QSC Post Quantum Cryptographic Library 1.1.0.2 (B2)
A post quantum secure library written in Ansi C
Loading...
Searching...
No Matches
x509verify.h
Go to the documentation of this file.
1/* 2020-2026 Quantum Resistant Cryptographic Solutions Corporation
2 * All Rights Reserved.
3 *
4 * NOTICE:
5 * This software and all accompanying materials are the exclusive property of
6 * Quantum Resistant Cryptographic Solutions Corporation (QRCS). The intellectual
7 * and technical concepts contained herein are proprietary to QRCS and are
8 * protected under applicable Canadian, U.S., and international copyright,
9 * patent, and trade secret laws.
10 *
11 * CRYPTOGRAPHIC ALGORITHMS AND IMPLEMENTATIONS:
12 * - This software includes implementations of cryptographic primitives and
13 * algorithms that are standardized or in the public domain, such as AES
14 * and SHA-3, which are not proprietary to QRCS.
15 * - This software also includes cryptographic primitives, constructions, and
16 * algorithms designed by QRCS, including but not limited to RCS, SCB, CSX, QMAC, and
17 * related components, which are proprietary to QRCS.
18 * - All source code, implementations, protocol compositions, optimizations,
19 * parameter selections, and engineering work contained in this software are
20 * original works of QRCS and are protected under this license.
21 *
22 * LICENSE AND USE RESTRICTIONS:
23 * - This software is licensed under the Quantum Resistant Cryptographic Solutions
24 * Public Research and Evaluation License (QRCS-PREL), 2025-2026.
25 * - Permission is granted solely for non-commercial evaluation, academic research,
26 * cryptographic analysis, interoperability testing, and feasibility assessment.
27 * - Commercial use, production deployment, commercial redistribution, or
28 * integration into products or services is strictly prohibited without a
29 * separate written license agreement executed with QRCS.
30 * - Licensing and authorized distribution are solely at the discretion of QRCS.
31 *
32 * EXPERIMENTAL CRYPTOGRAPHY NOTICE:
33 * Portions of this software may include experimental, novel, or evolving
34 * cryptographic designs. Use of this software is entirely at the user's risk.
35 *
36 * DISCLAIMER:
37 * THIS SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
38 * IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS
39 * FOR A PARTICULAR PURPOSE, SECURITY, OR NON-INFRINGEMENT. QRCS DISCLAIMS ALL
40 * LIABILITY FOR ANY DIRECT, INDIRECT, INCIDENTAL, OR CONSEQUENTIAL DAMAGES
41 * ARISING FROM THE USE OR MISUSE OF THIS SOFTWARE.
42 *
43 * FULL LICENSE:
44 * This software is subject to the Quantum Resistant Cryptographic Solutions
45 * Public Research and Evaluation License (QRCS-PREL), 2025-2026. The complete license terms
46 * are provided in the accompanying LICENSE file or at https://www.qrcscorp.ca.
47 *
48 * Written by: John G. Underhill
49 * Contact: contact@qrcscorp.ca
50 */
51
52#ifndef QSC_X509_VERIFY_H
53#define QSC_X509_VERIFY_H
54
55#include "qsccommon.h"
56#include "x509types.h"
57#include "x509time.h"
58#include "x509rev.h"
59
60QSC_CPLUSPLUS_ENABLED_START
61
73
102
117typedef bool (*qsc_x509_signature_verify_callback)(const qsc_x509_certificate* certificate, const qsc_x509_certificate* issuer, void* state);
118
129
145
158
170QSC_EXPORT_API bool qsc_x509_certificate_is_self_issued(const qsc_x509_certificate* certificate);
171
186QSC_EXPORT_API bool qsc_x509_certificate_is_self_signed(const qsc_x509_certificate* certificate, qsc_x509_signature_verify_callback callback, void* state);
187
199QSC_EXPORT_API bool qsc_x509_certificate_is_ca(const qsc_x509_certificate* certificate);
200
212QSC_EXPORT_API bool qsc_x509_certificate_allows_server_auth(const qsc_x509_certificate* certificate);
213
225QSC_EXPORT_API bool qsc_x509_certificate_allows_client_auth(const qsc_x509_certificate* certificate);
226
240QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_structure(const qsc_x509_certificate* certificate);
241
253QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_algorithms(const qsc_x509_certificate* certificate);
254
267QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_validity(const qsc_x509_certificate* certificate, const qsc_asn1_time* ascnow);
268
281QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_purpose(const qsc_x509_certificate* certificate, qsc_x509_verify_purpose purpose);
282
295QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_hostname(const qsc_x509_certificate* certificate, const char* hostname);
296
310QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_ip_address(const qsc_x509_certificate* certificate, const uint8_t* address, size_t addresslen);
311
325QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_issuer(const qsc_x509_certificate* issuer, const qsc_x509_certificate* subject, size_t remainingdepth);
326
343QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_verify(const qsc_x509_certificate* certificate, const qsc_x509_certificate* issuer, const qsc_asn1_time* now, qsc_x509_signature_verify_callback callback, void* state);
344
357QSC_EXPORT_API bool qsc_x509_chain_is_anchored(const qsc_x509_chain* chain, const qsc_x509_store* store);
358
375QSC_EXPORT_API qsc_x509_verify_status qsc_x509_chain_verify(const qsc_x509_chain* chain, const qsc_x509_store* store, const qsc_asn1_time* now, qsc_x509_signature_verify_callback callback, void* state);
376
394QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_verify_ex(const qsc_x509_certificate* certificate, const qsc_x509_certificate* issuer,
395 const qsc_asn1_time* now, qsc_x509_signature_verify_callback callback, void* state, const qsc_x509_verify_options* options);
396
414QSC_EXPORT_API qsc_x509_verify_status qsc_x509_chain_verify_ex(const qsc_x509_chain* chain, const qsc_x509_store* store,
415 const qsc_asn1_time* now, qsc_x509_signature_verify_callback callback, void* state, const qsc_x509_verify_options* options);
416
417QSC_CPLUSPLUS_ENABLED_END
418
419#endif
QSC_EXPORT_API struct qsc_asn1_time_t qsc_asn1_time
A normalized ASN.1 time representation.
Contains common definitions for the Quantum Secure Cryptographic (QSC) library.
#define QSC_EXPORT_API
API export macro for Microsoft compilers when importing from a DLL.
Definition qsccommon.h:605
Revocation checking configuration options.
Definition x509verify.h:140
const qsc_x509_revocation_options * revocation
Definition x509verify.h:142
bool rejectunsupportedcriticalextensions
Definition x509verify.h:143
qsc_x509_verify_purpose purpose
Definition x509verify.h:141
Optional controls for extended certificate and chain verification.
X.509 revocation policy and CRL-based certificate status checking interface.
X.509 time decoding, parsing, comparison, and validity helpers.
QSC_EXPORT_API bool qsc_x509_chain_is_anchored(const qsc_x509_chain *chain, const qsc_x509_store *store)
Test whether a chain terminates at a trusted anchor.
Definition x509verify.c:1187
QSC_EXPORT_API bool qsc_x509_certificate_allows_server_auth(const qsc_x509_certificate *certificate)
Test whether a certificate allows TLS server authentication.
Definition x509verify.c:606
qsc_x509_verify_purpose_t
Definition x509verify.h:124
@ QSC_X509_VERIFY_PURPOSE_GENERIC
Definition x509verify.h:125
@ QSC_X509_VERIFY_PURPOSE_TLS_SERVER
Definition x509verify.h:126
@ QSC_X509_VERIFY_PURPOSE_TLS_CLIENT
Definition x509verify.h:127
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_chain_verify_ex(const qsc_x509_chain *chain, const qsc_x509_store *store, const qsc_asn1_time *now, qsc_x509_signature_verify_callback callback, void *state, const qsc_x509_verify_options *options)
Verify a certification chain using extended options.
Definition x509verify.c:1031
QSC_EXPORT_API void qsc_x509_verify_options_initialize(qsc_x509_verify_options *options)
Initialize a verification options structure.
Definition x509verify.c:530
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_hostname(const qsc_x509_certificate *certificate, const char *hostname)
Check whether a certificate matches a hostname.
Definition x509verify.c:851
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_structure(const qsc_x509_certificate *certificate)
Check RFC-aligned certificate structural invariants.
Definition x509verify.c:671
QSC_EXPORT_API bool qsc_x509_certificate_allows_client_auth(const qsc_x509_certificate *certificate)
Test whether a certificate allows TLS client authentication.
Definition x509verify.c:639
QSC_EXPORT_API bool qsc_x509_certificate_is_self_issued(const qsc_x509_certificate *certificate)
Test whether a certificate is self-issued.
Definition x509verify.c:542
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_issuer(const qsc_x509_certificate *issuer, const qsc_x509_certificate *subject, size_t remainingdepth)
Check whether one certificate may issue another.
Definition x509verify.c:873
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_verify(const qsc_x509_certificate *certificate, const qsc_x509_certificate *issuer, const qsc_asn1_time *now, qsc_x509_signature_verify_callback callback, void *state)
Verify a certificate against its issuer.
Definition x509verify.c:1209
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_validity(const qsc_x509_certificate *certificate, const qsc_asn1_time *ascnow)
Check certificate validity at a supplied time.
Definition x509verify.c:767
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_algorithms(const qsc_x509_certificate *certificate)
Check certificate algorithm consistency.
Definition x509verify.c:732
QSC_EXPORT_API bool qsc_x509_certificate_is_self_signed(const qsc_x509_certificate *certificate, qsc_x509_signature_verify_callback callback, void *state)
Test whether a certificate is self-signed.
Definition x509verify.c:561
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_ip_address(const qsc_x509_certificate *certificate, const uint8_t *address, size_t addresslen)
Check whether a certificate matches an IP address.
Definition x509verify.c:862
bool(* qsc_x509_signature_verify_callback)(const qsc_x509_certificate *certificate, const qsc_x509_certificate *issuer, void *state)
Caller-supplied certificate signature verification callback.
Definition x509verify.h:117
QSC_EXPORT_API bool qsc_x509_certificate_is_ca(const qsc_x509_certificate *certificate)
Test whether a certificate is authorized to act as a CA.
Definition x509verify.c:581
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_verify_ex(const qsc_x509_certificate *certificate, const qsc_x509_certificate *issuer, const qsc_asn1_time *now, qsc_x509_signature_verify_callback callback, void *state, const qsc_x509_verify_options *options)
Verify a certificate against its issuer using extended options.
Definition x509verify.c:933
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_purpose(const qsc_x509_certificate *certificate, qsc_x509_verify_purpose purpose)
Check certificate suitability for a requested purpose.
Definition x509verify.c:813
qsc_x509_verify_status_t
Definition x509verify.h:79
@ QSC_X509_VERIFY_STATUS_NOT_YET_VALID
Definition x509verify.h:85
@ QSC_X509_VERIFY_STATUS_SIGNATURE_REJECTED
Definition x509verify.h:91
@ QSC_X509_VERIFY_STATUS_PATH_LENGTH_EXCEEDED
Definition x509verify.h:89
@ QSC_X509_VERIFY_STATUS_SUCCESS
Definition x509verify.h:80
@ QSC_X509_VERIFY_STATUS_NOT_CA
Definition x509verify.h:88
@ QSC_X509_VERIFY_STATUS_CHAIN_LOOP
Definition x509verify.h:99
@ QSC_X509_VERIFY_STATUS_TRUST_NOT_FOUND
Definition x509verify.h:92
@ QSC_X509_VERIFY_STATUS_UNSUPPORTED_CRITICAL_EXTENSION
Definition x509verify.h:95
@ QSC_X509_VERIFY_STATUS_EXPIRED
Definition x509verify.h:84
@ QSC_X509_VERIFY_STATUS_ALGORITHM_MISMATCH
Definition x509verify.h:83
@ QSC_X509_VERIFY_STATUS_KEY_USAGE_REJECTED
Definition x509verify.h:90
@ QSC_X509_VERIFY_STATUS_NAME_MISMATCH
Definition x509verify.h:100
@ QSC_X509_VERIFY_STATUS_INVALID_CERTIFICATE
Definition x509verify.h:82
@ QSC_X509_VERIFY_STATUS_REVOKED
Definition x509verify.h:97
@ QSC_X509_VERIFY_STATUS_PURPOSE_REJECTED
Definition x509verify.h:96
@ QSC_X509_VERIFY_STATUS_KEY_IDENTIFIER_MISMATCH
Definition x509verify.h:87
@ QSC_X509_VERIFY_STATUS_ISSUER_MISMATCH
Definition x509verify.h:86
@ QSC_X509_VERIFY_STATUS_INVALID_INPUT
Definition x509verify.h:81
@ QSC_X509_VERIFY_STATUS_UNSUPPORTED
Definition x509verify.h:93
@ QSC_X509_VERIFY_STATUS_REVOCATION_UNKNOWN
Definition x509verify.h:98
@ QSC_X509_VERIFY_STATUS_CALLBACK_FAILURE
Definition x509verify.h:94
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_chain_verify(const qsc_x509_chain *chain, const qsc_x509_store *store, const qsc_asn1_time *now, qsc_x509_signature_verify_callback callback, void *state)
Verify a certification chain.
Definition x509verify.c:1215