_digest hashes |name|'s DER encoding with |md| and writes the result to |out|. |EVP_MD_CTX_size| bytes are written, which is at most |EVP_MAX_MD_SIZE|. If |out_len| is not NULL, |*out_len| is set to the number of bytes written. This function returns one on success and zero on error.
X509_NAME_dup(Pointer<X509_NAME> name) → Pointer<X509_NAME>
X509_NAME_dup returns a newly-allocated copy of |name|, or NULL on error.
X509_NAME_entry_count(Pointer<X509_NAME> name) → int
X509_NAME_entry_count returns the number of entries in |name|.
X509_NAME_ENTRY_create_by_NID(Pointer<Pointer<X509_NAME_ENTRY>> out, int nid, int type, Pointer<Uint8> bytes, int len) → Pointer<X509_NAME_ENTRY>
X509_NAME_ENTRY_create_by_NID behaves like |X509_NAME_ENTRY_create_by_OBJ| except the attribute type is |nid|, which should be one of the |NID_*| constants.
X509_NAME_ENTRY_create_by_OBJ(Pointer<Pointer<X509_NAME_ENTRY>> out, Pointer<ASN1_OBJECT> obj, int type, Pointer<Uint8> bytes, int len) → Pointer<X509_NAME_ENTRY>
X509_NAME_ENTRY_create_by_OBJ creates a new |X509_NAME_ENTRY| with attribute type |obj|. The attribute value is determined from |type|, |bytes|, and |len| as in |X509_NAME_ENTRY_set_data|. It returns the |X509_NAME_ENTRY| on success and NULL on error.
X509_NAME_ENTRY_create_by_txt(Pointer<Pointer<X509_NAME_ENTRY>> out, Pointer<Char> field, int type, Pointer<Uint8> bytes, int len) → Pointer<X509_NAME_ENTRY>
X509_NAME_ENTRY_create_by_txt behaves like |X509_NAME_ENTRY_create_by_OBJ| except the attribute type is |field|, which is passed to |OBJ_txt2obj|.
X509_NAME_ENTRY_dup(Pointer<X509_NAME_ENTRY> entry) → Pointer<X509_NAME_ENTRY>
X509_NAME_ENTRY_dup returns a newly-allocated copy of |entry|, or NULL on error.
X509_NAME_ENTRY_free(Pointer<X509_NAME_ENTRY> entry) → void
X509_NAME_ENTRY_free releases memory associated with |entry|.
X509_NAME_ENTRY_get_data(Pointer<X509_NAME_ENTRY> entry) → Pointer<ASN1_OCTET_STRING>
X509_NAME_ENTRY_get_data returns |entry|'s attribute value, represented as an |ASN1_STRING|. This value may have any ASN.1 type, so callers must check the type before interpreting the contents. This function returns a non-const pointer for OpenSSL compatibility, but callers should not mutate the result. Doing so will break internal invariants in the library.
X509_NAME_ENTRY_get_object(Pointer<X509_NAME_ENTRY> entry) → Pointer<ASN1_OBJECT>
X509_NAME_ENTRY_get_object returns |entry|'s attribute type. This function returns a non-const pointer for OpenSSL compatibility, but callers should not mutate the result. Doing so will break internal invariants in the library.
X509_NAME_ENTRY_new() → Pointer<X509_NAME_ENTRY>
X509_NAME_ENTRY_new returns a new, empty |X509_NAME_ENTRY|, or NULL on error.
X509_NAME_ENTRY_set(Pointer<X509_NAME_ENTRY> entry) → int
X509_NAME_ENTRY_set returns the zero-based index of the RDN which contains |entry|. Consecutive entries with the same index are part of the same RDN.
X509_NAME_ENTRY_set_data(Pointer<X509_NAME_ENTRY> entry, int type, Pointer<Uint8> bytes, int len) → int
X509_NAME_ENTRY_set_data sets |entry|'s value to |len| bytes from |bytes|. It returns one on success and zero on error. If |len| is -1, |bytes| must be a NUL-terminated C string and the length is determined by |strlen|. |bytes| is converted to an ASN.1 type as follows:
X509_NAME_ENTRY_set_object(Pointer<X509_NAME_ENTRY> entry, Pointer<ASN1_OBJECT> obj) → int
X509_NAME_ENTRY_set_object sets |entry|'s attribute type to |obj|. It returns one on success and zero on error.
X509_NAME_free(Pointer<X509_NAME> name) → void
X509_NAME_free releases memory associated with |name|.
X509_NAME_get0_der(Pointer<X509_NAME> name, Pointer<Pointer<Uint8>> out_der, Pointer<Size> out_der_len) → int
X509_NAME_get0_der marshals |name| as a DER-encoded X.509 Name (RFC 5280). On success, it returns one and sets |*out_der| and |*out_der_len| to a buffer containing the result. Otherwise, it returns zero. |*out_der| is owned by |name| and must not be freed by the caller. It is invalidated after |name| is mutated or freed.
X509_NAME_get_entry(Pointer<X509_NAME> name, int loc) → Pointer<X509_NAME_ENTRY>
X509_NAME_get_entry returns the attribute in |name| at index |loc|, or NULL if |loc| is out of range. |loc| is interpreted using |X509_NAME|'s flattened representation. This function returns a non-const pointer for OpenSSL compatibility, but callers should not mutate the result. Doing so will break internal invariants in the library.
X509_NAME_get_index_by_NID(Pointer<X509_NAME> name, int nid, int lastpos) → int
X509_NAME_get_index_by_NID returns the zero-based index of the first attribute in |name| with type |nid|, or -1 if there is none. |nid| should be one of the |NID_*| constants. If |lastpos| is non-negative, it begins searching at |lastpos+1|. To search all attributes, pass in -1, not zero.
X509_NAME_get_index_by_OBJ(Pointer<X509_NAME> name, Pointer<ASN1_OBJECT> obj, int lastpos) → int
X509_NAME_get_index_by_OBJ behaves like |X509_NAME_get_index_by_NID| but looks for attributes with type |obj|.
X509_NAME_get_text_by_NID(Pointer<X509_NAME> name, int nid, Pointer<Char> buf, int len) → int
X509_NAME_get_text_by_NID behaves like |X509_NAME_get_text_by_OBJ| except it finds an attribute of type |nid|, which should be one of the |NID_*| constants.
X509_NAME_get_text_by_OBJ(Pointer<X509_NAME> name, Pointer<ASN1_OBJECT> obj, Pointer<Char> buf, int len) → int
X509_NAME_get_text_by_OBJ finds the first attribute with type |obj| in |name|. If found, it writes the value's UTF-8 representation to |buf|. followed by a NUL byte, and returns the number of bytes in the output, excluding the NUL byte. This is unlike OpenSSL which returns the raw ASN1_STRING data. The UTF-8 encoding of the |ASN1_STRING| may not contain a 0 codepoint.
X509_NAME_hash(Pointer<X509_NAME> name) → int
X509_NAME_hash returns a hash of |name|, or zero on error. This is the new hash used by |X509_LOOKUP_add_dir|.
X509_NAME_hash_old(Pointer<X509_NAME> name) → int
X509_NAME_hash_old returns a hash of |name|, or zero on error. This is the legacy hash used by |X509_LOOKUP_add_dir|, which is still supported for compatibility.
X509_NAME_new() → Pointer<X509_NAME>
X509_NAME_new returns a new, empty |X509_NAME|, or NULL on error.
X509_NAME_oneline(Pointer<X509_NAME> name, Pointer<Char> buf, int size) → Pointer<Char>
X509_NAME_oneline writes a human-readable representation to |name| to a buffer as a NUL-terminated C string.
X509_NAME_print(Pointer<BIO> bp, Pointer<X509_NAME> name, int obase) → int
X509_NAME_print prints a human-readable representation of |name| to |bp|. It returns one on success and zero on error. |obase| is ignored.
X509_NAME_print_ex(Pointer<BIO> out, Pointer<X509_NAME> nm, int indent, int flags) → int
X509_NAME_print_ex writes a human-readable representation of |nm| to |out|. Each line of output is indented by |indent| spaces. It returns the number of bytes written on success, and -1 on error. If |out| is NULL, it returns the number of bytes it would have written but does not write anything. |flags| should be some combination of |XN_FLAG_| and |ASN1_STRFLGS_| values and determines the output. If unsure, use |XN_FLAG_RFC2253|.
X509_NAME_print_ex_fp(Pointer<FILE> fp, Pointer<X509_NAME> nm, int indent, int flags) → int
X509_NAME_print_ex_fp behaves like |X509_NAME_print_ex| but writes to |fp|.
X509_NAME_set(Pointer<Pointer<X509_NAME>> xn, Pointer<X509_NAME> name) → int
X509_NAME_set makes a copy of |name|. On success, it frees |*xn|, sets |*xn| to the copy, and returns one. Otherwise, it returns zero.
X509_new() → Pointer<X509>
X509_new returns a newly-allocated, empty |X509| object, or NULL on error. This produces an incomplete certificate which may be filled in to issue a new certificate.
X509_OBJECT_free(Pointer<X509_OBJECT> obj) → void
X509_OBJECT_free releases memory associated with |obj|.
X509_OBJECT_free_contents(Pointer<X509_OBJECT> obj) → void
X509_OBJECT_free_contents sets |obj| to the empty object, freeing any values that were previously there.
X509_OBJECT_get0_X509(Pointer<X509_OBJECT> obj) → Pointer<X509>
X509_OBJECT_get0_X509 returns |obj| as a certificate, or NULL if |obj| is not a certificate.
X509_OBJECT_get_type(Pointer<X509_OBJECT> obj) → int
X509_OBJECT_get_type returns the type of |obj|, which will be one of the |X509_LU_*| constants.
X509_OBJECT_new() → Pointer<X509_OBJECT>
X509_OBJECT_new returns a newly-allocated, empty |X509_OBJECT| or NULL on error.
X509_parse_from_buffer(Pointer<CRYPTO_BUFFER> buf) → Pointer<X509>
X509_parse_from_buffer behaves like |X509_parse_with_algorithms| but uses a default algorithm list.
X509_parse_with_algorithms(Pointer<CRYPTO_BUFFER> buf, Pointer<Pointer<EVP_PKEY_ALG>> algs, int num_algs) → Pointer<X509>
X509_parse_with_algorithms parses an X.509 structure from |buf| and returns a fresh X509 or NULL on error. There must not be any trailing data in |buf|. The returned structure (if any) increment's |buf|'s reference count and retains a reference to it.
X509_print(Pointer<BIO> bp, Pointer<X509> x) → int
X509_print calls |X509_print_ex| with |XN_FLAG_COMPAT| and |X509_FLAG_COMPAT| flags.
X509_print_ex(Pointer<BIO> bp, Pointer<X509> x, int nmflag, int cflag) → int
X509_print_ex writes a human-readable representation of |x| to |bp|. It returns one on success and zero on error. |nmflags| is the flags parameter for |X509_NAME_print_ex| when printing the subject and issuer. |cflag| should be some combination of the |X509_FLAG_| and |X509V3_EXT_| constants.
X509_print_ex_fp(Pointer<FILE> fp, Pointer<X509> x, int nmflag, int cflag) → int
X509_print_ex_fp behaves like |X509_print_ex| but writes to |fp|.
X509_print_fp(Pointer<FILE> fp, Pointer<X509> x) → int
X509_print_fp behaves like |X509_print| but writes to |fp|.
X509_pubkey_digest(Pointer<X509> x509, Pointer<EVP_MD> md, Pointer<Uint8> out, Pointer<UnsignedInt> out_len) → int
X509_pubkey_digest hashes the contents of the BIT STRING in |x509|'s subjectPublicKeyInfo field with |md| and writes the result to |out|. |EVP_MD_CTX_size| bytes are written, which is at most |EVP_MAX_MD_SIZE|. If |out_len| is not NULL, |*out_len| is set to the number of bytes written. This function returns one on success and zero on error.
X509_PUBKEY_free(Pointer<X509_PUBKEY> key) → void
X509_PUBKEY_free releases memory associated with |key|.
X509_PUBKEY_get(Pointer<X509_PUBKEY> key) → Pointer<EVP_PKEY>
X509_PUBKEY_get behaves like |X509_PUBKEY_get0| but increments the reference count on the |EVP_PKEY|. The caller must release the result with |EVP_PKEY_free| when done. The |EVP_PKEY| is cached in |key|, so callers must not mutate the result.
X509_PUBKEY_get0(Pointer<X509_PUBKEY> key) → Pointer<EVP_PKEY>
X509_PUBKEY_get0 returns |key| as an |EVP_PKEY|, or NULL if |key| either could not be parsed or is an unrecognized algorithm. The |EVP_PKEY| is cached in |key|, so callers must not mutate the result.
X509_PUBKEY_get0_param(Pointer<Pointer<ASN1_OBJECT>> out_obj, Pointer<Pointer<Uint8>> out_key, Pointer<Int> out_key_len, Pointer<Pointer<X509_ALGOR>> out_alg, Pointer<X509_PUBKEY> pub) → int
X509_PUBKEY_get0_param outputs fields of |pub| and returns one. If |out_obj| is not NULL, it sets |*out_obj| to AlgorithmIdentifier's OID. If |out_key| is not NULL, it sets |*out_key| and |*out_key_len| to the encoded public key. If |out_alg| is not NULL, it sets |*out_alg| to the AlgorithmIdentifier.
X509_PUBKEY_get0_public_key(Pointer<X509_PUBKEY> pub) → Pointer<ASN1_OCTET_STRING>
X509_PUBKEY_get0_public_key returns |pub|'s encoded public key.
X509_PUBKEY_new() → Pointer<X509_PUBKEY>
X509_PUBKEY_new returns a newly-allocated, empty |X509_PUBKEY| object, or NULL on error.
X509_PUBKEY_set(Pointer<Pointer<X509_PUBKEY>> x, Pointer<EVP_PKEY> pkey) → int
X509_PUBKEY_set serializes |pkey| into a newly-allocated |X509_PUBKEY| structure. On success, it frees |*x| if non-NULL, then sets |*x| to the new object, and returns one. Otherwise, it returns zero.
X509_PUBKEY_set0_param(Pointer<X509_PUBKEY> pub, Pointer<ASN1_OBJECT> obj, int param_type, Pointer<Void> param_value, Pointer<Uint8> key, int key_len) → int
X509_PUBKEY_set0_param sets |pub| to a key with AlgorithmIdentifier determined by |obj|, |param_type|, and |param_value|, and an encoded public key of |key|. On success, it gives |pub| ownership of all the other parameters and returns one. Otherwise, it returns zero. |key| must have been allocated by |OPENSSL_malloc|. |obj| and, if applicable, |param_value| must not be freed after a successful call, and must have been allocated in a manner compatible with |ASN1_OBJECT_free| or |ASN1_STRING_free|.
X509_PURPOSE_get0(int id) → Pointer<X509_PURPOSE>
X509_PURPOSE_get0 returns the |X509_PURPOSE| object corresponding to |id|, which should be one of the |X509_PURPOSE_*| constants, or NULL if none exists.
X509_PURPOSE_get_by_sname(Pointer<Char> sname) → int
X509_PURPOSE_get_by_sname returns the |X509_PURPOSE_*| constant corresponding a short name |sname|, or -1 if |sname| was not recognized.
X509_PURPOSE_get_id(Pointer<X509_PURPOSE> purpose) → int
X509_PURPOSE_get_id returns |purpose|'s ID. This will be one of the |X509_PURPOSE_*| constants.
X509_reject_clear(Pointer<X509> x509) → void
X509_reject_clear clears the list of OIDs for which |x509| is distrusted. See also |X509_add1_reject_object|.
X509_REQ_add1_attr(Pointer<X509_REQ> req, Pointer<X509_ATTRIBUTE> attr) → int
X509_REQ_add1_attr appends a copy of |attr| to |req|'s list of attributes. It returns one on success and zero on error.
X509_REQ_add1_attr_by_NID(Pointer<X509_REQ> req, int nid, int attrtype, Pointer<UnsignedChar> data, int len) → int
X509_REQ_add1_attr_by_NID behaves like |X509_REQ_add1_attr_by_OBJ| except the attribute type is determined by |nid|.
X509_REQ_add1_attr_by_OBJ(Pointer<X509_REQ> req, Pointer<ASN1_OBJECT> obj, int attrtype, Pointer<UnsignedChar> data, int len) → int
X509_REQ_add1_attr_by_OBJ appends a new attribute to |req| with type |obj|. It returns one on success and zero on error. The value is determined by |X509_ATTRIBUTE_set1_data|.
X509_REQ_add1_attr_by_txt(Pointer<X509_REQ> req, Pointer<Char> attrname, int attrtype, Pointer<UnsignedChar> data, int len) → int
X509_REQ_add1_attr_by_txt behaves like |X509_REQ_add1_attr_by_OBJ| except the attribute type is determined by calling |OBJ_txt2obj| with |attrname|.
X509_REQ_add_extensions(Pointer<X509_REQ> req, Pointer<X509_EXTENSIONS> exts) → int
X509_REQ_add_extensions behaves like |X509_REQ_add_extensions_nid|, using the standard |NID_ext_req| for the attribute type.
X509_REQ_add_extensions_nid(Pointer<X509_REQ> req, Pointer<X509_EXTENSIONS> exts, int nid) → int
X509_REQ_add_extensions_nid adds an attribute to |req| of type |nid|, to request the certificate extensions in |exts|. It returns one on success and zero on error. |nid| should be |NID_ext_req| or |NID_ms_ext_req|.
X509_REQ_check_private_key(Pointer<X509_REQ> req, Pointer<EVP_PKEY> pkey) → int
X509_REQ_check_private_key returns one if |req|'s public key matches |pkey| and zero otherwise.
X509_REQ_delete_attr(Pointer<X509_REQ> req, int loc) → Pointer<X509_ATTRIBUTE>
X509_REQ_delete_attr removes the attribute at index |loc| in |req|. It returns the removed attribute to the caller, or NULL if |loc| was out of bounds. If non-NULL, the caller must release the result with |X509_ATTRIBUTE_free| when done. It is also safe, but not necessary, to call |X509_ATTRIBUTE_free| if the result is NULL.
X509_REQ_digest(Pointer<X509_REQ> req, Pointer<EVP_MD> md, Pointer<Uint8> out, Pointer<UnsignedInt> out_len) → int
X509_REQ_digest hashes |req|'s DER encoding with |md| and writes the result to |out|. |EVP_MD_CTX_size| bytes are written, which is at most |EVP_MAX_MD_SIZE|. If |out_len| is not NULL, |*out_len| is set to the number of bytes written. This function returns one on success and zero on error. Note this digest covers the entire certificate request, not just the signed portion.
X509_REQ_dup(Pointer<X509_REQ> req) → Pointer<X509_REQ>
X509_REQ_dup returns a newly-allocated copy of |req|, or NULL on error. This function works by serializing the structure, so if |req| is incomplete, it may fail.
X509_REQ_extension_nid(int nid) → int
X509_REQ_extension_nid returns one if |nid| is a supported CSR attribute type for carrying extensions and zero otherwise. The supported types are |NID_ext_req| (pkcs-9-at-extensionRequest from RFC 2985) and |NID_ms_ext_req| (a Microsoft szOID_CERT_EXTENSIONS variant).
X509_REQ_free(Pointer<X509_REQ> req) → void
X509_REQ_free releases memory associated with |req|.
X509_REQ_get0_pubkey(Pointer<X509_REQ> req) → Pointer<EVP_PKEY>
X509_REQ_get0_pubkey returns |req|'s public key as an |EVP_PKEY|, or NULL if the public key was unsupported or could not be decoded. The |EVP_PKEY| is cached in |req|, so callers must not mutate the result.
X509_REQ_get0_signature(Pointer<X509_REQ> req, Pointer<Pointer<ASN1_OCTET_STRING>> out_sig, Pointer<Pointer<X509_ALGOR>> out_alg) → void
X509_REQ_get0_signature sets |*out_sig| and |*out_alg| to the signature and signature algorithm of |req|, respectively. Either output pointer may be NULL to ignore the value.
X509_REQ_get1_email(Pointer<X509_REQ> req) → Pointer<stack_st_OPENSSL_STRING>
X509_REQ_get1_email returns a newly-allocated list of NUL-terminated strings containing all email addresses in |req|'s subject and all rfc822name names in |req|'s subject alternative names. The subject alternative names extension is extracted from the result of |X509_REQ_get_extensions|. Email addresses which contain embedded NUL bytes are skipped. The results are returned in an arbitrary order.
X509_REQ_get_attr(Pointer<X509_REQ> req, int loc) → Pointer<X509_ATTRIBUTE>
X509_REQ_get_attr returns the attribute at index |loc| in |req|, or NULL if out of bounds.
X509_REQ_get_attr_by_NID(Pointer<X509_REQ> req, int nid, int lastpos) → int
X509_REQ_get_attr_by_NID returns the index of the attribute in |req| of type |nid|, or a negative number if not found. If found, callers can use |X509_REQ_get_attr| to look up the attribute by index.
X509_REQ_get_attr_by_OBJ(Pointer<X509_REQ> req, Pointer<ASN1_OBJECT> obj, int lastpos) → int
X509_REQ_get_attr_by_OBJ behaves like |X509_REQ_get_attr_by_NID| but looks for attributes of type |obj|.
X509_REQ_get_attr_count(Pointer<X509_REQ> req) → int
X509_REQ_get_attr_count returns the number of attributes in |req|.
X509_REQ_get_extensions(Pointer<X509_REQ> req) → Pointer<X509_EXTENSIONS>
X509_REQ_get_extensions decodes the most preferred list of requested extensions in |req| and returns a newly-allocated |STACK_OF(X509_EXTENSION)| containing the result. It returns NULL on error, or if |req| did not request extensions.
X509_REQ_get_pubkey(Pointer<X509_REQ> req) → Pointer<EVP_PKEY>
X509_REQ_get_pubkey behaves like |X509_REQ_get0_pubkey| but increments the reference count on the |EVP_PKEY|. The caller must release the result with |EVP_PKEY_free| when done. The |EVP_PKEY| is cached in |req|, so callers must not mutate the result.
X509_REQ_get_signature_nid(Pointer<X509_REQ> req) → int
X509_REQ_get_signature_nid returns the NID corresponding to |req|'s signature algorithm, or |NID_undef| if the signature algorithm does not correspond to a known NID.
X509_REQ_get_subject_name(Pointer<X509_REQ> req) → Pointer<X509_NAME>
X509_REQ_get_subject_name returns |req|'s subject name. Note this function is not const-correct for legacy reasons.
X509_REQ_get_version(Pointer<X509_REQ> req) → int
X509_REQ_get_version returns the numerical value of |req|'s version. This will always be |X509_REQ_VERSION_1| for valid CSRs. For compatibility, |d2i_X509_REQ| also accepts some invalid version numbers, in which case this function may return other values.
X509_REQ_new() → Pointer<X509_REQ>
X509_REQ_new returns a newly-allocated, empty |X509_REQ| object, or NULL on error. This object may be filled in and then signed to construct a CSR.
X509_REQ_print(Pointer<BIO> bp, Pointer<X509_REQ> req) → int
X509_REQ_print calls |X509_REQ_print_ex| with |XN_FLAG_COMPAT| and |X509_FLAG_COMPAT| flags.
X509_REQ_print_ex(Pointer<BIO> bp, Pointer<X509_REQ> x, int nmflag, int cflag) → int
X509_REQ_print_ex writes a human-readable representation of |x| to |bp|. It returns one on success and zero on error. |nmflags| is the flags parameter for |X509_NAME_print_ex|, when printing the subject. |cflag| should be some combination of the |X509_FLAG_| and |X509V3_EXT_| constants.
X509_REQ_print_fp(Pointer<FILE> fp, Pointer<X509_REQ> req) → int
X509_REQ_print_fp behaves like |X509_REQ_print| but writes to |fp|.
X509_REQ_set1_signature_algo(Pointer<X509_REQ> req, Pointer<X509_ALGOR> algo) → int
X509_REQ_set1_signature_algo sets |req|'s signature algorithm to |algo| and returns one on success or zero on error.
X509_REQ_set1_signature_value(Pointer<X509_REQ> req, Pointer<Uint8> sig, int sig_len) → int
X509_REQ_set1_signature_value sets |req|'s signature to a copy of the |sig_len| bytes pointed by |sig|. It returns one on success and zero on error.
X509_REQ_set_pubkey(Pointer<X509_REQ> req, Pointer<EVP_PKEY> pkey) → int
X509_REQ_set_pubkey sets |req|'s public key to |pkey|. It returns one on success and zero on error. This function does not take ownership of |pkey| and internally copies and updates reference counts as needed.
X509_REQ_set_subject_name(Pointer<X509_REQ> req, Pointer<X509_NAME> name) → int
X509_REQ_set_subject_name sets |req|'s subject to a copy of |name|. It returns one on success and zero on error.
X509_REQ_set_version(Pointer<X509_REQ> req, int version) → int
X509_REQ_set_version sets |req|'s version to |version|, which should be |X509_REQ_VERSION_1|. It returns one on success and zero on error.
X509_REQ_sign(Pointer<X509_REQ> req, Pointer<EVP_PKEY> pkey, Pointer<EVP_MD> md) → int
X509_REQ_sign signs |req| with |pkey| and replaces the signature algorithm and signature fields. It returns the length of the signature on success and zero on error. This function uses digest algorithm |md|, or |pkey|'s default if NULL. Other signing parameters use |pkey|'s defaults. To customize them, use |X509_REQ_sign_ctx|.
X509_REQ_sign_ctx(Pointer<X509_REQ> req, Pointer<EVP_MD_CTX> ctx) → int
X509_REQ_sign_ctx signs |req| with |ctx| and replaces the signature algorithm and signature fields. It returns the length of the signature on success and zero on error. The signature algorithm and parameters come from |ctx|, which must have been initialized with |EVP_DigestSignInit|. The caller should configure the corresponding |EVP_PKEY_CTX| before calling this function.
X509_REQ_verify(Pointer<X509_REQ> req, Pointer<EVP_PKEY> pkey) → int
X509_REQ_verify checks that |req| has a valid signature by |pkey|. It returns one if the signature is valid and zero otherwise.
X509_REVOKED_add1_ext_i2d(Pointer<X509_REVOKED> x, int nid, Pointer<Void> value, int crit, int flags) → int
X509_REVOKED_add1_ext_i2d behaves like |X509V3_add1_i2d| but adds the extension to |x|'s extension list.
X509_REVOKED_add_ext(Pointer<X509_REVOKED> x, Pointer<X509_EXTENSION> ex, int loc) → int
X509_REVOKED_add_ext adds a copy of |ex| to |x|. It returns one on success and zero on failure. The caller retains ownership of |ex| and can release it independently of |x|.
X509_REVOKED_delete_ext(Pointer<X509_REVOKED> x, int loc) → Pointer<X509_EXTENSION>
X509_REVOKED_delete_ext removes the extension in |x| at index |loc| and returns the removed extension, or NULL if |loc| was out of bounds. If non-NULL, the caller must release the result with |X509_EXTENSION_free|.
X509_REVOKED_dup(Pointer<X509_REVOKED> rev) → Pointer<X509_REVOKED>
X509_REVOKED_dup returns a newly-allocated copy of |rev|, or NULL on error. This function works by serializing the structure, so if |rev| is incomplete, it may fail.
X509_REVOKED_free(Pointer<X509_REVOKED> rev) → void
X509_REVOKED_free releases memory associated with |rev|.
X509_REVOKED_get0_extensions(Pointer<X509_REVOKED> r) → Pointer<X509_EXTENSIONS>
X509_REVOKED_get0_extensions returns |r|'s extensions list, or NULL if |r| omits it. A CRL can have extensions on individual entries, which is this function, or on the overall CRL, which is |X509_CRL_get0_extensions|.
X509_REVOKED_get0_revocationDate(Pointer<X509_REVOKED> revoked) → Pointer<ASN1_OCTET_STRING>
X509_REVOKED_get0_revocationDate returns the revocation time of the certificate revoked by |revoked|.
X509_REVOKED_get0_serialNumber(Pointer<X509_REVOKED> revoked) → Pointer<ASN1_OCTET_STRING>
X509_REVOKED_get0_serialNumber returns the serial number of the certificate revoked by |revoked|.
X509_REVOKED_get_ext(Pointer<X509_REVOKED> x, int loc) → Pointer<X509_EXTENSION>
X509_REVOKED_get_ext returns the extension in |x| at index |loc|, or NULL if |loc| is out of bounds. This function returns a non-const pointer for OpenSSL compatibility, but callers should not mutate the result.
X509_REVOKED_get_ext_by_critical(Pointer<X509_REVOKED> x, int crit, int lastpos) → int
X509_REVOKED_get_ext_by_critical behaves like |X509v3_get_ext_by_critical| but searches for extensions in |x|.
X509_REVOKED_get_ext_by_NID(Pointer<X509_REVOKED> x, int nid, int lastpos) → int
X509_REVOKED_get_ext_by_NID behaves like |X509v3_get_ext_by_NID| but searches for extensions in |x|.
X509_REVOKED_get_ext_by_OBJ(Pointer<X509_REVOKED> x, Pointer<ASN1_OBJECT> obj, int lastpos) → int
X509_REVOKED_get_ext_by_OBJ behaves like |X509v3_get_ext_by_OBJ| but searches for extensions in |x|.
X509_REVOKED_get_ext_count(Pointer<X509_REVOKED> x) → int
X509_REVOKED_get_ext_count returns the number of extensions in |x|.
X509_REVOKED_get_ext_d2i(Pointer<X509_REVOKED> revoked, int nid, Pointer<Int> out_critical, Pointer<Int> out_idx) → Pointer<Void>
X509_REVOKED_get_ext_d2i behaves like |X509V3_get_d2i| but looks for the extension in |revoked|'s extension list.
X509_REVOKED_new() → Pointer<X509_REVOKED>
X509_REVOKED_new returns a newly-allocated, empty |X509_REVOKED| object, or NULL on allocation error.
X509_REVOKED_set_revocationDate(Pointer<X509_REVOKED> revoked, Pointer<ASN1_OCTET_STRING> tm$1) → int
X509_REVOKED_set_revocationDate sets |revoked|'s revocation time to |tm|. It returns one on success or zero on error.
X509_REVOKED_set_serialNumber(Pointer<X509_REVOKED> revoked, Pointer<ASN1_OCTET_STRING> serial) → int
X509_REVOKED_set_serialNumber sets |revoked|'s serial number to |serial|. It returns one on success or zero on error.
X509_set1_notAfter(Pointer<X509> x509, Pointer<ASN1_OCTET_STRING> tm$1) → int
X509_set1_notAfter sets |x509|'s notAfter time to |tm|. it returns one on success and zero on error.
X509_set1_notBefore(Pointer<X509> x509, Pointer<ASN1_OCTET_STRING> tm$1) → int
X509_set1_notBefore sets |x509|'s notBefore time to |tm|. It returns one on success and zero on error.
X509_set1_signature_algo(Pointer<X509> x509, Pointer<X509_ALGOR> algo) → int
X509_set1_signature_algo sets |x509|'s signature algorithm to |algo| and returns one on success or zero on error. It updates both the signature field of the TBSCertificate structure, and the signatureAlgorithm field of the Certificate.
X509_set1_signature_value(Pointer<X509> x509, Pointer<Uint8> sig, int sig_len) → int
X509_set1_signature_value sets |x509|'s signature to a copy of the |sig_len| bytes pointed by |sig|. It returns one on success and zero on error.
X509_set_ex_data(Pointer<X509> r, int idx, Pointer<Void> arg) → int
X509_set_issuer_name(Pointer<X509> x509, Pointer<X509_NAME> name) → int
X509_set_issuer_name sets |x509|'s issuer to a copy of |name|. It returns one on success and zero on error.
X509_set_notAfter(Pointer<X509> x509, Pointer<ASN1_OCTET_STRING> tm$1) → int
X509_set_notAfter calls |X509_set1_notAfter|. Use |X509_set1_notAfter| instead.
X509_set_notBefore(Pointer<X509> x509, Pointer<ASN1_OCTET_STRING> tm$1) → int
X509_set_notBefore calls |X509_set1_notBefore|. Use |X509_set1_notBefore| instead.
X509_set_pubkey(Pointer<X509> x509, Pointer<EVP_PKEY> pkey) → int
X509_set_pubkey sets |x509|'s public key to |pkey|. It returns one on success and zero on error. This function does not take ownership of |pkey| and internally copies and updates reference counts as needed.
X509_set_serialNumber(Pointer<X509> x509, Pointer<ASN1_OCTET_STRING> serial) → int
X509_set_serialNumber sets |x509|'s serial number to |serial|. It returns one on success and zero on error.
X509_set_subject_name(Pointer<X509> x509, Pointer<X509_NAME> name) → int
X509_set_subject_name sets |x509|'s subject to a copy of |name|. It returns one on success and zero on error.
X509_set_version(Pointer<X509> x509, int version) → int
X509_set_version sets |x509|'s version to |version|, which should be one of the |X509V_VERSION_*| constants. It returns one on success and zero on error.
X509_SIG_free(Pointer<X509_SIG> key) → void
X509_SIG_free releases memory associated with |key|.
X509_SIG_get0(Pointer<X509_SIG> sig, Pointer<Pointer<X509_ALGOR>> out_alg, Pointer<Pointer<ASN1_OCTET_STRING>> out_digest) → void
X509_SIG_get0 sets |*out_alg| and |*out_digest| to non-owning pointers to |sig|'s algorithm and digest fields, respectively. Either |out_alg| and |out_digest| may be NULL to skip those fields.
X509_SIG_getm(Pointer<X509_SIG> sig, Pointer<Pointer<X509_ALGOR>> out_alg, Pointer<Pointer<ASN1_OCTET_STRING>> out_digest) → void
X509_SIG_getm behaves like |X509_SIG_get0| but returns mutable pointers.
X509_SIG_new() → Pointer<X509_SIG>
X509_SIG_new returns a newly-allocated, empty |X509_SIG| object, or NULL on error.
X509_sign(Pointer<X509> x509, Pointer<EVP_PKEY> pkey, Pointer<EVP_MD> md) → int
X509_sign signs |x509| with |pkey| and replaces the signature algorithm and signature fields. It returns the length of the signature on success and zero on error. This function uses digest algorithm |md|, or |pkey|'s default if NULL. Other signing parameters use |pkey|'s defaults. To customize them, use |X509_sign_ctx|.
X509_sign_ctx(Pointer<X509> x509, Pointer<EVP_MD_CTX> ctx) → int
X509_sign_ctx signs |x509| with |ctx| and replaces the signature algorithm and signature fields. It returns the length of the signature on success and zero on error. The signature algorithm and parameters come from |ctx|, which must have been initialized with |EVP_DigestSignInit|. The caller should configure the corresponding |EVP_PKEY_CTX| before calling this function.
X509_signature_dump(Pointer<BIO> bio, Pointer<ASN1_OCTET_STRING> sig, int indent) → int
X509_signature_dump writes a human-readable representation of |sig| to |bio|, indented with |indent| spaces. It returns one on success and zero on error.
X509_signature_print(Pointer<BIO> bio, Pointer<X509_ALGOR> alg, Pointer<ASN1_OCTET_STRING> sig) → int
X509_signature_print writes a human-readable representation of |alg| and |sig| to |bio|. It returns one on success and zero on error.
X509_STORE_add_cert(Pointer<X509_STORE> store, Pointer<X509> x509) → int
X509_STORE_add_cert adds |x509| to |store| as a trusted certificate. It returns one on success and zero on error. This function internally increments |x509|'s reference count, so the caller retains ownership of |x509|.
X509_STORE_add_crl(Pointer<X509_STORE> store, Pointer<X509_CRL> crl) → int
X509_STORE_add_crl adds |crl| to |store|. It returns one on success and zero on error. This function internally increments |crl|'s reference count, so the caller retains ownership of |crl|. CRLs added in this way are candidates for CRL lookup when |X509_V_FLAG_CRL_CHECK| is set.
X509_STORE_add_lookup(Pointer<X509_STORE> store, Pointer<X509_LOOKUP_METHOD> method) → Pointer<X509_LOOKUP>
X509_STORE_add_lookup returns an |X509_LOOKUP| associated with |store| with type |method|, or NULL on error. The result is owned by |store|, so callers are not expected to free it. This may be used with |X509_LOOKUP_add_dir| or |X509_LOOKUP_load_file|, depending on |method|, to configure |store|.
X509_STORE_CTX_cleanup(Pointer<X509_STORE_CTX> ctx) → void
X509_STORE_CTX_cleanup resets |ctx| to the empty state.
X509_STORE_CTX_free(Pointer<X509_STORE_CTX> ctx) → void
X509_STORE_CTX_free releases memory associated with |ctx|.
X509_STORE_CTX_get0_cert(Pointer<X509_STORE_CTX> ctx) → Pointer<X509>
X509_STORE_CTX_get0_cert returns the leaf certificate that |ctx| is verifying.
X509_STORE_CTX_get0_chain(Pointer<X509_STORE_CTX> ctx) → Pointer<stack_st_X509>
X509_STORE_CTX_get0_chain, after a successful |X509_verify_cert| call, returns the verified certificate chain. The chain begins with the leaf and ends with trust anchor.
X509_STORE_CTX_get0_current_crl(Pointer<X509_STORE_CTX> ctx) → Pointer<X509_CRL>
X509_STORE_CTX_get0_current_crl returns the CRL which caused the error returned by |X509_STORE_CTX_get_error|.
X509_STORE_CTX_get0_param(Pointer<X509_STORE_CTX> ctx) → Pointer<X509_VERIFY_PARAM>
X509_STORE_CTX_get0_param returns |ctx|'s verification parameters. This object is mutable and may be modified by the caller.
X509_STORE_CTX_get0_parent_ctx(Pointer<X509_STORE_CTX> ctx) → Pointer<X509_STORE_CTX>
X509_STORE_CTX_get0_parent_ctx returns NULL.
X509_STORE_CTX_get0_store(Pointer<X509_STORE_CTX> ctx) → Pointer<X509_STORE>
X509_STORE_CTX_get0_store returns the |X509_STORE| that |ctx| uses.
X509_STORE_CTX_get0_untrusted(Pointer<X509_STORE_CTX> ctx) → Pointer<stack_st_X509>
X509_STORE_CTX_get0_untrusted returns the stack of untrusted intermediates used by |ctx| for certificate verification.
X509_STORE_CTX_get1_certs(Pointer<X509_STORE_CTX> ctx, Pointer<X509_NAME> name) → Pointer<stack_st_X509>
X509_STORE_CTX_get1_certs returns a newly-allocated stack containing all trusted certificates in |ctx|'s |X509_STORE| whose subject matches |name|, or NULL on error. The caller must release the result with |sk_X509_pop_free| and |X509_free| when done.
X509_STORE_CTX_get1_chain(Pointer<X509_STORE_CTX> ctx) → Pointer<stack_st_X509>
X509_STORE_CTX_get1_chain behaves like |X509_STORE_CTX_get0_chain| but returns a newly-allocated |STACK_OF(X509)| containing the completed chain, with each certificate's reference count incremented. Callers must free the result with |sk_X509_pop_free| and |X509_free| when done.
X509_STORE_CTX_get1_crls(Pointer<X509_STORE_CTX> ctx, Pointer<X509_NAME> name) → Pointer<stack_st_X509_CRL>
X509_STORE_CTX_get1_crls returns a newly-allocated stack containing all CRLs in |ctx|'s |X509_STORE| whose subject matches |name|, or NULL on error. The caller must release the result with |sk_X509_CRL_pop_free| and |X509_CRL_free| when done.
X509_STORE_CTX_get1_issuer(Pointer<Pointer<X509>> out_issuer, Pointer<X509_STORE_CTX> ctx, Pointer<X509> x509) → int
X509_STORE_CTX_get1_issuer looks up a candidate trusted issuer for |x509| out of |ctx|'s |X509_STORE|, based on the criteria in |X509_check_issued|. If one was found, it returns one and sets |*out_issuer| to the issuer. The caller must release |*out_issuer| with |X509_free| when done. If none was found, it returns zero and leaves |*out_issuer| unchanged.
X509_STORE_CTX_get_by_subject(Pointer<X509_STORE_CTX> ctx, int type, Pointer<X509_NAME> name, Pointer<X509_OBJECT> ret) → int
X509_STORE_CTX_get_by_subject looks up an object of type |type| in |ctx|'s |X509_STORE| that matches |name|. |type| should be one of the |X509_LU_*| constants to indicate the type of object. If a match was found, it stores the result in |ret| and returns one. Otherwise, it returns zero. If multiple objects match, this function outputs an arbitrary one.
X509_STORE_CTX_get_chain(Pointer<X509_STORE_CTX> ctx) → Pointer<stack_st_X509>
X509_STORE_CTX_get_chain is a legacy alias for |X509_STORE_CTX_get0_chain|.
X509_STORE_CTX_get_current_cert(Pointer<X509_STORE_CTX> ctx) → Pointer<X509>
X509_STORE_CTX_get_current_cert returns the certificate which caused the error returned by |X509_STORE_CTX_get_error|.
X509_STORE_CTX_get_error(Pointer<X509_STORE_CTX> ctx) → int
X509_STORE_CTX_get_error, after |X509_verify_cert| returns, returns |X509_V_OK| if verification succeeded or an |X509_V_ERR_*| describing why verification failed. This will be consistent with |X509_verify_cert|'s return value, unless the caller used the deprecated verification callback (see |X509_STORE_CTX_set_verify_cb|) in a way that breaks |ctx|'s invariants.
X509_STORE_CTX_get_error_depth(Pointer<X509_STORE_CTX> ctx) → int
X509_STORE_CTX_get_error_depth returns the depth at which the error returned by |X509_STORE_CTX_get_error| occurred. This is zero-indexed integer into the certificate chain. Zero indicates the target certificate, one its issuer, and so on.
X509_STORE_CTX_get_ex_data(Pointer<X509_STORE_CTX> ctx, int idx) → Pointer<Void>
X509_STORE_CTX_get_ex_new_index(int argl, Pointer<Void> argp, Pointer<Int> unused, Pointer<CRYPTO_EX_dup> dup_unused, Pointer<CRYPTO_EX_free> free_func) → int
X509_STORE_CTX_init(Pointer<X509_STORE_CTX> ctx, Pointer<X509_STORE> store, Pointer<X509> x509, Pointer<stack_st_X509> chain) → int
X509_STORE_CTX_init initializes |ctx| to verify |x509|, using trusted certificates and parameters in |store|. It returns one on success and zero on error. |chain| is a list of untrusted intermediate certificates to use in verification.
X509_STORE_CTX_new() → Pointer<X509_STORE_CTX>
X509_STORE_CTX_new returns a newly-allocated, empty |X509_STORE_CTX|, or NULL on error.
X509_STORE_CTX_set0_crls(Pointer<X509_STORE_CTX> ctx, Pointer<stack_st_X509_CRL> sk) → void
X509_STORE_CTX_set0_crls configures |ctx| to consider the CRLs in |sk| as candidates for CRL lookup. |sk| must remain valid for the duration of |ctx|. These CRLs are considered in addition to CRLs found in |X509_STORE|.
X509_STORE_CTX_set0_param(Pointer<X509_STORE_CTX> ctx, Pointer<X509_VERIFY_PARAM> param) → void
X509_STORE_CTX_set0_param returns |ctx|'s verification parameters to |param| and takes ownership of |param|. After this function returns, the caller should not free |param|.
X509_STORE_CTX_set0_trusted_stack(Pointer<X509_STORE_CTX> ctx, Pointer<stack_st_X509> sk) → void
X509_STORE_CTX_set0_trusted_stack configures |ctx| to trust the certificates in |sk|. |sk| must remain valid for the duration of |ctx|. Calling this function causes |ctx| to ignore any certificates configured in the |X509_STORE|. Certificates in |sk| are still subject to the check described in |X509_VERIFY_PARAM_set_trust|.
X509_STORE_CTX_set_chain(Pointer<X509_STORE_CTX> ctx, Pointer<stack_st_X509> sk) → void
X509_STORE_CTX_set_chain configures |ctx| to use |sk| for untrusted intermediate certificates to use in verification. This function is redundant with the |chain| parameter of |X509_STORE_CTX_init|. Use the parameter instead.
X509_STORE_CTX_set_default(Pointer<X509_STORE_CTX> ctx, Pointer<Char> name) → int
X509_STORE_CTX_set_default looks up the set of parameters named |name| and applies those default verification parameters for |ctx|. As in |X509_VERIFY_PARAM_inherit|, only unset parameters are changed. This function returns one on success and zero on error.
X509_STORE_CTX_set_depth(Pointer<X509_STORE_CTX> ctx, int depth) → void
X509_STORE_CTX_set_depth configures |ctx| to, by default, limit certificate chains to |depth| intermediate certificates. This count excludes both the target certificate and the trust anchor (root certificate).
X509_STORE_CTX_set_error(Pointer<X509_STORE_CTX> ctx, int err) → void
X509_STORE_CTX_set_error sets |ctx|'s error to |err|, which should be |X509_V_OK| or an |X509_V_ERR_*| constant. It is not expected to be called in typical |X509_STORE_CTX| usage, but may be used in callback APIs where applications synthesize |X509_STORE_CTX| error conditions. See also |X509_STORE_CTX_set_verify_cb| and |SSL_CTX_set_cert_verify_callback|.
X509_STORE_CTX_set_ex_data(Pointer<X509_STORE_CTX> ctx, int idx, Pointer<Void> data) → int
X509_STORE_CTX_set_flags(Pointer<X509_STORE_CTX> ctx, int flags) → void
X509_STORE_CTX_set_flags enables all values in |flags| in |ctx|'s verification flags. |flags| should be a combination of |X509_V_FLAG_*| constants.
X509_STORE_CTX_set_purpose(Pointer<X509_STORE_CTX> ctx, int purpose) → int
X509_STORE_CTX_set_purpose simultaneously configures |ctx|'s purpose and trust checks, if unset. It returns one on success and zero if |purpose| is not a valid purpose value. |purpose| should be an |X509_PURPOSE_*| constant. If so, it configures |ctx| with a purpose check of |purpose| and a trust check of |purpose|'s corresponding trust value. If either the purpose or trust check had already been specified for |ctx|, that corresponding modification is silently dropped.
X509_STORE_CTX_set_time(Pointer<X509_STORE_CTX> ctx, int flags, int t) → void
X509_STORE_CTX_set_time configures certificate verification to use |t| instead of the current time. |flags| is ignored and should be zero.
X509_STORE_CTX_set_time_posix(Pointer<X509_STORE_CTX> ctx, int flags, int t) → void
X509_STORE_CTX_set_time_posix configures certificate verification to use |t| instead of the current time. |t| is interpreted as a POSIX timestamp in seconds. |flags| is ignored and should be zero.
X509_STORE_CTX_set_trust(Pointer<X509_STORE_CTX> ctx, int trust) → int
X509_STORE_CTX_set_trust configures |ctx|'s trust check, if unset. It returns one on success and zero if |trust| is not a valid trust value. |trust| should be an |X509_TRUST_*| constant. If so, it configures |ctx| with a trust check of |trust|. If the trust check had already been specified for |ctx|, it silently does nothing.
X509_STORE_CTX_set_verify_cb(Pointer<X509_STORE_CTX> ctx, Pointer<NativeFunction<Int Function(Int ok, Pointer<X509_STORE_CTX> ctx)>> verify_cb) → void
X509_STORE_CTX_set_verify_cb configures a callback function for |ctx| that is called multiple times during |X509_verify_cert|. The callback returns zero to fail verification and one to proceed. Typically, it will return |ok|, which preserves the default behavior. Returning one when |ok| is zero will proceed past some error. The callback may inspect |ctx| and the error queue to attempt to determine the current stage of certificate verification, but this is often unreliable. When synthesizing an error, callbacks should use |X509_STORE_CTX_set_error| to set a corresponding error.
X509_STORE_CTX_trusted_stack(Pointer<X509_STORE_CTX> ctx, Pointer<stack_st_X509> sk) → void
X509_STORE_CTX_trusted_stack is a deprecated alias for |X509_STORE_CTX_set0_trusted_stack|.
X509_STORE_free(Pointer<X509_STORE> store) → void
X509_STORE_free releases memory associated with |store|.
X509_STORE_get0_objects(Pointer<X509_STORE> store) → Pointer<stack_st_X509_OBJECT>
X509_STORE_get0_objects returns a non-owning pointer of |store|'s internal object list. Although this function is not const, callers must not modify the result of this function.
X509_STORE_get0_param(Pointer<X509_STORE> store) → Pointer<X509_VERIFY_PARAM>
X509_STORE_get0_param returns |store|'s verification parameters. This object is mutable and may be modified by the caller. For an individual certificate verification operation, |X509_STORE_CTX_init| initializes the |X509_STORE_CTX|'s parameters with these parameters.
X509_STORE_get1_objects(Pointer<X509_STORE> store) → Pointer<stack_st_X509_OBJECT>
X509_STORE_get1_objects returns a newly-allocated stack containing the contents of |store|, or NULL on error. The caller must release the result with |sk_X509_OBJECT_pop_free| and |X509_OBJECT_free| when done.
X509_STORE_load_locations(Pointer<X509_STORE> store, Pointer<Char> file, Pointer<Char> dir) → int
X509_STORE_load_locations configures |store| to load data from filepaths |file| and |dir|. It returns one on success and zero on error. Either of |file| or |dir| may be NULL, but at least one must be non-NULL.
X509_STORE_new() → Pointer<X509_STORE>
X509_STORE_new returns a newly-allocated |X509_STORE|, or NULL on error.
X509_STORE_set1_param(Pointer<X509_STORE> store, Pointer<X509_VERIFY_PARAM> param) → int
X509_STORE_set1_param copies verification parameters from |param| as in |X509_VERIFY_PARAM_set1|. It returns one on success and zero on error.
X509_STORE_set_default_paths(Pointer<X509_STORE> store) → int
X509_STORE_set_default_paths configures |store| to read from some "default" filesystem paths. It returns one on success and zero on error. The filesystem paths are determined by a combination of hardcoded paths and the SSL_CERT_DIR and SSL_CERT_FILE environment variables.
X509_STORE_set_depth(Pointer<X509_STORE> store, int depth) → int
X509_STORE_set_depth configures |store| to, by default, limit certificate chains to |depth| intermediate certificates. This count excludes both the target certificate and the trust anchor (root certificate).
X509_STORE_set_flags(Pointer<X509_STORE> store, int flags) → int
X509_STORE_set_flags enables all values in |flags| in |store|'s verification flags. |flags| should be a combination of |X509_V_FLAG_*| constants.
X509_STORE_set_purpose(Pointer<X509_STORE> store, int purpose) → int
X509_STORE_set_purpose configures the purpose check for |store|. See |X509_VERIFY_PARAM_set_purpose| for details.
X509_STORE_set_trust(Pointer<X509_STORE> store, int trust) → int
X509_STORE_set_trust configures the trust check for |store|. See |X509_VERIFY_PARAM_set_trust| for details.
X509_STORE_set_verify_cb(Pointer<X509_STORE> store, X509_STORE_CTX_verify_cb verify_cb) → void
X509_STORE_set_verify_cb acts like |X509_STORE_CTX_set_verify_cb| but sets the verify callback for any |X509_STORE_CTX| created from this |X509_STORE|
X509_STORE_up_ref(Pointer<X509_STORE> store) → int
X509_STORE_up_ref adds one to the reference count of |store| and returns one. Although |store| is not const, this function's use of |store| is thread-safe.
X509_subject_name_cmp(Pointer<X509> a, Pointer<X509> b) → int
X509_subject_name_cmp behaves like |X509_NAME_cmp|, but compares |a| and |b|'s subject names.
X509_subject_name_hash(Pointer<X509> x509) → int
X509_subject_name_hash returns the hash of |x509|'s subject name with |X509_NAME_hash|.
X509_subject_name_hash_old(Pointer<X509> x509) → int
X509_subject_name_hash_old returns the hash of |x509|'s usjbect name with |X509_NAME_hash_old|.
X509_supported_extension(Pointer<X509_EXTENSION> ex) → int
X509_supported_extension returns one if |ex| is a critical X.509 certificate extension, supported by |X509_verify_cert|, and zero otherwise.
X509_time_adj(Pointer<ASN1_OCTET_STRING> s, int offset_sec, Pointer<Long> t) → Pointer<ASN1_OCTET_STRING>
X509_time_adj calls |X509_time_adj_ex| with |offset_day| equal to zero.
X509_time_adj_ex(Pointer<ASN1_OCTET_STRING> s, int offset_day, int offset_sec, Pointer<Long> t) → Pointer<ASN1_OCTET_STRING>
X509_time_adj_ex behaves like |ASN1_TIME_adj|, but adds an offset to |*t|. If |t| is NULL, it uses the current time instead of |*t|.
X509_trust_clear(Pointer<X509> x509) → void
X509_trust_clear clears the list of OIDs for which |x509| is trusted. See also |X509_add1_trust_object|.
X509_up_ref(Pointer<X509> x509) → int
X509_up_ref adds one to the reference count of |x509| and returns one.
X509_verify(Pointer<X509> x509, Pointer<EVP_PKEY> pkey) → int
X509_verify checks that |x509| has a valid signature by |pkey|. It returns one if the signature is valid and zero otherwise. Note this function only checks the signature itself and does not perform a full certificate validation.
X509_verify_cert(Pointer<X509_STORE_CTX> ctx) → int
X509_verify_cert performs certificate verification with |ctx|, which must have been initialized with |X509_STORE_CTX_init|. It returns one on success and zero on error. On success, |X509_STORE_CTX_get0_chain| or |X509_STORE_CTX_get1_chain| may be used to return the verified certificate chain. On error, |X509_STORE_CTX_get_error| may be used to return additional error information.
X509_verify_cert_error_string(int err) → Pointer<Char>
X509_verify_cert_error_string returns |err| as a human-readable string, where |err| should be one of the |X509_V_*| values. If |err| is unknown, it returns a default description.
X509_VERIFY_PARAM_add0_policy(Pointer<X509_VERIFY_PARAM> param, Pointer<ASN1_OBJECT> policy) → int
X509_VERIFY_PARAM_add0_policy adds |policy| to the user-initial-policy-set (see Section 6.1.1 of RFC 5280). On success, it takes ownership of |policy| and returns one. Otherwise, it returns zero and the caller retains owneship of |policy|.
X509_VERIFY_PARAM_add1_host(Pointer<X509_VERIFY_PARAM> param, Pointer<Char> name, int name_len) → int
X509_VERIFY_PARAM_add1_host adds |name| to the list of names checked by |param|. If any configured DNS name matches the certificate, verification succeeds. It returns one on success and zero on error.
X509_VERIFY_PARAM_clear_flags(Pointer<X509_VERIFY_PARAM> param, int flags) → int
X509_VERIFY_PARAM_clear_flags disables all values in |flags| in |param|'s verification flags and returns one. |flags| should be a combination of |X509_V_FLAG_*| constants.
X509_VERIFY_PARAM_free(Pointer<X509_VERIFY_PARAM> param) → void
X509_VERIFY_PARAM_free releases memory associated with |param|.
X509_VERIFY_PARAM_get_depth(Pointer<X509_VERIFY_PARAM> param) → int
X509_VERIFY_PARAM_get_depth returns the maximum depth configured in |param|. See |X509_VERIFY_PARAM_set_depth|.
X509_VERIFY_PARAM_get_flags(Pointer<X509_VERIFY_PARAM> param) → int
X509_VERIFY_PARAM_get_flags returns |param|'s verification flags.
X509_VERIFY_PARAM_inherit(Pointer<X509_VERIFY_PARAM> to, Pointer<X509_VERIFY_PARAM> from) → int
X509_VERIFY_PARAM_inherit applies |from| as the default values for |to|. That is, for each parameter that is unset in |to|, it copies the value in |from|. This function returns one on success and zero on error.
X509_VERIFY_PARAM_new() → Pointer<X509_VERIFY_PARAM>
X509_VERIFY_PARAM_new returns a newly-allocated |X509_VERIFY_PARAM|, or NULL on error.
X509_VERIFY_PARAM_set1(Pointer<X509_VERIFY_PARAM> to, Pointer<X509_VERIFY_PARAM> from) → int
X509_VERIFY_PARAM_set1 copies parameters from |from| to |to|. If a parameter is unset in |from|, the existing value in |to| is preserved. This function returns one on success and zero on error.
X509_VERIFY_PARAM_set1_email(Pointer<X509_VERIFY_PARAM> param, Pointer<Char> email, int email_len) → int
X509_VERIFY_PARAM_set1_email configures |param| to check for the email address specified by |email|. It returns one on success and zero on error.
X509_VERIFY_PARAM_set1_host(Pointer<X509_VERIFY_PARAM> param, Pointer<Char> name, int name_len) → int
X509_VERIFY_PARAM_set1_host configures |param| to check for the DNS name specified by |name|. It returns one on success and zero on error.
X509_VERIFY_PARAM_set1_ip(Pointer<X509_VERIFY_PARAM> param, Pointer<Uint8> ip, int ip_len) → int
X509_VERIFY_PARAM_set1_ip configures |param| to check for the IP address specified by |ip|. It returns one on success and zero on error. The IP address is specified in its binary representation. |ip_len| must be 4 for an IPv4 address and 16 for an IPv6 address.
X509_VERIFY_PARAM_set1_ip_asc(Pointer<X509_VERIFY_PARAM> param, Pointer<Char> ipasc) → int
X509_VERIFY_PARAM_set1_ip_asc decodes |ipasc| as the ASCII representation of an IPv4 or IPv6 address, and configures |param| to check for it. It returns one on success and zero on error.
X509_VERIFY_PARAM_set1_policies(Pointer<X509_VERIFY_PARAM> param, Pointer<EXTENDED_KEY_USAGE> policies) → int
X509_VERIFY_PARAM_set1_policies sets the user-initial-policy-set (see Section 6.1.1 of RFC 5280) to a copy of |policies|. It returns one on success and zero on error.
X509_VERIFY_PARAM_set_depth(Pointer<X509_VERIFY_PARAM> param, int depth) → void
X509_VERIFY_PARAM_set_depth configures |param| to limit certificate chains to |depth| intermediate certificates. This count excludes both the target certificate and the trust anchor (root certificate).
X509_VERIFY_PARAM_set_flags(Pointer<X509_VERIFY_PARAM> param, int flags) → int
X509_VERIFY_PARAM_set_flags enables all values in |flags| in |param|'s verification flags and returns one. |flags| should be a combination of |X509_V_FLAG_*| constants.
X509_VERIFY_PARAM_set_hostflags(Pointer<X509_VERIFY_PARAM> param, int flags) → void
X509_VERIFY_PARAM_set_hostflags sets the name-checking flags on |param| to |flags|. |flags| should be a combination of |X509_CHECK_FLAG_*| constants.
X509_VERIFY_PARAM_set_purpose(Pointer<X509_VERIFY_PARAM> param, int purpose) → int
X509_VERIFY_PARAM_set_purpose configures |param| to validate certificates for a specified purpose. It returns one on success and zero if |purpose| is not a valid purpose type. |purpose| should be one of the |X509_PURPOSE_*| values.
X509_VERIFY_PARAM_set_time(Pointer<X509_VERIFY_PARAM> param, int t) → void
X509_VERIFY_PARAM_set_time configures certificate verification to use |t| instead of the current time.
X509_VERIFY_PARAM_set_time_posix(Pointer<X509_VERIFY_PARAM> param, int t) → void
X509_VERIFY_PARAM_set_time_posix configures certificate verification to use |t| instead of the current time. |t| is interpreted as a POSIX timestamp in seconds.
X509_VERIFY_PARAM_set_trust(Pointer<X509_VERIFY_PARAM> param, int trust) → int
X509_VERIFY_PARAM_set_trust configures which certificates from |X509_STORE| are trust anchors. It returns one on success and zero if |trust| is not a valid trust value. |trust| should be one of the |X509_TRUST_*| constants. This function allows applications to vary trust anchors when the same set of trusted certificates is used in multiple contexts.
X509V3_add1_i2d(Pointer<Pointer<X509_EXTENSIONS>> x, int nid, Pointer<Void> value, int crit, int flags) → int
X509V3_add1_i2d casts |value| to the type that corresponds to |nid|, serializes it, and appends it to the extension list in |*x|. If |*x| is NULL, it will set |x| to a newly-allocated |STACK_OF(X509_EXTENSION)| as needed. The |crit| parameter determines whether the new extension is critical. |flags| may be some combination of the |X509V3_ADD_| constants to control the function's behavior on duplicate extension.
X509v3_add_ext(Pointer<Pointer<X509_EXTENSIONS>> x, Pointer<X509_EXTENSION> ex, int loc) → Pointer<X509_EXTENSIONS>
X509v3_add_ext adds a copy of |ex| to the extension list in |*x|. If |*x| is NULL, it allocates a new |STACK_OF(X509_EXTENSION)| to hold the copy and sets |*x| to the new list. It returns |*x| on success and NULL on error. The caller retains ownership of |ex| and can release it independently of |*x|.
X509V3_add_standard_extensions() → int
X509V3_add_standard_extensions returns one.
X509V3_conf_free(Pointer<CONF_VALUE> val) → void
X509V3_conf_free releases memory associated with |CONF_VALUE|.
X509v3_delete_ext(Pointer<X509_EXTENSIONS> x, int loc) → Pointer<X509_EXTENSION>
X509v3_delete_ext removes the extension in |x| at index |loc| and returns the removed extension, or NULL if |loc| was out of bounds. If an extension was returned, the caller must release it with |X509_EXTENSION_free|.
X509V3_EXT_add(Pointer<X509V3_EXT_METHOD> ext) → int
X509V3_EXT_add registers |ext| as a custom extension for the extension type |ext->ext_nid|. |ext| must be valid for the remainder of the address space's lifetime. It returns one on success and zero on error.
X509V3_EXT_add_alias(int nid_to, int nid_from) → int
X509V3_EXT_add_alias registers a custom extension with NID |nid_to|. The corresponding ASN.1 type is copied from |nid_from|. It returns one on success and zero on error.
X509V3_EXT_add_nconf(Pointer<CONF> conf, Pointer<X509V3_CTX> ctx, Pointer<Char> section, Pointer<X509> cert) → int
X509V3_EXT_add_nconf adds extensions to |cert| as in |X509V3_EXT_add_nconf_sk|. It returns one on success and zero on error.
X509V3_EXT_add_nconf_sk(Pointer<CONF> conf, Pointer<X509V3_CTX> ctx, Pointer<Char> section, Pointer<Pointer<X509_EXTENSIONS>> sk) → int
X509V3_EXT_add_nconf_sk looks up the section named |section| in |conf|. For each |CONF_VALUE| in the section, it constructs an extension as in |X509V3_EXT_nconf|, taking |name| and |value| from the |CONF_VALUE|. Each new extension is appended to |*sk|. If |*sk| is non-NULL, and at least one extension is added, it sets |*sk| to a newly-allocated |STACK_OF(X509_EXTENSION)|. It returns one on success and zero on error.
X509V3_EXT_CRL_add_nconf(Pointer<CONF> conf, Pointer<X509V3_CTX> ctx, Pointer<Char> section, Pointer<X509_CRL> crl) → int
X509V3_EXT_CRL_add_nconf adds extensions to |crl| as in |X509V3_EXT_add_nconf_sk|. It returns one on success and zero on error.
X509V3_EXT_d2i(Pointer<X509_EXTENSION> ext) → Pointer<Void>
X509V3_EXT_d2i decodes |ext| and returns a pointer to a newly-allocated structure, with type dependent on the type of the extension. It returns NULL if |ext| is an unsupported extension or if there was a syntax error in the extension. The caller should cast the return value to the expected type and free the structure when done.
X509V3_EXT_free(int nid, Pointer<Void> ext_data) → int
X509V3_EXT_free casts |ext_data| into the type that corresponds to |nid| and releases memory associated with it. It returns one on success and zero if |nid| is not a known extension.
X509V3_EXT_get(Pointer<X509_EXTENSION> ext) → Pointer<X509V3_EXT_METHOD>
X509V3_EXT_get returns the |X509V3_EXT_METHOD| corresponding to |ext|'s extension type, or NULL if none was registered.
X509V3_EXT_get_nid(int nid) → Pointer<X509V3_EXT_METHOD>
X509V3_EXT_get_nid returns the |X509V3_EXT_METHOD| corresponding to |nid|, or NULL if none was registered.
X509V3_EXT_i2d(int ext_nid, int crit, Pointer<Void> ext_struc) → Pointer<X509_EXTENSION>
X509V3_EXT_i2d casts |ext_struc| into the type that corresponds to |ext_nid|, serializes it, and returns a newly-allocated |X509_EXTENSION| object containing the serialization, or NULL on error. The |X509_EXTENSION| has OID |ext_nid| and is critical if |crit| is one.
X509V3_EXT_nconf(Pointer<CONF> conf, Pointer<X509V3_CTX> ctx, Pointer<Char> name, Pointer<Char> value) → Pointer<X509_EXTENSION>
X509V3_EXT_nconf constructs an extension of type specified by |name|, and value specified by |value|. It returns a newly-allocated |X509_EXTENSION| object on success, or NULL on error. |conf| and |ctx| specify additional information referenced by some formats. Either |conf| or |ctx| may be NULL, in which case features which use it will be disabled.
X509V3_EXT_nconf_nid(Pointer<CONF> conf, Pointer<X509V3_CTX> ctx, int ext_nid, Pointer<Char> value) → Pointer<X509_EXTENSION>
X509V3_EXT_nconf_nid behaves like |X509V3_EXT_nconf|, except the extension type is specified as a NID.
X509V3_EXT_print(Pointer<BIO> out, Pointer<X509_EXTENSION> ext, int flag, int indent) → int
X509V3_EXT_print prints a human-readable representation of |ext| to out. It returns one on success and zero on error. The output is indented by |indent| spaces. |flag| is one of the |X509V3_EXT_*| constants and controls printing of unknown extensions and syntax errors.
X509V3_EXT_print_fp(Pointer<FILE> out, Pointer<X509_EXTENSION> ext, int flag, int indent) → int
X509V3_EXT_print_fp behaves like |X509V3_EXT_print| but writes to a |FILE| instead of a |BIO|.
X509V3_EXT_REQ_add_nconf(Pointer<CONF> conf, Pointer<X509V3_CTX> ctx, Pointer<Char> section, Pointer<X509_REQ> req) → int
X509V3_EXT_REQ_add_nconf adds extensions to |req| as in |X509V3_EXT_add_nconf_sk|. It returns one on success and zero on error.
X509V3_extensions_print(Pointer<BIO> out, Pointer<Char> title, Pointer<X509_EXTENSIONS> exts, int flag, int indent) → int
X509V3_extensions_print prints |title|, followed by a human-readable representation of |exts| to |out|. It returns one on success and zero on error. The output is indented by |indent| spaces. |flag| is one of the |X509V3_EXT_*| constants and controls printing of unknown extensions and syntax errors.
X509V3_get_d2i(Pointer<X509_EXTENSIONS> extensions, int nid, Pointer<Int> out_critical, Pointer<Int> out_idx) → Pointer<Void>
X509V3_get_d2i finds and decodes the extension in |extensions| of type |nid|. If found, it decodes it and returns a newly-allocated structure, with type dependent on |nid|. If the extension is not found or on error, it returns NULL. The caller may distinguish these cases using the |out_critical| value.
X509v3_get_ext(Pointer<X509_EXTENSIONS> x, int loc) → Pointer<X509_EXTENSION>
X509v3_get_ext returns the extension in |x| at index |loc|, or NULL if |loc| is out of bounds. This function returns a non-const pointer for OpenSSL compatibility, but callers should not mutate the result.
X509v3_get_ext_by_critical(Pointer<X509_EXTENSIONS> x, int crit, int lastpos) → int
X509v3_get_ext_by_critical returns the index of the first extension in |x| whose critical bit matches |crit|, or a negative number if no such extension was found.
X509v3_get_ext_by_NID(Pointer<X509_EXTENSIONS> x, int nid, int lastpos) → int
X509v3_get_ext_by_NID returns the index of the first extension in |x| with type |nid|, or a negative number if not found. If found, callers can use |X509v3_get_ext| to look up the extension by index.
X509v3_get_ext_by_OBJ(Pointer<X509_EXTENSIONS> x, Pointer<ASN1_OBJECT> obj, int lastpos) → int
X509v3_get_ext_by_OBJ behaves like |X509v3_get_ext_by_NID| but looks for extensions matching |obj|.
X509v3_get_ext_count(Pointer<X509_EXTENSIONS> x) → int
X509v3_get_ext_count returns the number of extensions in |x|.
X509V3_set_ctx(Pointer<X509V3_CTX> ctx, Pointer<X509> issuer, Pointer<X509> subject, Pointer<X509_REQ> req, Pointer<X509_CRL> crl, int flags) → void
X509V3_set_ctx initializes |ctx| with the specified objects. Some string formats will reference fields in these objects. Each object may be NULL to omit it, in which case those formats cannot be used. |flags| should be zero, unless called via |X509V3_set_ctx_test|.
X509V3_set_nconf(Pointer<X509V3_CTX> ctx, Pointer<CONF> conf) → void
X509V3_set_nconf sets |ctx| to use |conf| as the config database. |ctx| must have previously been initialized by |X509V3_set_ctx| or |X509V3_set_ctx_test|. Some string formats will reference sections in |conf|. |conf| may be NULL, in which case these formats cannot be used. If non-NULL, |conf| must outlive |ctx|.

Typedefs

ACCESS_DESCRIPTION = ACCESS_DESCRIPTION_st
AES_KEY = aes_key_st
ASN1_BIT_STRING = asn1_string_st
ASN1_BMPSTRING = asn1_string_st
ASN1_BOOLEAN = Int
ASN1_ENUMERATED = asn1_string_st
ASN1_GENERALIZEDTIME = asn1_string_st
ASN1_GENERALSTRING = asn1_string_st
ASN1_IA5STRING = asn1_string_st
ASN1_INTEGER = asn1_string_st
ASN1_ITEM = ASN1_ITEM_st
ASN1_ITEM_EXP = ASN1_ITEM
ASN1_ITEM_EXP is an abstraction for referencing an |ASN1_ITEM| in a constant-initialized structure, such as a method table. It exists because, on some OpenSSL platforms, |ASN1_ITEM| references are indirected through functions. Structures reference the |ASN1_ITEM| by declaring a field like |ASN1_ITEM_EXP *item| and initializing it with |ASN1_ITEM_ref|.
ASN1_NULL = asn1_null_st
An |ASN1_NULL| is an opaque type. asn1.h represents the ASN.1 NULL value as an opaque, non-NULL |ASN1_NULL*| pointer.
ASN1_OBJECT = asn1_object_st
ASN1_OCTET_STRING = asn1_string_st
ASN1_PCTX = asn1_pctx_st
ASN1_PRINTABLESTRING = asn1_string_st
ASN1_SEQUENCE_ANY = stack_st_ASN1_TYPE
ASN1_STRING = asn1_string_st
ASN1_T61STRING = asn1_string_st
ASN1_TIME = asn1_string_st
ASN1_TYPE = asn1_type_st
ASN1_UNIVERSALSTRING = asn1_string_st
ASN1_UTCTIME = asn1_string_st
ASN1_UTF8STRING = asn1_string_st
ASN1_VALUE = ASN1_VALUE_st
ASN1_VALUE_st (aka |ASN1_VALUE|) is an opaque type used as a placeholder for the C type corresponding to an |ASN1_ITEM|.
ASN1_VISIBLESTRING = asn1_string_st
AUTHORITY_INFO_ACCESS = stack_st_ACCESS_DESCRIPTION
AUTHORITY_KEYID = AUTHORITY_KEYID_st
BASIC_CONSTRAINTS = BASIC_CONSTRAINTS_st
BIGNUM = bignum_st
BIO = bio_st
BIO_info_cb = NativeFunction<Int Function(Pointer<BIO>, Int, Int)>
bio_info_cb = BIO_info_cb
BIO_METHOD = bio_method_st
BLAKE2B_CTX = blake2b_state_st
blkcnt_t = __blkcnt_t
blksize_t = __blksize_t
BN_CTX = bignum_ctx
BN_GENCB = bn_gencb_st
BN_MONT_CTX = bn_mont_ctx_st
BN_ULONG = Uint64
BUF_MEM = buf_mem_st
caddr_t = __caddr_t
CBB = cbb_st
CBS = cbs_st
CBS_ASN1_TAG = Uint32
CBS_ASN1_TAG is the type used by |CBS| and |CBB| for ASN.1 tags. See that header for details. This type is defined in base.h as a forward declaration.
CERTIFICATEPOLICIES = stack_st_POLICYINFO
clock_t = __clock_t
clockid_t = __clockid_t
CMAC_CTX = cmac_ctx_st
CMS_ContentInfo = CMS_ContentInfo_st
CMS_SignerInfo = CMS_SignerInfo_st
CONF = conf_st
CONF_VALUE = conf_value_st
CRL_DIST_POINTS = stack_st_DIST_POINT
CRYPTO_BUFFER = crypto_buffer_st
CRYPTO_BUFFER_POOL = crypto_buffer_pool_st
CRYPTO_EX_DATA = crypto_ex_data_st
CRYPTO_EX_DATA, in the public API, is an opaque struct that is never returned from the library.
CRYPTO_EX_dup = NativeFunction<Int Function(Pointer<CRYPTO_EX_DATA> to, Pointer<CRYPTO_EX_DATA> from, Pointer<Pointer<Void>> from_d, Int index, Long argl, Pointer<Void> argp)>
CRYPTO_EX_dup is a legacy callback function type which is ignored.
CRYPTO_EX_free = NativeFunction<Void Function(Pointer<Void> parent, Pointer<Void> ptr, Pointer<CRYPTO_EX_DATA> ad, Int index, Long argl, Pointer<Void> argp)>
CRYPTO_EX_free is a callback function that is called when an object of the class with extra data pointers is being destroyed. For example, if this callback has been passed to |SSL_get_ex_new_index| then it may be called each time an |SSL*| is destroyed.
CRYPTO_EX_unused = Int
CRYPTO_EX_unused is a placeholder for an unused callback. It is aliased to int to ensure non-NULL callers fail to compile rather than fail silently.
CRYPTO_IOVEC = crypto_iovec_st
CRYPTO_IVEC = crypto_ivec_st
CRYPTO_MUST_BE_NULL = crypto_must_be_null_st
CRYPTO_MUST_BE_NULL is an opaque type that is never returned from BoringSSL. It is used in function parameters that must be NULL.
CRYPTO_THREADID = Int
CRYPTO_THREADID is a dummy value.
CTR_DRBG_STATE = ctr_drbg_state_st
d2i_of_void = NativeFunction<Pointer<Void> Function(Pointer<Pointer<Void>>, Pointer<Pointer<UnsignedChar>>, Long)>
The following typedefs are sometimes used for pointers to functions like |d2i_SAMPLE| and |i2d_SAMPLE|. Note, however, that these act on |void*|. Calling a function with a different pointer type is undefined in C, so this is only valid with a wrapper.
daddr_t = __daddr_t
Dart__blkcnt64_t = int
Dart__blkcnt_t = int
Dart__blksize_t = int
Dart__clock_t = int
Dart__clockid_t = int
Dart__compar_fn_tFunction = int Function(Pointer<Void>, Pointer<Void>)
Dart__daddr_t = int
Dart__dev_t = int
Dart__fd_mask = int
Dart__fsblkcnt64_t = int
Dart__fsblkcnt_t = int
Dart__fsfilcnt64_t = int
Dart__fsfilcnt_t = int
Dart__fsword_t = int
Dart__gid_t = int
Dart__gwchar_t = int
Dart__id_t = int
Dart__ino64_t = int
Dart__ino_t = int
Dart__int16_t = int
Dart__int32_t = int
Dart__int64_t = int
Dart__int8_t = int
Dart__intmax_t = int
Dart__intptr_t = int
Dart__key_t = int
Dart__mode_t = int
Dart__off64_t = int
Dart__off_t = int
Dart__pid_t = int
Dart__quad_t = int
Dart__rlim64_t = int
Dart__rlim_t = int
Dart__sig_atomic_t = int
Dart__socklen_t = int
Dart__ssize_t = int
Dart__suseconds64_t = int
Dart__suseconds_t = int
Dart__syscall_slong_t = int
Dart__syscall_ulong_t = int
Dart__thrd_t = int
Dart__time_t = int
Dart__tss_t = int
Dart__u_char = int
Dart__u_int = int
Dart__u_long = int
Dart__u_quad_t = int
Dart__u_short = int
Dart__uid_t = int
Dart__uint16_t = int
Dart__uint32_t = int
Dart__uint64_t = int
Dart__uint8_t = int
Dart__uintmax_t = int
Dart__useconds_t = int
Dart_Float32 = double
Dart_Float32x = double
Dart_Float64 = double
Dart_IO_lock_t = void
DartASN1_BOOLEAN = int
DartBN_ULONG = int
DartCBS_ASN1_TAG = int
DartCRYPTO_EX_unused = int
DartCRYPTO_THREADID = int
DartERR_print_errors_callback_tFunction = int Function(Pointer<Char> str, int len, Pointer<Void> ctx)
Dartint_fast16_t = int
Dartint_fast32_t = int
Dartint_fast64_t = int
Dartint_fast8_t = int
DartOPENSSL_sk_call_cmp_funcFunction = int Function(OPENSSL_sk_cmp_func, Pointer<Void>, Pointer<Void>)
DartOPENSSL_sk_call_delete_if_funcFunction = int Function(OPENSSL_sk_delete_if_func, Pointer<Void>, Pointer<Void>)
DartOPENSSL_sk_call_free_funcFunction = void Function(OPENSSL_sk_free_func, Pointer<Void>)
DartOPENSSL_sk_cmp_funcFunction = int Function(Pointer<Pointer<Void>> a, Pointer<Pointer<Void>> b)
DartOPENSSL_sk_delete_if_funcFunction = int Function(Pointer<Void>, Pointer<Void>)
DartOPENSSL_sk_free_funcFunction = void Function(Pointer<Void> method)
DartPKCS7_DIGEST = void
DartPKCS7_ENCRYPT = void
DartPKCS7_ENVELOPE = void
DartPKCS7_SIGNER_INFO = void
Dartpthread_key_t = int
Dartpthread_once_t = int
Dartpthread_t = int
Dartptrdiff_t = int
Dartregister_t = int
Dartsk_ACCESS_DESCRIPTION_cmp_funcFunction = int Function(Pointer<Pointer<ACCESS_DESCRIPTION>>, Pointer<Pointer<ACCESS_DESCRIPTION>>)
Dartsk_ACCESS_DESCRIPTION_delete_if_funcFunction = int Function(Pointer<ACCESS_DESCRIPTION>, Pointer<Void>)
Dartsk_ACCESS_DESCRIPTION_free_funcFunction = void Function(Pointer<ACCESS_DESCRIPTION> desc)
Dartsk_ASN1_INTEGER_cmp_funcFunction = int Function(Pointer<Pointer<ASN1_OCTET_STRING>>, Pointer<Pointer<ASN1_OCTET_STRING>>)
Dartsk_ASN1_INTEGER_delete_if_funcFunction = int Function(Pointer<ASN1_OCTET_STRING>, Pointer<Void>)
Dartsk_ASN1_INTEGER_free_funcFunction = void Function(Pointer<ASN1_OCTET_STRING> str)
Dartsk_ASN1_OBJECT_cmp_funcFunction = int Function(Pointer<Pointer<ASN1_OBJECT>>, Pointer<Pointer<ASN1_OBJECT>>)
Dartsk_ASN1_OBJECT_delete_if_funcFunction = int Function(Pointer<ASN1_OBJECT>, Pointer<Void>)
Dartsk_ASN1_OBJECT_free_funcFunction = void Function(Pointer<ASN1_OBJECT> a)
Dartsk_ASN1_TYPE_cmp_funcFunction = int Function(Pointer<Pointer<ASN1_TYPE>>, Pointer<Pointer<ASN1_TYPE>>)
Dartsk_ASN1_TYPE_delete_if_funcFunction = int Function(Pointer<ASN1_TYPE>, Pointer<Void>)
Dartsk_ASN1_TYPE_free_funcFunction = void Function(Pointer<ASN1_TYPE> a)
Dartsk_BIO_cmp_funcFunction = int Function(Pointer<Pointer<BIO>>, Pointer<Pointer<BIO>>)
Dartsk_BIO_delete_if_funcFunction = int Function(Pointer<BIO>, Pointer<Void>)
Dartsk_BIO_free_funcFunction = void Function(Pointer<BIO> bio)
Dartsk_CONF_VALUE_cmp_funcFunction = int Function(Pointer<Pointer<CONF_VALUE>>, Pointer<Pointer<CONF_VALUE>>)
Dartsk_CONF_VALUE_delete_if_funcFunction = int Function(Pointer<CONF_VALUE>, Pointer<Void>)
Dartsk_CONF_VALUE_free_funcFunction = void Function(Pointer<CONF_VALUE> val)
Dartsk_CRYPTO_BUFFER_cmp_funcFunction = int Function(Pointer<Pointer<CRYPTO_BUFFER>>, Pointer<Pointer<CRYPTO_BUFFER>>)
Dartsk_CRYPTO_BUFFER_delete_if_funcFunction = int Function(Pointer<CRYPTO_BUFFER>, Pointer<Void>)
Dartsk_CRYPTO_BUFFER_free_funcFunction = void Function(Pointer<CRYPTO_BUFFER> buf)
Dartsk_DIST_POINT_cmp_funcFunction = int Function(Pointer<Pointer<DIST_POINT>>, Pointer<Pointer<DIST_POINT>>)
Dartsk_DIST_POINT_delete_if_funcFunction = int Function(Pointer<DIST_POINT>, Pointer<Void>)
Dartsk_DIST_POINT_free_funcFunction = void Function(Pointer<DIST_POINT> dp)
Dartsk_GENERAL_NAME_cmp_funcFunction = int Function(Pointer<Pointer<GENERAL_NAME>>, Pointer<Pointer<GENERAL_NAME>>)
Dartsk_GENERAL_NAME_delete_if_funcFunction = int Function(Pointer<GENERAL_NAME>, Pointer<Void>)
Dartsk_GENERAL_NAME_free_funcFunction = void Function(Pointer<GENERAL_NAME> gen)
Dartsk_GENERAL_SUBTREE_cmp_funcFunction = int Function(Pointer<Pointer<GENERAL_SUBTREE>>, Pointer<Pointer<GENERAL_SUBTREE>>)
Dartsk_GENERAL_SUBTREE_delete_if_funcFunction = int Function(Pointer<GENERAL_SUBTREE>, Pointer<Void>)
Dartsk_GENERAL_SUBTREE_free_funcFunction = void Function(Pointer<GENERAL_SUBTREE> subtree)
Dartsk_OPENSSL_STRING_cmp_funcFunction = int Function(Pointer<Pointer<Char>>, Pointer<Pointer<Char>>)
Dartsk_OPENSSL_STRING_delete_if_funcFunction = int Function(Pointer<Char>, Pointer<Void>)
Dartsk_OPENSSL_STRING_free_funcFunction = void Function(Pointer<Char> format)
Dartsk_POLICY_MAPPING_cmp_funcFunction = int Function(Pointer<Pointer<POLICY_MAPPING>>, Pointer<Pointer<POLICY_MAPPING>>)
Dartsk_POLICY_MAPPING_delete_if_funcFunction = int Function(Pointer<POLICY_MAPPING>, Pointer<Void>)
Dartsk_POLICY_MAPPING_free_funcFunction = void Function(Pointer<POLICY_MAPPING> mapping)
Dartsk_POLICYINFO_cmp_funcFunction = int Function(Pointer<Pointer<POLICYINFO>>, Pointer<Pointer<POLICYINFO>>)
Dartsk_POLICYINFO_delete_if_funcFunction = int Function(Pointer<POLICYINFO>, Pointer<Void>)
Dartsk_POLICYINFO_free_funcFunction = void Function(Pointer<POLICYINFO> info)
Dartsk_POLICYQUALINFO_cmp_funcFunction = int Function(Pointer<Pointer<POLICYQUALINFO>>, Pointer<Pointer<POLICYQUALINFO>>)
Dartsk_POLICYQUALINFO_delete_if_funcFunction = int Function(Pointer<POLICYQUALINFO>, Pointer<Void>)
Dartsk_POLICYQUALINFO_free_funcFunction = void Function(Pointer<POLICYQUALINFO> info)
Dartsk_void_cmp_funcFunction = int Function(Pointer<Pointer<Void>> a, Pointer<Pointer<Void>> b)
Dartsk_void_delete_if_funcFunction = int Function(Pointer<Void>, Pointer<Void>)
Dartsk_void_free_funcFunction = void Function(Pointer<Void> method)
Dartsk_X509_ALGOR_cmp_funcFunction = int Function(Pointer<Pointer<X509_ALGOR>>, Pointer<Pointer<X509_ALGOR>>)
Dartsk_X509_ALGOR_delete_if_funcFunction = int Function(Pointer<X509_ALGOR>, Pointer<Void>)
Dartsk_X509_ALGOR_free_funcFunction = void Function(Pointer<X509_ALGOR> alg)
Dartsk_X509_ATTRIBUTE_cmp_funcFunction = int Function(Pointer<Pointer<X509_ATTRIBUTE>>, Pointer<Pointer<X509_ATTRIBUTE>>)
Dartsk_X509_ATTRIBUTE_delete_if_funcFunction = int Function(Pointer<X509_ATTRIBUTE>, Pointer<Void>)
Dartsk_X509_ATTRIBUTE_free_funcFunction = void Function(Pointer<X509_ATTRIBUTE> attr)
Dartsk_X509_cmp_funcFunction = int Function(Pointer<Pointer<X509>>, Pointer<Pointer<X509>>)
Dartsk_X509_CRL_cmp_funcFunction = int Function(Pointer<Pointer<X509_CRL>>, Pointer<Pointer<X509_CRL>>)
Dartsk_X509_CRL_delete_if_funcFunction = int Function(Pointer<X509_CRL>, Pointer<Void>)
Dartsk_X509_CRL_free_funcFunction = void Function(Pointer<X509_CRL> crl)
Dartsk_X509_delete_if_funcFunction = int Function(Pointer<X509>, Pointer<Void>)
Dartsk_X509_EXTENSION_cmp_funcFunction = int Function(Pointer<Pointer<X509_EXTENSION>>, Pointer<Pointer<X509_EXTENSION>>)
Dartsk_X509_EXTENSION_delete_if_funcFunction = int Function(Pointer<X509_EXTENSION>, Pointer<Void>)
Dartsk_X509_EXTENSION_free_funcFunction = void Function(Pointer<X509_EXTENSION> ex)
Dartsk_X509_free_funcFunction = void Function(Pointer<X509> x509)
Dartsk_X509_INFO_cmp_funcFunction = int Function(Pointer<Pointer<X509_INFO>>, Pointer<Pointer<X509_INFO>>)
Dartsk_X509_INFO_delete_if_funcFunction = int Function(Pointer<X509_INFO>, Pointer<Void>)
Dartsk_X509_INFO_free_funcFunction = void Function(Pointer<X509_INFO> info)
Dartsk_X509_NAME_cmp_funcFunction = int Function(Pointer<Pointer<X509_NAME>>, Pointer<Pointer<X509_NAME>>)
Dartsk_X509_NAME_delete_if_funcFunction = int Function(Pointer<X509_NAME>, Pointer<Void>)
Dartsk_X509_NAME_ENTRY_cmp_funcFunction = int Function(Pointer<Pointer<X509_NAME_ENTRY>>, Pointer<Pointer<X509_NAME_ENTRY>>)
Dartsk_X509_NAME_ENTRY_delete_if_funcFunction = int Function(Pointer<X509_NAME_ENTRY>, Pointer<Void>)
Dartsk_X509_NAME_ENTRY_free_funcFunction = void Function(Pointer<X509_NAME_ENTRY> entry)
Dartsk_X509_NAME_free_funcFunction = void Function(Pointer<X509_NAME> name)
Dartsk_X509_OBJECT_cmp_funcFunction = int Function(Pointer<Pointer<X509_OBJECT>>, Pointer<Pointer<X509_OBJECT>>)
Dartsk_X509_OBJECT_delete_if_funcFunction = int Function(Pointer<X509_OBJECT>, Pointer<Void>)
Dartsk_X509_OBJECT_free_funcFunction = void Function(Pointer<X509_OBJECT> obj)
Dartsk_X509_REVOKED_cmp_funcFunction = int Function(Pointer<Pointer<X509_REVOKED>>, Pointer<Pointer<X509_REVOKED>>)
Dartsk_X509_REVOKED_delete_if_funcFunction = int Function(Pointer<X509_REVOKED>, Pointer<Void>)
Dartsk_X509_REVOKED_free_funcFunction = void Function(Pointer<X509_REVOKED> rev)
Dartuint = int
Dartuint_fast16_t = int
Dartuint_fast32_t = int
Dartuint_fast64_t = int
Dartuint_fast8_t = int
Dartulong = int
Dartushort = int
DartX509_STORE_CTX_verify_cbFunction = int Function(int, Pointer<X509_STORE_CTX>)
DartX509V3_EXT_D2IFunction = Pointer<Void> Function(Pointer<Void> ext, Pointer<Pointer<Uint8>> inp, int len)
DartX509V3_EXT_FREEFunction = void Function(Pointer<Void> method)
DartX509V3_EXT_I2DFunction = int Function(Pointer<Void> ext, Pointer<Pointer<Uint8>> outp)
DartX509V3_EXT_I2RFunction = int Function(Pointer<X509V3_EXT_METHOD> method, Pointer<Void> ext, Pointer<BIO> out, int indent)
dev_t = __dev_t
DH = dh_st
DIST_POINT = DIST_POINT_st
DIST_POINT_NAME = DIST_POINT_NAME_st
DSA = dsa_st
DSA_SIG = DSA_SIG_st
EC_GROUP = ec_group_st
EC_KEY = ec_key_st
EC_METHOD = ec_method_st
EC_POINT = ec_point_st
ECDSA_METHOD = ecdsa_method_st
ECDSA_SIG = ecdsa_sig_st
EDIPARTYNAME = EDIPartyName_st
ENGINE = engine_st
ERR_FNS = st_ERR_FNS
ERR_print_errors_callback_t = Pointer<NativeFunction<ERR_print_errors_callback_tFunction>>
ERR_print_errors_callback_t is the type of a function used by |ERR_print_errors_cb|. It takes a pointer to a human readable string (and its length) that describes an entry in the error queue. The |ctx| argument is an opaque pointer given to |ERR_print_errors_cb|.
ERR_print_errors_callback_tFunction = Int Function(Pointer<Char> str, Size len, Pointer<Void> ctx)
EVP_AEAD = evp_aead_st
EVP_AEAD_CTX = evp_aead_ctx_st
EVP_CIPHER = evp_cipher_st
EVP_CIPHER_CTX = evp_cipher_ctx_st
EVP_CIPHER_INFO = evp_cipher_info_st
EVP_ENCODE_CTX = evp_encode_ctx_st
EVP_HPKE_AEAD = evp_hpke_aead_st
EVP_HPKE_CTX = evp_hpke_ctx_st
EVP_HPKE_KDF = evp_hpke_kdf_st
EVP_HPKE_KEM = evp_hpke_kem_st
EVP_HPKE_KEY = evp_hpke_key_st
EVP_KEM = evp_kem_st
EVP_MD = env_md_st
EVP_MD_CTX = env_md_ctx_st
EVP_PKEY = evp_pkey_st
EVP_PKEY_ALG = evp_pkey_alg_st
EVP_PKEY_CTX = evp_pkey_ctx_st
EXTENDED_KEY_USAGE = stack_st_ASN1_OBJECT
Extended key usage.
fd_mask = __fd_mask
FILE = _IO_FILE
fpos_t = __fpos_t
fsblkcnt_t = __fsblkcnt_t
fsfilcnt_t = __fsfilcnt_t
fsid_t = __fsid_t
GENERAL_NAME = GENERAL_NAME_st
GENERAL_NAMES = stack_st_GENERAL_NAME
GENERAL_SUBTREE = GENERAL_SUBTREE_st
gid_t = __gid_t
HMAC_CTX = hmac_ctx_st
i2d_of_void = NativeFunction<Int Function(Pointer<Void>, Pointer<Pointer<UnsignedChar>>)>
id_t = __id_t
ino_t = __ino_t
int_fast16_t = Long
int_fast32_t = Long
int_fast64_t = Long
int_fast8_t = SignedChar
int_least16_t = __int_least16_t
int_least32_t = __int_least32_t
int_least64_t = __int_least64_t
int_least8_t = __int_least8_t
intmax_t = __intmax_t
ISSUING_DIST_POINT = ISSUING_DIST_POINT_st
key_t = __key_t
locale_t = __locale_t
loff_t = __loff_t
MD4_CTX = md4_state_st
MD5_CTX = md5_state_st
mode_t = __mode_t
NAME_CONSTRAINTS = NAME_CONSTRAINTS_st
NETSCAPE_SPKAC = Netscape_spkac_st
NETSCAPE_SPKI = Netscape_spki_st
NOTICEREF = NOTICEREF_st
OBJ_NAME = obj_name_st
off_t = __off_t
OPENSSL_BLOCK = Pointer<Void>
OPENSSL_INIT_SETTINGS = ossl_init_settings_st
OPENSSL_sk_call_cmp_func = Pointer<NativeFunction<OPENSSL_sk_call_cmp_funcFunction>>
OPENSSL_sk_call_cmp_funcFunction = Int Function(OPENSSL_sk_cmp_func, Pointer<Void>, Pointer<Void>)
OPENSSL_sk_call_copy_func = Pointer<NativeFunction<OPENSSL_sk_call_copy_funcFunction>>
OPENSSL_sk_call_copy_funcFunction = Pointer<Void> Function(OPENSSL_sk_copy_func, Pointer<Void>)
OPENSSL_sk_call_delete_if_func = Pointer<NativeFunction<OPENSSL_sk_call_delete_if_funcFunction>>
OPENSSL_sk_call_delete_if_funcFunction = Int Function(OPENSSL_sk_delete_if_func, Pointer<Void>, Pointer<Void>)
OPENSSL_sk_call_free_func = Pointer<NativeFunction<OPENSSL_sk_call_free_funcFunction>>
The following function types call the above type-erased signatures with the true types.
OPENSSL_sk_call_free_funcFunction = Void Function(OPENSSL_sk_free_func, Pointer<Void>)
OPENSSL_sk_cmp_func = Pointer<NativeFunction<OPENSSL_sk_cmp_funcFunction>>
OPENSSL_sk_cmp_func is a comparison function that returns a value < 0, 0 or > 0 if |*a| is less than, equal to or greater than |*b|, respectively. Note the extra indirection - the function is given a pointer to a pointer to the element. This differs from the usual qsort/bsearch comparison function.
OPENSSL_sk_cmp_funcFunction = Int Function(Pointer<Pointer<Void>> a, Pointer<Pointer<Void>> b)
OPENSSL_sk_copy_func = Pointer<NativeFunction<OPENSSL_sk_copy_funcFunction>>
OPENSSL_sk_copy_func is a function that copies an element in a stack. Note its actual type is T ()(const T ) for some T. Low-level |sk_| functions will be passed a type-specific wrapper to call it correctly.
OPENSSL_sk_copy_funcFunction = Pointer<Void> Function(Pointer<Void> ptr)
OPENSSL_sk_delete_if_func = Pointer<NativeFunction<OPENSSL_sk_delete_if_funcFunction>>
OPENSSL_sk_delete_if_func is the generic version of |sk_SAMPLE_delete_if_func|.
OPENSSL_sk_delete_if_funcFunction = Int Function(Pointer<Void> obj, Pointer<Void> data)
OPENSSL_sk_free_func = Pointer<NativeFunction<OPENSSL_sk_free_funcFunction>>
OPENSSL_sk_free_func is a function that frees an element in a stack. Note its actual type is void (*)(T ) for some T. Low-level |sk_| functions will be passed a type-specific wrapper to call it correctly.
OPENSSL_sk_free_funcFunction = Void Function(Pointer<Void> ptr)
OPENSSL_STACK = stack_st
An OPENSSL_STACK contains an array of pointers. It is not designed to be used directly, rather the wrapper macros should be used.
OPENSSL_STRING = Pointer<Char>
Built-in stacks.
OSSL_LIB_CTX = ossl_lib_ctx_st
OSSL_PARAM = ossl_param_st
ossl_ssize_t = ptrdiff_t
ossl_ssize_t is a signed type which is large enough to fit the size of any valid memory allocation. We prefer using |size_t|, but sometimes we need a signed type for OpenSSL API compatibility. This type can be used in such cases to avoid overflow.
OTHERNAME = otherName_st
pem_password_cb = NativeFunction<Int Function(Pointer<Char> buf, Int size, Int rwflag, Pointer<Void> userdata)>
"userdata": new with OpenSSL 0.9.4
pid_t = __pid_t
PKCS12 = pkcs12_st
PKCS7_DIGEST = Void
PKCS7_ENCRYPT = Void
PKCS7_ENVELOPE = Void
PKCS7_SIGNER_INFO = Void
PKCS8_PRIV_KEY_INFO = pkcs8_priv_key_info_st
POLICY_CONSTRAINTS = POLICY_CONSTRAINTS_st
POLICY_MAPPING = POLICY_MAPPING_st
POLICY_MAPPINGS = stack_st_POLICY_MAPPING
POLICYINFO = POLICYINFO_st
POLICYQUALINFO = POLICYQUALINFO_st
pthread_key_t = UnsignedInt
pthread_once_t = Int
pthread_t = UnsignedLong
ptrdiff_t = Long
quad_t = __quad_t
RAND_METHOD = rand_meth_st
RC4_KEY = rc4_key_st
register_t = Long
RIPEMD160_CTX = RIPEMD160state_st
RSA = rsa_st
RSA_METHOD = rsa_meth_st
RSA_PSS_PARAMS = rsa_pss_params_st
SHA256_CTX = sha256_state_st
SHA512_CTX = sha512_state_st
SHA_CTX = sha_state_st
sigset_t = __sigset_t
sk_ACCESS_DESCRIPTION_cmp_func = Pointer<NativeFunction<sk_ACCESS_DESCRIPTION_cmp_funcFunction>>
sk_ACCESS_DESCRIPTION_cmp_funcFunction = Int Function(Pointer<Pointer<ACCESS_DESCRIPTION>>, Pointer<Pointer<ACCESS_DESCRIPTION>>)
sk_ACCESS_DESCRIPTION_copy_func = Pointer<NativeFunction<sk_ACCESS_DESCRIPTION_copy_funcFunction>>
sk_ACCESS_DESCRIPTION_copy_funcFunction = Pointer<ACCESS_DESCRIPTION> Function(Pointer<ACCESS_DESCRIPTION>)
sk_ACCESS_DESCRIPTION_delete_if_func = Pointer<NativeFunction<sk_ACCESS_DESCRIPTION_delete_if_funcFunction>>
sk_ACCESS_DESCRIPTION_delete_if_funcFunction = Int Function(Pointer<ACCESS_DESCRIPTION>, Pointer<Void>)
sk_ACCESS_DESCRIPTION_free_func = Pointer<NativeFunction<sk_ACCESS_DESCRIPTION_free_funcFunction>>
sk_ACCESS_DESCRIPTION_free_funcFunction = Void Function(Pointer<ACCESS_DESCRIPTION>)
sk_ASN1_INTEGER_cmp_func = Pointer<NativeFunction<sk_ASN1_INTEGER_cmp_funcFunction>>
sk_ASN1_INTEGER_cmp_funcFunction = Int Function(Pointer<Pointer<ASN1_OCTET_STRING>>, Pointer<Pointer<ASN1_OCTET_STRING>>)
sk_ASN1_INTEGER_copy_func = Pointer<NativeFunction<sk_ASN1_INTEGER_copy_funcFunction>>
sk_ASN1_INTEGER_copy_funcFunction = Pointer<ASN1_OCTET_STRING> Function(Pointer<ASN1_OCTET_STRING> x)
sk_ASN1_INTEGER_delete_if_func = Pointer<NativeFunction<sk_ASN1_INTEGER_delete_if_funcFunction>>
sk_ASN1_INTEGER_delete_if_funcFunction = Int Function(Pointer<ASN1_OCTET_STRING>, Pointer<Void>)
sk_ASN1_INTEGER_free_func = Pointer<NativeFunction<sk_ASN1_INTEGER_free_funcFunction>>
sk_ASN1_INTEGER_free_funcFunction = Void Function(Pointer<ASN1_OCTET_STRING>)
sk_ASN1_OBJECT_cmp_func = Pointer<NativeFunction<sk_ASN1_OBJECT_cmp_funcFunction>>
sk_ASN1_OBJECT_cmp_funcFunction = Int Function(Pointer<Pointer<ASN1_OBJECT>>, Pointer<Pointer<ASN1_OBJECT>>)
sk_ASN1_OBJECT_copy_func = Pointer<NativeFunction<sk_ASN1_OBJECT_copy_funcFunction>>
sk_ASN1_OBJECT_copy_funcFunction = Pointer<ASN1_OBJECT> Function(Pointer<ASN1_OBJECT> obj)
sk_ASN1_OBJECT_delete_if_func = Pointer<NativeFunction<sk_ASN1_OBJECT_delete_if_funcFunction>>
sk_ASN1_OBJECT_delete_if_funcFunction = Int Function(Pointer<ASN1_OBJECT>, Pointer<Void>)
sk_ASN1_OBJECT_free_func = Pointer<NativeFunction<sk_ASN1_OBJECT_free_funcFunction>>
sk_ASN1_OBJECT_free_funcFunction = Void Function(Pointer<ASN1_OBJECT>)
sk_ASN1_TYPE_cmp_func = Pointer<NativeFunction<sk_ASN1_TYPE_cmp_funcFunction>>
sk_ASN1_TYPE_cmp_funcFunction = Int Function(Pointer<Pointer<ASN1_TYPE>>, Pointer<Pointer<ASN1_TYPE>>)
sk_ASN1_TYPE_copy_func = Pointer<NativeFunction<sk_ASN1_TYPE_copy_funcFunction>>
sk_ASN1_TYPE_copy_funcFunction = Pointer<ASN1_TYPE> Function(Pointer<ASN1_TYPE>)
sk_ASN1_TYPE_delete_if_func = Pointer<NativeFunction<sk_ASN1_TYPE_delete_if_funcFunction>>
sk_ASN1_TYPE_delete_if_funcFunction = Int Function(Pointer<ASN1_TYPE>, Pointer<Void>)
sk_ASN1_TYPE_free_func = Pointer<NativeFunction<sk_ASN1_TYPE_free_funcFunction>>
sk_ASN1_TYPE_free_funcFunction = Void Function(Pointer<ASN1_TYPE>)
sk_BIO_cmp_func = Pointer<NativeFunction<sk_BIO_cmp_funcFunction>>
sk_BIO_cmp_funcFunction = Int Function(Pointer<Pointer<BIO>>, Pointer<Pointer<BIO>>)
sk_BIO_copy_func = Pointer<NativeFunction<sk_BIO_copy_funcFunction>>
sk_BIO_copy_funcFunction = Pointer<BIO> Function(Pointer<BIO> bio)
sk_BIO_delete_if_func = Pointer<NativeFunction<sk_BIO_delete_if_funcFunction>>
sk_BIO_delete_if_funcFunction = Int Function(Pointer<BIO>, Pointer<Void>)
sk_BIO_free_func = Pointer<NativeFunction<sk_BIO_free_funcFunction>>
sk_BIO_free_funcFunction = Void Function(Pointer<BIO>)
sk_CONF_VALUE_cmp_func = Pointer<NativeFunction<sk_CONF_VALUE_cmp_funcFunction>>
sk_CONF_VALUE_cmp_funcFunction = Int Function(Pointer<Pointer<CONF_VALUE>>, Pointer<Pointer<CONF_VALUE>>)
sk_CONF_VALUE_copy_func = Pointer<NativeFunction<sk_CONF_VALUE_copy_funcFunction>>
sk_CONF_VALUE_copy_funcFunction = Pointer<CONF_VALUE> Function(Pointer<CONF_VALUE>)
sk_CONF_VALUE_delete_if_func = Pointer<NativeFunction<sk_CONF_VALUE_delete_if_funcFunction>>
sk_CONF_VALUE_delete_if_funcFunction = Int Function(Pointer<CONF_VALUE>, Pointer<Void>)
sk_CONF_VALUE_free_func = Pointer<NativeFunction<sk_CONF_VALUE_free_funcFunction>>
sk_CONF_VALUE_free_funcFunction = Void Function(Pointer<CONF_VALUE>)
sk_CRYPTO_BUFFER_cmp_func = Pointer<NativeFunction<sk_CRYPTO_BUFFER_cmp_funcFunction>>
sk_CRYPTO_BUFFER_cmp_funcFunction = Int Function(Pointer<Pointer<CRYPTO_BUFFER>>, Pointer<Pointer<CRYPTO_BUFFER>>)
sk_CRYPTO_BUFFER_copy_func = Pointer<NativeFunction<sk_CRYPTO_BUFFER_copy_funcFunction>>
sk_CRYPTO_BUFFER_copy_funcFunction = Pointer<CRYPTO_BUFFER> Function(Pointer<CRYPTO_BUFFER> buf)
sk_CRYPTO_BUFFER_delete_if_func = Pointer<NativeFunction<sk_CRYPTO_BUFFER_delete_if_funcFunction>>
sk_CRYPTO_BUFFER_delete_if_funcFunction = Int Function(Pointer<CRYPTO_BUFFER>, Pointer<Void>)
sk_CRYPTO_BUFFER_free_func = Pointer<NativeFunction<sk_CRYPTO_BUFFER_free_funcFunction>>
Buffers and buffer pools.
sk_CRYPTO_BUFFER_free_funcFunction = Void Function(Pointer<CRYPTO_BUFFER>)
sk_DIST_POINT_cmp_func = Pointer<NativeFunction<sk_DIST_POINT_cmp_funcFunction>>
sk_DIST_POINT_cmp_funcFunction = Int Function(Pointer<Pointer<DIST_POINT>>, Pointer<Pointer<DIST_POINT>>)
sk_DIST_POINT_copy_func = Pointer<NativeFunction<sk_DIST_POINT_copy_funcFunction>>
sk_DIST_POINT_copy_funcFunction = Pointer<DIST_POINT> Function(Pointer<DIST_POINT>)
sk_DIST_POINT_delete_if_func = Pointer<NativeFunction<sk_DIST_POINT_delete_if_funcFunction>>
sk_DIST_POINT_delete_if_funcFunction = Int Function(Pointer<DIST_POINT>, Pointer<Void>)
sk_DIST_POINT_free_func = Pointer<NativeFunction<sk_DIST_POINT_free_funcFunction>>
sk_DIST_POINT_free_funcFunction = Void Function(Pointer<DIST_POINT>)
sk_GENERAL_NAME_cmp_func = Pointer<NativeFunction<sk_GENERAL_NAME_cmp_funcFunction>>
sk_GENERAL_NAME_cmp_funcFunction = Int Function(Pointer<Pointer<GENERAL_NAME>>, Pointer<Pointer<GENERAL_NAME>>)
sk_GENERAL_NAME_copy_func = Pointer<NativeFunction<sk_GENERAL_NAME_copy_funcFunction>>
sk_GENERAL_NAME_copy_funcFunction = Pointer<GENERAL_NAME> Function(Pointer<GENERAL_NAME> gen)
sk_GENERAL_NAME_delete_if_func = Pointer<NativeFunction<sk_GENERAL_NAME_delete_if_funcFunction>>
sk_GENERAL_NAME_delete_if_funcFunction = Int Function(Pointer<GENERAL_NAME>, Pointer<Void>)
sk_GENERAL_NAME_free_func = Pointer<NativeFunction<sk_GENERAL_NAME_free_funcFunction>>
sk_GENERAL_NAME_free_funcFunction = Void Function(Pointer<GENERAL_NAME>)
sk_GENERAL_SUBTREE_cmp_func = Pointer<NativeFunction<sk_GENERAL_SUBTREE_cmp_funcFunction>>
sk_GENERAL_SUBTREE_cmp_funcFunction = Int Function(Pointer<Pointer<GENERAL_SUBTREE>>, Pointer<Pointer<GENERAL_SUBTREE>>)
sk_GENERAL_SUBTREE_copy_func = Pointer<NativeFunction<sk_GENERAL_SUBTREE_copy_funcFunction>>
sk_GENERAL_SUBTREE_copy_funcFunction = Pointer<GENERAL_SUBTREE> Function(Pointer<GENERAL_SUBTREE>)
sk_GENERAL_SUBTREE_delete_if_func = Pointer<NativeFunction<sk_GENERAL_SUBTREE_delete_if_funcFunction>>
sk_GENERAL_SUBTREE_delete_if_funcFunction = Int Function(Pointer<GENERAL_SUBTREE>, Pointer<Void>)
sk_GENERAL_SUBTREE_free_func = Pointer<NativeFunction<sk_GENERAL_SUBTREE_free_funcFunction>>
sk_GENERAL_SUBTREE_free_funcFunction = Void Function(Pointer<GENERAL_SUBTREE>)
sk_OPENSSL_STRING_cmp_func = Pointer<NativeFunction<sk_OPENSSL_STRING_cmp_funcFunction>>
sk_OPENSSL_STRING_cmp_funcFunction = Int Function(Pointer<Pointer<Char>>, Pointer<Pointer<Char>>)
sk_OPENSSL_STRING_copy_func = Pointer<NativeFunction<sk_OPENSSL_STRING_copy_funcFunction>>
sk_OPENSSL_STRING_copy_funcFunction = Pointer<Char> Function(Pointer<Char> str)
sk_OPENSSL_STRING_delete_if_func = Pointer<NativeFunction<sk_OPENSSL_STRING_delete_if_funcFunction>>
sk_OPENSSL_STRING_delete_if_funcFunction = Int Function(Pointer<Char>, Pointer<Void>)
sk_OPENSSL_STRING_free_func = Pointer<NativeFunction<sk_OPENSSL_STRING_free_funcFunction>>
sk_OPENSSL_STRING_free_funcFunction = Void Function(Pointer<Char>)
sk_POLICY_MAPPING_cmp_func = Pointer<NativeFunction<sk_POLICY_MAPPING_cmp_funcFunction>>
sk_POLICY_MAPPING_cmp_funcFunction = Int Function(Pointer<Pointer<POLICY_MAPPING>>, Pointer<Pointer<POLICY_MAPPING>>)
sk_POLICY_MAPPING_copy_func = Pointer<NativeFunction<sk_POLICY_MAPPING_copy_funcFunction>>
sk_POLICY_MAPPING_copy_funcFunction = Pointer<POLICY_MAPPING> Function(Pointer<POLICY_MAPPING>)
sk_POLICY_MAPPING_delete_if_func = Pointer<NativeFunction<sk_POLICY_MAPPING_delete_if_funcFunction>>
sk_POLICY_MAPPING_delete_if_funcFunction = Int Function(Pointer<POLICY_MAPPING>, Pointer<Void>)
sk_POLICY_MAPPING_free_func = Pointer<NativeFunction<sk_POLICY_MAPPING_free_funcFunction>>
sk_POLICY_MAPPING_free_funcFunction = Void Function(Pointer<POLICY_MAPPING>)
sk_POLICYINFO_cmp_func = Pointer<NativeFunction<sk_POLICYINFO_cmp_funcFunction>>
sk_POLICYINFO_cmp_funcFunction = Int Function(Pointer<Pointer<POLICYINFO>>, Pointer<Pointer<POLICYINFO>>)
sk_POLICYINFO_copy_func = Pointer<NativeFunction<sk_POLICYINFO_copy_funcFunction>>
sk_POLICYINFO_copy_funcFunction = Pointer<POLICYINFO> Function(Pointer<POLICYINFO>)
sk_POLICYINFO_delete_if_func = Pointer<NativeFunction<sk_POLICYINFO_delete_if_funcFunction>>
sk_POLICYINFO_delete_if_funcFunction = Int Function(Pointer<POLICYINFO>, Pointer<Void>)
sk_POLICYINFO_free_func = Pointer<NativeFunction<sk_POLICYINFO_free_funcFunction>>
sk_POLICYINFO_free_funcFunction = Void Function(Pointer<POLICYINFO>)
sk_POLICYQUALINFO_cmp_func = Pointer<NativeFunction<sk_POLICYQUALINFO_cmp_funcFunction>>
sk_POLICYQUALINFO_cmp_funcFunction = Int Function(Pointer<Pointer<POLICYQUALINFO>>, Pointer<Pointer<POLICYQUALINFO>>)
sk_POLICYQUALINFO_copy_func = Pointer<NativeFunction<sk_POLICYQUALINFO_copy_funcFunction>>
sk_POLICYQUALINFO_copy_funcFunction = Pointer<POLICYQUALINFO> Function(Pointer<POLICYQUALINFO>)
sk_POLICYQUALINFO_delete_if_func = Pointer<NativeFunction<sk_POLICYQUALINFO_delete_if_funcFunction>>
sk_POLICYQUALINFO_delete_if_funcFunction = Int Function(Pointer<POLICYQUALINFO>, Pointer<Void>)
sk_POLICYQUALINFO_free_func = Pointer<NativeFunction<sk_POLICYQUALINFO_free_funcFunction>>
sk_POLICYQUALINFO_free_funcFunction = Void Function(Pointer<POLICYQUALINFO>)
sk_void_cmp_func = Pointer<NativeFunction<OPENSSL_sk_cmp_funcFunction>>
sk_void_cmp_funcFunction = Int Function(Pointer<Pointer<Void>> a, Pointer<Pointer<Void>> b)
sk_void_copy_func = Pointer<NativeFunction<OPENSSL_sk_copy_funcFunction>>
sk_void_copy_funcFunction = Pointer<Void> Function(Pointer<Void> ptr)
sk_void_delete_if_func = Pointer<NativeFunction<OPENSSL_sk_delete_if_funcFunction>>
sk_void_delete_if_funcFunction = Int Function(Pointer<Void> obj, Pointer<Void> data)
sk_void_free_func = Pointer<NativeFunction<OPENSSL_sk_free_funcFunction>>
We also disable -Wcast-qual. As part of this C-based type erasure setup,
the wrapper macros need to cast away const in places. In C++, const_cast
suppresses the warning, but it seemingly cannot be suppressed in C.
sk_void_free_funcFunction = Void Function(Pointer<Void> ptr)
sk_X509_ALGOR_cmp_func = Pointer<NativeFunction<sk_X509_ALGOR_cmp_funcFunction>>
sk_X509_ALGOR_cmp_funcFunction = Int Function(Pointer<Pointer<X509_ALGOR>>, Pointer<Pointer<X509_ALGOR>>)
sk_X509_ALGOR_copy_func = Pointer<NativeFunction<sk_X509_ALGOR_copy_funcFunction>>
sk_X509_ALGOR_copy_funcFunction = Pointer<X509_ALGOR> Function(Pointer<X509_ALGOR> alg)
sk_X509_ALGOR_delete_if_func = Pointer<NativeFunction<sk_X509_ALGOR_delete_if_funcFunction>>
sk_X509_ALGOR_delete_if_funcFunction = Int Function(Pointer<X509_ALGOR>, Pointer<Void>)
sk_X509_ALGOR_free_func = Pointer<NativeFunction<sk_X509_ALGOR_free_funcFunction>>
sk_X509_ALGOR_free_funcFunction = Void Function(Pointer<X509_ALGOR>)
sk_X509_ATTRIBUTE_cmp_func = Pointer<NativeFunction<sk_X509_ATTRIBUTE_cmp_funcFunction>>
sk_X509_ATTRIBUTE_cmp_funcFunction = Int Function(Pointer<Pointer<X509_ATTRIBUTE>>, Pointer<Pointer<X509_ATTRIBUTE>>)
sk_X509_ATTRIBUTE_copy_func = Pointer<NativeFunction<sk_X509_ATTRIBUTE_copy_funcFunction>>
sk_X509_ATTRIBUTE_copy_funcFunction = Pointer<X509_ATTRIBUTE> Function(Pointer<X509_ATTRIBUTE> attr)
sk_X509_ATTRIBUTE_delete_if_func = Pointer<NativeFunction<sk_X509_ATTRIBUTE_delete_if_funcFunction>>
sk_X509_ATTRIBUTE_delete_if_funcFunction = Int Function(Pointer<X509_ATTRIBUTE>, Pointer<Void>)
sk_X509_ATTRIBUTE_free_func = Pointer<NativeFunction<sk_X509_ATTRIBUTE_free_funcFunction>>
sk_X509_ATTRIBUTE_free_funcFunction = Void Function(Pointer<X509_ATTRIBUTE>)
sk_X509_cmp_func = Pointer<NativeFunction<sk_X509_cmp_funcFunction>>
sk_X509_cmp_funcFunction = Int Function(Pointer<Pointer<X509>>, Pointer<Pointer<X509>>)
sk_X509_copy_func = Pointer<NativeFunction<sk_X509_copy_funcFunction>>
sk_X509_copy_funcFunction = Pointer<X509> Function(Pointer<X509> x509)
sk_X509_CRL_cmp_func = Pointer<NativeFunction<sk_X509_CRL_cmp_funcFunction>>
sk_X509_CRL_cmp_funcFunction = Int Function(Pointer<Pointer<X509_CRL>>, Pointer<Pointer<X509_CRL>>)
sk_X509_CRL_copy_func = Pointer<NativeFunction<sk_X509_CRL_copy_funcFunction>>
sk_X509_CRL_copy_funcFunction = Pointer<X509_CRL> Function(Pointer<X509_CRL> crl)
sk_X509_CRL_delete_if_func = Pointer<NativeFunction<sk_X509_CRL_delete_if_funcFunction>>
sk_X509_CRL_delete_if_funcFunction = Int Function(Pointer<X509_CRL>, Pointer<Void>)
sk_X509_CRL_free_func = Pointer<NativeFunction<sk_X509_CRL_free_funcFunction>>
Certificate revocation lists.
sk_X509_CRL_free_funcFunction = Void Function(Pointer<X509_CRL>)
sk_X509_delete_if_func = Pointer<NativeFunction<sk_X509_delete_if_funcFunction>>
sk_X509_delete_if_funcFunction = Int Function(Pointer<X509>, Pointer<Void>)
sk_X509_EXTENSION_cmp_func = Pointer<NativeFunction<sk_X509_EXTENSION_cmp_funcFunction>>
sk_X509_EXTENSION_cmp_funcFunction = Int Function(Pointer<Pointer<X509_EXTENSION>>, Pointer<Pointer<X509_EXTENSION>>)
sk_X509_EXTENSION_copy_func = Pointer<NativeFunction<sk_X509_EXTENSION_copy_funcFunction>>
sk_X509_EXTENSION_copy_funcFunction = Pointer<X509_EXTENSION> Function(Pointer<X509_EXTENSION> ex)
sk_X509_EXTENSION_delete_if_func = Pointer<NativeFunction<sk_X509_EXTENSION_delete_if_funcFunction>>
sk_X509_EXTENSION_delete_if_funcFunction = Int Function(Pointer<X509_EXTENSION>, Pointer<Void>)
sk_X509_EXTENSION_free_func = Pointer<NativeFunction<sk_X509_EXTENSION_free_funcFunction>>
sk_X509_EXTENSION_free_funcFunction = Void Function(Pointer<X509_EXTENSION>)
sk_X509_free_func = Pointer<NativeFunction<sk_X509_free_funcFunction>>
Certificates.
sk_X509_free_funcFunction = Void Function(Pointer<X509>)
sk_X509_INFO_cmp_func = Pointer<NativeFunction<sk_X509_INFO_cmp_funcFunction>>
sk_X509_INFO_cmp_funcFunction = Int Function(Pointer<Pointer<X509_INFO>>, Pointer<Pointer<X509_INFO>>)
sk_X509_INFO_copy_func = Pointer<NativeFunction<sk_X509_INFO_copy_funcFunction>>
sk_X509_INFO_copy_funcFunction = Pointer<X509_INFO> Function(Pointer<X509_INFO>)
sk_X509_INFO_delete_if_func = Pointer<NativeFunction<sk_X509_INFO_delete_if_funcFunction>>
sk_X509_INFO_delete_if_funcFunction = Int Function(Pointer<X509_INFO>, Pointer<Void>)
sk_X509_INFO_free_func = Pointer<NativeFunction<sk_X509_INFO_free_funcFunction>>
sk_X509_INFO_free_funcFunction = Void Function(Pointer<X509_INFO>)
sk_X509_NAME_cmp_func = Pointer<NativeFunction<sk_X509_NAME_cmp_funcFunction>>
sk_X509_NAME_cmp_funcFunction = Int Function(Pointer<Pointer<X509_NAME>>, Pointer<Pointer<X509_NAME>>)
sk_X509_NAME_copy_func = Pointer<NativeFunction<sk_X509_NAME_copy_funcFunction>>
sk_X509_NAME_copy_funcFunction = Pointer<X509_NAME> Function(Pointer<X509_NAME> name)
sk_X509_NAME_delete_if_func = Pointer<NativeFunction<sk_X509_NAME_delete_if_funcFunction>>
sk_X509_NAME_delete_if_funcFunction = Int Function(Pointer<X509_NAME>, Pointer<Void>)
sk_X509_NAME_ENTRY_cmp_func = Pointer<NativeFunction<sk_X509_NAME_ENTRY_cmp_funcFunction>>
sk_X509_NAME_ENTRY_cmp_funcFunction = Int Function(Pointer<Pointer<X509_NAME_ENTRY>>, Pointer<Pointer<X509_NAME_ENTRY>>)
sk_X509_NAME_ENTRY_copy_func = Pointer<NativeFunction<sk_X509_NAME_ENTRY_copy_funcFunction>>
sk_X509_NAME_ENTRY_copy_funcFunction = Pointer<X509_NAME_ENTRY> Function(Pointer<X509_NAME_ENTRY> entry)
sk_X509_NAME_ENTRY_delete_if_func = Pointer<NativeFunction<sk_X509_NAME_ENTRY_delete_if_funcFunction>>
sk_X509_NAME_ENTRY_delete_if_funcFunction = Int Function(Pointer<X509_NAME_ENTRY>, Pointer<Void>)
sk_X509_NAME_ENTRY_free_func = Pointer<NativeFunction<sk_X509_NAME_ENTRY_free_funcFunction>>
sk_X509_NAME_ENTRY_free_funcFunction = Void Function(Pointer<X509_NAME_ENTRY>)
sk_X509_NAME_free_func = Pointer<NativeFunction<sk_X509_NAME_free_funcFunction>>
sk_X509_NAME_free_funcFunction = Void Function(Pointer<X509_NAME>)
sk_X509_OBJECT_cmp_func = Pointer<NativeFunction<sk_X509_OBJECT_cmp_funcFunction>>
sk_X509_OBJECT_cmp_funcFunction = Int Function(Pointer<Pointer<X509_OBJECT>>, Pointer<Pointer<X509_OBJECT>>)
sk_X509_OBJECT_copy_func = Pointer<NativeFunction<sk_X509_OBJECT_copy_funcFunction>>
sk_X509_OBJECT_copy_funcFunction = Pointer<X509_OBJECT> Function(Pointer<X509_OBJECT>)
sk_X509_OBJECT_delete_if_func = Pointer<NativeFunction<sk_X509_OBJECT_delete_if_funcFunction>>
sk_X509_OBJECT_delete_if_funcFunction = Int Function(Pointer<X509_OBJECT>, Pointer<Void>)
sk_X509_OBJECT_free_func = Pointer<NativeFunction<sk_X509_OBJECT_free_funcFunction>>
sk_X509_OBJECT_free_funcFunction = Void Function(Pointer<X509_OBJECT>)
sk_X509_REVOKED_cmp_func = Pointer<NativeFunction<sk_X509_REVOKED_cmp_funcFunction>>
sk_X509_REVOKED_cmp_funcFunction = Int Function(Pointer<Pointer<X509_REVOKED>>, Pointer<Pointer<X509_REVOKED>>)
sk_X509_REVOKED_copy_func = Pointer<NativeFunction<sk_X509_REVOKED_copy_funcFunction>>
sk_X509_REVOKED_copy_funcFunction = Pointer<X509_REVOKED> Function(Pointer<X509_REVOKED> rev)
sk_X509_REVOKED_delete_if_func = Pointer<NativeFunction<sk_X509_REVOKED_delete_if_funcFunction>>
sk_X509_REVOKED_delete_if_funcFunction = Int Function(Pointer<X509_REVOKED>, Pointer<Void>)
sk_X509_REVOKED_free_func = Pointer<NativeFunction<sk_X509_REVOKED_free_funcFunction>>
sk_X509_REVOKED_free_funcFunction = Void Function(Pointer<X509_REVOKED>)
SPAKE2_CTX = spake2_ctx_st
SRTP_PROTECTION_PROFILE = srtp_protection_profile_st
ssize_t = __ssize_t
SSL = ssl_st
SSL_CIPHER = ssl_cipher_st
SSL_CLIENT_HELLO = ssl_early_callback_ctx
SSL_CREDENTIAL = ssl_credential_st
SSL_CTX = ssl_ctx_st
SSL_ECH_KEYS = ssl_ech_keys_st
SSL_METHOD = ssl_method_st
SSL_PRIVATE_KEY_METHOD = ssl_private_key_method_st
SSL_QUIC_METHOD = ssl_quic_method_st
SSL_SESSION = ssl_session_st
SSL_TICKET_AEAD_METHOD = ssl_ticket_aead_method_st
suseconds_t = __suseconds_t
time_t = __time_t
timer_t = __timer_t
TRUST_TOKEN = trust_token_st
TRUST_TOKEN_CLIENT = trust_token_client_st
TRUST_TOKEN_ISSUER = trust_token_issuer_st
TRUST_TOKEN_METHOD = trust_token_method_st
u_char = __u_char
u_int = __u_int
u_int16_t = __uint16_t
u_int32_t = __uint32_t
u_int64_t = __uint64_t
u_int8_t = __uint8_t
u_long = __u_long
u_quad_t = __u_quad_t
u_short = __u_short
uid_t = __uid_t
uint = UnsignedInt
uint_fast16_t = UnsignedLong
uint_fast32_t = UnsignedLong
uint_fast64_t = UnsignedLong
uint_fast8_t = UnsignedChar
uint_least16_t = __uint_least16_t
uint_least32_t = __uint_least32_t
uint_least64_t = __uint_least64_t
uint_least8_t = __uint_least8_t
uintmax_t = __uintmax_t
ulong = UnsignedLong
USERNOTICE = USERNOTICE_st
ushort = UnsignedShort
X509 = x509_st
X509_ALGOR = X509_algor_st
X509_ATTRIBUTE = x509_attributes_st
X509_CRL = X509_crl_st
X509_EXTENSION = X509_extension_st
X509_EXTENSIONS = stack_st_X509_EXTENSION
X509_INFO = X509_info_st
X509_LOOKUP = x509_lookup_st
X509_LOOKUP_METHOD = x509_lookup_method_st
X509_NAME = X509_name_st
X509_NAME_ENTRY = X509_name_entry_st
X509_OBJECT = x509_object_st
X509_PKEY = private_key_st
X509_PUBKEY = X509_pubkey_st
X509_PURPOSE = x509_purpose_st
X509_REQ = X509_req_st
X509_REVOKED = x509_revoked_st
X509_SIG = X509_sig_st
X509_STORE = x509_store_st
X509_STORE_CTX = x509_store_ctx_st
X509_STORE_CTX_verify_cb = Pointer<NativeFunction<Int Function(Int ok, Pointer<X509_STORE_CTX> ctx)>>
X509_STORE_CTX_verify_cbFunction = Int Function(Int ok, Pointer<X509_STORE_CTX> ctx)
X509_VERIFY_PARAM = X509_VERIFY_PARAM_st
X509V3_CTX = v3_ext_ctx
X509V3_EXT_D2I = Pointer<NativeFunction<X509V3_EXT_D2IFunction>>
X509V3_EXT_D2IFunction = Pointer<Void> Function(Pointer<Void> ext, Pointer<Pointer<Uint8>> inp, Long len)
X509V3_EXT_FREE = Pointer<NativeFunction<OPENSSL_sk_free_funcFunction>>
X509V3_EXT_FREEFunction = Void Function(Pointer<Void> ptr)
X509V3_EXT_I2D = Pointer<NativeFunction<X509V3_EXT_I2DFunction>>
X509V3_EXT_I2DFunction = Int Function(Pointer<Void> ext, Pointer<Pointer<Uint8>> outp)
X509V3_EXT_I2R = Pointer<NativeFunction<X509V3_EXT_I2RFunction>>
X509V3_EXT_I2RFunction = Int Function(Pointer<X509V3_EXT_METHOD> method, Pointer<Void> ext, Pointer<BIO> out, Int indent)
X509V3_EXT_I2S = Pointer<NativeFunction<X509V3_EXT_I2SFunction>>
X509V3_EXT_I2SFunction = Pointer<Char> Function(Pointer<X509V3_EXT_METHOD> method, Pointer<Void> ext)
X509V3_EXT_I2V = Pointer<NativeFunction<X509V3_EXT_I2VFunction>>
X509V3_EXT_I2VFunction = Pointer<stack_st_CONF_VALUE> Function(Pointer<X509V3_EXT_METHOD> method, Pointer<Void> ext, Pointer<stack_st_CONF_VALUE> extlist)
X509V3_EXT_METHOD = v3_ext_method
X509V3_EXT_NEW = Pointer<NativeFunction<X509V3_EXT_NEWFunction>>
The following function pointer types are used in |X509V3_EXT_METHOD|.
X509V3_EXT_NEWFunction = Pointer<Void> Function()
X509V3_EXT_R2I = Pointer<NativeFunction<X509V3_EXT_R2IFunction>>
X509V3_EXT_R2IFunction = Pointer<Void> Function(Pointer<X509V3_EXT_METHOD> method, Pointer<X509V3_CTX> ctx, Pointer<Char> str)
X509V3_EXT_S2I = Pointer<NativeFunction<X509V3_EXT_R2IFunction>>
X509V3_EXT_S2IFunction = Pointer<Void> Function(Pointer<X509V3_EXT_METHOD> method, Pointer<X509V3_CTX> ctx, Pointer<Char> str)
X509V3_EXT_V2I = Pointer<NativeFunction<X509V3_EXT_V2IFunction>>
X509V3_EXT_V2IFunction = Pointer<Void> Function(Pointer<X509V3_EXT_METHOD> method, Pointer<X509V3_CTX> ctx, Pointer<stack_st_CONF_VALUE> values)