X509_VERIFY_PARAM_set_trust function
- @RecordUse.new()
- @Native<Int Function(Pointer<
X509_VERIFY_PARAM> , Int)>(ffi.Pointer<X509_VERIFY_PARAM>, ffi.Int)>(symbol: 'bssl_dart_X509_VERIFY_PARAM_set_trust')
- Pointer<
X509_VERIFY_PARAM> param, - int trust
X509_VERIFY_PARAM_set_trust configures which certificates from |X509_STORE| are trust anchors. It returns one on success and zero if |trust| is not a valid trust value. |trust| should be one of the |X509_TRUST_*| constants. This function allows applications to vary trust anchors when the same set of trusted certificates is used in multiple contexts.
Two properties determine whether a certificate is a trust anchor:
-
Whether it is trusted or distrusted for some OID, via auxiliary information configured by |X509_add1_trust_object| or |X509_add1_reject_object|.
-
Whether it is "self-signed". That is, whether |X509_get_extension_flags| includes |EXFLAG_SS|. The signature itself is not checked.
When this function is called, |trust| determines the OID to check in the first case. If the certificate is not explicitly trusted or distrusted for any OID, it is trusted if self-signed instead.
If unset, the default behavior is to check for the |NID_anyExtendedKeyUsage| OID. If the certificate is not explicitly trusted or distrusted for this OID, it is trusted if self-signed instead. Note this slightly differs from the above.
If the |X509_V_FLAG_PARTIAL_CHAIN| is set, every certificate from |X509_STORE| is a trust anchor, unless it was explicitly distrusted for the OID.
It is currently not possible to configure custom trust OIDs. Contact the BoringSSL maintainers if your application needs to do so. OpenSSL had an |X509_TRUST_add| API, but it was not thread-safe and relied on global mutable state, so we removed it.
Implementation
@meta.RecordUse()
@ffi.Native<ffi.Int Function(ffi.Pointer<X509_VERIFY_PARAM>, ffi.Int)>(
symbol: 'bssl_dart_X509_VERIFY_PARAM_set_trust',
)
external int X509_VERIFY_PARAM_set_trust(
ffi.Pointer<X509_VERIFY_PARAM> param,
int trust,
);