1 | =pod
|
---|
2 |
|
---|
3 | =head1 NAME
|
---|
4 |
|
---|
5 | i2t_ASN1_OBJECT,
|
---|
6 | OBJ_length, OBJ_get0_data, OBJ_nid2obj, OBJ_nid2ln,
|
---|
7 | OBJ_nid2sn, OBJ_obj2nid, OBJ_txt2nid, OBJ_ln2nid, OBJ_sn2nid, OBJ_cmp,
|
---|
8 | OBJ_dup, OBJ_txt2obj, OBJ_obj2txt, OBJ_create, OBJ_cleanup, OBJ_add_sigid
|
---|
9 | - ASN1 object utility functions
|
---|
10 |
|
---|
11 | =head1 SYNOPSIS
|
---|
12 |
|
---|
13 | #include <openssl/objects.h>
|
---|
14 |
|
---|
15 | ASN1_OBJECT *OBJ_nid2obj(int n);
|
---|
16 | const char *OBJ_nid2ln(int n);
|
---|
17 | const char *OBJ_nid2sn(int n);
|
---|
18 |
|
---|
19 | int OBJ_obj2nid(const ASN1_OBJECT *o);
|
---|
20 | int OBJ_ln2nid(const char *ln);
|
---|
21 | int OBJ_sn2nid(const char *sn);
|
---|
22 |
|
---|
23 | int OBJ_txt2nid(const char *s);
|
---|
24 |
|
---|
25 | ASN1_OBJECT *OBJ_txt2obj(const char *s, int no_name);
|
---|
26 | int OBJ_obj2txt(char *buf, int buf_len, const ASN1_OBJECT *a, int no_name);
|
---|
27 |
|
---|
28 | int i2t_ASN1_OBJECT(char *buf, int buf_len, const ASN1_OBJECT *a);
|
---|
29 |
|
---|
30 | int OBJ_cmp(const ASN1_OBJECT *a, const ASN1_OBJECT *b);
|
---|
31 | ASN1_OBJECT *OBJ_dup(const ASN1_OBJECT *o);
|
---|
32 |
|
---|
33 | int OBJ_create(const char *oid, const char *sn, const char *ln);
|
---|
34 |
|
---|
35 | size_t OBJ_length(const ASN1_OBJECT *obj);
|
---|
36 | const unsigned char *OBJ_get0_data(const ASN1_OBJECT *obj);
|
---|
37 |
|
---|
38 | int OBJ_add_sigid(int signid, int dig_id, int pkey_id);
|
---|
39 |
|
---|
40 | The following function has been deprecated since OpenSSL 1.1.0, and can be
|
---|
41 | hidden entirely by defining B<OPENSSL_API_COMPAT> with a suitable version value,
|
---|
42 | see L<openssl_user_macros(7)>:
|
---|
43 |
|
---|
44 | void OBJ_cleanup(void);
|
---|
45 |
|
---|
46 | =head1 DESCRIPTION
|
---|
47 |
|
---|
48 | The ASN1 object utility functions process ASN1_OBJECT structures which are
|
---|
49 | a representation of the ASN1 OBJECT IDENTIFIER (OID) type.
|
---|
50 | For convenience, OIDs are usually represented in source code as numeric
|
---|
51 | identifiers, or B<NID>s. OpenSSL has an internal table of OIDs that
|
---|
52 | are generated when the library is built, and their corresponding NIDs
|
---|
53 | are available as defined constants. For the functions below, application
|
---|
54 | code should treat all returned values -- OIDs, NIDs, or names -- as
|
---|
55 | constants.
|
---|
56 |
|
---|
57 | OBJ_nid2obj(), OBJ_nid2ln() and OBJ_nid2sn() convert the NID I<n> to
|
---|
58 | an ASN1_OBJECT structure, its long name and its short name respectively,
|
---|
59 | or B<NULL> if an error occurred.
|
---|
60 |
|
---|
61 | OBJ_obj2nid(), OBJ_ln2nid(), OBJ_sn2nid() return the corresponding NID
|
---|
62 | for the object I<o>, the long name I<ln> or the short name I<sn> respectively
|
---|
63 | or NID_undef if an error occurred.
|
---|
64 |
|
---|
65 | OBJ_txt2nid() returns NID corresponding to text string I<s>. I<s> can be
|
---|
66 | a long name, a short name or the numerical representation of an object.
|
---|
67 |
|
---|
68 | OBJ_txt2obj() converts the text string I<s> into an ASN1_OBJECT structure.
|
---|
69 | If I<no_name> is 0 then long names and short names will be interpreted
|
---|
70 | as well as numerical forms. If I<no_name> is 1 only the numerical form
|
---|
71 | is acceptable.
|
---|
72 |
|
---|
73 | OBJ_obj2txt() converts the B<ASN1_OBJECT> I<a> into a textual representation.
|
---|
74 | Unless I<buf> is NULL,
|
---|
75 | the representation is written as a NUL-terminated string to I<buf>, where
|
---|
76 | at most I<buf_len> bytes are written, truncating the result if necessary.
|
---|
77 | In any case it returns the total string length, excluding the NUL character,
|
---|
78 | required for non-truncated representation, or -1 on error.
|
---|
79 | If I<no_name> is 0 then if the object has a long or short name
|
---|
80 | then that will be used, otherwise the numerical form will be used.
|
---|
81 | If I<no_name> is 1 then the numerical form will always be used.
|
---|
82 |
|
---|
83 | i2t_ASN1_OBJECT() is the same as OBJ_obj2txt() with the I<no_name> set to zero.
|
---|
84 |
|
---|
85 | OBJ_cmp() compares I<a> to I<b>. If the two are identical 0 is returned.
|
---|
86 |
|
---|
87 | OBJ_dup() returns a copy of I<o>.
|
---|
88 |
|
---|
89 | OBJ_create() adds a new object to the internal table. I<oid> is the
|
---|
90 | numerical form of the object, I<sn> the short name and I<ln> the
|
---|
91 | long name. A new NID is returned for the created object in case of
|
---|
92 | success and NID_undef in case of failure.
|
---|
93 |
|
---|
94 | OBJ_length() returns the size of the content octets of I<obj>.
|
---|
95 |
|
---|
96 | OBJ_get0_data() returns a pointer to the content octets of I<obj>.
|
---|
97 | The returned pointer is an internal pointer which B<must not> be freed.
|
---|
98 |
|
---|
99 | OBJ_add_sigid() creates a new composite "Signature Algorithm" that associates a
|
---|
100 | given NID with two other NIDs - one representing the underlying signature
|
---|
101 | algorithm and the other representing a digest algorithm to be used in
|
---|
102 | conjunction with it. I<signid> represents the NID for the composite "Signature
|
---|
103 | Algorithm", I<dig_id> is the NID for the digest algorithm and I<pkey_id> is the
|
---|
104 | NID for the underlying signature algorithm.
|
---|
105 |
|
---|
106 | OBJ_cleanup() releases any resources allocated by creating new objects.
|
---|
107 |
|
---|
108 | =head1 NOTES
|
---|
109 |
|
---|
110 | Objects in OpenSSL can have a short name, a long name and a numerical
|
---|
111 | identifier (NID) associated with them. A standard set of objects is
|
---|
112 | represented in an internal table. The appropriate values are defined
|
---|
113 | in the header file B<objects.h>.
|
---|
114 |
|
---|
115 | For example the OID for commonName has the following definitions:
|
---|
116 |
|
---|
117 | #define SN_commonName "CN"
|
---|
118 | #define LN_commonName "commonName"
|
---|
119 | #define NID_commonName 13
|
---|
120 |
|
---|
121 | New objects can be added by calling OBJ_create().
|
---|
122 |
|
---|
123 | Table objects have certain advantages over other objects: for example
|
---|
124 | their NIDs can be used in a C language switch statement. They are
|
---|
125 | also static constant structures which are shared: that is there
|
---|
126 | is only a single constant structure for each table object.
|
---|
127 |
|
---|
128 | Objects which are not in the table have the NID value NID_undef.
|
---|
129 |
|
---|
130 | Objects do not need to be in the internal tables to be processed,
|
---|
131 | the functions OBJ_txt2obj() and OBJ_obj2txt() can process the numerical
|
---|
132 | form of an OID.
|
---|
133 |
|
---|
134 | Some objects are used to represent algorithms which do not have a
|
---|
135 | corresponding ASN.1 OBJECT IDENTIFIER encoding (for example no OID currently
|
---|
136 | exists for a particular algorithm). As a result they B<cannot> be encoded or
|
---|
137 | decoded as part of ASN.1 structures. Applications can determine if there
|
---|
138 | is a corresponding OBJECT IDENTIFIER by checking OBJ_length() is not zero.
|
---|
139 |
|
---|
140 | These functions cannot return B<const> because an B<ASN1_OBJECT> can
|
---|
141 | represent both an internal, constant, OID and a dynamically-created one.
|
---|
142 | The latter cannot be constant because it needs to be freed after use.
|
---|
143 |
|
---|
144 | =head1 RETURN VALUES
|
---|
145 |
|
---|
146 | OBJ_nid2obj() returns an B<ASN1_OBJECT> structure or B<NULL> is an
|
---|
147 | error occurred.
|
---|
148 |
|
---|
149 | OBJ_nid2ln() and OBJ_nid2sn() returns a valid string or B<NULL>
|
---|
150 | on error.
|
---|
151 |
|
---|
152 | OBJ_obj2nid(), OBJ_ln2nid(), OBJ_sn2nid() and OBJ_txt2nid() return
|
---|
153 | a NID or B<NID_undef> on error.
|
---|
154 |
|
---|
155 | OBJ_add_sigid() returns 1 on success or 0 on error.
|
---|
156 |
|
---|
157 | i2t_ASN1_OBJECT() an OBJ_obj2txt() return -1 on error.
|
---|
158 | On success, they return the length of the string written to I<buf> if I<buf> is
|
---|
159 | not NULL and I<buf_len> is big enough, otherwise the total string length.
|
---|
160 | Note that this does not count the trailing NUL character.
|
---|
161 |
|
---|
162 | =head1 EXAMPLES
|
---|
163 |
|
---|
164 | Create an object for B<commonName>:
|
---|
165 |
|
---|
166 | ASN1_OBJECT *o = OBJ_nid2obj(NID_commonName);
|
---|
167 |
|
---|
168 | Check if an object is B<commonName>
|
---|
169 |
|
---|
170 | if (OBJ_obj2nid(obj) == NID_commonName)
|
---|
171 | /* Do something */
|
---|
172 |
|
---|
173 | Create a new NID and initialize an object from it:
|
---|
174 |
|
---|
175 | int new_nid = OBJ_create("1.2.3.4", "NewOID", "New Object Identifier");
|
---|
176 | ASN1_OBJECT *obj = OBJ_nid2obj(new_nid);
|
---|
177 |
|
---|
178 | Create a new object directly:
|
---|
179 |
|
---|
180 | obj = OBJ_txt2obj("1.2.3.4", 1);
|
---|
181 |
|
---|
182 | =head1 BUGS
|
---|
183 |
|
---|
184 | Neither OBJ_create() nor OBJ_add_sigid() do any locking and are thus not
|
---|
185 | thread safe. Moreover, none of the other functions should be called while
|
---|
186 | concurrent calls to these two functions are possible.
|
---|
187 |
|
---|
188 | =head1 SEE ALSO
|
---|
189 |
|
---|
190 | L<ERR_get_error(3)>
|
---|
191 |
|
---|
192 | =head1 HISTORY
|
---|
193 |
|
---|
194 | OBJ_cleanup() was deprecated in OpenSSL 1.1.0 by L<OPENSSL_init_crypto(3)>
|
---|
195 | and should not be used.
|
---|
196 |
|
---|
197 | =head1 COPYRIGHT
|
---|
198 |
|
---|
199 | Copyright 2002-2021 The OpenSSL Project Authors. All Rights Reserved.
|
---|
200 |
|
---|
201 | Licensed under the Apache License 2.0 (the "License"). You may not use
|
---|
202 | this file except in compliance with the License. You can obtain a copy
|
---|
203 | in the file LICENSE in the source distribution or at
|
---|
204 | L<https://www.openssl.org/source/license.html>.
|
---|
205 |
|
---|
206 | =cut
|
---|