52#ifndef QSC_X509_VERIFY_H
53#define QSC_X509_VERIFY_H
60QSC_CPLUSPLUS_ENABLED_START
101} qsc_x509_verify_status;
128} qsc_x509_verify_purpose;
417QSC_CPLUSPLUS_ENABLED_END
QSC_EXPORT_API struct qsc_asn1_time_t qsc_asn1_time
A normalized ASN.1 time representation.
Contains common definitions for the Quantum Secure Cryptographic (QSC) library.
#define QSC_EXPORT_API
API export macro for Microsoft compilers when importing from a DLL.
Definition qsccommon.h:605
Revocation checking configuration options.
Definition x509verify.h:140
const qsc_x509_revocation_options * revocation
Definition x509verify.h:142
bool rejectunsupportedcriticalextensions
Definition x509verify.h:143
qsc_x509_verify_purpose purpose
Definition x509verify.h:141
Optional controls for extended certificate and chain verification.
X.509 revocation policy and CRL-based certificate status checking interface.
X.509 time decoding, parsing, comparison, and validity helpers.
QSC_EXPORT_API bool qsc_x509_chain_is_anchored(const qsc_x509_chain *chain, const qsc_x509_store *store)
Test whether a chain terminates at a trusted anchor.
Definition x509verify.c:1187
QSC_EXPORT_API bool qsc_x509_certificate_allows_server_auth(const qsc_x509_certificate *certificate)
Test whether a certificate allows TLS server authentication.
Definition x509verify.c:606
qsc_x509_verify_purpose_t
Definition x509verify.h:124
@ QSC_X509_VERIFY_PURPOSE_GENERIC
Definition x509verify.h:125
@ QSC_X509_VERIFY_PURPOSE_TLS_SERVER
Definition x509verify.h:126
@ QSC_X509_VERIFY_PURPOSE_TLS_CLIENT
Definition x509verify.h:127
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_chain_verify_ex(const qsc_x509_chain *chain, const qsc_x509_store *store, const qsc_asn1_time *now, qsc_x509_signature_verify_callback callback, void *state, const qsc_x509_verify_options *options)
Verify a certification chain using extended options.
Definition x509verify.c:1031
QSC_EXPORT_API void qsc_x509_verify_options_initialize(qsc_x509_verify_options *options)
Initialize a verification options structure.
Definition x509verify.c:530
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_hostname(const qsc_x509_certificate *certificate, const char *hostname)
Check whether a certificate matches a hostname.
Definition x509verify.c:851
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_structure(const qsc_x509_certificate *certificate)
Check RFC-aligned certificate structural invariants.
Definition x509verify.c:671
QSC_EXPORT_API bool qsc_x509_certificate_allows_client_auth(const qsc_x509_certificate *certificate)
Test whether a certificate allows TLS client authentication.
Definition x509verify.c:639
QSC_EXPORT_API bool qsc_x509_certificate_is_self_issued(const qsc_x509_certificate *certificate)
Test whether a certificate is self-issued.
Definition x509verify.c:542
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_issuer(const qsc_x509_certificate *issuer, const qsc_x509_certificate *subject, size_t remainingdepth)
Check whether one certificate may issue another.
Definition x509verify.c:873
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_verify(const qsc_x509_certificate *certificate, const qsc_x509_certificate *issuer, const qsc_asn1_time *now, qsc_x509_signature_verify_callback callback, void *state)
Verify a certificate against its issuer.
Definition x509verify.c:1209
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_validity(const qsc_x509_certificate *certificate, const qsc_asn1_time *ascnow)
Check certificate validity at a supplied time.
Definition x509verify.c:767
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_algorithms(const qsc_x509_certificate *certificate)
Check certificate algorithm consistency.
Definition x509verify.c:732
QSC_EXPORT_API bool qsc_x509_certificate_is_self_signed(const qsc_x509_certificate *certificate, qsc_x509_signature_verify_callback callback, void *state)
Test whether a certificate is self-signed.
Definition x509verify.c:561
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_ip_address(const qsc_x509_certificate *certificate, const uint8_t *address, size_t addresslen)
Check whether a certificate matches an IP address.
Definition x509verify.c:862
bool(* qsc_x509_signature_verify_callback)(const qsc_x509_certificate *certificate, const qsc_x509_certificate *issuer, void *state)
Caller-supplied certificate signature verification callback.
Definition x509verify.h:117
QSC_EXPORT_API bool qsc_x509_certificate_is_ca(const qsc_x509_certificate *certificate)
Test whether a certificate is authorized to act as a CA.
Definition x509verify.c:581
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_verify_ex(const qsc_x509_certificate *certificate, const qsc_x509_certificate *issuer, const qsc_asn1_time *now, qsc_x509_signature_verify_callback callback, void *state, const qsc_x509_verify_options *options)
Verify a certificate against its issuer using extended options.
Definition x509verify.c:933
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_certificate_check_purpose(const qsc_x509_certificate *certificate, qsc_x509_verify_purpose purpose)
Check certificate suitability for a requested purpose.
Definition x509verify.c:813
qsc_x509_verify_status_t
Definition x509verify.h:79
@ QSC_X509_VERIFY_STATUS_NOT_YET_VALID
Definition x509verify.h:85
@ QSC_X509_VERIFY_STATUS_SIGNATURE_REJECTED
Definition x509verify.h:91
@ QSC_X509_VERIFY_STATUS_PATH_LENGTH_EXCEEDED
Definition x509verify.h:89
@ QSC_X509_VERIFY_STATUS_SUCCESS
Definition x509verify.h:80
@ QSC_X509_VERIFY_STATUS_NOT_CA
Definition x509verify.h:88
@ QSC_X509_VERIFY_STATUS_CHAIN_LOOP
Definition x509verify.h:99
@ QSC_X509_VERIFY_STATUS_TRUST_NOT_FOUND
Definition x509verify.h:92
@ QSC_X509_VERIFY_STATUS_UNSUPPORTED_CRITICAL_EXTENSION
Definition x509verify.h:95
@ QSC_X509_VERIFY_STATUS_EXPIRED
Definition x509verify.h:84
@ QSC_X509_VERIFY_STATUS_ALGORITHM_MISMATCH
Definition x509verify.h:83
@ QSC_X509_VERIFY_STATUS_KEY_USAGE_REJECTED
Definition x509verify.h:90
@ QSC_X509_VERIFY_STATUS_NAME_MISMATCH
Definition x509verify.h:100
@ QSC_X509_VERIFY_STATUS_INVALID_CERTIFICATE
Definition x509verify.h:82
@ QSC_X509_VERIFY_STATUS_REVOKED
Definition x509verify.h:97
@ QSC_X509_VERIFY_STATUS_PURPOSE_REJECTED
Definition x509verify.h:96
@ QSC_X509_VERIFY_STATUS_KEY_IDENTIFIER_MISMATCH
Definition x509verify.h:87
@ QSC_X509_VERIFY_STATUS_ISSUER_MISMATCH
Definition x509verify.h:86
@ QSC_X509_VERIFY_STATUS_INVALID_INPUT
Definition x509verify.h:81
@ QSC_X509_VERIFY_STATUS_UNSUPPORTED
Definition x509verify.h:93
@ QSC_X509_VERIFY_STATUS_REVOCATION_UNKNOWN
Definition x509verify.h:98
@ QSC_X509_VERIFY_STATUS_CALLBACK_FAILURE
Definition x509verify.h:94
QSC_EXPORT_API qsc_x509_verify_status qsc_x509_chain_verify(const qsc_x509_chain *chain, const qsc_x509_store *store, const qsc_asn1_time *now, qsc_x509_signature_verify_callback callback, void *state)
Verify a certification chain.
Definition x509verify.c:1215