Types
Name |
Description |
AccessDescription: access method OID and GeneralName location (RFC 5280 AIA/SIA). |
|
RFC 3779 AS identifier: either a single AS number or an ASRange. |
|
RFC 3779 choice between inheriting AS identifiers and listing them explicitly. |
|
RFC 3779 ASIdentifiers extension: AS numbers and routing domain identifiers. |
|
Saved DER encoding of an ASN.1 value, used when re‐emitting the original bytes (for example so invalid encodings do not break signatures). |
|
Opaque ASN.1 item descriptor used by the generic encode/decode/print APIs. |
|
Opaque field descriptor used when building ASN.1 ITEM templates. |
|
Opaque ASN.1 tag/length cache (struct ASN1_TLC_st) used while decoding constructed types; layout is private to the ASN.1 implementation. |
|
Opaque ASN.1 value handle used by generic item encode/decode and S/MIME helpers. |
|
Inclusive Autonomous System Number range used in RFC 3779 ASIdentifiers. |
|
X.509v3 AuthorityKeyIdentifier extension value. |
|
Common PKI AdmissionSyntax extension: admission authority and contents of admissions. |
|
One admissions entry in Common PKI AdmissionSyntax (authority and profession infos). |
|
Basic Constraints extension: whether the subject is a CA and optional path length. |
|
Output union for BIO_sock_info(); currently holds a BIO_ADDR pointer. |
|
Mapping of a named bit in an ASN.1 BIT STRING to its bit number. |
|
Opaque CMAC (Cipher‐based MAC) context (deprecated; prefer EVP_MAC). |
|
One certificate choice in a CMS SignedData certificates set (X.509, attribute, or other). |
|
Top‐level Cryptographic Message Syntax (CMS) ContentInfo structure. |
|
Opaque CMS EnvelopedData: recipient infos and encrypted content info. |
|
Optional other‐key‐attribute identifying material in a CMS KEK RecipientInfo. |
|
ESS receipt request attribute carried on a CMS SignerInfo. |
|
ESS signed receipt content verifying that a signed message was received. |
|
Encrypted key for one recipient in a CMS key‐agreement (KARI) RecipientInfo. |
|
Per‐recipient information in a CMS EnvelopedData or AuthEnvelopedData message. |
|
One revocation‐info choice in a CMS SignedData crls set (CRL or other). |
|
CMS SignedData content: digest algorithms, content, certificates, CRLs, and signer infos. |
|
Opaque CMS SignerInfo: per‐signer algorithms, sid, signed/unsigned attrs, and signature. |
|
One configuration entry: section, name, and string value. |
|
Legacy placeholder type once used for dynamic lock callbacks (deprecated). |
|
Legacy DES expanded key schedule (sixteen round subkeys; prefer EVP). |
|
Distribution point name: either a full GeneralNames set or a relative name. |
|
Opaque CRL distribution‐point structure from a certificate extension. |
|
Opaque DSA signature value holding the ASN.1 integers r and s. |
|
Opaque ECDSA signature holding the integers r and s. |
|
Built‐in named curve entry (NID plus a short description). |
|
EDI party name form of a GeneralName (nameAssigner optional, partyName required). |
|
Describes one ENGINE‐specific control command for ENGINE_set_cmd_defns(). |
|
Mapping from a packed OpenSSL error code to a human‐readable string. |
|
ESS CertID: SHA‐1 hash identifying a signing certificate (RFC 2634). |
|
ESS CertIDv2: hash identifying a signing certificate with a chosen digest (RFC 5035). |
|
ESS IssuerSerial: certificate issuer name and serial number (RFC 2634). |
|
ESS SigningCertificate attribute listing CertIDs for the signer chain (RFC 2634). |
|
ESS SigningCertificateV2 attribute with CertIDv2 entries (RFC 5035). |
|
|
Parameters for TLS 1.1 AES multiblock EVP_CIPHER_CTX_ctrl operations. |
X.509 GeneralName: one alternative name form selected by |
|
Name Constraints subtree: a base GeneralName with optional minimum/maximum. |
|
RFC 3779 choice between inheriting IP address blocks and listing them. |
|
RFC 3779 IP address family entry: AFI/SAFI octets plus an address choice. |
|
RFC 3779 IP address: either a prefix or an explicit address range. |
|
Inclusive IP address range encoded as bit strings (RFC 3779). |
|
Issuer Signing Tool extension naming signing and CA tools and their certificates. |
|
Opaque Issuing Distribution Point extension value (CRL IDP). |
|
Incremental MD4 digest state (also typedef'd as MD4_CTX); deprecated low‐level API. |
|
Incremental MD5 digest state (also typedef'd as MD5_CTX); deprecated low‐level API. |
|
Opaque Name Constraints extension value (permitted/excluded subtrees). |
|
Notice reference: organization name and notice numbers for a user notice qualifier. |
|
Naming authority identifying who issues profession or admission attributes (Common PKI). |
|
Netscape Certificate Sequence: a type OID plus a stack of certificates. |
|
Netscape Signed Public Key And Challenge (SPKAC) request body. |
|
Netscape SPKI: an SPKAC plus the signature algorithm and signature bits. |
|
HPKE cipher suite identifying the KEM, KDF, and AEAD algorithms (RFC 9180). |
|
PKCS#5 PBES2 parameters: key‐derivation function and encryption scheme. |
|
PKCS#5 PBES1 password‐based encryption parameters (salt and iteration count). |
|
PKCS#5 PBKDF2 parameters: salt, iteration count, optional key length, and PRF. |
|
MAC salt, iteration count, and digest algorithm for a PKCS#12 PFX integrity check. |
|
One PKCS#12 safeBag holding a certificate, key, CRL, secret, or nested safeContents. |
|
Top‐level PKCS#12 PFX structure (version, authSafes, and optional MAC). |
|
Library/provider context carried by PKCS#7 objects when fetching algorithms. |
|
Private key usage period extension giving the interval when the key is valid. |
|
Single certificate policy: policy OID plus optional qualifiers. |
|
Certificate policy qualifier: CPS URI, user notice, or other typed value. |
|
Policy Constraints extension: requireExplicitPolicy and inhibitPolicyMapping skip counts. |
|
Mapping from an issuer domain policy OID to a subject domain policy OID. |
|
Proxy Certificate Information extension (RFC 3820): path length and proxy policy. |
|
Proxy certificate policy: language OID and optional policy octets (RFC 3820). |
|
Profession information: naming authority, profession items/OIDs, and registration number. |
|
Legacy RIPEMD‐160 hashing context (deprecated; prefer EVP_MD APIs). |
|
PKCS#5 scrypt password‐based key derivation parameters. |
|
Incremental SHA‐224 / SHA‐256 digest state (also typedef'd as SHA256_CTX); deprecated low‐level API. |
|
Incremental SHA‐384 / SHA‐512 digest state (also typedef'd as SHA512_CTX). |
|
Incremental SHA‐1 digest state (also typedef'd as SHA_CTX); deprecated low‐level API. |
|
In‐memory SRP verifier database loaded from a verifier file. |
|
Cache entry mapping a base64‐encoded SRP group parameter to a BIGNUM. |
|
Named SRP group parameters (generator |
|
SRP verifier database entry for one user (salt, verifier, and group parameters). |
|
Strong Extranet (SXNET) zone and user identifier pair. |
|
Strong Extranet (SXNET) certificate extension value. |
|
RFC 3161 Accuracy: optional seconds, millis, and micros time precision. |
|
RFC 3161 MessageImprint: hash algorithm and hashed message octets. |
|
RFC 3161 TimeStampReq: version, message imprint, policy, nonce, and extensions. |
|
Opaque context used while generating RFC 3161 time‐stamp responses. |
|
RFC 3161 TimeStampResp: status info and optional signed time‐stamp token. |
|
RFC 3161 PKIStatusInfo: status, optional statusString, and failureInfo. |
|
RFC 3161 TSTInfo: policy, imprint, serial, time, accuracy, and TSA fields. |
|
Opaque context holding flags and expected values for time‐stamp verification. |
|
User notice policy qualifier: optional notice reference and explicit text. |
|
Incremental WHIRLPOOL digest state (deprecated; prefer EVP_MD APIs). |
|
Callback table for reading configuration database sections used by X509v3 helpers. |
|
Opaque cache of processed certificate policy data used during path validation. |
|
Opaque single depth level within an X.509 certificate policy tree. |
|
Opaque node in an X.509 certificate policy tree. |
|
Opaque X.509 certificate policy tree built during path validation (RFC 5280). |
|
Opaque verification‐parameter object (purpose, trust, time, flags, …). |
|
Opaque ASN.1 AlgorithmIdentifier (algorithm OID plus optional parameters). |
|
Opaque TBSCertList / CRL info structure inside an X509_CRL. |
|
Opaque X.509 certificate revocation list. |
|
Opaque X.509 extension object (OID, criticality, and octet‐string value). |
|
Bundle of certificate, CRL, and/or encrypted private key as found in PEM info files. |
|
Single Relative Distinguished Name attribute (type OID plus value) within an X509_NAME. |
|
Opaque X.509 distinguished name (SEQUENCE OF RelativeDistinguishedName). |
|
Opaque SubjectPublicKeyInfo container (algorithm + public key BIT STRING). |
|
Opaque TBSCertificateRequest / certification request info inside an X509_REQ. |
|
Opaque PKCS#10 certification request (CertificateRequest). |
|
Opaque DigestInfo / encrypted‐key structure used by PKCS#8 and related APIs. |
|
Validity period (notBefore / notAfter) used inside X.509 certificates and CRLs. |
|
Expanded AES key schedule for the low‐level AES_* APIs (deprecated; prefer EVP). |
|
Opaque ASN.1 OBJECT IDENTIFIER (OID) value. |
|
Opaque ASN.1 print context controlling formatting flags for item printers. |
|
Opaque ASN.1 scan context used while decoding constructed types. |
|
ASN.1 INTEGER stored in the generic asn1_string_st representation. |
|
Table entry describing size limits and encoding masks for an ASN.1 string NID. |
|
ASN.1 ANY / CHOICE container holding a typed value and its V_ASN1_* tag. |
|
Opaque state for an asynchronous job. |
|
Opaque wait context describing file descriptors an ASYNC_JOB is blocked on. |
|
Legacy Blowfish expanded key schedule (P‐array and S‐boxes). |
|
Temporary‐variable pool used by BIGNUM arithmetic helpers. |
|
Arbitrary‐precision integer used throughout OpenSSL's public‐key math. |
|
Opaque socket address union used by BIO socket and datagram APIs. |
|
Opaque linked address‐info node returned by BIO_lookup() / BIO_lookup_ex(). |
|
Opaque BIO method table describing how a BIO type reads, writes, and controls I/O. |
|
Argument bundle passed to multi‐message BIO callbacks (sendmmsg/recvmmsg). |
|
Single message descriptor for BIO_sendmmsg() / BIO_recvmmsg(). |
|
Pollable I/O target returned by BIO_get_rpoll_descriptor / BIO_get_wpoll_descriptor. |
|
Opaque Basic I/O abstraction (filters and source/sink streams). |
|
Opaque RSA/modular blinding state (BN_BLINDING_*). |
|
Progress‐callback object used by prime generation and similar BN routines. |
|
Montgomery multiplication context for a fixed odd modulus (BN_MONT_CTX_*). |
|
Reciprocal context accelerating repeated modular division/remainder. |
|
Growable memory buffer used by BIO memory BIOs and similar helpers. |
|
Legacy Camellia expanded key schedule (deprecated low‐level type; prefer EVP_CIPHER APIs). |
|
Legacy CAST‐128 expanded key schedule (deprecated low‐level type; prefer EVP). |
|
Opaque context for CRYPTO_ccm128_* Counter with CBC‐MAC helpers. |
|
Opaque compression/decompression stream context used with COMP_METHOD. |
|
Opaque compression method table (zlib, brotli, zstd, and related COMP_* APIs). |
|
Opaque instance of a loaded CONF module (per‐section module state). |
|
Legacy CONF method vtable (deprecated; contents will become opaque). |
|
Opaque registration record for a CONF DSO module implementation. |
|
Opaque NCONF configuration object holding sections and name/value pairs. |
|
Opaque bag of application‐specific ex_data slots attached to OpenSSL objects. |
|
Legacy thread‐id placeholder retained for API compatibility (no longer used). |
|
Opaque Certificate Transparency policy evaluation context. |
|
Opaque Certificate Transparency log identity (public key + description). |
|
Opaque store of Certificate Transparency logs trusted for SCT verification. |
|
Opaque DH method table (deprecated engine‐style DH_METHOD_*). |
|
Opaque Diffie‐Hellman key/parameters object (deprecated low‐level DH_* API). |
|
Opaque DSA_METHOD table of low‐level DSA callbacks (deprecated). |
|
Opaque DSA key/parameters object (deprecated low‐level DSA_* API). |
|
Opaque elliptic‐curve parameter/group object (field, curve equation, and generator). |
|
Opaque method table customizing EC_KEY operations (deprecated ENGINE‐style API). |
|
Opaque elliptic‐curve key containing group parameters and public/private points. |
|
Opaque description of the field arithmetic and curve methods for an EC_GROUP. |
|
Opaque ASN.1 EcpkParameters / ECParameters encoding helper type. |
|
Opaque elliptic‐curve point (coordinates over the field of an EC_GROUP). |
|
ASN.1 EC private‐key parameters CHOICE (named curve OID or explicit ECParameters). |
|
Opaque cryptographic ENGINE handle for legacy algorithm implementations (deprecated; prefer providers). |
|
Opaque per‐thread (or saved) OpenSSL error‐queue state. |
|
Opaque context for EVP_Encode and EVP_Decode base64 streaming. |
|
Opaque asymmetric cipher method (EVP_ASYM_CIPHER_fetch). |
|
Opaque symmetric‐cipher operation context (EVP_EncryptInit and related EVP_Cipher APIs). |
|
Cipher algorithm pointer paired with an initialization vector buffer. |
|
Opaque symmetric cipher method (algorithm implementation) used with EVP_CIPHER_CTX. |
|
Opaque key‐derivation function context (EVP_KDF_CTX_*). |
|
Opaque key‐derivation function method returned by EVP_KDF_fetch(). |
|
Opaque key‐encapsulation mechanism algorithm (EVP_KEM_*). |
|
Opaque key‐exchange algorithm method (EVP_KEYEXCH_fetch). |
|
Opaque key‐management algorithm implementation (provider keymgmt). |
|
Opaque MAC operation context (EVP_MAC_CTX_new / EVP_MAC_init / EVP_MAC_update / EVP_MAC_final). |
|
Opaque MAC algorithm (EVP_MAC_fetch / EVP_Q_mac). |
|
Opaque message‐digest operation context (EVP_Digest* / EVP_DigestSign*). |
|
Opaque message‐digest method (algorithm implementation) used with EVP_MD_CTX. |
|
Opaque ASN.1 method table describing how an EVP_PKEY type is encoded. |
|
Opaque context for public‐key operations (sign, verify, encrypt, derive, keygen, and related controls). |
|
Opaque legacy method table implementing an EVP_PKEY algorithm (deprecated in 3.0). |
|
Opaque public/private key handle used throughout the EVP and X.509 APIs. |
|
Opaque RAND operation context created from an EVP_RAND method. |
|
Opaque random‐number generator method fetched from a provider (DRBG and related). |
|
Opaque signature algorithm method (EVP_SIGNATURE_fetch). |
|
Opaque context for CRYPTO_gcm128_* Galois/Counter Mode helpers. |
|
Opaque HMAC computation context (legacy HMAC_* API). |
|
Resolve |
|
Expanded IDEA key schedule for the low‐level IDEA_* APIs (deprecated; prefer EVP). |
|
Opaque hash‐table node used internally by OPENSSL_LHASH. |
|
Opaque dynamic hash table (LHASH) of void* elements. |
|
Hash table of SSL_SESSION objects used for the internal session cache. |
|
Incremental MDC‐2 digest state (also typedef'd as MDC2_CTX); deprecated low‐level API. |
|
One entry in OpenSSL's name table mapping algorithm names to type‐specific data. |
|
Opaque context for CRYPTO_ocb128_* Offset Codebook Mode helpers. |
|
OCSP BasicOCSPResponse: ResponseData with signature and optional certificates. |
|
OCSP CertID identifying a certificate by issuer name/key hashes and serial (RFC 6960). |
|
OCSP CertStatus CHOICE: good, revoked, or unknown (RFC 6960). |
|
OCSP CrlID extension identifying a CRL by URL, number, or time. |
|
Single OCSP request entry with a CertID and optional extensions (RFC 6960). |
|
OCSP TBSRequest: version, optional requestor name, request list, and extensions. |
|
OCSP Request message containing TBSRequest and optional signature (RFC 6960). |
|
OCSP ResponseBytes: responseType OID and response OCTET STRING payload. |
|
Opaque OCSP ResponderID (byName or byKey). |
|
OCSP ResponseData (tbsResponseData): version, ResponderID, producedAt, and responses. |
|
Opaque OCSP response structure (RFC 6960). |
|
OCSP RevokedInfo: revocation time and optional CRL reason (RFC 6960). |
|
OCSP ServiceLocator extension with issuer name and locator AccessDescriptions. |
|
Optional signature over an OCSP request, with algorithm and certificates. |
|
OCSP SingleResponse for one CertID: status, thisUpdate, nextUpdate, and extensions. |
|
Opaque core‐side library context handle passed across the provider boundary. |
|
Opaque provider algorithm description (name, property, implementation). |
|
CertRepMessage from RFC 4210 section 5.3.3: CA Pubs and certResponse sequence. |
|
CertResponse from RFC 4210 section 5.3.3: certReqId, status, and optional cert/key. |
|
CertStatus from RFC 4210 section 5.3.18: certHash and certReqId for certConf. |
|
Opaque CMP client or server context holding transaction state and options. |
|
Opaque InfoTypeAndValue (ITAV) key‐value pair used in CMP messages (RFC 4210 section 5.3.19). |
|
Opaque PKIMessage structure (PKIHeader and body) from RFC 4210. |
|
Opaque PKIHeader structure for a CMP PKIMessage (RFC 4210 section 5.2). |
|
Opaque PKIStatusInfo structure with status, statusString, and failInfo (RFC 4210 section 5.3.14). |
|
Opaque PollRepContent entry with certReqId, checkAfter, and optional reason (RFC 4210 section 5.3.22). |
|
RevRepContent from RFC 4210 section 5.3.4: status for each certReqId in an RR. |
|
Opaque CMP server context holding callbacks and server‐side state. |
|
Opaque core‐side BIO handle passed across the provider boundary for upcalls. |
|
Opaque core handle passed to a provider's OSSL_provider_init() for upcalls. |
|
AttributeTypeAndValue for CRMF regCtrl or regInfo attributes. |
|
CertId from RFC 4211: issuer GeneralName and certificate serial number. |
|
CertRequest from RFC 4211: certReqId, certTemplate, and optional controls. |
|
CertTemplate from RFC 4211: selected certificate fields for a requested certificate. |
|
EncryptedValue from RFC 4211: optional algorithm identifiers and an encrypted bit string. |
|
CertReqMsg from RFC 4211: certificate request, optional proof‐of‐possession, and optional regInfo. |
|
OptionalValidity from RFC 4211: optional notBefore and notAfter times in a certTemplate. |
|
PBMParameter from RFC 4211: salt, one‐way function, iteration count, and MAC algorithm. |
|
PKIPublicationInfo from RFC 4211 section 6.3: publication action and optional SinglePubInfo list. |
|
POPOSigningKey from RFC 4211: optional POPOSigningKeyInput, algorithm identifier, and signature. |
|
SinglePubInfo from RFC 4211: publication method and optional publication location. |
|
Opaque context that drives OSSL_DECODER providers when decoding keys/objects. |
|
Opaque pairing of an OSSL_DECODER with its per‐instance decoder context during a decode run. |
|
Opaque decoder method that converts external key/cert encodings into OpenSSL objects. |
|
Function‐pointer dispatch table entry exchanged between libcrypto and providers. |
|
Opaque encoder context that drives OSSL_ENCODER output of keys and related objects. |
|
Opaque pairing of an OSSL_ENCODER with its per‐instance encoder context during an encode run. |
|
Opaque encoder method that serializes keys and related objects. |
|
Opaque HPKE session state holding secrets and sequence for sender or receiver role. |
|
Opaque HTTP request context used by OSSL_HTTP_* client helpers. |
|
Opaque OpenSSL library initialization settings passed to OPENSSL_init_crypto(). |
|
Opaque provider item pairing an identifier with a pointer payload. |
|
Opaque library context that scopes providers, properties, and algorithm fetches. |
|
Opaque builder that assembles a dynamic OSSL_PARAM array. |
|
Key/type/data triple used to pass parameters across provider boundaries. |
|
Opaque provider object representing a loaded algorithm implementation module. |
|
Opaque self‐test event object used by provider FIPS self‐test callbacks. |
|
Opaque context for an open OSSL_STORE channel to a URI or BIO. |
|
Opaque object returned by OSSL_STORE describing a loaded key, cert, or CRL. |
|
Opaque per‐open context used by a deprecated ENGINE‐based store loader. |
|
Opaque OSSL_STORE loader implementation for a URI scheme. |
|
Opaque search criterion object used with OSSL_STORE_expect / find APIs. |
|
otherName form of a GeneralName: an OID typed value. |
|
Bag payload choice structure (certBag, crlBag, secretBag, or other ASN.1 value). |
|
PKCS#7 DigestedData content: digest algorithm, encapsulated content, and message digest. |
|
PKCS#7 EncryptedContentInfo: content type, content‐encryption algorithm, and ciphertext. |
|
PKCS#7 EncryptedData content: encrypted content info. |
|
PKCS#7 EnvelopedData content: per‐recipient key infos and encrypted content. |
|
Issuer name and certificate serial number identifying a PKCS#7 signer or recipient. |
|
PKCS#7 RecipientInfo: recipient identity and encrypted content‐encryption key. |
|
PKCS#7 SignedData content: digests, optional certificates/CRLs, signer infos, and encapsulated content. |
|
PKCS#7 SignedAndEnvelopedData content: digests, optional certificates/CRLs, signer infos, per‐recipient key infos, and encrypted content. |
|
PKCS#7 SignerInfo: identity, digest/signature algorithms, attributes, and signature. |
|
PKCS#7 ContentInfo container holding typed content and related state. |
|
Opaque PKCS#8 PrivateKeyInfo structure (RFC 5208). |
|
PKCS#8 encrypted private key container used with PEM reading/writing. |
|
Legacy deterministic random bit generator handle (deprecated; prefer EVP_RAND). |
|
Legacy RAND method table (deprecated; prefer EVP_RAND providers). |
|
Expanded RC2 key schedule used by the deprecated low‐level RC2_* encryptors. |
|
Legacy RC4 key stream state (deprecated; prefer EVP_CIPHER APIs). |
|
Opaque RSA method table for ENGINE‐style RSA implementations (deprecated). |
|
Opaque RSAES‐OAEP parameter structure (hashFunc / maskGenFunc / pSourceFunc). |
|
Opaque RSASSA‐PSS parameter structure (hashAlg / maskGenAlg / saltLength / trailerField). |
|
Opaque RSA key object (deprecated; prefer EVP_PKEY). |
|
Opaque context used when verifying Certificate Transparency SCTs. |
|
Opaque Certificate Transparency Signed Certificate Timestamp. |
|
Legacy SEED expanded key schedule (deprecated low‐level type; prefer EVP). |
|
SRTP protection profile for the use_srtp DTLS extension (RFC 5764). |
|
Opaque description of an SSL/TLS cipher suite. |
|
Opaque SSL/TLS compression method entry. |
|
Opaque configuration context used with the SSL_CONF_* command API. |
|
Information describing why and how a QUIC connection was closed. |
|
Opaque TLS/DTLS/QUIC context holding shared configuration and certificates. |
|
Opaque DANE (DNS‐based Authentication of Named Entities) state for TLS. |
|
Opaque SSL/TLS protocol method table used with SSL_CTX_new and related APIs. |
|
One pollable resource and event masks for an SSL_poll() array entry. |
|
Opaque SSL/TLS session state used for resumption and caching. |
|
Extended arguments for SSL_shutdown_ex() (currently QUIC‐specific). |
|
Opaque TLS/DTLS/QUIC connection object. |
|
Arguments for SSL_stream_reset() describing how a QUIC stream is aborted. |
|
Memory‐management callbacks passed into a dynamically loaded ENGINE. |
|
Callbacks and static‐state cookie passed when binding a dynamic ENGINE. |
|
Opaque generic pointer stack; prefer the typed STACK_OF(...) wrappers. |
|
Opaque STACK_OF(ACCESS_DESCRIPTION) container type. |
|
Opaque STACK_OF(ADMISSIONS) container type. |
|
Opaque STACK_OF(ASIdOrRange) container type. |
|
Opaque STACK_OF(ASN1_GENERALSTRING) container type. |
|
Opaque STACK_OF(ASN1_INTEGER) container type. |
|
Opaque STACK_OF(ASN1_STRING_TABLE) container type. |
|
Opaque STACK_OF(ASN1_TYPE) container type. |
|
Opaque STACK_OF(ASN1_UTF8STRING) container type. |
|
STACK_OF container for mutable BIGNUM pointers. |
|
STACK_OF container for const BIGNUM pointers. |
|
Opaque STACK_OF(BIO) container type. |
|
Opaque STACK_OF(CMS_RevocationInfoChoice) container type. |
|
Opaque STACK_OF(CMS_SignerInfo) container type. |
|
Opaque STACK_OF(CONF_IMODULE) container type for per‐section module instances. |
|
Opaque STACK_OF(CONF_MODULE) container type for loaded DSO configuration modules. |
|
Opaque STACK_OF(CTLOG) container type. |
|
Opaque STACK_OF(DIST_POINT) container type. |
|
Opaque STACK_OF(GENERAL_NAME) container type. |
|
Opaque STACK_OF(GENERAL_NAMES) container type. |
|
Opaque STACK_OF(GENERAL_SUBTREE) container type. |
|
Opaque STACK_OF(IPAddressFamily) container type. |
|
Opaque STACK_OF(IPAddressOrRange) container type. |
|
|
|
Opaque STACK_OF(PKCS7) container type. |
|
Opaque STACK_OF(PKCS7_RECIP_INFO) container type. |
|
Opaque STACK_OF(POLICYINFO) container type. |
|
Opaque STACK_OF(POLICY_MAPPING) container type. |
|
Opaque STACK_OF(PROFESSION_INFO) container type. |
|
|
Opaque STACK_OF(SRTP_PROTECTION_PROFILE) container type. |
Opaque STACK_OF(SSL_COMP) container type. |
|
Opaque STACK_OF(SXNETID) container type. |
|
Opaque STACK_OF(UI_STRING) container type. |
|
Opaque STACK_OF(X509V3_EXT_METHOD) container type. |
|
Opaque STACK_OF(X509_CRL) container type. |
|
Opaque STACK_OF(X509_LOOKUP) container type. |
|
Opaque STACK_OF(X509_NAME_ENTRY) container type. |
|
Opaque STACK_OF(X509_PURPOSE) container type. |
|
Opaque STACK_OF(X509_REVOKED) container type. |
|
Opaque STACK_OF(X509_TRUST) container type. |
|
Opaque STACK_OF(X509_VERIFY_PARAM) container type. |
|
TLS session‐ticket extension payload (length plus opaque data bytes). |
|
Opaque container for TLS signature algorithm preferences. |
|
In‐memory text database parsed from newline‐separated, comma‐separated rows. |
|
Opaque UI_METHOD table implementing interactive user prompting. |
|
Opaque interactive user‐interface object used with UI_METHOD prompting. |
|
Prompt or output string entry stored in a UI for method writers to consume. |
|
Opaque context passed to X.509v3 extension helpers (issuer/subject/cert/request). |
|
Method table describing encode/decode/print behaviour for one X.509v3 extension NID. |
|
Opaque X.509 Attribute (AttributeTypeAndValue sequence) used in CSRs and PKCS#12. |
|
Auxiliary trust/reject OID lists and related metadata attached to an X509. |
|
Opaque TBSCertificate structure holding the unsigned certificate fields. |
|
Opaque method table customizing CRL lookup/verification behaviour. |
|
Opaque method table describing how an X509_LOOKUP finds certificates/CRLs. |
|
Opaque certificate/CRL lookup method instance attached to an X509_STORE. |
|
Opaque X509_STORE cache entry holding a certificate or CRL. |
|
Certificate purpose entry used by X509_check_purpose and related helpers. |
|
Opaque single revoked‐certificate entry within an X509_CRL. |
|
Opaque signature metadata (security bits / TLS usage flags) for an X.509 signature. |
|
Opaque X.509 certificate (RFC 5280 Certificate). |
|
Opaque certificate‐verification context (one chain validation attempt). |
|
Opaque trust store of certificates and CRLs used during verification. |
|
Entry describing a named X.509 trust purpose and its checker callback. |
|
Opaque context holding the two keys used by CRYPTO_xts128_encrypt(). |
Type Aliases
Name |
Description |
AccessDescription: access method OID and GeneralName location (RFC 5280 AIA/SIA). |
|
One admissions entry in Common PKI AdmissionSyntax (authority and profession infos). |
|
Common PKI AdmissionSyntax extension: admission authority and contents of admissions. |
|
Expanded AES key schedule for the low‐level AES_* APIs (deprecated; prefer EVP). |
|
RFC 3779 AS identifier: either a single AS number or an ASRange. |
|
Stack of ASIdOrRange values used in an ASIdentifierChoice. |
|
RFC 3779 choice between inheriting AS identifiers and listing them explicitly. |
|
RFC 3779 ASIdentifiers extension: AS numbers and routing domain identifiers. |
|
ASN.1 BIT STRING stored in the generic asn1_string_st representation. |
|
ASN.1 BMPString (UCS‐2 / Basic Multilingual Plane) stored as an asn1_string_st. |
|
ASN.1 BOOLEAN represented as an int (‐1 unset, 0 FALSE, 0xff TRUE). |
|
Saved DER encoding of an ASN.1 value, used when re‐emitting the original bytes (for example so invalid encodings do not break signatures). |
|
ASN.1 ENUMERATED stored in the generic asn1_string_st representation. |
|
ASN.1 GeneralizedTime value stored as an asn1_string_st. |
|
ASN.1 GeneralString stored in the generic asn1_string_st representation. |
|
ASN.1 IA5String stored in the generic asn1_string_st representation. |
|
ASN.1 INTEGER stored in the generic asn1_string_st representation. |
|
Opaque ASN.1 item descriptor used by the generic encode/decode/print APIs. |
|
Function type that returns a pointer to a static ASN1_ITEM descriptor. |
|
ASN.1 NULL placeholder type (no payload). |
|
Opaque ASN.1 OBJECT IDENTIFIER (OID) value. |
|
ASN.1 OCTET STRING stored in the generic asn1_string_st representation. |
|
Opaque ASN.1 print context controlling formatting flags for item printers. |
|
ASN.1 PrintableString stored as an asn1_string_st. |
|
Opaque ASN.1 scan context used while decoding constructed types. |
|
Stack of ASN1_TYPE values representing SEQUENCE OF ANY or SET OF ANY. |
|
Generic ASN.1 string container (length, type, and data bytes). |
|
Table entry describing size limits and encoding masks for an ASN.1 string NID. |
|
ASN.1 TeletexString/T61String stored as an asn1_string_st. |
|
Opaque field descriptor used when building ASN.1 ITEM templates. |
|
ASN.1 Time choice (UTCTime or GeneralizedTime) stored as an asn1_string_st. |
|
Opaque ASN.1 tag/length cache (struct ASN1_TLC_st) used while decoding constructed types; layout is private to the ASN.1 implementation. |
|
ASN.1 ANY / CHOICE container holding a typed value and its V_ASN1_* tag. |
|
ASN.1 UniversalString stored as an asn1_string_st. |
|
ASN.1 UTCTime value stored as an asn1_string_st. |
|
ASN.1 UTF8String stored as an asn1_string_st. |
|
Opaque ASN.1 value handle used by generic item encode/decode and S/MIME helpers. |
|
ASN.1 VisibleString stored in the generic asn1_string_st representation. |
|
Inclusive Autonomous System Number range used in RFC 3779 ASIdentifiers. |
|
Opaque state for an asynchronous job. |
|
Opaque wait context describing file descriptors an ASYNC_JOB is blocked on. |
|
Callback invoked when an asynchronous wait context is ready. |
|
Allocate a stack for an asynchronous job (POSIX custom stack allocator). |
|
Free a stack previously returned by an ASYNC_stack_alloc_fn callback. |
|
Authority Information Access extension: stack of ACCESS_DESCRIPTION entries. |
|
X.509v3 AuthorityKeyIdentifier extension value. |
|
Basic Constraints extension: whether the subject is a CA and optional path length. |
|
Legacy Blowfish expanded key schedule (P‐array and S‐boxes). |
|
Arbitrary‐precision integer used throughout OpenSSL's public‐key math. |
|
Opaque Basic I/O abstraction (filters and source/sink streams). |
|
Opaque socket address union used by BIO socket and datagram APIs. |
|
Opaque linked address‐info node returned by BIO_lookup() / BIO_lookup_ex(). |
|
Opaque BIO method table describing how a BIO type reads, writes, and controls I/O. |
|
Argument bundle passed to multi‐message BIO callbacks (sendmmsg/recvmmsg). |
|
Single message descriptor for BIO_sendmmsg() / BIO_recvmmsg(). |
|
Pollable I/O target returned by BIO_get_rpoll_descriptor / BIO_get_wpoll_descriptor. |
|
Legacy BIO callback invoked immediately before and after I/O operations (deprecated). |
|
Extended BIO callback invoked immediately before and after I/O operations. |
|
|
Callback invoked when an SCTP datagram BIO receives a notification message. |
Ctrl‐style info callback type used with BIO_callback_ctrl() / BIO_set_info_callback(). |
|
Mapping of a named bit in an ASN.1 BIT STRING to its bit number. |
|
Opaque RSA/modular blinding state (BN_BLINDING_*). |
|
Temporary‐variable pool used by BIGNUM arithmetic helpers. |
|
Progress‐callback object used by prime generation and similar BN routines. |
|
Montgomery multiplication context for a fixed odd modulus (BN_MONT_CTX_*). |
|
Reciprocal context accelerating repeated modular division/remainder. |
|
Growable memory buffer used by BIO memory BIOs and similar helpers. |
|
Typedef alias for struct camellia_key_st used by the deprecated Camellia_* primitives. |
|
Legacy CAST‐128 expanded key schedule (deprecated low‐level type; prefer EVP). |
|
Opaque context for CRYPTO_ccm128_* Counter with CBC‐MAC helpers. |
|
Certificate Policies extension: stack of POLICYINFO entries. |
|
Opaque CMAC (Cipher‐based MAC) context (deprecated; prefer EVP_MAC). |
|
One certificate choice in a CMS SignedData certificates set (X.509, attribute, or other). |
|
Top‐level Cryptographic Message Syntax (CMS) ContentInfo structure. |
|
Opaque CMS EnvelopedData: recipient infos and encrypted content info. |
|
Optional other‐key‐attribute identifying material in a CMS KEK RecipientInfo. |
|
ESS signed receipt content verifying that a signed message was received. |
|
ESS receipt request attribute carried on a CMS SignerInfo. |
|
Encrypted key for one recipient in a CMS key‐agreement (KARI) RecipientInfo. |
|
Per‐recipient information in a CMS EnvelopedData or AuthEnvelopedData message. |
|
One revocation‐info choice in a CMS SignedData crls set (CRL or other). |
|
CMS SignedData content: digest algorithms, content, certificates, CRLs, and signer infos. |
|
Opaque CMS SignerInfo: per‐signer algorithms, sid, signed/unsigned attrs, and signature. |
|
Opaque compression/decompression stream context used with COMP_METHOD. |
|
Opaque compression method table (zlib, brotli, zstd, and related COMP_* APIs). |
|
Opaque NCONF configuration object holding sections and name/value pairs. |
|
Opaque instance of a loaded CONF module (per‐section module state). |
|
Legacy CONF vtable type (see struct conf_method_st in conftypes.h). |
|
Opaque registration record for a CONF DSO module implementation. |
|
CRL Distribution Points extension: stack of DIST_POINT entries. |
|
Opaque bag of application‐specific ex_data slots attached to OpenSSL objects. |
|
Callback that duplicates one ex_data slot when an object is copied. |
|
Callback invoked when an ex_data slot is freed or the owning object is destroyed. |
|
Callback invoked when a new ex_data slot is first associated with an object. |
|
Once‐control type used with CRYPTO_THREAD_run_once() on POSIX builds. |
|
Opaque read/write lock used by CRYPTO_THREAD_* and CRYPTO_atomic_* helpers. |
|
Legacy thread‐id placeholder retained for API compatibility (no longer used). |
|
Platform thread identifier used by CRYPTO_THREAD_get_current_id() and friends. |
|
Platform thread‐local storage key used by CRYPTO_THREAD_*_local(). |
|
Deallocator callback type used by CRYPTO_set_mem_functions(). |
|
Allocator callback type used by CRYPTO_set_mem_functions(). |
|
Reallocator callback type used by CRYPTO_set_mem_functions(). |
|
Opaque Certificate Transparency log identity (public key + description). |
|
Opaque store of Certificate Transparency logs trusted for SCT verification. |
|
Opaque Certificate Transparency policy evaluation context. |
|
Host unsigned word type used by low‐level DES block primitives. |
|
Eight‐byte DES block (key or data) used by the legacy DES_* APIs. |
|
Legacy DES expanded key schedule (sixteen round subkeys; prefer EVP). |
|
Opaque Diffie‐Hellman key/parameters object (deprecated low‐level DH_* API). |
|
Opaque DH method table (deprecated engine‐style DH_METHOD_*). |
|
Opaque CRL distribution‐point structure from a certificate extension. |
|
Distribution point name: either a full GeneralNames set or a relative name. |
|
Opaque DSA key/parameters object (deprecated low‐level DSA_* API). |
|
Opaque DSA_METHOD table of low‐level DSA callbacks (deprecated). |
|
Opaque DSA signature value holding the ASN.1 integers r and s. |
|
Callback that chooses the next DTLS retransmission timeout in microseconds. |
|
Opaque ECDSA signature holding the integers r and s. |
|
Opaque ASN.1 EcpkParameters / ECParameters encoding helper type. |
|
ASN.1 EC private‐key parameters CHOICE (named curve OID or explicit ECParameters). |
|
Opaque elliptic‐curve parameter/group object (field, curve equation, and generator). |
|
Opaque elliptic‐curve key containing group parameters and public/private points. |
|
Opaque method table customizing EC_KEY operations (deprecated ENGINE‐style API). |
|
Opaque description of the field arithmetic and curve methods for an EC_GROUP. |
|
Opaque elliptic‐curve point (coordinates over the field of an EC_GROUP). |
|
EDI party name form of a GeneralName (nameAssigner optional, partyName required). |
|
Opaque cryptographic ENGINE handle for legacy algorithm implementations (deprecated; prefer providers). |
|
ENGINE ciphers handler: list supported NIDs or return an EVP_CIPHER for a NID. |
|
Describes one ENGINE‐specific control command for ENGINE_set_cmd_defns(). |
|
ENGINE control‐command handler (same calling convention as ENGINE_ctrl()). |
|
ENGINE digests handler: list supported NIDs or return an EVP_MD for a NID. |
|
Generic ENGINE callback with no parameters. |
|
Generic ENGINE callback receiving the ENGINE being operated on. |
|
Callback that loads a key from an ENGINE‐backed store. |
|
ENGINE ASN.1 method handler: list supported NIDs or return an EVP_PKEY_ASN1_METHOD. |
|
ENGINE public‐key method handler: list supported NIDs or return an EVP_PKEY_METHOD. |
|
ENGINE callback that supplies a client certificate and key for an SSL connection. |
|
BIT_STRING_BITNAME entry describing a named ASN.1 ENUMERATED value (long name / short name / number). |
|
Opaque per‐thread (or saved) OpenSSL error‐queue state. |
|
Mapping from a packed OpenSSL error code to a human‐readable string. |
|
ESS CertID: SHA‐1 hash identifying a signing certificate (RFC 2634). |
|
ESS CertIDv2: hash identifying a signing certificate with a chosen digest (RFC 5035). |
|
ESS IssuerSerial: certificate issuer name and serial number (RFC 2634). |
|
ESS SigningCertificate attribute listing CertIDs for the signer chain (RFC 2634). |
|
ESS SigningCertificateV2 attribute with CertIDv2 entries (RFC 5035). |
|
Opaque asymmetric cipher method (EVP_ASYM_CIPHER_fetch). |
|
Opaque symmetric cipher method (algorithm implementation) used with EVP_CIPHER_CTX. |
|
Opaque symmetric‐cipher operation context (EVP_EncryptInit and related EVP_Cipher APIs). |
|
Cipher algorithm pointer paired with an initialization vector buffer. |
|
Opaque context for EVP_Encode and EVP_Decode base64 streaming. |
|
Opaque key‐derivation function method returned by EVP_KDF_fetch(). |
|
Opaque key‐derivation function context (EVP_KDF_CTX_*). |
|
Opaque key‐encapsulation mechanism algorithm (EVP_KEM_*). |
|
Opaque key‐exchange algorithm method (EVP_KEYEXCH_fetch). |
|
Opaque key‐management algorithm implementation (provider keymgmt). |
|
Opaque MAC algorithm (EVP_MAC_fetch / EVP_Q_mac). |
|
Opaque MAC operation context (EVP_MAC_CTX_new / EVP_MAC_init / EVP_MAC_update / EVP_MAC_final). |
|
Opaque message‐digest method (algorithm implementation) used with EVP_MD_CTX. |
|
Opaque message‐digest operation context (EVP_Digest* / EVP_DigestSign*). |
|
Callback type that derives a key/IV from a password and initializes a cipher context for PBE. |
|
Extended password‐based encryption key‐setup callback with library context support. |
|
Opaque public/private key handle used throughout the EVP and X.509 APIs. |
|
Opaque ASN.1 method table describing how an EVP_PKEY type is encoded. |
|
Opaque context for public‐key operations (sign, verify, encrypt, derive, keygen, and related controls). |
|
Opaque legacy method table implementing an EVP_PKEY algorithm (deprecated in 3.0). |
|
Callback type invoked during key or parameter generation to report progress or cancel. |
|
Opaque random‐number generator method fetched from a provider (DRBG and related). |
|
Opaque RAND operation context created from an EVP_RAND method. |
|
Opaque signature algorithm method (EVP_SIGNATURE_fetch). |
|
Extended Key Usage extension: stack of key‐purpose object identifiers. |
|
Opaque context for CRYPTO_gcm128_* Galois/Counter Mode helpers. |
|
X.509 GeneralName: one alternative name form selected by |
|
Stack of GeneralName values (SubjectAltName, IssuerAltName, distribution points, etc.). |
|
Name Constraints subtree: a base GeneralName with optional minimum/maximum. |
|
Server callback that generates a new SSL/TLS session ID. |
|
Opaque HMAC computation context (legacy HMAC_* API). |
|
Unsigned word type used in the IDEA key schedule tables. |
|
Expanded IDEA key schedule for the low‐level IDEA_* APIs (deprecated; prefer EVP). |
|
RFC 3779 IPAddrBlocks extension: stack of per‐family address blocks. |
|
RFC 3779 choice between inheriting IP address blocks and listing them. |
|
RFC 3779 IP address family entry: AFI/SAFI octets plus an address choice. |
|
RFC 3779 IP address: either a prefix or an explicit address range. |
|
Stack of IPAddressOrRange values for one address family choice. |
|
Inclusive IP address range encoded as bit strings (RFC 3779). |
|
Issuer Signing Tool extension naming signing and CA tools and their certificates. |
|
Opaque Issuing Distribution Point extension value (CRL IDP). |
|
Expanded Camellia round‐key table stored as CAMELLIA_TABLE_WORD_LEN unsigned ints. |
|
Incremental MD4 digest state (also typedef'd as MD4_CTX); deprecated low‐level API. |
|
Incremental MD5 digest state (also typedef'd as MD5_CTX); deprecated low‐level API. |
|
Incremental MDC‐2 digest state (also typedef'd as MDC2_CTX); deprecated low‐level API. |
|
Opaque Name Constraints extension value (permitted/excluded subtrees). |
|
Naming authority identifying who issues profession or admission attributes (Common PKI). |
|
Netscape Certificate Sequence: a type OID plus a stack of certificates. |
|
Netscape Signed Public Key And Challenge (SPKAC) request body. |
|
Netscape SPKI: an SPKAC plus the signature algorithm and signature bits. |
|
Notice reference: organization name and notice numbers for a user notice qualifier. |
|
One entry in OpenSSL's name table mapping algorithm names to type‐specific data. |
|
Opaque context for CRYPTO_ocb128_* Offset Codebook Mode helpers. |
|
OCSP BasicOCSPResponse: ResponseData with signature and optional certificates. |
|
OCSP CertID identifying a certificate by issuer name/key hashes and serial (RFC 6960). |
|
OCSP CertStatus CHOICE: good, revoked, or unknown (RFC 6960). |
|
OCSP CrlID extension identifying a CRL by URL, number, or time. |
|
Single OCSP request entry with a CertID and optional extensions (RFC 6960). |
|
OCSP TBSRequest: version, optional requestor name, request list, and extensions. |
|
OCSP Request message containing TBSRequest and optional signature (RFC 6960). |
|
Legacy alias for OSSL_HTTP_REQ_CTX used by older OCSP HTTP client APIs. |
|
OCSP ResponseBytes: responseType OID and response OCTET STRING payload. |
|
OCSP ResponseData (tbsResponseData): version, ResponderID, producedAt, and responses. |
|
Opaque OCSP ResponderID (byName or byKey). |
|
Opaque OCSP response structure (RFC 6960). |
|
OCSP RevokedInfo: revocation time and optional CRL reason (RFC 6960). |
|
OCSP ServiceLocator extension with issuer name and locator AccessDescriptions. |
|
Optional signature over an OCSP request, with algorithm and certificates. |
|
OCSP SingleResponse for one CertID: status, thisUpdate, nextUpdate, and extensions. |
|
Opaque pointer to a non‐NUL‐terminated byte block for STACK_OF(OPENSSL_BLOCK) (unused by OpenSSL; deprecated). |
|
Opaque core‐side library context handle passed across the provider boundary. |
|
Const NUL‐terminated C string pointer used with STACK_OF(OPENSSL_CSTRING). |
|
Opaque OpenSSL library initialization settings passed to OPENSSL_init_crypto(). |
|
Opaque dynamic hash table (LHASH) of void* elements. |
|
Comparison callback returning <0 / 0 / >0 for two LHASH element pointers. |
|
Adapter that invokes a typed OPENSSL_LH_COMPFUNC on two void* elements. |
|
Callback applied to each element by OPENSSL_LH_doall(). |
|
Callback applied to each element by OPENSSL_LH_doall_arg() with a user argument. |
|
Adapter that invokes a typed OPENSSL_LH_DOALL_FUNCARG on void* element/arg. |
|
Adapter that invokes a typed OPENSSL_LH_DOALL_FUNC on a void* element. |
|
Hash callback that maps an LHASH element pointer to an unsigned long hash value. |
|
Adapter that invokes a typed OPENSSL_LH_HASHFUNC on a void* element. |
|
Opaque hash‐table node used internally by OPENSSL_LHASH. |
|
Pointer to an OPENSSL_STRING (char *); used as the row type in TXT_DB stacks. |
|
Opaque generic pointer stack; prefer the typed STACK_OF(...) wrappers. |
|
Mutable NUL‐terminated C string pointer used with STACK_OF(OPENSSL_STRING) / LHASH. |
|
Comparison callback used to order or search OPENSSL_STACK elements. |
|
Deep‐copy callback used by OPENSSL_sk_deep_copy() to duplicate one stack element. |
|
Callback that frees one element when OPENSSL_sk_pop_free() drains a stack. |
|
Opaque provider algorithm description (name, property, implementation). |
|
Generic provider/libcrypto callback receiving an OSSL_PARAM array. |
|
CertRepMessage from RFC 4210 section 5.3.3: CA Pubs and certResponse sequence. |
|
CertResponse from RFC 4210 section 5.3.3: certReqId, status, and optional cert/key. |
|
CertStatus from RFC 4210 section 5.3.18: certHash and certReqId for certConf. |
|
Opaque CMP client or server context holding transaction state and options. |
|
Opaque InfoTypeAndValue (ITAV) key‐value pair used in CMP messages (RFC 4210 section 5.3.19). |
|
Opaque PKIMessage structure (PKIHeader and body) from RFC 4210. |
|
ASN.1 BIT STRING encoding PKIFailureInfo failure flags (RFC 4210). |
|
Sequence of UTF8String status or error detail text in PKIStatusInfo (RFC 4210). |
|
Opaque PKIHeader structure for a CMP PKIMessage (RFC 4210 section 5.2). |
|
Opaque PKIStatusInfo structure with status, statusString, and failInfo (RFC 4210 section 5.3.14). |
|
ASN.1 INTEGER encoding a PKIStatus value (RFC 4210). |
|
Opaque PollRepContent entry with certReqId, checkAfter, and optional reason (RFC 4210 section 5.3.22). |
|
STACK_OF(OSSL_CMP_POLLREP) representing a PollRepContent sequence. |
|
RevRepContent from RFC 4210 section 5.3.4: status for each certReqId in an RR. |
|
Opaque CMP server context holding callbacks and server‐side state. |
|
|
Server callback type for processing incoming certConf messages. |
|
Server callback type for processing IR/CR/KUR/P10CR certificate requests. |
|
Callback type for cleaning up server state after a transaction completes. |
|
Callback type for deciding whether to delay delivery of a CMP response. |
Server callback invoked when constructing an error message response. |
|
Callback type for processing CMP General Message (genm) requests on the server. |
|
|
Server callback type for processing pollReq messages. |
Server callback type for processing Revocation Request (RR) messages. |
|
Callback type for evaluating a newly enrolled certificate before certConf. |
|
Callback type for CMP logging: receive component, source location, severity, and message. |
|
Syslog‐style severity level for CMP log messages (OSSL_CMP_LOG_*). |
|
Callback type for sending a CMP request and returning the response message. |
|
Opaque core‐side BIO handle passed across the provider boundary for upcalls. |
|
Opaque core handle passed to a provider's OSSL_provider_init() for upcalls. |
|
AttributeTypeAndValue for CRMF regCtrl or regInfo attributes. |
|
CertId from RFC 4211: issuer GeneralName and certificate serial number. |
|
CertRequest from RFC 4211: certReqId, certTemplate, and optional controls. |
|
CertTemplate from RFC 4211: selected certificate fields for a requested certificate. |
|
EncryptedValue from RFC 4211: optional algorithm identifiers and an encrypted bit string. |
|
CertReqMsg from RFC 4211: certificate request, optional proof‐of‐possession, and optional regInfo. |
|
CertReqMessages from RFC 4211: a sequence of CertReqMsg values. |
|
OptionalValidity from RFC 4211: optional notBefore and notAfter times in a certTemplate. |
|
PBMParameter from RFC 4211: salt, one‐way function, iteration count, and MAC algorithm. |
|
PKIPublicationInfo from RFC 4211 section 6.3: publication action and optional SinglePubInfo list. |
|
POPOSigningKey from RFC 4211: optional POPOSigningKeyInput, algorithm identifier, and signature. |
|
SinglePubInfo from RFC 4211: publication method and optional publication location. |
|
Opaque decoder method that converts external key/cert encodings into OpenSSL objects. |
|
Callback that frees construct data when an OSSL_DECODER_CTX is freed. |
|
Callback that builds an application object from a decoder's provider‐native result. |
|
Opaque context that drives OSSL_DECODER providers when decoding keys/objects. |
|
Opaque pairing of an OSSL_DECODER with its per‐instance decoder context during a decode run. |
|
Function‐pointer dispatch table entry exchanged between libcrypto and providers. |
|
Opaque encoder method that serializes keys and related objects. |
|
Cleanup callback that releases construct_data after encoding finishes. |
|
Callback that builds the provider‐native object passed to an encoder instance. |
|
Opaque encoder context that drives OSSL_ENCODER output of keys and related objects. |
|
Opaque pairing of an OSSL_ENCODER with its per‐instance encoder context during an encode run. |
|
Opaque HPKE context used for encapsulation, sealing, opening, and export (RFC 9180). |
|
Opaque HTTP request context used by OSSL_HTTP_* client helpers. |
|
Optional callback that updates or replaces the HTTP connection BIO around connect/TLS. |
|
Callback that both consumes input parameters and may populate output parameters. |
|
Opaque provider item pairing an identifier with a pointer payload. |
|
Opaque library context that scopes providers, properties, and algorithm fetches. |
|
Key/type/data triple used to pass parameters across provider boundaries. |
|
Opaque builder that assembles a dynamic OSSL_PARAM array. |
|
Callback that obtains a passphrase, optionally guided by OSSL_PARAM descriptors. |
|
Opaque provider object representing a loaded algorithm implementation module. |
|
Opaque self‐test event object used by provider FIPS self‐test callbacks. |
|
Opaque context for an open OSSL_STORE channel to a URI or BIO. |
|
Opaque object returned by OSSL_STORE describing a loaded key, cert, or CRL. |
|
Opaque OSSL_STORE loader implementation for a URI scheme. |
|
Opaque per‐open context used by a deprecated ENGINE‐based store loader. |
|
Opaque search criterion object used with OSSL_STORE_expect / find APIs. |
|
Deprecated loader callback that attaches to a BIO. |
|
Deprecated loader callback that closes and frees a loader context. |
|
Deprecated loader callback implementing OSSL_STORE_ctrl() / vctrl(). |
|
Deprecated loader callback implementing OSSL_STORE_eof(). |
|
Deprecated loader callback implementing OSSL_STORE_error(). |
|
Deprecated loader callback implementing OSSL_STORE_expect(). |
|
Deprecated loader callback implementing OSSL_STORE_find(). |
|
Deprecated loader callback implementing OSSL_STORE_load(). |
|
Deprecated loader callback that opens a URI with library context and property query. |
|
Deprecated loader callback that opens a URI and returns a loader context. |
|
|
Callback that may rewrite or drop each OSSL_STORE_INFO after it is loaded. |
Provider module entry‐point signature invoked when OpenSSL loads the provider. |
|
Callback invoked when a thread is stopping so a provider can release thread‐local state. |
|
Application callback that receives OpenSSL trace output for a category. |
|
otherName form of a GeneralName: an OID typed value. |
|
PKCS#5 PBES2 parameters: key‐derivation function and encryption scheme. |
|
PKCS#5 PBES1 password‐based encryption parameters (salt and iteration count). |
|
PKCS#5 PBKDF2 parameters: salt, iteration count, optional key length, and PRF. |
|
Top‐level PKCS#12 PFX structure (version, authSafes, and optional MAC). |
|
Bag payload choice structure (certBag, crlBag, secretBag, or other ASN.1 value). |
|
MAC salt, iteration count, and digest algorithm for a PKCS#12 PFX integrity check. |
|
One PKCS#12 safeBag holding a certificate, key, CRL, secret, or nested safeContents. |
|
Callback invoked for each safeBag while building a PKCS#12 structure. |
|
PKCS#7 ContentInfo container holding typed content and related state. |
|
Library/provider context carried by PKCS#7 objects when fetching algorithms. |
|
PKCS#7 DigestedData content: digest algorithm, encapsulated content, and message digest. |
|
PKCS#7 EncryptedData content: encrypted content info. |
|
PKCS#7 EncryptedContentInfo: content type, content‐encryption algorithm, and ciphertext. |
|
PKCS#7 EnvelopedData content: per‐recipient key infos and encrypted content. |
|
Issuer name and certificate serial number identifying a PKCS#7 signer or recipient. |
|
PKCS#7 RecipientInfo: recipient identity and encrypted content‐encryption key. |
|
PKCS#7 SignedData content: digests, optional certificates/CRLs, signer infos, and encapsulated content. |
|
PKCS#7 SignerInfo: identity, digest/signature algorithms, attributes, and signature. |
|
PKCS#7 SignedAndEnvelopedData content: digests, optional certificates/CRLs, signer infos, per‐recipient key infos, and encrypted content. |
|
Opaque PKCS#8 PrivateKeyInfo structure (RFC 5208). |
|
Private key usage period extension giving the interval when the key is valid. |
|
Single certificate policy: policy OID plus optional qualifiers. |
|
Certificate policy qualifier: CPS URI, user notice, or other typed value. |
|
Policy Constraints extension: requireExplicitPolicy and inhibitPolicyMapping skip counts. |
|
Mapping from an issuer domain policy OID to a subject domain policy OID. |
|
Stack of POLICY_MAPPING entries used by the policy‐mappings certificate extension. |
|
Profession information: naming authority, profession items/OIDs, and registration number. |
|
Stack of PROFESSION_INFO entries used inside an ADMISSIONS structure. |
|
Proxy Certificate Information extension (RFC 3820): path length and proxy policy. |
|
Proxy certificate policy: language OID and optional policy octets (RFC 3820). |
|
Legacy deterministic random bit generator handle (deprecated; prefer EVP_RAND). |
|
Legacy RAND method table (deprecated; prefer EVP_RAND providers). |
|
Unsigned integer word type used in the deprecated low‐level RC2 key schedule. |
|
Expanded RC2 key schedule used by the deprecated low‐level RC2_* encryptors. |
|
Legacy RC4 key stream state (deprecated; prefer EVP_CIPHER APIs). |
|
Legacy RIPEMD‐160 hashing context (deprecated; prefer EVP_MD APIs). |
|
Opaque RSA key object (deprecated; prefer EVP_PKEY). |
|
Opaque RSA method table for ENGINE‐style RSA implementations (deprecated). |
|
Opaque RSAES‐OAEP parameter structure (hashFunc / maskGenFunc / pSourceFunc). |
|
Opaque RSASSA‐PSS parameter structure (hashAlg / maskGenAlg / saltLength / trailerField). |
|
PKCS#5 scrypt password‐based key derivation parameters. |
|
Opaque Certificate Transparency Signed Certificate Timestamp. |
|
Opaque context used when verifying Certificate Transparency SCTs. |
|
Legacy SEED expanded key schedule (deprecated low‐level type; prefer EVP). |
|
Incremental SHA‐224 / SHA‐256 digest state (also typedef'd as SHA256_CTX); deprecated low‐level API. |
|
Incremental SHA‐384 / SHA‐512 digest state (also typedef'd as SHA512_CTX). |
|
Incremental SHA‐1 digest state (also typedef'd as SHA_CTX); deprecated low‐level API. |
|
In‐memory SRP verifier database loaded from a verifier file. |
|
Named SRP group parameters (generator |
|
Cache entry mapping a base64‐encoded SRP group parameter to a BIGNUM. |
|
SRP verifier database entry for one user (salt, verifier, and group parameters). |
|
SRTP protection profile for the use_srtp DTLS extension (RFC 5764). |
|
Opaque TLS/DTLS/QUIC connection object. |
|
Opaque description of an SSL/TLS cipher suite. |
|
Opaque SSL/TLS compression method entry. |
|
Opaque configuration context used with the SSL_CONF_* command API. |
|
Information describing why and how a QUIC connection was closed. |
|
Opaque TLS/DTLS/QUIC context holding shared configuration and certificates. |
|
|
Server callback that selects an ALPN protocol from the client's offer. |
|
Application callback that decrypts/validates a received session ticket. |
|
Callback invoked just before a server creates a session ticket (set ticket appdata here). |
Callback that logs a single line of TLS key material for debugging. |
|
|
NPN server callback that advertises the server's protocol list. |
|
NPN client callback that selects a protocol from the server's list. |
Opaque DANE (DNS‐based Authentication of Named Entities) state for TLS. |
|
Opaque SSL/TLS protocol method table used with SSL_CTX_new and related APIs. |
|
One pollable resource and event masks for an SSL_poll() array entry. |
|
Opaque SSL/TLS session state used for resumption and caching. |
|
Extended arguments for SSL_shutdown_ex() (currently QUIC‐specific). |
|
Arguments for SSL_stream_reset() describing how a QUIC stream is aborted. |
|
Return code from the decrypt‐session‐ticket callback controlling ticket use and renewal. |
|
Status code describing the outcome of session‐ticket decryption for the ticket callback. |
|
|
Server callback that decides whether to accept TLSv1.3 early data for a connection. |
Callback invoked when an asynchronous SSL cryptography operation completes. |
|
Server callback invoked after a ClientHello is received and parsed. |
|
Callback that supplies the contents of a custom TLS extension being sent. |
|
|
Free temporary storage allocated while adding a custom TLS extension. |
|
Parse a received custom TLS extension (context‐aware form). |
Client callback that selects a PSK identity and pre‐shared key for TLSv1.2 and below. |
|
|
TLSv1.3 server callback that looks up a PSK session by identity. |
PSK server callback that supplies the pre‐shared key for a client identity. |
|
|
TLSv1.3 client callback that selects a PSK session to offer. |
Certificate verification callback invoked during chain checking. |
|
Strong Extranet (SXNET) certificate extension value. |
|
Strong Extranet (SXNET) zone and user identifier pair. |
|
TLS Feature extension: stack of TLS extension feature integers (RFC 7633). |
|
TLS session‐ticket extension payload (length plus opaque data bytes). |
|
Opaque container for TLS signature algorithm preferences. |
|
RFC 3161 Accuracy: optional seconds, millis, and micros time precision. |
|
RFC 3161 MessageImprint: hash algorithm and hashed message octets. |
|
RFC 3161 TimeStampReq: version, message imprint, policy, nonce, and extensions. |
|
RFC 3161 TimeStampResp: status info and optional signed time‐stamp token. |
|
Opaque context used while generating RFC 3161 time‐stamp responses. |
|
RFC 3161 PKIStatusInfo: status, optional statusString, and failureInfo. |
|
RFC 3161 TSTInfo: policy, imprint, serial, time, accuracy, and TSA fields. |
|
Opaque context holding flags and expected values for time‐stamp verification. |
|
Callback that processes a requested extension while building TSTInfo. |
|
Callback that allocates a unique TSTInfo serial number for a response. |
|
Callback that supplies the current time for TSTInfo genTime. |
|
In‐memory text database parsed from newline‐separated, comma‐separated rows. |
|
Opaque interactive user‐interface object used with UI_METHOD prompting. |
|
Opaque UI_METHOD table implementing interactive user prompting. |
|
Prompt or output string entry stored in a UI for method writers to consume. |
|
User notice policy qualifier: optional notice reference and explicit text. |
|
Opaque X.509 certificate (RFC 5280 Certificate). |
|
Callback table for reading configuration database sections used by X509v3 helpers. |
|
Opaque context passed to X.509v3 extension helpers (issuer/subject/cert/request). |
|
Decode an X.509v3 extension value from DER. |
|
Free an X.509v3 extension‐specific value allocated by the matching NEW/D2I/S2I handlers. |
|
Encode an X.509v3 extension value to DER. |
|
Print an extension‐specific value to a BIO. |
|
Convert an extension value to a configuration string. |
|
Convert an extension value to a stack of configuration name/value pairs. |
|
Method table describing how an X.509v3 extension type is encoded and printed. |
|
Callback that allocates a fresh extension‐specific value for an X.509v3 method. |
|
Parse a raw configuration string into an extension value. |
|
Callback that parses a configuration string into an extension‐specific structure. |
|
Parse configuration name/value pairs into an extension‐specific value. |
|
Opaque ASN.1 AlgorithmIdentifier (algorithm OID plus optional parameters). |
|
Stack of X509_ALGOR AlgorithmIdentifier values. |
|
Opaque X.509 Attribute (AttributeTypeAndValue sequence) used in CSRs and PKCS#12. |
|
Auxiliary trust/reject OID lists and related metadata attached to an X509. |
|
Opaque TBSCertificate structure holding the unsigned certificate fields. |
|
Opaque X.509 certificate revocation list. |
|
Opaque TBSCertList / CRL info structure inside an X509_CRL. |
|
Opaque method table customizing CRL lookup/verification behaviour. |
|
Opaque X.509 extension object (OID, criticality, and octet‐string value). |
|
Typedef for a STACK_OF(X509_EXTENSION) used as an ASN.1 SEQUENCE OF Extension. |
|
Bundle of certificate, CRL, and/or encrypted private key as found in PEM info files. |
|
Opaque certificate/CRL lookup method instance attached to an X509_STORE. |
|
Opaque method table describing how an X509_LOOKUP finds certificates/CRLs. |
|
Extended control callback for an X509_LOOKUP_METHOD (with library context). |
|
Control‐command callback for an X509_LOOKUP_METHOD. |
|
|
Callback type that looks up a certificate or CRL by alias / friendly name. |
|
Callback type that looks up a certificate or CRL by fingerprint. |
|
Callback type that looks up a certificate by issuer name and serial number. |
|
Callback type that looks up a certificate or CRL by subject name, with provider selection. |
|
Callback type that looks up a certificate or CRL by subject name. |
Opaque X.509 distinguished name (SEQUENCE OF RelativeDistinguishedName). |
|
Single Relative Distinguished Name attribute (type OID plus value) within an X509_NAME. |
|
Opaque X509_STORE cache entry holding a certificate or CRL. |
|
PKCS#8 encrypted private key container used with PEM reading/writing. |
|
Opaque cache of processed certificate policy data used during path validation. |
|
Opaque single depth level within an X.509 certificate policy tree. |
|
Opaque node in an X.509 certificate policy tree. |
|
Opaque X.509 certificate policy tree built during path validation (RFC 5280). |
|
Opaque SubjectPublicKeyInfo container (algorithm + public key BIT STRING). |
|
Certificate purpose entry used by X509_check_purpose and related helpers. |
|
Opaque PKCS#10 certification request (CertificateRequest). |
|
Opaque TBSCertificateRequest / certification request info inside an X509_REQ. |
|
Opaque single revoked‐certificate entry within an X509_CRL. |
|
Opaque DigestInfo / encrypted‐key structure used by PKCS#8 and related APIs. |
|
Opaque signature metadata (security bits / TLS usage flags) for an X.509 signature. |
|
Opaque trust store of certificates and CRLs used during verification. |
|
Opaque certificate‐verification context (one chain validation attempt). |
|
|
Callback type that checks the revocation status of a certificate against a CRL. |
|
Callback type that verifies the signature/validity of a CRL in context |
|
Callback type that checks whether |
|
Callback type that evaluates certificate policies for a verification context. |
|
Callback that checks revocation status for certificates in a store context. |
Callback type invoked to clean up application state associated with a store context. |
|
|
Callback type that locates a CRL for certificate |
|
Callback that finds an issuer certificate for |
|
Callback type that looks up certificates in a store by subject name. |
|
Callback type that returns CRLs matching issuer name |
Verify‐result callback invoked for each certificate during chain verification. |
|
Callback that verifies a certificate chain in an X509_STORE_CTX. |
|
Entry describing a named X.509 trust purpose and its checker callback. |
|
Validity period (notBefore / notAfter) used inside X.509 certificates and CRLs. |
|
Opaque verification‐parameter object (purpose, trust, time, flags, …). |
|
Opaque context holding the two keys used by CRYPTO_xts128_encrypt(). |
|
Prefix/suffix producer for an ASN.1 filter BIO (BIO_f_asn1). |
|
Backward‐compatible alias for BIO_info_cb. |
|
Callback that encrypts or decrypts one 16‐byte block with a cipher key. |
|
Callback that encrypts or decrypts a contiguous span of bytes in CBC mode. |
|
Streaming CCM helper that processes whole 16‐byte blocks and updates CMAC state. |
|
DSO module finalizer called when a CONF module is unloaded. |
|
DSO module initializer called when a CONF module is loaded. |
|
Const‐qualified eight‐byte DES block typedef for read‐only key/IV inputs. |
|
Callback that encrypts or decrypts whole 16‐byte blocks in CTR mode. |
|
Callback that supplies payload bytes for a legacy custom TLS extension being sent. |
|
Free custom extension output produced by a matching add callback. |
|
Callback that parses a received custom TLS extension. |
|
Function‐pointer type for a type‐erased ASN.1 DER decoder (d2i_*). |
|
Free callback supplied by the loading application to a dynamic ENGINE. |
|
Allocator callback supplied by the loading application to a dynamic ENGINE. |
|
Reallocator callback supplied by the loading application to a dynamic ENGINE. |
|
Memory‐management callbacks passed into a dynamically loaded ENGINE. |
|
Bind entry point that populates an ENGINE loaded from a shared library. |
|
Callbacks and static‐state cookie passed when binding a dynamic ENGINE. |
|
Version‐check entry point expected from a dynamically loaded ENGINE. |
|
Callback that encrypts or decrypts a contiguous span of 16‐byte blocks in ECB mode. |
|
Function‐pointer type for a type‐erased ASN.1 DER encoder (i2d_*). |
|
Streaming OCB helper that processes whole 16‐byte blocks and updates checksum state. |
|
Signed 64‐bit fallback when stdint.h max‐width types are unavailable. |
|
Unsigned 64‐bit fallback when stdint.h max‐width types are unavailable. |
|
Callback that supplies a passphrase when reading or writing encrypted PEM. |
|
Incomplete pointer‐to‐SSL type used in SSL_CTX callback prototypes. |
|
Callback that decides whether received SCTs satisfy Certificate Transparency policy. |
|
EAP‐FAST callback that supplies the TLS master secret for a connection. |
|
|
Callback invoked with the TLS session‐ticket extension payload. |
Enums
Name |
Description |
How BIO_parse_hostserv() disambiguates host vs service in a combined string. |
|
Whether BIO_lookup resolves addresses for a client connect or server bind. |
|
Kinds of socket metadata that BIO_sock_info() can retrieve. |
|
Fine‐grained TLS/DTLS handshake state machine values reported by SSL_get_state(). |
|
Certificate Transparency validation policy for SSL_CTX_enable_ct(). |
|
Kind of object returned by an X509_LOOKUP. |
|
Certificate Transparency log entry type for an SCT. |
|
Enum for the point conversion form as defined in X9.62 (ECDSA) for the encoding of a elliptic curve point (x,y) |
|
Origin of a Signed Certificate Timestamp. |
|
Result of validating a Signed Certificate Timestamp. |
|
Version of a Signed Certificate Timestamp. |
Functions
Name |
Description |
Free an AccessDescription value and its contents. |
|
Return the ASN.1 item descriptor for ACCESS_DESCRIPTION. |
|
Allocate a new AccessDescription value (Authority Info Access entry). |
|
Free an ADMISSIONS value and its contents. |
|
Return the admission authority GENERAL_NAME from an ADMISSIONS entry. |
|
Return the naming authority from an ADMISSIONS entry. |
|
Return the profession‐info stack from an ADMISSIONS entry. |
|
Return the ASN.1 item descriptor for ADMISSIONS. |
|
Allocate a new ADMISSIONS value. |
|
Set the admission authority GENERAL_NAME on an ADMISSIONS entry, transferring ownership. |
|
Set the naming authority on an ADMISSIONS entry, taking ownership of |
|
Set the profession‐info stack on an ADMISSIONS entry, transferring ownership. |
|
Free an ADMISSION_SYNTAX value and its contents. |
|
|
Return the admission authority GeneralName from an ADMISSION_SYNTAX. |
|
Return the stack of ADMISSIONS entries from an ADMISSION_SYNTAX. |
Return the ASN.1 item descriptor for ADMISSION_SYNTAX. |
|
Allocate a new ADMISSION_SYNTAX value. |
|
|
Set the admission authority GeneralName on an ADMISSION_SYNTAX, taking ownership of |
|
Set the admissions stack on an ADMISSION_SYNTAX, taking ownership of |
|
Encrypt or decrypt with AES in bidirectional IGE mode (deprecated; prefer EVP). |
|
Encrypt or decrypt data with AES in CBC mode (deprecated; prefer EVP). |
|
Encrypt or decrypt data with AES in 128‐bit CFB mode (deprecated; prefer EVP). |
|
Encrypt or decrypt data with AES in 1‐bit CFB mode (deprecated; prefer EVP). |
|
Encrypt or decrypt data with AES in 8‐bit CFB mode (deprecated; prefer EVP). |
|
Decrypt one 16‐byte AES block with a key schedule (deprecated; prefer EVP). |
|
Encrypt or decrypt one 16‐byte AES block in ECB mode (deprecated; prefer EVP). |
|
Encrypt one 16‐byte AES block with a key schedule (deprecated; prefer EVP). |
|
Encrypt or decrypt with AES in infinite garble extension (IGE) mode (deprecated; prefer EVP). |
|
Encrypt or decrypt data with AES in 128‐bit OFB mode (deprecated; prefer EVP). |
|
Return a short string describing compiled AES implementation options (deprecated). |
|
Expand a user key into an AES decryption key schedule (deprecated; prefer EVP). |
|
Expand a user key into an AES encryption key schedule (deprecated; prefer EVP). |
|
Unwrap (decrypt) a key with AES Key Wrap per RFC 3394 (deprecated; prefer EVP). |
|
Wrap (encrypt) a key with AES Key Wrap per RFC 3394 (deprecated; prefer EVP). |
Free an ASIdOrRange value and its contents. |
|
Return the ASN.1 item descriptor for ASIdOrRange. |
|
Allocate a new ASIdOrRange value. |
|
Free an ASIdentifierChoice value and its contents. |
|
Return the ASN.1 item descriptor for ASIdentifierChoice. |
|
Allocate a new ASIdentifierChoice value. |
|
Free an ASIdentifiers extension value and its contents. |
|
Return the ASN.1 item descriptor for ASIdentifiers. |
|
Allocate a new ASIdentifiers extension value. |
|
Return the ASN.1 item descriptor for ASN.1 ANY (ASN1_TYPE). |
|
Verify that every set bit in |
|
Free an ASN.1 BIT STRING and its contents. |
|
Test whether bit |
|
Return the ASN.1 item descriptor for ASN1_BIT_STRING. |
|
Print the long names of set bits from a BIT_STRING_BITNAME table. |
|
Allocate an empty ASN.1 BIT STRING. |
|
Look up the bit number for a named bit in a BIT_STRING_BITNAME table. |
|
Replace the raw bit‐string payload of an ASN1_BIT_STRING. |
|
Set or clear a named bit in an ASN.1 bit string using a name table. |
|
Set or clear a single bit in an ASN.1 BIT STRING. |
|
Free a ASN.1 BMPString and its contents. |
|
Return the ASN.1 item descriptor for ASN1_BMPSTRING. |
|
Allocate an empty ASN.1 BMPString. |
|
Free an ASN.1 ENUMERATED value and its contents. |
|
Return the value of an ASN.1 ENUMERATED as a long (legacy; prefer ASN1_ENUMERATED_get_int64). |
|
Convert an ASN1_ENUMERATED to a signed 64‐bit integer. |
|
Return the ASN.1 item descriptor for ASN1_ENUMERATED. |
|
Allocate an empty ASN.1 ENUMERATED value. |
|
Set an ASN.1 ENUMERATED to a C long value. |
|
Set an ASN.1 ENUMERATED to a signed 64‐bit value. |
|
Convert an ASN.1 ENUMERATED value to a BIGNUM. |
|
Set an ASN.1 GeneralizedTime to |
|
Check that an ASN1_GENERALIZEDTIME value has valid GeneralizedTime syntax. |
|
Deep‐copy an ASN1_GENERALIZEDTIME value. |
|
Free an ASN.1 GeneralizedTime and its contents. |
|
Return the ASN.1 item descriptor for ASN1_GENERALIZEDTIME. |
|
Allocate an empty ASN.1 GeneralizedTime. |
|
Print an ASN.1 GeneralizedTime to a BIO in a human‐readable form. |
|
Set an ASN1_GENERALIZEDTIME to the calendar time |
|
Set an ASN1_GENERALIZEDTIME from an ASN.1 GeneralizedTime string (or only validate when |
|
Free an ASN.1 GeneralString and its contents. |
|
Return the ASN.1 item descriptor for ASN1_GENERALSTRING. |
|
Allocate an empty ASN.1 GeneralString. |
|
Free an ASN.1 IA5String and its contents. |
|
Return the ASN.1 item descriptor for ASN1_IA5STRING. |
|
Allocate an empty ASN.1 IA5String. |
|
Compare two ASN.1 INTEGER values numerically (including sign). |
|
Deep‐copy an ASN.1 INTEGER. |
|
Free an ASN.1 INTEGER and its contents. |
|
Return the value of an ASN.1 INTEGER as a C long. |
|
Convert an ASN.1 INTEGER to a host int64_t. |
|
Convert an ASN.1 INTEGER to a host uint64_t (must be non‐negative and in range). |
|
Return the ASN.1 item descriptor for ASN1_INTEGER. |
|
Allocate an empty ASN.1 INTEGER. |
|
Set an ASN.1 INTEGER to a C long value. |
|
Set an ASN.1 INTEGER to a signed 64‐bit value. |
|
Set an ASN.1 INTEGER to an unsigned 64‐bit value. |
|
Convert an ASN.1 INTEGER to a BIGNUM (allocating or reusing |
|
Return the built‐in ASN1_ITEM at index |
|
Look up a built‐in ASN1_ITEM by its structure name. |
|
Free an ASN.1 NULL value. |
|
Return the ASN.1 item descriptor for ASN1_NULL. |
|
Allocate an ASN.1 NULL value. |
|
Allocate a dynamically owned ASN1_OBJECT from DER content and optional names. |
|
Free an ASN.1 OBJECT identifier and its contents. |
|
Return the ASN.1 item descriptor for ASN1_OBJECT. |
|
Allocate an empty ASN.1 OBJECT identifier. |
|
Return the ASN.1 item descriptor for indefinite‐length OCTET STRING (NDEF). |
|
Compare two ASN.1 OCTET STRING values lexicographically by content. |
|
Deep‐copy an ASN.1 OCTET STRING. |
|
Free an ASN.1 OCTET STRING and its contents. |
|
Return the ASN.1 item descriptor for ASN1_OCTET_STRING. |
|
Allocate an empty ASN.1 OCTET STRING. |
|
Copy |
|
Free an ASN1_PCTX allocated by ASN1_PCTX_new(). |
|
Return the certificate‐field print flags stored in a print context. |
|
Return the general ASN1_PCTX_FLAGS_* print‐control flags from a print context. |
|
Return the name‐printing flags from an ASN.1 print context. |
|
Return the OID print flags currently set on an ASN.1 print context. |
|
Return the ASN1_STRFLGS_* flags controlling how string fields are printed. |
|
Allocate a new ASN.1 print context with default formatting flags. |
|
Set certificate‐field print flags on an ASN.1 print context. |
|
Set the general ASN1_PCTX_FLAGS_* print‐control flags on a print context. |
|
Set name‐printing flags for an ASN.1 print context. |
|
Set ASN1_STRFLGS_* flags controlling how object identifiers are printed. |
|
Set ASN1_STRFLGS_* flags controlling how string fields are printed. |
|
Free an ASN.1 PrintableString and its contents. |
|
Return the ASN.1 item descriptor for ASN1_PRINTABLESTRING. |
|
Allocate an empty ASN.1 PrintableString. |
|
Free an ASN1_PRINTABLE string and its contents. |
|
Return the ASN.1 item descriptor for ASN1_PRINTABLE. |
|
Allocate an empty ASN1_PRINTABLE string (PrintableString CHOICE wrapper). |
|
Choose a PrintableString / IA5String / T61String type that can hold |
|
Free an ASN.1 scan context previously created with ASN1_SCTX_new(). |
|
Return the application pointer previously stored on an ASN.1 scan context. |
|
Return scan flags for the current field in an ASN.1 scan context. |
|
Return the ASN1_ITEM currently being scanned by an ASN.1 scan context. |
|
Return the ASN1_TEMPLATE currently being scanned by an ASN.1 scan context. |
|
Allocate an ASN.1 scan context with the given per‐field scan callback. |
|
Store an application pointer on an ASN.1 scan context for use by the scan callback. |
|
Return the ASN.1 item descriptor for ASN1_SEQUENCE_ANY. |
|
Return the ASN.1 item descriptor for ASN1_SET_ANY. |
|
Add or update a local ASN1_STRING_TABLE entry for |
|
Free dynamically registered ASN1_STRING_TABLE entries added at run time. |
|
Look up the ASN1_STRING_TABLE entry for a string‐valued NID. |
|
Zero the content octets then free an ASN.1 string. |
|
Compare two ASN1_STRING values by type and content octets. |
|
Copy type, data, and flags from |
|
|
Return a mutable pointer to the raw octets stored in an ASN1_STRING (deprecated). |
Deep‐copy an ASN.1 string (type, data, and flags). |
|
Free an ASN.1 string and its contents. |
|
Return a const pointer to the raw content octets of an ASN.1 string. |
|
Return the process‐wide default ASN.1 string type mask. |
|
Return the content length of an ASN.1 string in bytes. |
|
|
Set the reported content length of an ASN.1 string without resizing its buffer (deprecated). |
Allocate an empty ASN1_STRING with default type V_ASN1_OCTET_STRING. |
|
Print an ASN.1 string to a BIO, replacing unprintable bytes with '.'. |
|
Print an ASN.1 string to a BIO using ASN1_STRFLGS_* formatting options. |
|
Print an ASN.1 string to a FILE with ASN1_STRING_print_ex() formatting flags. |
|
Copy |
|
Assign an ASN.1 string ownership of an existing data buffer. |
|
Create or update an ASN.1 string from multibyte input using the string table for |
|
Set the process‐wide default B_ASN1_* mask used when selecting ASN.1 string types. |
|
|
Set the default ASN.1 string type mask from an ASCII name or mask expression. |
Convert an ASN.1 string to a newly allocated UTF‐8 byte sequence. |
|
Return the ASN.1 type tag stored in an ASN.1 string. |
|
Allocate an empty ASN1_STRING with the given ASN.1 string type. |
|
Free a ASN.1 TeletexString (T61String) and its contents. |
|
Return the ASN.1 item descriptor for ASN1_T61STRING. |
|
Allocate an empty ASN.1 TeletexString (T61String). |
|
Set an ASN.1 Time to |
|
Check that an ASN1_TIME value has valid UTCTime or GeneralizedTime syntax. |
|
Compare an ASN.1 time value with a calendar time_t. |
|
Compare two ASN.1 time values chronologically. |
|
Compute the day and second difference between two ASN.1 time values. |
|
Duplicate an ASN1_TIME value (UTCTime or GeneralizedTime). |
|
Free a ASN.1 time value (UTCTime or GeneralizedTime) and its contents. |
|
Return the ASN.1 item descriptor for ASN1_TIME. |
|
Allocate an empty ASN.1 time value (UTCTime or GeneralizedTime). |
|
Normalize an ASN1_TIME so it is suitable for certificates and consistent printing. |
|
Print an ASN.1 Time (UTCTime or GeneralizedTime) to a BIO in a human‐readable form. |
|
Print an ASN.1 Time to a BIO with ASN1_DTFLGS_* formatting flags. |
|
Set an ASN.1 Time to the given POSIX time (UTCTime or GeneralizedTime). |
|
Set an ASN.1 time from an ASN.1 time string (UTCTime or GeneralizedTime form). |
|
Set an ASN1_TIME from a string, preferring the X.509 UTCTime/GeneralizedTime rules. |
|
Convert an ASN1_TIME to GeneralizedTime form. |
|
Convert an ASN.1 time value to a broken‐down UTC struct tm. |
|
Compare two ASN1_TYPE values for identical type and content. |
|
Free an ASN.1 ANY / ASN1_TYPE value and its contents. |
|
Return the type tag stored in an ASN1_TYPE, or 0 if unset or empty. |
|
Extract the INTEGER and OCTET STRING from an ASN1_TYPE holding that SEQUENCE pair. |
|
Copy the OCTET STRING contents of an ASN1_TYPE into |
|
Allocate an empty ASN.1 ANY / ASN1_TYPE container. |
|
Encode a typed structure as a SEQUENCE and store it in an ASN1_TYPE. |
|
Set an ASN1_TYPE to |
|
Set an ASN1_TYPE to |
|
Set an ASN1_TYPE to the SEQUENCE { INTEGER, OCTET STRING } pair used by some algorithm parameters. |
|
Set an ASN1_TYPE to an OCTET STRING containing a copy of |
|
Decode the SEQUENCE contents of an ASN1_TYPE into a typed structure. |
|
Free an ASN.1 UniversalString and its contents. |
|
Return the ASN.1 item descriptor for ASN1_UNIVERSALSTRING. |
|
Allocate an empty ASN.1 UniversalString. |
|
Convert a UniversalString that holds only Latin‐1 code points into a Printable/IA5/T61 string in place. |
|
Set an ASN1_UTCTIME from |
|
Check that an ASN1_UTCTIME value has valid UTCTime syntax. |
|
Compare an ASN.1 UTCTime value with a calendar time_t. |
|
Deep‐copy an ASN1_UTCTIME value. |
|
Free an ASN.1 UTCTime and its contents. |
|
Return the ASN.1 item descriptor for ASN1_UTCTIME. |
|
Allocate an empty ASN.1 UTCTime. |
|
Print an ASN.1 UTCTime to a BIO in human‐readable form. |
|
Set an ASN1_UTCTIME to the calendar time |
|
Set an ASN1_UTCTIME from an ASN.1 UTCTime string (or only validate when |
|
Free an ASN.1 UTF8String and its contents. |
|
Return the ASN.1 item descriptor for ASN1_UTF8STRING. |
|
Allocate an empty ASN.1 UTF8String. |
|
Free an ASN.1 VisibleString and its contents. |
|
Return the ASN.1 item descriptor for ASN1_VISIBLESTRING. |
|
Allocate an empty ASN.1 VisibleString. |
|
Register the built‐in CONF module that loads OID name mappings from an "oid_section". |
|
Register the built‐in ASN.1 string‐table (STABLE) configuration module. |
|
Print a labeled BIGNUM to a BIO in hex, with indentation. |
|
Print a byte buffer as colon‐separated hex to a BIO with indentation. |
|
Check for an indefinite‐length end‐of‐contents (EOC) marker without consuming it. |
|
Consume an indefinite‐length end‐of‐contents (EOC) marker of two zero octets. |
|
Decode an ASN.1 value from a BIO using allocator and d2i callbacks. |
|
Decode an ASN.1 value from a FILE using allocator and d2i callbacks. |
|
|
Digest the DER encoding of an ASN.1 structure using a supplied i2d encoder (deprecated). |
Deep‐copy an ASN.1 value by encoding with |
|
Build an ASN1_TYPE from an ASN.1 generation string, resolving CONF macros. |
|
Build an ASN1_TYPE from an ASN.1 generation string, resolving extras via an X509V3_CTX. |
|
Parse the ASN.1 identifier and length octets at *`pp.` |
|
Encode an ASN.1 value to a BIO using a type‐specific i2d function. |
|
Encode an ASN.1 value to a FILE using a type‐specific i2d function. |
|
Decode a DER‐encoded ASN.1 value using an item descriptor (default library context). |
|
Decode an ASN.1 value described by |
|
Decode an ASN.1 value described by |
|
Decode a DER‐encoded ASN.1 value using an item descriptor and library context. |
|
Decode an ASN.1 value described by |
|
Decode an ASN.1 value described by |
|
Digest the ASN.1 encoding of |
|
Deep‐copy an ASN.1 value described by |
|
Free an ASN.1 value described by an ASN1_ITEM. |
|
Encode an ASN.1 value described by |
|
Encode an ASN.1 value to DER and write it to a BIO using an ASN1_ITEM. |
|
Encode an ASN.1 item to DER and write the encoding to a FILE stream. |
|
Encode an ASN.1 value described by |
|
Encode an ASN.1 value to DER/BER using indefinite‐length (NDEF) constructed form where applicable. |
|
Allocate a new ASN.1 value described by |
|
Allocate a new ASN.1 value described by |
|
Encode |
|
Pretty‐print an ASN.1 value described by |
|
Sign the DER encoding of an ASN.1 value described by |
|
Sign the DER encoding of |
|
Sign the DER encoding of |
|
Decode the DER content of an OCTET STRING / ASN1_STRING using item |
|
Decode DER from an ASN1_STRING using |
|
Verify |
|
Verify |
|
Verify |
|
Convert multibyte input into an ASN.1 string, choosing a type allowed by |
|
Like ASN1_mbstring_copy(), also enforcing minimum and maximum character counts. |
|
Compute the total DER size of a tagged ASN.1 value given its content length. |
|
Recursively dump a DER ASN.1 structure to a BIO as indented text. |
|
Recursively dump a DER ASN.1 structure to a BIO, optionally hex‐dumping string contents. |
|
Write a two‐octet ASN.1 end‐of‐contents (0x00 0x00) marker and advance |
|
Write an ASN.1 identifier and length octet(s) at *`pp` and advance the pointer. |
|
|
Sign ASN.1 data described by an i2d encoder using |
Parse a pipe‐separated list of ASN1_STRFLGS_* flag names into a mask. |
|
Map an ASN.1 universal tag number to the corresponding B_ASN1_* bit mask. |
|
Return a human‐readable name for an ASN.1 universal tag number. |
|
|
Verify a signature over the DER encoding produced by |
Free an AS number range value and its contents. |
|
Return the ASN.1 item descriptor for ASRange. |
|
Allocate a new AS number range value. |
|
Remove the wait file descriptor associated with |
|
Free an asynchronous wait context and its associated resources. |
|
|
Collect every wait file descriptor currently registered on |
Retrieve the completion callback previously set on an async wait context. |
|
|
Retrieve file descriptors added to or removed from a wait context since the last poll. |
Look up the wait file descriptor registered under |
|
Get the current status of an asynchronous wait context. |
|
Allocate a new asynchronous wait context. |
|
Register a callback notified when an engine completes an async operation. |
|
Set the engine‐reported status of an asynchronous wait context. |
|
|
Associate a waitable file descriptor with a key in the wait context. |
Temporarily ignore ASYNC_pause_job() on the current thread. |
|
Release per‐thread asynchronous job resources allocated by ASYNC_init_thread(). |
|
Return the ASYNC_JOB currently executing on this thread, if any. |
|
Retrieve the current custom ASYNC stack allocator callbacks. |
|
Return the wait context associated with an asynchronous job. |
|
Initialise per‐thread asynchronous job support for the current thread. |
|
Report whether the current platform supports asynchronous jobs. |
|
Pause the current ASYNC_JOB and return control to ASYNC_start_job(). |
|
Install custom stack allocators used for ASYNC jobs on POSIX. |
|
Start or resume an asynchronous job. |
|
Allow ASYNC_pause_job() again after a matching ASYNC_block_pause(). |
|
Free an Authority Information Access extension value and its contents. |
|
Return the ASN.1 item descriptor for AUTHORITY_INFO_ACCESS. |
|
Allocate a new Authority Information Access extension value. |
|
Free an AUTHORITY_KEYID structure and its contents. |
|
Return the ASN.1 item descriptor for AUTHORITY_KEYID. |
|
Allocate a new Authority Key Identifier extension value. |
|
Free a BASIC_CONSTRAINTS structure and its contents. |
|
Return the ASN.1 item descriptor for BASIC_CONSTRAINTS. |
|
Allocate a new Basic Constraints extension value. |
|
|
Encrypt or decrypt data with Blowfish in CBC mode (deprecated). |
|
Encrypt or decrypt with Blowfish in 64‐bit CFB mode (deprecated; prefer EVP_EncryptInit_ex and related EVP APIs). |
|
Decrypt one Blowfish block in place (deprecated low‐level primitive). |
|
Encrypt or decrypt one 8‐byte Blowfish block in ECB mode (deprecated). |
|
Encrypt one Blowfish block in place (deprecated low‐level primitive). |
|
Encrypt or decrypt with Blowfish in 64‐bit OFB mode (deprecated). |
|
Return a short string describing the compiled Blowfish implementation (deprecated). |
|
Expand a raw Blowfish key into a BF_KEY schedule (deprecated). |
Return the BIO_ADDR carried by an address‐info list node. |
|
Return the address family of a BIO_ADDRINFO node (for example AF_INET). |
|
Free a BIO_ADDRINFO list allocated by BIO_lookup() / BIO_lookup_ex(). |
|
Advance to the next node in a BIO_ADDRINFO linked list. |
|
Return the protocol number from an address‐info element (for example IPPROTO_TCP). |
|
Return the socket type of a BIO_ADDRINFO node (for example SOCK_STREAM). |
|
Reset a BIO_ADDR to an empty/uninitialized state. |
|
Copy a BIO_ADDR value from |
|
Duplicate a BIO_ADDR, copying its family and address bytes. |
|
Return the address family stored in a BIO_ADDR (for example AF_INET). |
|
Free a BIO_ADDR allocated with BIO_ADDR_new() or BIO_ADDR_dup(). |
|
Format the host portion of a BIO_ADDR as an allocated string. |
|
Allocate a zero‐initialized BIO_ADDR for socket address APIs. |
|
Return a newly allocated string for the filesystem path in a Unix‐domain BIO_ADDR. |
|
Extract the raw network address bytes from a BIO_ADDR. |
|
Populate a BIO_ADDR from a raw address family, bytes, and port. |
|
Return the port number from a BIO_ADDR in host byte order. |
|
Format the service/port portion of a BIO_ADDR as an allocated string. |
|
|
Accept a connection on a listening socket and return peer host:port text (deprecated). |
Accept a connection on |
|
Retrieve the ASN.1 prefix producer and optional free callback from a BIO. |
|
Retrieve the ASN.1 suffix producer and optional free callback from a BIO. |
|
Install prefix encode/free callbacks on a BIO_f_asn1() filter BIO. |
|
Install suffix encode/free callbacks on a BIO_f_asn1() filter BIO. |
|
Bind socket |
|
Invoke a BIO ctrl that takes a BIO_info_cb callback pointer. |
|
Clear the given BIO_FLAGS_* bits from a BIO. |
|
Close a socket descriptor with OpenSSL error reporting. |
|
Connect socket |
|
Copy retry reason/flags from the next BIO in the chain onto |
|
Invoke a type‐specific control operation on a BIO. |
|
Return how many bytes the peer half of a BIO pair last tried to read while the buffer was empty. |
|
Return how many bytes can currently be written without blocking or growing buffers. |
|
Return the number of bytes buffered for reading in a BIO (ctrl pending read count). |
|
Clear the pending read‐request size tracked by a buffering BIO. |
|
Return the number of bytes buffered for writing in a BIO (ctrl pending write count). |
|
|
Default legacy BIO debug logger writing to the BIO's callback‐argument BIO (deprecated). |
Default BIO info callback that logs operations to the BIO's callback argument BIO. |
|
Report whether a datagram socket errno / WSA error is a non‐fatal retryable condition. |
|
Drive BIO_do_connect() with retries until connected, failed, or |
|
Hex‐dump |
|
Hex‐dump |
|
Hex‐dump |
|
Hex‐dump |
|
Hex‐dump |
|
Hex‐dump |
|
Duplicate an entire BIO chain, copying type‐specific state where supported. |
|
Report whether a system or socket error code is a non‐fatal retryable I/O condition. |
|
Return the filter BIO_METHOD that encodes ASN.1 values to a downstream BIO. |
|
Return the BIO filter method that Base64‐encodes or decodes data. |
|
Return the BIO filter method that buffers reads and writes to the next BIO. |
|
Return the filter BIO_METHOD that encrypts or decrypts data with an EVP_CIPHER. |
|
Return the BIO_METHOD for a line‐buffering filter BIO. |
|
Return the message‐digest filter BIO method. |
|
Return the BIO filter method that randomly injects non‐blocking retry conditions (test aid). |
|
Return the BIO_METHOD for a null filter that discards writes and yields EOF on reads. |
|
Return the BIO filter method that prefixes each output line with a configurable string. |
|
Return the BIO filter method that read‐ahead buffers data from the next BIO. |
|
Return the BIO filter method that adds a digest‐protected reliable stream. |
|
Return the SSL filter BIO method that wraps TLS I/O in a BIO. |
|
Report whether a file‐descriptor errno is a non‐fatal retryable I/O condition. |
|
Decide whether a file‐descriptor BIO I/O result should be retried. |
|
Walk a BIO chain and return the first BIO whose method type matches |
|
Free a single BIO (does not free BIOs linked after it in a chain). |
|
Free |
|
|
Create a listening TCP socket for |
|
Return the legacy BIO callback previously set with BIO_set_callback() (deprecated). |
Return the opaque callback‐argument pointer stored on a BIO. |
|
Return the extended BIO callback installed with BIO_set_callback_ex(). |
|
Return the implementation‐specific pointer stored on a BIO. |
|
Retrieve application data previously stored on a BIO with BIO_set_ex_data(). |
|
|
Resolve a hostname to four IPv4 octets (deprecated; prefer BIO_lookup()). |
Test whether a custom BIO has been initialized by its create() callback. |
|
Read bytes until a newline or EOF, without requiring a trailing NUL in the source. |
|
Allocate a new unique BIO type index for a custom BIO_METHOD. |
|
|
Parse a service name or numeric port string (deprecated; prefer modern address APIs). |
Walk a BIO chain after BIO_should_io_special() and locate the BIO requesting a retry. |
|
Return the BIO_RR_* retry reason stored on a BIO. |
|
Fill |
|
Return whether BIO_free() will close the underlying I/O resource. |
|
Fill |
|
|
Resolve |
Read a line from a BIO into |
|
Write |
|
Write up to |
|
Invoke a BIO ctrl that takes an integer argument in the low word. |
|
Bind and listen on a socket using |
|
Resolve |
|
Resolve |
|
Free a BIO_METHOD allocated with BIO_meth_new(). |
|
Return the callback‐ctrl function installed on a BIO_METHOD. |
|
Return the create callback installed on a BIO_METHOD. |
|
Return the ctrl function installed on a BIO_METHOD. |
|
Return the destroy callback installed on a BIO_METHOD. |
|
Return the gets function installed on a BIO_METHOD. |
|
Return the puts callback installed on a BIO_METHOD. |
|
Return the legacy read function installed on a BIO_METHOD. |
|
Return the extended read function installed on a BIO_METHOD. |
|
Return the multi‐message receive callback installed on a BIO_METHOD. |
|
Return the multi‐message send callback installed on a BIO_METHOD. |
|
Return the legacy write function installed on a BIO_METHOD. |
|
Return the extended write function installed on a BIO_METHOD. |
|
Allocate a new custom BIO_METHOD with the given type index and name. |
|
Install the callback‐ctrl function on a custom BIO_METHOD. |
|
Install the create callback invoked when a BIO of this method is allocated. |
|
Install the ctrl callback on a BIO_METHOD. |
|
Install the destroy callback invoked when a BIO of this method is freed. |
|
Install the gets callback on a BIO_METHOD. |
|
Install the puts callback on a BIO_METHOD. |
|
Install the legacy read callback on a BIO_METHOD. |
|
Install the extended read callback on a BIO_METHOD. |
|
Install the multi‐message receive callback on a BIO_METHOD. |
|
Install the multi‐message send callback used by BIO_sendmmsg() on a BIO_METHOD. |
|
Install the legacy write callback on a BIO_METHOD. |
|
Install the size_t‐based write callback on a BIO_METHOD. |
|
Return the human‐readable name of the BIO_METHOD attached to |
|
Return the BIO type code of the method used by |
|
Allocate a new BIO using |
|
Wrap a CMS ContentInfo in a filter BIO that writes indefinite‐length BER to |
|
Create a streaming BIO that encodes |
|
Create a filter BIO that finalises and writes streaming PKCS#7 ASN.1 to |
|
Create an accept BIO bound to |
|
Create a connected pair of in‐memory datagram BIOs. |
|
Create two connected memory BIOs that form a reliable in‐memory byte pipe. |
|
Create a BIO chain of buffering BIO, SSL BIO, and connect BIO. |
|
Create a BIO_s_connect() BIO configured for |
|
Create a datagram (UDP‐style) BIO wrapping an existing socket descriptor. |
|
Allocate a new BIO for |
|
Create a file‐descriptor BIO wrapping an existing OS descriptor. |
|
Open |
|
Wrap a stdio FILE* in a BIO_s_file() BIO. |
|
Wrap a provider OSSL_CORE_BIO in a library BIO_s_core() BIO. |
|
Create a read‐only memory BIO that reads from an existing buffer. |
|
Wrap an existing socket descriptor in a BIO_s_socket() BIO. |
|
Allocate an SSL filter BIO using the given context. |
|
Create a BIO chain of an SSL BIO and a connect BIO. |
|
Return the next BIO in a filter chain after |
|
Consume up to |
|
Peek at readable bytes in a memory BIO without consuming them. |
|
Return the cumulative number of bytes successfully read through a BIO. |
|
Return the cumulative number of bytes successfully written through a BIO. |
|
Obtain a writable buffer from a memory BIO and advance its write pointer. |
|
Obtain a writable buffer from a memory BIO without advancing the write pointer. |
|
Split a host:service string into separately allocated host and service names. |
|
Remove the first BIO from a chain and return the new head. |
|
Formatted print to a BIO, analogous to fprintf(). |
|
Invoke a BIO ctrl that returns a pointer result. |
|
Append |
|
Write the NUL‐terminated string |
|
Read up to |
|
Attempt to read up to |
|
Receive multiple datagram messages through a BIO (recvmmsg‐style). |
|
Return the BIO_METHOD for a passive TCP accept socket BIO. |
|
Return the BIO_METHOD for a BIO‐pair endpoint (in‐memory pipe half). |
|
Return the BIO_METHOD for a TCP connect (client) socket BIO. |
|
Return the BIO_METHOD for a core BIO that reads/writes via an OSSL_CORE_BIO. |
|
Return the BIO_METHOD for a datagram (UDP) socket BIO. |
|
Return the BIO_METHOD for an in‐memory datagram BIO. |
|
Return the BIO_METHOD for a datagram BIO‐pair endpoint (in‐memory UDP‐style pipe half). |
|
Return the BIO_METHOD for a file‐descriptor source/sink BIO. |
|
Return the BIO_METHOD for stdio FILE‐backed source/sink BIOs. |
|
Return the BIO_METHOD for a logging sink BIO (writes to the system log). |
|
Return the BIO_METHOD for a memory (RAM buffer) source/sink BIO. |
|
Return the BIO_METHOD for a null source/sink that discards writes and returns EOF on reads. |
|
Return the BIO_METHOD for a secure‐heap memory BIO. |
|
Return the BIO_METHOD for a socket source/sink BIO. |
|
Send multiple messages through a BIO (sendmmsg‐style interface). |
|
|
Install a legacy pre/post I/O callback on a BIO (deprecated; prefer BIO_set_callback_ex). |
Store an opaque pointer passed to BIO callbacks as the callback argument. |
|
Install an extended pre/post I/O callback on a BIO. |
|
Configure a cipher filter BIO with algorithm, key, IV, and encrypt/decrypt mode. |
|
Store an implementation‐specific pointer on a BIO (used by custom BIO methods). |
|
Store application‐specific data on a BIO at the given ex_data index. |
|
Set the given flag bits on a BIO (bitwise OR into the BIO's flags). |
|
Mark whether a custom BIO method has completed its create() initialization. |
|
Set the next BIO in a filter chain after |
|
Store a BIO_RR_* retry reason on a BIO (used by BIO methods after special I/O). |
|
Set whether BIO_free() should close the underlying I/O resource. |
|
Enable or disable TCP_NODELAY on a socket. |
|
Bounded snprintf‐style formatting into |
|
Return the pending socket error for |
|
Query socket metadata into a BIO_sock_info_u union. |
|
Initialize platform socket support used by BIO socket helpers (Winsock on Windows). |
|
Report whether a socket errno / WSA error is a non‐fatal retryable condition. |
|
Decide whether a socket BIO operation should be retried after return value |
|
Create a socket with optional BIO_SOCK_* behaviour flags applied. |
|
Perform an ioctl on a socket descriptor with BIO error reporting. |
|
Set or clear non‐blocking mode on a socket file descriptor. |
|
Wait on a socket until it is ready for I/O or until |
|
Copy the SSL session ID between two BIO chains that contain SSL BIOs. |
|
Shut down the SSL session on an SSL BIO chain. |
|
Test whether any of the given flag bits are set on a BIO. |
|
Increment the reference count of a BIO. |
|
Free a BIO and every BIO linked after it in the chain. |
|
printf‐style formatted write to a BIO using a va_list. |
|
Format a string into |
|
Wait until a BIO is ready for I/O or until |
|
Write |
|
Write up to |
|
Blind |
|
Blind |
|
Create or refresh RSA blinding factors A and Aˆ‐1 mod |
|
Free a BN_BLINDING object and its associated factors. |
|
Return the behavioural flag mask stored on a BN_BLINDING object. |
|
Unblind |
|
Unblind |
|
Report whether |
|
Acquire the mutex associated with a BN_BLINDING object. |
|
Allocate a BN_BLINDING object from blinding factors A and Aˆ‐1 mod |
|
Record the calling thread as the owner of blinding context |
|
Set behavioural flags on a BN_BLINDING object. |
|
Release the mutex associated with a BN_BLINDING object. |
|
Refresh a BN_BLINDING object by squaring its blinding factors. |
|
End a BN_CTX temporary frame started with BN_CTX_start(), releasing its BN_CTX_get() values. |
|
Free a BN_CTX and any BIGNUMs still owned by its stack frames. |
|
Obtain a temporary BIGNUM from the current BN_CTX frame started by BN_CTX_start(). |
|
Allocate a BN_CTX using the default library context. |
|
Allocate a BN_CTX associated with library context |
|
Allocate a BN_CTX whose temporary BIGNUMs use the secure heap. |
|
Allocate a BN_CTX whose temporary BIGNUMs use secure heap storage. |
|
Begin a temporary BIGNUM frame on a BN_CTX. |
|
Invoke a BN_GENCB progress callback with event codes |
|
Free a BN_GENCB allocated by BN_GENCB_new(). |
|
Return the user argument previously associated with a BN_GENCB. |
|
Allocate a BN_GENCB used to report progress from prime generation. |
|
Populate a BN_GENCB with a new‐style progress callback that returns success/failure. |
|
Populate a BN_GENCB with a legacy void‐returning progress callback. |
|
Add binary polynomials over GF(2): r = a XOR b (addition without carry). |
|
Build a GF(2ˆm) irreducible polynomial BIGNUM from an exponent index array. |
|
Reduce |
|
Reduce |
|
Compute r = (a / b) mod p for binary polynomial‐field (GF(2ˆm)) values. |
|
Compute |
|
Compute r = (a ˆ b) mod p for binary polynomial‐field (GF(2ˆm)) values. |
|
Exponentiate in GF(2ˆm) with the modulus given as an int array: r = (a ˆ b) mod p. |
|
Compute the multiplicative inverse in GF(2ˆm): r = (1 / b) mod p. |
|
Compute the inverse of |
|
Multiply then reduce in GF(2ˆm): r = (a * b) mod p. |
|
Multiply then reduce in GF(2ˆm) with the modulus given as an int array: r = (a * b) mod p. |
|
Solve the quadratic rˆ2 + r = a mod p over GF(2ˆm). |
|
|
Solve the quadratic rˆ2 + r = a mod p over GF(2ˆm) with the modulus given as an int array. |
Square then reduce in GF(2ˆm): r = (a * a) mod p. |
|
Square then reduce in GF(2ˆm) with the modulus given as an int array: r = (a * a) mod p. |
|
Compute a square root in GF(2ˆm): r = sqrt(a) mod p. |
|
Compute a square root in GF(2ˆm) with the modulus given as an int array: r = sqrt(a) mod p. |
|
Convert a GF(2ˆm) polynomial BIGNUM into a descending exponent index array. |
|
Copy Montgomery context |
|
Free a BN_MONT_CTX allocated by BN_MONT_CTX_new(). |
|
Allocate an empty Montgomery multiplication context. |
|
Initialize a Montgomery context for modulus |
|
Lazily initialize a shared Montgomery context under a lock. |
|
Free a BN_RECP_CTX allocated by BN_RECP_CTX_new(). |
|
Allocate a BN_RECP_CTX used to accelerate repeated modular reduction. |
|
Configure a reciprocal context for repeated division by modulus |
|
|
Derive an X9.31 prime p from Xp/Xp1/Xp2 parameters (deprecated). |
|
Generate random X9.31 parameters Xp and Xq of half the requested RSA bit length (deprecated). |
|
Generate an X9.31‐style probable prime derived from parameters |
Test whether the absolute value of |
|
Add signed BIGNUMs: |
|
Add word |
|
Test whether |
|
Parse an ASCII decimal or hexadecimal integer into a BIGNUM. |
|
Convert |
|
Encode the absolute value of |
|
Encode a BIGNUM as a fixed‐length big‐endian unsigned byte string. |
|
Convert a BIGNUM to a newly allocated decimal string. |
|
Convert a BIGNUM to a newly allocated hexadecimal string. |
|
Encode a BIGNUM as fixed‐length little‐endian unsigned bytes with zero padding. |
|
Encode |
|
Encode a BIGNUM as a fixed‐length native‐endian unsigned byte string. |
|
Generate a non‐cryptographic test random BIGNUM for BN self‐tests. |
|
Test whether |
|
Set a BIGNUM to zero and scrub its limb storage. |
|
Clear bit |
|
Clear sensitive digits of a BIGNUM and free it. |
|
Compare two BIGNUMs considering sign. |
|
Conditionally swap the top |
|
Copy BIGNUM |
|
Parse a decimal ASCII string into a BIGNUM. |
|
Divide |
|
Divide |
|
Divide |
|
Allocate a new BIGNUM that is a deep copy of |
|
Compute r = aˆp (non‐modular exponentiation). |
|
Free a BIGNUM and its limbs (no‐op for static BIGNUMs flagged BN_FLG_STATIC_DATA). |
|
Convert |
|
Compute the greatest common divisor of |
|
Generate a DSA/ECDSA per‐signature nonce in [0, ]`range).` |
|
|
Generate a prime of approximately |
Generate a probable prime of the requested size and congruence constraints. |
|
Generate a probable prime into |
|
Return the NIST P‐192 prime as a shared BIGNUM. |
|
Return the NIST P‐224 prime as a shared BIGNUM. |
|
Return the NIST P‐256 prime as a shared BIGNUM. |
|
Return the NIST P‐384 prime as a shared BIGNUM. |
|
Return the NIST P‐521 prime (2ˆ521 ‐ 1) as a shared BIGNUM. |
|
Test whether the given BN_FLG_* bits are set on a BIGNUM. |
|
|
Return a legacy BN library tuning parameter (deprecated no‐op on modern OpenSSL). |
Return the 1024‐bit MODP group prime from RFC 2409. |
|
Return the 768‐bit MODP group prime from RFC 2409. |
|
Return the 1536‐bit MODP group prime from RFC 3526. |
|
Return the 2048‐bit MODP group prime from RFC 3526. |
|
Return the 3072‐bit MODP group prime from RFC 3526. |
|
Return the 4096‐bit MODP group prime from RFC 3526. |
|
Return the 6144‐bit MODP group prime from RFC 3526. |
|
Return the 8192‐bit MODP group prime from RFC 3526. |
|
Return |
|
Parse a hexadecimal ASCII string into a BIGNUM. |
|
Test whether bit |
|
BN_is_negative returns 1 if the BIGNUM is negative |
|
Test whether a BIGNUM is odd. |
|
Test whether a BIGNUM equals one. |
|
|
Probable‐primality test without trial division (deprecated; prefer BN_check_prime()). |
|
Test whether |
|
Probable‐primality test with optional trial division (deprecated). |
|
Probable‐primality test with optional trial division (deprecated; prefer BN_check_prime). |
Test whether a BIGNUM equals the single word |
|
Test whether a BIGNUM is zero. |
|
Compute the Kronecker symbol (a/b), a generalization of the Jacobi symbol. |
|
Convert a little‐endian unsigned byte array to a BIGNUM. |
|
Compute r = a << n (left shift by |
|
Compute r = a << 1 (left shift by one bit), i.e. r = 2 * a. |
|
Truncate |
|
Modular addition: |
|
Compute |
|
Compute modular exponentiation: |
|
Montgomery modular dual exponentiation: r = a1ˆp1 * a2ˆp2 mod m. |
|
Compute modular exponentiation using Montgomery reduction: r = (a ˆ p) mod m. |
|
Compute modular exponentiation in constant time: |
|
|
Compute two constant‐time Montgomery modular exponentiations together. |
Montgomery modular exponentiation with a single‐word base: r = (a ˆ p) mod m. |
|
Compute modular exponentiation using reciprocal reduction: r = (a ˆ p) mod m. |
|
Compute modular exponentiation with a simple sliding‐window algorithm: r = (a ˆ p) mod m. |
|
Compute the modular inverse of |
|
Compute r = (a << n) mod m (left‐shift then reduce). |
|
Compute r = (a << 1) mod m. |
|
Compute r = (a << 1) mod m, assuming 0 <= a < m. |
|
Left‐shift then reduce quickly: |
|
Compute r = (a * b) mod m. |
|
Montgomery multiply |
|
Multiply then reduce using a reciprocal context: r = (x * y) mod m (m from |
|
Compute |
|
Compute a modular square root: retˆ2 ≡ a (mod n) when a quadratic residue. |
|
Compute |
|
Compute |
|
Return |
|
Decode an MPI‐format integer (4‐byte length prefix plus big‐endian content). |
|
Multiply two BIGNUMs: |
|
Multiply BIGNUM |
|
Decode a native‐endian unsigned byte string into a BIGNUM. |
|
Allocate a new BIGNUM initialized to zero. |
|
Fast reduction of |
|
Fast reduction of |
|
Fast reduction of |
|
Fast reduction of |
|
Fast reduction of |
|
Return a fast modular‐reduction function for a known NIST prime. |
|
Compute a non‐negative remainder |
|
Return the size of |
|
Return the number of significant bits in a single BN_ULONG word. |
|
Return a short string describing compiled BIGNUM word size / options. |
|
Write the hexadecimal encoding of a BIGNUM to a BIO. |
|
Write the hexadecimal encoding of a BIGNUM to a FILE stream. |
|
Generate a cryptographically strong private random BIGNUM of |
|
Generate a cryptographically strong private random BIGNUM with strength. |
|
Generate a cryptographically strong uniform private random BIGNUM in [0, ]`range).` |
|
Generate a private random BIGNUM uniformly in [0, ]`range)` with strength bits. |
|
|
Generate a pseudo‐random BIGNUM (deprecated; prefer BN_rand / BN_priv_rand). |
|
Generate a pseudo‐random BIGNUM in [0, ]`range)` (deprecated; prefer BN_rand_range). |
Generate a cryptographically strong public random BIGNUM of |
|
Generate a cryptographically strong public random BIGNUM with explicit strength. |
|
Generate a cryptographically strong uniform public random BIGNUM in [0, ]`range).` |
|
Generate a cryptographically strong uniform random BIGNUM in [0, range).] |
|
Compute a reciprocal |
|
Compute r = a >> n (right shift by |
|
Compute r = a >> 1 (right shift by one bit). |
|
Allocate a BIGNUM whose limb storage is allocated from the secure heap. |
|
Estimate the security strength in bits for asymmetric parameters of sizes |
|
Set bit |
|
Set selected BIGNUM flag bits on |
|
BN_set_negative sets sign of a BIGNUM |
|
|
Set legacy BIGNUM tuning parameters (deprecated no‐op on modern builds). |
Set BIGNUM |
|
Convert a big‐endian two's‐complement byte array to a signed BIGNUM. |
|
Encode a signed BIGNUM as big‐endian two's‐complement of fixed width. |
|
Encode a signed BIGNUM as little‐endian two's‐complement of fixed width. |
|
Encode a BIGNUM as a fixed‐length native‐endian two's‐complement byte string. |
|
Convert a little‐endian two's‐complement byte array to a signed BIGNUM. |
|
Convert a native‐endian two's‐complement byte array to a signed BIGNUM. |
|
Square a BIGNUM: |
|
Subtract signed BIGNUMs: |
|
Subtract word |
|
Exchange the values of two BIGNUMs in constant time relative to their limb counts. |
|
Convert a BIGNUM to an ASN.1 ENUMERATED value. |
|
Convert a BIGNUM to an ASN.1 INTEGER (allocating or reusing |
|
Convert |
|
Add unsigned BIGNUMs: |
|
Compare absolute values of two BIGNUMs (ignores signs). |
|
Subtract unsigned BIGNUMs: |
|
Return a shared BIGNUM constant equal to 1. |
|
Make |
|
Set a BIGNUM to zero without allocating or freeing limbs. |
|
Free a BUF_MEM and its data buffer. |
|
Grow or shrink a BUF_MEM so its valid length is |
|
Grow or shrink a BUF_MEM buffer, zeroing any released or newly unused bytes. |
|
Allocate an empty BUF_MEM with default (non‐secure) allocation flags. |
|
Allocate a new BUF_MEM with the given allocation flags. |
|
Reverse |
|
|
Encrypt or decrypt data with CAST in CBC mode (deprecated; prefer EVP). |
|
Encrypt or decrypt data with CAST in 64‐bit CFB mode (deprecated; prefer EVP). |
|
Decrypt one CAST block in place as two CAST_LONG words (deprecated low‐level). |
|
Encrypt or decrypt one 8‐byte CAST block in ECB mode (deprecated; prefer EVP). |
|
Encrypt one CAST block in place as two CAST_LONG words (deprecated low‐level). |
|
Encrypt or decrypt data with CAST in 64‐bit OFB mode (deprecated; prefer EVP). |
|
Expand a CAST user key into a CAST_KEY schedule (deprecated; prefer EVP). |
Free a Certificate Policies extension value and its contents. |
|
Return the ASN.1 item descriptor for CERTIFICATEPOLICIES. |
|
Allocate an empty Certificate Policies extension value. |
|
|
Clear sensitive CMAC state while keeping the context allocated (deprecated). |
|
Copy CMAC state from |
|
Free a CMAC context and its resources. |
|
Return the internal EVP_CIPHER_CTX used by a CMAC context (deprecated). |
|
Allocate a new CMAC context (deprecated; prefer EVP_MAC). |
|
Finish a CMAC and write the authentication tag (deprecated). |
|
Initialize a CMAC context with a key and block cipher (deprecated; prefer EVP_MAC). |
|
Absorb more message bytes into a CMAC computation (deprecated). |
|
Reinitialize a CMAC context after CMAC_Final() so more data can be absorbed (deprecated). |
Create an empty CMS AuthEnvelopedData ContentInfo for an AEAD cipher. |
|
Create an empty CMS AuthEnvelopedData ContentInfo using a library context. |
|
Free a CMS ContentInfo structure and its contents. |
|
Return the ASN.1 item descriptor for CMS_ContentInfo. |
|
Allocate an empty CMS ContentInfo structure. |
|
Allocate a CMS ContentInfo associated with a library context and property query. |
|
Print a CMS_ContentInfo structure to a BIO. |
|
Decrypt a CMS EncryptedData ContentInfo with a symmetric key. |
|
Create a CMS EncryptedData ContentInfo by encrypting data from a BIO. |
|
Create a CMS EncryptedData ContentInfo by encrypting data from a BIO (with libctx). |
|
Set the content‐encryption cipher and copy the symmetric key into a CMS EncryptedData. |
|
Create an empty CMS EnvelopedData ContentInfo for |
|
Create an empty CMS EnvelopedData ContentInfo using a library context. |
|
Decrypt a CMS EnvelopedData structure and return a BIO of the plaintext. |
|
Return the ASN.1 item descriptor for CMS_EnvelopedData. |
|
Allocate a CMS signed‐receipt request with the given identifiers and recipient lists. |
|
Allocate a CMS signed‐receipt request using a library context for RNG. |
|
Free a CMS ReceiptRequest structure and its contents. |
|
Read the fields of a CMS ReceiptRequest without transferring ownership. |
|
Return the ASN.1 item descriptor for CMS_ReceiptRequest. |
|
Allocate an empty CMS ReceiptRequest structure. |
|
Compare a certificate against the recipient identifier of a RecipientEncryptedKey. |
|
Extract KeyAgreeRecipientIdentifier fields from a RecipientEncryptedKey. |
|
Decrypt one CMS RecipientInfo after associating the recipient key with it. |
|
Encrypt the content‐encryption key into one CMS RecipientInfo. |
|
Return the EVP_PKEY_CTX used for key transport or key agreement on a recipient info. |
|
Unwrap the content‐encryption key from one KARI RecipientEncryptedKey into |
|
Get the key‐encryption algorithm and optional UKM from a key‐agreement recipient info. |
|
Return the key‐wrap cipher context associated with a key‐agreement RecipientInfo. |
|
|
Get the originator identifier from a key‐agreement RecipientInfo. |
|
Return the stack of RecipientEncryptedKey values from a key‐agreement RecipientInfo. |
|
Compare a certificate against the originator identifier of a KARI RecipientInfo. |
|
Associate a private key with a key‐agreement (KARI) CMS RecipientInfo. |
|
Associate a private key and optional peer certificate with a key‐agreement CMS RecipientInfo. |
Return non‐owning pointers to the key‐encryption key identifier fields of a KEKRI. |
|
Compare a key identifier against the keyIdentifier of a KEK RecipientInfo. |
|
Compare a certificate against the recipient identifier in a key‐transport RecipientInfo. |
|
|
Retrieve key‐transport algorithms and related objects from a RecipientInfo. |
|
Get the certificate recipient identifier from a key‐transport RecipientInfo. |
Attach a symmetric key‐encryption key to a KEK RecipientInfo (transfers ownership of |
|
Supply the password used to derive the KEK for a PasswordRecipientInfo. |
|
Transfer ownership of a private key into a key‐transport RecipientInfo. |
|
Return the CMS RecipientInfo type of |
|
DER‐encode a CMS SharedInfo structure used in key‐encryption key derivation. |
|
Free a CMS SignedData structure and its contents. |
|
Initialize |
|
Allocate an empty CMS SignedData structure. |
|
Verify a CMS SignedData structure and return a BIO of the signed content on success. |
|
Compare a certificate against the signer identifier of a CMS SignerInfo. |
|
Retrieve algorithm and key pointers from a CMS SignerInfo. |
|
Return the message‐digest context used while signing or verifying a CMS SignerInfo. |
|
Return the EVP_PKEY_CTX used while signing or verifying a CMS SignerInfo. |
|
Return a pointer to the signature OCTET STRING inside a CMS SignerInfo. |
|
Get the signer identifier from a CMS SignerInfo (key id, or issuer and serial). |
|
Associate a signer certificate with a CMS SignerInfo (increments the cert reference). |
|
Explicitly finalize and sign a CMS SignerInfo (for CMS_PARTIAL with CMS_REUSE_DIGEST). |
|
Verify the signature on a CMS SignerInfo's signed attributes. |
|
Verify that the content digest matches a CMS SignerInfo (messageDigest or signature). |
|
Append an empty CertificateChoices slot to a CMS SignedData certificates set. |
|
Append an empty RevocationInfoChoice to a CMS ContentInfo's CRL set. |
|
Add a certificate to a SignedData or EnvelopedData CMS ContentInfo (transfers ownership). |
|
Add a CRL to a SignedData or EnvelopedData CMS ContentInfo (transfers ownership). |
|
Add a KEKRecipientInfo that wraps the content‐encryption key with a symmetric KEK. |
|
Add a PasswordRecipientInfo that derives a KEK from a password. |
|
Add a CMS signed receipt request to a SignerInfo. |
|
Add a certificate to a CMS ContentInfo, taking a reference on |
|
Add a CRL to a SignedData or EnvelopedData CMS ContentInfo (up‐refs the CRL). |
|
Add a recipient certificate and optional originator key material to enveloped CMS. |
|
Add a KeyTransRecipientInfo for |
|
Add a signer certificate and private key to a CMS SignedData ContentInfo. |
|
Append one S/MIME capability AlgorithmIdentifier to a stack. |
|
Encode a stack of algorithms as an SMIMECapabilities signed attribute on a SignerInfo. |
|
Populate |
|
Create a CMS CompressedData ContentInfo from content read from a BIO. |
|
Write the payload of a CMS Data ContentInfo to a BIO. |
|
Finalize CMS content processing after streaming through the BIO from CMS_dataInit(). |
|
Build a BIO chain that reads or writes the CMS content for |
|
Create a CMS Data ContentInfo from bytes read from |
|
Create a CMS Data contentInfo wrapping the octets read from |
|
Decrypt a CMS EnvelopedData or AuthEnvelopedData and write the content. |
|
Install a KEKRecipientInfo key on a CMS ContentInfo so CMS_decrypt can use it. |
|
Decrypt CMS PasswordRecipientInfo key material and store it for a later CMS_decrypt(). |
|
Decrypt CMS recipient key material using a private key, then store it for CMS_decrypt(). |
|
|
Decrypt CMS EnvelopedData/AuthEnvelopedData recipient key material using a private key and optional peer certificate. |
Create a CMS DigestedData ContentInfo from content read from a BIO. |
|
Create a CMS DigestedData ContentInfo using a library context and property query. |
|
Verify a CMS DigestedData ContentInfo and optionally write the content. |
|
Create a CMS EnvelopedData or AuthEnvelopedData encrypting content for recipient certificates. |
|
Create a CMS EnvelopedData or AuthEnvelopedData encrypting content for recipient certificates. |
|
Finalise a partially built CMS_ContentInfo (for example digest computation and field fill‐in). |
|
Finalize a partially built CMS SignedData using a precomputed content digest. |
|
Return the RecipientInfo structures from a CMS EnvelopedData message. |
|
Return all CMS_SignerInfo structures from a SignedData ContentInfo. |
|
Return a pointer to the embedded content octet string of a CMS ContentInfo. |
|
Return the embedded eContentType OID of a CMS ContentInfo. |
|
Return the signer certificates collected during a successful CMS_verify(). |
|
Return the ASN.1 content‐type OID of a CMS ContentInfo. |
|
Extract a CMS ReceiptRequest attribute from a SignerInfo. |
|
Return a new stack of all certificates carried in a CMS ContentInfo. |
|
Return a newly allocated stack of CRLs embedded in a CMS ContentInfo. |
|
Test whether a CMS ContentInfo carries detached (absent) embedded content. |
|
Set the embedded eContentType OID of a CMS ContentInfo (copied). |
|
Attach signer certificates from |
|
Mark CMS content as detached (external) or embedded. |
|
Create a CMS SignedData structure with the default library context. |
|
Create a CMS SignedData structure using a library context. |
|
Create a CMS signed receipt ContentInfo for a SignerInfo that requested a receipt. |
|
Append a copy of an X509_ATTRIBUTE to a CMS SignerInfo's signed attributes. |
|
|
Append a signed attribute identified by NID to a CMS SignerInfo. |
|
Append a signed attribute identified by ASN.1 object to a CMS SignerInfo. |
|
Append a signed attribute identified by short name to a CMS SignerInfo. |
Remove and return the signed attribute at index |
|
|
Return the first matching signed‐attribute value of a given ASN.1 type. |
Return the signed attribute at index |
|
|
Find a signed attribute in |
|
Find the next signed attribute matching an OID in a CMS SignerInfo. |
Return the number of signed attributes on a CMS SignerInfo. |
|
Prepare a CMS ContentInfo for indefinite‐length (streaming) ASN.1 encoding. |
|
Decompress a CMS CompressedData ContentInfo to |
|
Append a copy of an X509_ATTRIBUTE to a CMS SignerInfo's unsigned attributes. |
|
|
Append an unsigned attribute identified by NID to a CMS SignerInfo. |
|
Append an unsigned attribute identified by ASN.1 object to a CMS SignerInfo. |
|
Append an unsigned attribute identified by name to a CMS SignerInfo. |
Remove and return the unsigned attribute at an index in a CMS SignerInfo. |
|
|
Find an unsigned attribute by OID and return its first ASN.1 value data pointer. |
Return the unsigned attribute at an index in a CMS SignerInfo. |
|
|
Find an unsigned attribute by NID in a CMS SignerInfo. |
|
Find an unsigned attribute by ASN.1 object in a CMS SignerInfo. |
Return how many unsigned attributes are present on a CMS SignerInfo. |
|
Verify CMS SignedData signatures and write the content to |
|
Verify a CMS signed receipt against the original SignedData that requested it. |
|
Free a compression context. |
|
Return the compression method associated with a context. |
|
Get the numeric type identifier of a compression context's method. |
|
Create a compression context for the given method. |
|
Return the stream‐based brotli compression method. |
|
Return the one‐shot brotli compression method. |
|
Compress a block of data. |
|
Decompress |
|
Return the human‐readable name of a compression method. |
|
Get the numeric type identifier of a compression method. |
|
Return the zlib compression method. |
|
Return the one‐shot zlib compression method. |
|
Return the Zstandard compression method. |
|
Return the one‐shot Zstandard COMP_METHOD (compresses each BIO_write as a complete frame). |
|
Dump a legacy CONF hash table to a BIO in name=value form. |
|
Dump a legacy CONF LHASH to a FILE in a human‐readable form. |
|
Free a legacy CONF LHASH and all contained CONF_VALUE entries. |
|
Return a newly allocated path to the default OpenSSL configuration file. |
|
Look up a numeric value in a legacy CONF LHASH. |
|
Return all CONF_VALUE entries belonging to |
|
Look up a string value in a legacy CONF LHASH. |
|
Return the CONF_MFLAGS_* control flags stored on a loaded module instance. |
|
Return the CONF_MODULE registration object for an initialized module instance. |
|
Return the configured name of an initialized CONF module instance. |
|
Return the opaque application pointer stored on a CONF module instance. |
|
Return the value string associated with an initialized CONF module instance. |
|
Set control flags on a loaded configuration module instance. |
|
Store an opaque application pointer on a loaded configuration module instance. |
|
Load a CONF file into an LHASH of CONF_VALUE (legacy CONF API). |
|
Load configuration name/value pairs from a BIO into an LHASH (legacy API). |
|
Load a CONF file from an open FILE into an LHASH of CONF_VALUE (legacy API). |
|
Register a built‐in configuration module under |
|
Return the application pointer previously stored on a CONF_MODULE. |
|
Store an opaque application pointer on a registered CONF DSO module. |
|
Finish and tear down all currently loaded CONF modules. |
|
Initialize configured OpenSSL modules listed in |
|
Load and initialize CONF modules from a file using the default library context. |
|
Load and initialize CONF modules from a file using library context |
|
Unload CONF modules previously loaded into the process. |
|
Split |
|
Set the default CONF_METHOD used by the legacy CONF_load family. |
|
Attach a legacy LHASH of CONF_VALUE entries as the data store of a CONF object. |
|
Free a CRL Distribution Points extension value and its contents. |
|
Return the ASN.1 item descriptor for CRL_DIST_POINTS. |
|
Allocate a new CRL Distribution Points extension value. |
|
Unwrap a key with AES Key Wrap (RFC 3394) using |
|
Unwrap a key with AES Key Wrap with Padding (RFC 5649) using |
|
Wrap a key with AES Key Wrap (RFC 3394) using |
|
Wrap a key with AES Key Wrap with Padding (RFC 5649) using |
|
Destroy a thread‐local key previously created with CRYPTO_THREAD_init_local(). |
|
Compare two CRYPTO_THREAD_ID values for equality. |
|
Return an identifier for the calling thread. |
|
Return the calling thread's value for thread‐local key |
|
Allocate a thread‐local storage key for use with CRYPTO_THREAD_get/set_local(). |
|
Free a CRYPTO_RWLOCK allocated by CRYPTO_THREAD_lock_new(). |
|
Allocate a new read/write lock for CRYPTO_THREAD_* locking helpers. |
|
Acquire a shared (read) lock on a CRYPTO_RWLOCK. |
|
Run |
|
Store |
|
Release a previously acquired read or write lock on a CRYPTO_RWLOCK. |
|
Acquire a CRYPTO_RWLOCK for exclusive (write) access. |
|
Allocate ex_data at index |
|
Atomically add |
|
Atomically load a 64‐bit value, optionally under |
|
Atomically load an int value, optionally under |
|
Atomically bitwise‐OR |
|
Decrypt with a 128‐bit block cipher in CBC mode. |
|
Encrypt with a 128‐bit block cipher in CBC mode. |
|
Absorb additional authenticated data into a CCM context. |
|
Decrypt ciphertext and update the CCM authentication state. |
|
Decrypt ciphertext in CCM using a ccm128_f acceleration callback. |
|
Encrypt plaintext and update the CCM authentication state. |
|
Encrypt plaintext in CCM using a ccm128_f acceleration callback. |
|
Initialise a CCM128_CONTEXT with tag length, length‐field size, and block cipher. |
|
Set the CCM nonce and message length for a subsequent encrypt or decrypt. |
|
Write the computed CCM authentication tag into |
|
Encrypt or decrypt with a 128‐bit block cipher in 1‐bit CFB mode. |
|
Encrypt or decrypt with a 128‐bit block cipher in 8‐bit CFB mode. |
|
Encrypt or decrypt with a 128‐bit block cipher in full‐block CFB mode. |
|
Securely clear |
|
Reallocate a buffer, securely clearing any released trailing bytes. |
|
Encrypt or decrypt with a 128‐bit block cipher in CTR mode. |
|
Encrypt or decrypt in CTR mode using a 32‐bit counter stream function. |
|
Decrypt CS1 ciphertext stealing using a CBC decrypt function. |
|
Decrypt CS1 ciphertext stealing using a single‐block decrypt/encrypt pair via |
|
Encrypt with CS1 ciphertext stealing using a CBC encrypt function. |
|
Encrypt with CS1 ciphertext stealing using a single‐block encrypt function. |
|
Duplicate CRYPTO_EX_DATA entries from |
|
Free memory previously allocated by CRYPTO_malloc() / OPENSSL_malloc(). |
|
Free all ex_data attached to |
|
Release an application ex_data index previously allocated for a class (historically a no‐op cleanup). |
|
Absorb additional authenticated data into a GCM context before ciphertext. |
|
Decrypt ciphertext and update the GCM authentication state. |
|
Decrypt ciphertext in GCM using a 32‐bit CTR stream acceleration callback. |
|
Encrypt plaintext and update the GCM authentication state. |
|
Encrypt plaintext in GCM using a 32‐bit CTR stream acceleration callback. |
|
Finalise GCM and optionally verify a received authentication tag. |
|
Initialise (or reinitialise) a caller‐owned GCM128_CONTEXT. |
|
Allocate and initialise a GCM128_CONTEXT for |
|
Free a GCM128_CONTEXT allocated by CRYPTO_gcm128_new(). |
|
Set the GCM IV / nonce for a subsequent encrypt or decrypt operation. |
|
Write the computed GCM authentication tag into |
|
Retrieve the pointer stored at ex_data index |
|
Allocate a new application‐specific ex_data index for a CRYPTO_EX_INDEX_* class. |
|
Retrieve the process‐wide CRYPTO memory allocator callbacks currently installed. |
|
Allocate |
|
Compare two memory regions in constant time with respect to their contents. |
|
Duplicate |
|
Initialise |
|
Decrypt NIST CS2/CS3‐style ciphertext stealing using a CBC decrypt function. |
|
Decrypt NIST CS2/CS3‐style ciphertext stealing using a block decrypt function. |
|
Encrypt with NIST CS2/CS3‐style ciphertext stealing using a CBC encrypt function. |
|
Encrypt with NIST CS2/CS3‐style ciphertext stealing using a block encrypt function. |
|
Absorb additional authenticated data into an OCB context. |
|
Release internal OCB tables and cleanse the context (does not free |
|
Copy an OCB context, optionally replacing the encrypt/decrypt key pointers. |
|
Decrypt ciphertext and update the OCB authentication state. |
|
Encrypt plaintext and update the OCB authentication state. |
|
Finalise OCB and verify a received authentication tag. |
|
Initialise an existing OCB128_CONTEXT for the given keys and block functions. |
|
Allocate and initialise an OCB128_CONTEXT for the given keys and block functions. |
|
Set the OCB IV / nonce and authentication tag length for an operation. |
|
Write the computed OCB authentication tag into |
|
Encrypt or decrypt with a 128‐bit block cipher in OFB mode. |
|
Resize an OpenSSL allocation to |
|
Return the actual secure‐heap block size reserved for |
|
Report whether |
|
Clear |
|
Free memory previously allocated from the secure heap. |
|
Allocate |
|
Tear down the secure heap after CRYPTO_secure_malloc_init() (when unused). |
|
Initialize the secure heap used by CRYPTO_secure_malloc(). |
|
Report whether the secure heap has been successfully initialised. |
|
Return how many bytes are currently allocated from the secure heap. |
|
Allocate |
|
Store |
|
Install process‐wide CRYPTO memory allocator callbacks (before first allocation). |
|
Duplicate a NUL‐terminated string using the OpenSSL allocator. |
|
Duplicate at most |
|
Encrypt or decrypt data with a 128‐bit block cipher in XTS mode. |
|
Allocate |
|
Free a CT log store and the CT log instances it holds. |
|
|
Find a CT log in a store by log ID. |
Load the default CT log list into a store. |
|
Load a CT log list into a store from a file. |
|
Allocate an empty CT log store. |
|
Create a new CT log store associated with |
|
Free a Certificate Transparency log entry and its owned fields. |
|
Get the ID of a CT log. |
|
Get the name of a CT log. |
|
Get the public key of a CT log. |
|
Create a CT log with a public key and name using the default library context. |
|
Create a CT log for |
|
Create a CT log from a base64‐encoded key using the default library context. |
|
Create a CT log from a base64‐encoded SubjectPublicKeyInfo DER key. |
|
Delete a policy evaluation context and anything it owns. |
|
|
Return the peer certificate associated with SCTs in a policy context. |
|
Get the issuer of the certificate associated with the received SCTs. |
|
Return the CT log store used when evaluating SCTs in this context. |
|
Get the evaluation time used when checking whether an SCT is in the future. |
Create an empty CT policy evaluation context with the default library context. |
|
|
Create a new, empty CT policy evaluation context for |
|
Set the certificate that the SCTs in a policy context were issued for. |
|
Set the issuer certificate used when validating precertificate SCTs. |
|
Set the shared CT log store used when evaluating SCTs. |
|
Set the time used when evaluating SCT timestamps in a policy context. |
|
Encrypt or decrypt data with Camellia in CBC mode (deprecated). |
|
Encrypt or decrypt data with Camellia in 128‐bit CFB mode (deprecated). |
|
Encrypt or decrypt data with Camellia in 1‐bit CFB mode (deprecated). |
|
Encrypt or decrypt data with Camellia in 8‐bit CFB mode (deprecated). |
|
Encrypt or decrypt data with Camellia in 128‐bit CTR mode (deprecated). |
|
Decrypt one 16‐byte Camellia block (deprecated; prefer EVP_DecryptInit_ex and related EVP APIs). |
|
Encrypt or decrypt one 16‐byte Camellia block in ECB mode (deprecated). |
|
Encrypt one 16‐byte Camellia block (deprecated; prefer EVP_EncryptInit_ex and related EVP APIs). |
|
Encrypt or decrypt data with Camellia in 128‐bit OFB mode (deprecated). |
|
Expand a raw Camellia key into a CAMELLIA_KEY schedule (deprecated; prefer EVP). |
|
Compute a DES CBC checksum of |
|
Encrypt or decrypt with DES in CBC mode without updating the IV (deprecated; prefer DES_ncbc_encrypt or EVP). |
|
Encrypt or decrypt with DES in 64‐bit CFB mode (deprecated; prefer EVP). |
|
Encrypt or decrypt with DES in CFB mode with a configurable bit width (deprecated; prefer EVP). |
|
Test whether each byte of a DES key has odd parity (deprecated). |
|
Compute a traditional Unix DES‐based password hash using a static result buffer (deprecated). |
|
Decrypt one block with triple‐DES EDE using three schedules (deprecated low‐level). |
|
Encrypt or decrypt one 8‐byte block with triple‐DES EDE in ECB mode (deprecated; prefer EVP). |
|
Encrypt or decrypt one 8‐byte DES block in ECB mode (deprecated; prefer EVP). |
|
Encrypt or decrypt with triple‐DES EDE in CBC mode (deprecated; prefer EVP). |
|
Encrypt or decrypt with triple‐DES EDE in 64‐bit CFB mode (deprecated; prefer EVP). |
|
Encrypt or decrypt with triple‐DES EDE in CFB mode with a configurable bit width (deprecated; prefer EVP). |
|
Encrypt or decrypt with triple‐DES EDE in 64‐bit OFB mode (deprecated; prefer EVP). |
|
Encrypt or decrypt one DES block in place with IP and FP (deprecated low‐level core). |
|
Encrypt or decrypt one DES block without IP/FP (used internally for 3DES; deprecated). |
|
Encrypt one block with triple‐DES EDE using three schedules (deprecated low‐level). |
|
Compute a traditional Unix DES‐based password hash into a caller buffer (deprecated). |
|
Test whether a DES key is one of the known weak or semi‐weak keys (deprecated). |
|
Expand a DES key into a key schedule (alias of DES_set_key; deprecated). |
|
Encrypt or decrypt with DES in CBC mode, updating the IV (deprecated; prefer EVP). |
|
Encrypt or decrypt with DES in 64‐bit OFB mode (deprecated; prefer EVP). |
|
Encrypt or decrypt with DES in OFB mode with a configurable bit width (deprecated; prefer EVP). |
|
Return a short string describing compiled DES implementation options (deprecated). |
|
Encrypt or decrypt with DES in PCBC mode (deprecated; prefer EVP). |
|
Compute a DES‐based quadratic checksum over |
|
Generate a random DES key with odd parity that is not a weak key (deprecated). |
|
Expand a DES key into a key schedule (checked or unchecked per DES_check_key; deprecated). |
|
Expand a DES key into a key schedule after checking parity and weak keys (deprecated). |
|
Expand a DES key into a key schedule without parity or weak‐key checks (deprecated). |
|
Set odd parity bits on each byte of a DES key block (deprecated). |
|
Derive two DES keys from a NUL‐terminated ASCII string (deprecated). |
|
Derive a single DES key from a NUL‐terminated ASCII string (deprecated). |
|
Encrypt or decrypt with DES in RSA DESX‐CBC (XCBC) mode (deprecated; prefer EVP). |
|
Derive keying material with the ANSI X9.42 / RFC 2631 KDF (deprecated). |
|
Return the built‐in OpenSSL software DH_METHOD (deprecated). |
|
Return the bit length of the Diffie‐Hellman prime modulus p (deprecated). |
|
Validate Diffie‐Hellman parameters and return a bitmask of problems (deprecated). |
|
Validate Diffie‐Hellman parameters and report problems via the error queue (deprecated). |
|
Perform a lightweight check that DH parameters p and g look plausible (deprecated). |
|
Validate Diffie‐Hellman p/g (and q if present) and report problems via the error queue (deprecated). |
|
Validate a Diffie‐Hellman public key and return a bitmask of problems (deprecated). |
|
Validate a Diffie‐Hellman public key and report problems via the error queue (deprecated). |
|
Clear selected flag bits on a DH object (deprecated). |
|
Derive the DH shared secret from a peer public key (deprecated). |
|
Derive the DH shared secret with NIST SP 800‐56A leading‐zero padding (deprecated). |
|
Free a DH object and decrement its reference count (deprecated). |
|
Generate a Diffie‐Hellman private/public key pair on |
|
Generate Diffie‐Hellman parameters with a legacy progress callback (deprecated). |
|
Generate Diffie‐Hellman domain parameters into |
|
Return the ENGINE bound to a DH object, if any (deprecated). |
|
Return the generator g stored in a DH object (deprecated). |
|
Borrow pointers to the public and private key BIGNUMs of a DH object (deprecated). |
|
Return the prime modulus p stored in a DH object (deprecated). |
|
Borrow pointers to the prime, optional subprime, and generator of a DH object (deprecated). |
|
Return the private key BIGNUM stored in a DH object, if any. |
|
Return the public key component of a DH object without duplicating it (deprecated). |
|
Return the optional subprime q stored in a DH object (deprecated). |
|
Allocate a DH object with the RFC 5114 1024‐bit MODP group using a 160‐bit subgroup (deprecated). |
|
Allocate a DH object with the RFC 5114 2048‐bit MODP group using a 224‐bit subgroup (deprecated). |
|
Allocate a DH object with the RFC 5114 2048‐bit MODP group using a 256‐bit subgroup (deprecated). |
|
Return the process‐wide default DH_METHOD (deprecated). |
|
Return application data previously stored on a DH object (deprecated). |
|
Return the optional private‐value length hint stored on a DH object (deprecated). |
|
Return the named‐group NID for a DH object if its parameters match a known group (deprecated). |
|
Duplicate a DH_METHOD, copying its name and callbacks (deprecated). |
|
Free a DH_METHOD structure and any associated memory (deprecated). |
|
Return the opaque application data pointer stored on a DH_METHOD (deprecated). |
|
Return the display name stored on a DH_METHOD (deprecated). |
|
Return the modular‐exponentiation callback from a DH_METHOD (deprecated). |
|
Return the shared‐secret compute_key callback from a DH_METHOD (deprecated). |
|
Return the finish/cleanup callback installed on a custom DH_METHOD (deprecated). |
|
Return the flag mask stored on a DH_METHOD (deprecated). |
|
Return the key‐generation callback from a DH_METHOD (deprecated). |
|
Return the parameter‐generation callback from a DH_METHOD (deprecated). |
|
Return the DH object‐initialization callback from a DH_METHOD (deprecated). |
|
Allocate a custom DH_METHOD with a duplicated name (deprecated). |
|
Attach opaque application data to a DH_METHOD, transferring ownership of the pointer (deprecated). |
|
Replace the display name stored on a DH_METHOD (deprecated). |
|
Set the modular‐exponentiation callback on a DH_METHOD (deprecated). |
|
Set the shared‐secret compute_key callback on a DH_METHOD (deprecated). |
|
Set the DH object teardown callback on a DH_METHOD (deprecated). |
|
Replace the flag mask stored on a DH_METHOD (deprecated). |
|
Set the key‐generation callback on a DH_METHOD (deprecated). |
|
Set the parameter‐generation callback on a DH_METHOD (deprecated). |
|
Set the DH object‐initialization callback on a DH_METHOD (deprecated). |
|
Allocate and initialize an empty DH object (deprecated). |
|
Allocate a DH object preloaded with named safe‐prime parameters. |
|
Allocate a DH object that uses |
|
Estimate the security strength in bits of a DH key's parameters (deprecated). |
|
Set the public and/or private key BIGNUMs on a DH object, transferring ownership (deprecated). |
|
Set the prime, optional subprime, and generator on a DH object, transferring ownership (deprecated). |
|
Set the process‐wide default DH_METHOD (deprecated). |
|
Store application data on a DH object at a CRYPTO_EX index (deprecated). |
|
Set flag bits on a DH object without clearing existing flags (deprecated). |
|
Set the optional private‐value length hint on a DH object (deprecated). |
|
Select the DH_METHOD used for operations on |
|
Return the Diffie‐Hellman shared‐secret size in bytes (deprecated). |
|
Return which of the requested flag bits are currently set on a DH object (deprecated). |
|
Increment the reference count of a DH object (deprecated). |
|
Duplicate Diffie‐Hellman domain parameters (DHparams_dup) (deprecated). |
Return the ASN.1 item descriptor for Diffie‐Hellman domain parameters. |
|
|
Print Diffie‐Hellman parameters to a BIO in human‐readable form (deprecated). |
|
Print DH parameters to a FILE in human‐readable form (deprecated). |
Free a DirectoryString and its contents. |
|
Return the ASN.1 item descriptor for DirectoryString. |
|
Allocate an empty DirectoryString (ASN.1 string CHOICE wrapper). |
|
Free a DisplayText (ASN.1 string CHOICE) and its contents. |
|
Return the ASN.1 item descriptor for DISPLAYTEXT. |
|
Allocate an empty DisplayText (ASN.1 string CHOICE). |
|
Free a distribution point name value and its contents. |
|
Return the ASN.1 item descriptor for DIST_POINT_NAME. |
|
Allocate a new distribution point name value. |
|
Free a CRL distribution point value and its contents. |
|
Return the ASN.1 item descriptor for DIST_POINT. |
|
Allocate a new CRL distribution point value. |
|
Fill a relative distribution‐point name using an issuer X509_NAME. |
|
|
Return the built‐in OpenSSL software DSA_METHOD (deprecated). |
Free a DSA_SIG and its r and s BIGNUM components. |
|
Borrow pointers to the r and s components of a DSA signature. |
|
Allocate an empty DSA signature structure holding r and s. |
|
Set the r and s components of a DSA signature, transferring ownership. |
|
|
Return the bit length of the DSA prime modulus p (deprecated). |
|
Clear selected flag bits on a DSA object (deprecated). |
|
Sign a digest with a DSA private key, returning a DSA_SIG structure (deprecated). |
|
Verify a DSA signature against a digest using a DSA_SIG structure (deprecated). |
|
Duplicate DSA parameters (and key material when present) into a new DH object (deprecated). |
|
Free a DSA object and its associated resources (deprecated). |
|
Generate a DSA public/private key pair from parameters already in |
|
Generate DSA domain parameters with a legacy progress callback (deprecated). |
|
Generate DSA domain parameters into an existing DSA object (deprecated). |
|
Return the ENGINE associated with a DSA key, if any. |
|
Return the DSA generator g without duplicating it (deprecated). |
|
Return pointers to the DSA public and private key components without transferring ownership (deprecated). |
|
Return the DSA prime modulus p without duplicating it (deprecated). |
|
Return pointers to the DSA domain parameters p, q, and g without transferring ownership (deprecated). |
|
Return the private key component of a DSA object without duplicating it (deprecated). |
|
Return the public key component of a DSA object without duplicating it (deprecated). |
|
Return the DSA subgroup order q without duplicating it (deprecated). |
|
Return the current default DSA_METHOD (deprecated). |
|
Retrieve application data previously stored on a DSA object (deprecated). |
|
Return the DSA_METHOD currently bound to |
|
Duplicate a DSA_METHOD object (deprecated). |
|
Free a DSA_METHOD structure and any associated memory (deprecated). |
|
Return the opaque application data pointer stored on a DSA_METHOD (deprecated). |
|
Return the descriptive name stored on a DSA_METHOD (deprecated). |
|
Return the modular‐exponentiation callback from a DSA_METHOD (deprecated). |
|
Return the DSA object‐finalization callback from a DSA_METHOD (deprecated). |
|
Return the flag mask stored on a DSA_METHOD (deprecated). |
|
Return the DSA object‐initialization callback from a DSA_METHOD (deprecated). |
|
Return the key‐generation callback from a DSA_METHOD (deprecated). |
|
Return the modular‐exponentiation callback from a DSA_METHOD (deprecated). |
|
Return the parameter‐generation callback from a DSA_METHOD (deprecated). |
|
Return the signing callback installed on a DSA_METHOD. |
|
Return the sign‐setup callback installed on a DSA_METHOD (deprecated). |
|
Return the signature‐verification callback from a DSA_METHOD (deprecated). |
|
Allocate a new DSA_METHOD with the given name and default flags (deprecated). |
|
Store an opaque application pointer on a DSA_METHOD (deprecated). |
|
Set the descriptive name of a DSA_METHOD (deprecated). |
|
Set the modular‐exponentiation callback on a custom DSA_METHOD (deprecated). |
|
Set the DSA object‐finalization callback on a DSA_METHOD (deprecated). |
|
Set the flag mask on a DSA_METHOD (deprecated). |
|
Set the DSA object‐initialization callback on a custom DSA_METHOD (deprecated). |
|
Set the key‐generation callback on a custom DSA_METHOD (deprecated). |
|
Set the modular‐exponentiation callback on a DSA_METHOD (deprecated). |
|
Set the parameter‐generation callback on a custom DSA_METHOD (deprecated). |
|
Install the DSA signing callback on a DSA_METHOD (deprecated). |
|
Set the signature precomputation callback on a DSA_METHOD (deprecated). |
|
Set the DSA signature‐verification callback on a custom DSA_METHOD (deprecated). |
|
Allocate an empty DSA object using the default method (deprecated). |
|
Allocate a DSA object that uses methods from |
|
Print a human‐readable representation of a DSA key to a BIO (deprecated). |
|
Print a human‐readable representation of a DSA key to a FILE (deprecated). |
|
Estimate the security strength in bits of a DSA key from its parameters (deprecated). |
|
Set the public and optional private key components of a DSA object (deprecated). |
|
Set the DSA domain parameters p, q, and g, transferring ownership (deprecated). |
|
Set the process‐wide default DSA_METHOD (deprecated). |
|
Store application‐specific data on a DSA object at a CRYPTO ex_data index (deprecated). |
|
Set flag bits on a DSA object without clearing existing flags (deprecated). |
|
Select the DSA_METHOD used for operations on |
|
Create a DER‐encoded DSA signature over a message digest (deprecated). |
|
Legacy DSA precomputation stub retained for ABI compatibility (deprecated; do not use). |
|
Return the maximum ASN.1 encoded DSA signature size for |
|
Test whether all bits in |
|
Increment the reference count of a DSA object (deprecated). |
|
Verify a DSA signature over a message digest (deprecated). |
|
Deep‐copy DSA domain parameters into a new DSA object (deprecated). |
|
Print DSA domain parameters (p, q, g) to a BIO in human‐readable form (deprecated). |
|
Print DSA domain parameters to a FILE (deprecated). |
Return a client‐only SSL_METHOD negotiating DTLSv1.0 or DTLSv1.2. |
|
Return the maximum application‐data payload size for a DTLS connection. |
|
Return a client‐or‐server SSL_METHOD that negotiates DTLS 1.0 or 1.2. |
|
Return a server‐only SSL_METHOD that negotiates DTLS 1.0 or 1.2. |
|
Set a callback that controls DTLS retransmission timer duration. |
|
|
Return a client‐only SSL_METHOD for DTLSv1.2 (deprecated). |
|
Return an SSL_METHOD for DTLSv1.2 only (client and server; deprecated). |
|
Return a server‐only SSL_METHOD for DTLSv1.2 (deprecated). |
|
Return a client‐only SSL_METHOD for DTLSv1.0 (deprecated). |
Statelessly listen for a new DTLS ClientHello and verify the cookie exchange. |
|
|
Return a client‐or‐server SSL_METHOD restricted to DTLS 1.0 (deprecated). |
|
Return a server‐only SSL_METHOD for DTLSv1.0 (deprecated). |
|
Derive key material from an ECDH shared secret using the X9.63 KDF (deprecated). |
|
Perform ECDH and optionally apply a KDF to the shared secret (deprecated). |
frees a ECDSA_SIG structure |
|
Borrow pointers to the r and s components of an ECDSA signature. |
|
Return a borrowed pointer to the r component of an ECDSA signature. |
|
Return a borrowed pointer to the s component of an ECDSA signature. |
|
Allocates and initialize a ECDSA_SIG structure |
|
Set the r and s components of an ECDSA signature, transferring ownership. |
|
|
Computes the ECDSA signature of the given hash value using the supplied private key and returns the created signature. |
|
Computes ECDSA signature of a given hash value using the supplied private key (note: sig must point to ECDSA_size(eckey) bytes of memory). |
|
Verifies that the supplied signature is a valid ECDSA signature of the supplied hash value using the supplied public key. |
|
Computes ECDSA signature of a given hash value using the supplied private key (note: sig must point to ECDSA_size(eckey) bytes of memory). |
|
Computes ECDSA signature of a given hash value using the supplied private key (note: sig must point to ECDSA_size(eckey) bytes of memory). |
|
Precompute parts of the signing operation |
|
Returns the maximum length of the DER encoded signature |
|
Verifies that the given signature is valid ECDSA signature of the supplied hash value using the specified public key. |
Free an ECPARAMETERS object. |
|
Return the ASN.1 item descriptor for ECPARAMETERS. |
|
Allocate a new ECPARAMETERS object. |
|
Free an ECPKPARAMETERS object. |
|
Return the ASN.1 item descriptor for ECPKPARAMETERS. |
|
Allocate a new ECPKPARAMETERS object. |
|
|
Print EC domain parameters from an EC_GROUP to a BIO (deprecated). |
|
Print EC public‐key parameters from |
|
Prints out the ec parameters on human readable form. |
|
Prints out the ec parameters on human readable form. |
|
Returns the basic GF2m ec method |
|
Returns GFp methods using montgomery multiplication. |
|
Returns GFp methods using optimized methods for NIST recommended curves |
|
Returns the basic GFp ec methods which provides the basis for the optimized methods. |
Checks whether the parameter in the EC_GROUP define a valid ec group |
|
Checks whether the discriminant of the elliptic curve is zero or not |
|
Identify whether |
|
|
Clears and frees a EC_GROUP object |
Compares two EC_GROUP objects |
|
Copies EC_GROUP objects. Note: both EC_GROUPs must use the same EC_METHOD. |
|
Creates a new EC_GROUP object and copies the content form src to the newly created EC_KEY object |
|
Frees a EC_GROUP object |
|
Gets the cofactor of an EC_GROUP |
|
Gets the field of an EC_GROUP |
|
Returns the generator of a EC_GROUP object. |
|
Gets the order of an EC_GROUP |
|
Return a pointer to the optional seed associated with an EC_GROUP. |
|
Return whether an EC_GROUP encodes as a named curve or with explicit parameters. |
|
Return the NID of the basis type used to represent field elements of |
|
Gets the cofactor of a EC_GROUP |
|
Gets the parameters of the ec curve defined by yˆ2 = xˆ3 + a*x + b (for GFp) or yˆ2 + x_y = xˆ3 + a_xˆ2 + b (for GF2m) |
|
|
Gets the parameters of an ec curve. Synonym for EC_GROUP_get_curve |
|
Gets the parameters of an ec curve. Synonym for EC_GROUP_get_curve |
Returns the curve name of a EC_GROUP object |
|
Returns the number of bits needed to represent a field element |
|
Creates an ECPARAMETERS object for the given EC_GROUP object. |
|
Creates an ECPKPARAMETERS object for the given EC_GROUP object. |
|
Returns the field type of the EC_GROUP. |
|
Returns the montgomery data for order(Generator) |
|
Gets the order of a EC_GROUP |
|
Return the pentanomial basis degrees k1, k2, k3 for a characteristic‐2 curve group. |
|
|
Return how EC points in this group are encoded by default. |
Return the length of the optional seed associated with an EC_GROUP. |
|
Return the trinomial basis degree k for a characteristic‐2 curve group. |
|
|
Reports whether a precomputation has been done |
|
Returns the EC_METHOD of the EC_GROUP object. |
|
Creates a new EC_GROUP object |
|
Creates a EC_GROUP object with a curve specified by a NID. Same as EC_GROUP_new_by_curve_name_ex but the libctx and propq are always NULL. |
|
Creates a EC_GROUP object with a curve specified by a NID |
Creates a new EC_GROUP object with the specified parameters defined over GF2m (defined by the equation yˆ2 + x_y = xˆ3 + a_xˆ2 + b) |
|
Creates a new EC_GROUP object with the specified parameters defined over GFp (defined by the equation yˆ2 = xˆ3 + a*x + b) |
|
Creates a new EC_GROUP object from an ECPARAMETERS object |
|
|
Creates a new EC_GROUP object from an ECPKPARAMETERS object |
Creates a EC_GROUP object with a curve specified by parameters. The parameters may be explicit or a named curve, |
|
Gets the number of bits of the order of an EC_GROUP |
|
|
Stores multiples of generator for faster point multiplication |
Select whether an EC_GROUP encodes as a named curve or with explicit parameters. |
|
Sets the parameters of an ec curve defined by yˆ2 = xˆ3 + a*x + b (for GFp) or yˆ2 + x_y = xˆ3 + a_xˆ2 + b (for GF2m) |
|
|
Sets the parameter of an ec curve. Synonym for EC_GROUP_set_curve |
|
Sets the parameters of an ec curve. Synonym for EC_GROUP_set_curve |
Sets the name of a EC_GROUP object |
|
Sets the generator and its order/cofactor of a EC_GROUP object. |
|
|
Select how EC points in this group are encoded (compressed, uncompressed, or hybrid). |
Set the optional seed bytes associated with an EC_GROUP. |
|
Creates an OSSL_PARAM array with the parameters describing the given EC_GROUP. The resulting parameters may contain an explicit or a named curve depending on the EC_GROUP. |
|
|
Free an EC_KEY_METHOD. |
|
Retrieve the ECDH shared‐secret callback from an EC_KEY_METHOD (deprecated). |
|
Retrieve init/finish/copy/set_* callbacks from an EC_KEY_METHOD (deprecated). |
|
Retrieve the key‐generation callback from an EC_KEY_METHOD (deprecated). |
|
Retrieve ECDSA signing callbacks from an EC_KEY_METHOD (deprecated). |
|
Retrieve ECDSA verify callbacks from an EC_KEY_METHOD (deprecated). |
|
Allocate a new EC_KEY_METHOD, optionally copying |
|
Set the ECDH shared‐secret callback on an EC_KEY_METHOD (deprecated). |
|
Install lifecycle and field‐assignment callbacks on an EC_KEY_METHOD (deprecated). |
|
Set the key‐generation callback on an EC_KEY_METHOD (deprecated). |
|
Install ECDSA signing callbacks on an EC_KEY_METHOD. |
|
Set ECDSA verify callbacks on an EC_KEY_METHOD (deprecated). |
|
Return the built‐in OpenSSL EC_KEY_METHOD (deprecated). |
|
Indicates if an EC_KEY can be used for signing. |
|
Verifies that a private and/or public key is valid. |
|
Clear the given flag bits on an EC_KEY (deprecated). |
|
Copies a EC_KEY object. |
|
Report whether |
|
Creates a new EC_KEY object and copies the content from src to it. |
|
Frees a EC_KEY object. |
|
Creates a new ec private (and optional a new public) key. |
|
Returns the ENGINE object of a EC_KEY object |
|
Returns the EC_GROUP object of a EC_KEY object |
|
Returns the private key of a EC_KEY object. |
|
Returns the public key of a EC_KEY object. |
|
Return the point‐conversion form used when encoding an EC_KEY public point (deprecated). |
|
Return the current default EC_KEY_METHOD (deprecated). |
|
Return encoding‐control flags from an EC_KEY (deprecated). |
|
Retrieve application data previously stored on an EC_KEY (deprecated). |
|
Return the flag bits currently set on an EC_KEY (deprecated). |
|
Return the EC_KEY_METHOD currently used by |
|
Encodes an EC_KEY public key to an allocated octet string |
|
Creates a new EC_KEY object. Same as calling EC_KEY_new_ex with a NULL library context |
|
Creates a new EC_KEY object using a named curve as underlying EC_GROUP object. Same as calling EC_KEY_new_by_curve_name_ex with a NULL library context and property query string. |
|
Creates a new EC_KEY object using a named curve as underlying EC_GROUP object. |
|
Create a new empty EC_KEY using a library context (deprecated). |
|
Allocate an EC_KEY using the EC method from |
|
Decodes a EC_KEY public key from a octet string |
|
Decodes an EC_KEY private key from an octet string |
|
Creates a table of pre‐computed multiples of the generator to accelerate further EC_KEY operations. |
|
Prints out the contents of a EC_KEY object |
|
Prints out the contents of a EC_KEY object |
|
Encodes an EC_KEY private key to an allocated octet string |
|
Encodes a EC_KEY private key to an octet string |
|
Set ASN.1 encoding flags on the EC_GROUP inside |
|
Set the point‐conversion form used when encoding an EC_KEY public point (deprecated). |
|
Set the process‐wide default EC_KEY_METHOD used by newly created EC keys (deprecated). |
|
Set encoding‐control flags on an EC_KEY (deprecated). |
|
Store application data on an EC_KEY at CRYPTO_EX index |
|
Set the given flag bits on an EC_KEY (deprecated; OR'd with existing flags). |
|
Sets the EC_GROUP of a EC_KEY object. |
|
Attach an EC_KEY_METHOD to |
|
Sets the private key of a EC_KEY object. |
|
Sets the public key of a EC_KEY object. |
|
Sets a public key from affine coordinates performing necessary NIST PKV tests. |
|
Increases the internal reference count of a EC_KEY object. |
|
Returns the field type of the EC_METHOD. |
Computes the sum of two EC_POINT |
|
|
Decode an EC point from a BIGNUM holding the SEC1 octet form (deprecated). |
Clears and frees a EC_POINT object |
|
Compares two EC_POINTs |
|
Copies EC_POINT object |
|
Computes the double of a EC_POINT |
|
Creates a new EC_POINT object and copies the content of the supplied EC_POINT |
|
Frees a EC_POINT object |
|
|
Gets the jacobian projective coordinates of a EC_POINT over GFp |
Gets the affine coordinates of an EC_POINT. |
|
|
Gets the affine coordinates of an EC_POINT. A synonym of EC_POINT_get_affine_coordinates |
|
Gets the affine coordinates of an EC_POINT. A synonym of EC_POINT_get_affine_coordinates |
Decode an EC point from a hex‐encoded octet string. |
|
Computes the inverse of a EC_POINT |
|
Checks whether the point is the neutral element of the group |
|
Checks whether the point is on the curve |
|
|
Convert |
|
Returns the EC_METHOD used in EC_POINT object |
Computes r = generator * n + q * m |
|
Creates a new EC_POINT object for the specified EC_GROUP |
|
Decodes a EC_POINT from a octet string |
|
|
Encode an EC point as a BIGNUM holding the SEC1 octet form (deprecated). |
Encodes an EC_POINT object to an allocated octet string |
|
Encode an EC point as a newly allocated hexadecimal octet string. |
|
Encodes a EC_POINT object to a octet string |
|
|
Sets the jacobian projective coordinates of a EC_POINT over GFp |
Sets the affine coordinates of an EC_POINT |
|
|
Sets the affine coordinates of an EC_POINT. A synonym of EC_POINT_set_affine_coordinates |
|
Sets the affine coordinates of an EC_POINT. A synonym of EC_POINT_set_affine_coordinates |
|
Sets the x9.62 compressed coordinates of a EC_POINT |
|
Sets the x9.62 compressed coordinates of a EC_POINT. A synonym of EC_POINT_set_compressed_coordinates |
|
Sets the x9.62 compressed coordinates of a EC_POINT. A synonym of EC_POINT_set_compressed_coordinates |
Sets a point to infinity (neutral element) |
|
|
Convert an array of EC_POINT objects to affine coordinates (deprecated). |
|
Computes r = generator * n + sum_{i=0}ˆ{num‐1} p[i]* m[i] |
Map an OpenSSL curve NID to its NIST curve name string. |
|
Map a NIST curve name such as "P‐256" to the corresponding OpenSSL NID. |
|
Copy built‐in elliptic‐curve descriptors into |
|
Free an EDIPARTYNAME structure and its contents. |
|
Return the ASN.1 item descriptor for EDIPARTYNAME. |
|
Allocate a new EDI party name GeneralName payload. |
|
|
Add |
|
Register the built‐in OpenSSL CONF module that loads ENGINE sections. |
|
Look up a registered ENGINE by its unique id string (deprecated). |
|
Test whether an ENGINE control command may be used as a config/setting command (deprecated). |
|
Dispatch a control command to an ENGINE (deprecated). |
|
Invoke an ENGINE control command looked up by name rather than number. |
|
Run a named ENGINE control command whose argument is a string (deprecated). |
|
Release a functional reference obtained from ENGINE_init() or a get‐default call. |
|
Release one structural reference to an ENGINE. |
|
Return the DH_METHOD currently attached to an ENGINE. |
|
Return the DSA_METHOD currently attached to an ENGINE. |
|
Return the EC_KEY_METHOD currently attached to an ENGINE (deprecated). |
|
Return the RAND_METHOD implemented by an ENGINE (deprecated). |
|
Return the RSA_METHOD currently attached to an ENGINE (deprecated). |
|
Return the EVP_CIPHER that |
|
Obtain a functional reference to the default ENGINE implementing cipher |
|
Return the ciphers enumeration/lookup callback registered on an ENGINE. |
|
Return the control‐command definition table registered on an ENGINE. |
|
Return the ctrl callback registered on an ENGINE (deprecated). |
|
Obtain a functional reference to the default ENGINE for DH operations. |
|
Obtain a functional reference to the default ENGINE for DSA operations. |
|
Obtain a functional reference to the default ENGINE for EC operations. |
|
Obtain a functional reference to the default ENGINE for RAND operations. |
|
Obtain a functional reference to the default ENGINE for RSA operations. |
|
Return the destroy callback registered on an ENGINE. |
|
Return the EVP_MD that |
|
Obtain a functional reference to the default ENGINE implementing digest |
|
Return the digests enumeration/lookup callback registered on an ENGINE. |
|
Retrieve application data previously stored on an ENGINE. |
|
Return the finish callback registered on an ENGINE. |
|
Return the first ENGINE in OpenSSL's loaded list. |
|
Return the behavioural flag mask stored on an ENGINE (deprecated). |
|
Return the unique identifier string of an ENGINE (deprecated). |
|
Return the init callback registered on an ENGINE. |
|
Return the last ENGINE in the global ENGINE list (deprecated). |
|
Return the private‐key loader callback registered on an ENGINE. |
|
Return the public‐key loader callback registered on an ENGINE. |
|
Return the human‐readable name string of an ENGINE. |
|
Return the next ENGINE in OpenSSL's loaded list and release |
|
Return the EVP_PKEY_ASN1_METHOD that |
|
Obtain a functional reference to the default ENGINE implementing ASN.1 method |
|
Look up an ENGINE's EVP_PKEY_ASN1_METHOD by PEM string name. |
|
Return the EVP_PKEY_ASN1_METHOD enumeration/lookup callback registered on an ENGINE. |
|
Return the EVP_PKEY_METHOD that |
|
Obtain a functional reference to the default ENGINE implementing pkey method |
|
Return the EVP_PKEY_METHOD enumeration/lookup callback registered on an ENGINE. |
|
Return the previous ENGINE in OpenSSL's loaded list and release |
|
Return the SSL client‐certificate loader registered on an ENGINE. |
Return a pointer that identifies this process's OpenSSL static data for ENGINE loaders. |
|
|
Return the global ENGINE algorithm‐table flags. |
|
Initialise an ENGINE for functional use (deprecated). |
|
Register all compiled‐in ENGINE implementations (deprecated in OpenSSL 3). |
|
Load a private key from an ENGINE by key identifier (deprecated). |
|
Load a public key from storage managed by an ENGINE. |
|
Load an SSL client certificate and key via an ENGINE (deprecated). |
|
Allocate a new empty ENGINE with a structural reference count of one. |
|
Find an EVP_PKEY_ASN1_METHOD by PEM/string name across ENGINEs (deprecated). |
|
Register |
|
Register |
|
Register |
|
Register |
|
Register |
|
Register every loaded ENGINE that provides a DH method. |
|
Register every loaded ENGINE that provides a DSA method. |
|
Register every loaded ENGINE that provides an EC method. |
|
Register every loaded ENGINE that provides a RAND method. |
|
Register every loaded ENGINE that provides an RSA method. |
|
Register every loaded ENGINE that provides cipher implementations. |
|
Register all loaded ENGINEs for every algorithm they implement (deprecated). |
|
Register every loaded ENGINE that provides digest implementations (deprecated). |
|
Register every loaded ENGINE that provides EVP_PKEY ASN.1 methods (deprecated). |
|
Register every loaded ENGINE that provides EVP_PKEY_METHOD implementations. |
|
Register |
|
Register every algorithm category that |
|
Register |
|
Register the ASN.1 public‐key methods provided by |
|
Register |
|
Remove an ENGINE from the global ENGINE list (deprecated). |
|
Attach a DH_METHOD implementation to an ENGINE (deprecated). |
|
Attach a DSA_METHOD implementation to an ENGINE. |
|
Attach an EC_KEY_METHOD implementation to an ENGINE (deprecated). |
|
Attach a RAND_METHOD implementation to an ENGINE. |
|
Attach an RSA_METHOD to an ENGINE (deprecated). |
|
Set the cipher enumeration callback for an ENGINE (deprecated). |
|
Attach the ENGINE_CMD_DEFN table describing control commands for an ENGINE. |
|
Set the ctrl callback used by ENGINE_ctrl() for an ENGINE (deprecated). |
|
Register |
|
Register |
|
Register |
|
Register |
|
Register |
|
Register |
|
Register |
|
Register |
|
Register |
|
Register |
|
Set defaults for the method kinds named in a comma‐separated list. |
|
Set the callback invoked when the last structural reference to an ENGINE is released. |
|
Set the callback that enumerates or looks up EVP_MD digests provided by an ENGINE. |
|
Store application data on an ENGINE at an ex_data index. |
|
Set the callback invoked by ENGINE_finish() to shut down an ENGINE. |
|
Replace the behavioural flags stored on an ENGINE. |
|
Set the unique string identifier for an ENGINE (deprecated). |
|
Set the callback invoked by ENGINE_init() to bring an ENGINE to operational state. |
|
Set the callback used by ENGINE_load_private_key() to load private keys. |
|
Set the callback used by ENGINE_load_public_key() to load public keys. |
|
Set the callback that loads an SSL/TLS client certificate and key from an ENGINE (deprecated). |
|
Set the human‐readable name string for an ENGINE (deprecated). |
|
Install the ENGINE callback that enumerates public‐key ASN.1 methods (deprecated). |
|
Set the callback that enumerates or looks up EVP_PKEY_METHOD entries provided by an ENGINE. |
|
Set the global ENGINE algorithm‐table flags (deprecated). |
|
Remove |
|
Remove |
|
Remove |
|
Unregister an ENGINE as a RAND implementation (deprecated). |
|
Remove |
|
Unregister all cipher implementations previously registered from |
|
Unregister |
|
Unregister the EVP_PKEY ASN.1 methods previously registered from |
|
Unregister |
|
Increment the structural reference count of an ENGINE. |
Return whether an error code is a system‐independent common ERR reason. |
|
Return whether a packed error code is marked fatal. |
|
Extract the library number from a packed OpenSSL error code. |
|
Extract the reason code from a packed OpenSSL or system error code. |
|
Extract reason‐flag bits (ERR_RFLAG_*) from a packed OpenSSL error code. |
|
Append concatenated C strings as auxiliary data to the most recent error. |
|
Append the contents of memory BIO |
|
Append text to the most recent error, optionally inserting a separator first. |
|
Append additional string data to the most recent error, from a va_list. |
|
Clear all errors from the current thread's OpenSSL error queue. |
|
Remove the most recently set error‐stack mark without popping errors. |
|
Count error‐stack entries above the most recently set mark. |
|
Format a human‐readable description of error code |
|
Format an OpenSSL error code into a caller‐provided buffer. |
|
|
Return the function name for a packed error code (deprecated; always returns NULL in 3.0). |
Pop the earliest error code from the current thread's error queue. |
|
Pop the earliest error and optionally return file, line, function, data, and flags. |
|
|
Pop the earliest error and optionally return file and line (deprecated). |
|
Pop the earliest error with file, line, data, and flags (deprecated). |
Allocate a unique library number for a dynamically registered error library. |
|
|
Return the current thread's ERR_STATE (deprecated internal accessor). |
Return the human‐readable library name for a packed error code. |
|
|
Load ASN.1 library error strings into the error queue (deprecated no‐op in OpenSSL 3+). |
|
Load ASYNC library error strings into the error queue (deprecated no‐op in OpenSSL 3+). |
|
Load BIO library error strings into the error queue (deprecated no‐op in OpenSSL 3+). |
|
Load BN library error strings (no‐op in OpenSSL 3; deprecated). |
|
Load BUF library error strings into the error queue (deprecated no‐op in OpenSSL 3+). |
|
Load CMS library error strings into the error queue (deprecated no‐op in OpenSSL 3+). |
|
Load legacy COMP library error strings (deprecated; no longer needed). |
|
Load CONF library error strings into the error queue (deprecated no‐op in OpenSSL 3+). |
|
Load CRYPTO library error strings into the error queue (deprecated no‐op in OpenSSL 3+). |
|
Load Certificate Transparency library error strings (deprecated no‐op in OpenSSL 3+). |
|
Load Diffie‐Hellman library error strings (no‐op in OpenSSL 3; deprecated). |
|
Load legacy DSA error reason strings (deprecated no‐op in OpenSSL 3). |
|
Load EC library error strings (no‐op in OpenSSL 3; deprecated). |
|
Load ENGINE library error strings into the error queue (deprecated no‐op in OpenSSL 3+). |
|
Load core ERR library error strings (no‐op in OpenSSL 3; deprecated). |
|
Load EVP library error strings (no‐op in OpenSSL 3; deprecated). |
|
Load KDF library error strings (no‐op in OpenSSL 3; deprecated). |
|
Load legacy OBJ library error strings (deprecated; no longer needed). |
|
Load legacy OCSP library error strings (deprecated; no longer needed). |
|
Load OSSL_STORE library error strings into the error queue (deprecated no‐op in OpenSSL 3+). |
|
Load PEM library error strings into the error queue (deprecated no‐op in OpenSSL 3+). |
|
Load PKCS#12 library error strings into the error queue (deprecated no‐op in OpenSSL 3+). |
|
Load PKCS#7 library error strings into the error queue (deprecated no‐op in OpenSSL 3+). |
|
Load RAND library error strings into the error queue (deprecated no‐op in OpenSSL 3+). |
|
Load RSA library error strings into the error queue (deprecated no‐op in OpenSSL 3+). |
|
Load libssl reason error strings into the error queue. |
|
Load legacy ERR reason strings for the TS library (deprecated no‐op). |
|
Load legacy UI library error strings (deprecated; no longer needed). |
|
Load X509V3 library error strings into the error queue (deprecated no‐op in OpenSSL 3+). |
|
Load X509 library error strings into the error queue (deprecated no‐op in OpenSSL 3+). |
Register a mutable ERR_STRING_DATA table for library |
|
Register a const ERR_STRING_DATA table whose last entry has error == 0. |
|
Allocate a new empty slot on the current thread's OpenSSL error queue. |
|
Return the earliest error code without removing it from the queue. |
|
Peek at the earliest error and optionally return file, line, function, data, and flags. |
|
Peek at the earliest error and optionally return auxiliary data and flags. |
|
Peek at the earliest error and optionally return its function name. |
|
Peek at the earliest error and optionally return its source file and line. |
|
|
Peek at the earliest error with file, line, data, and flags (deprecated). |
Return the newest error code without removing it from the queue. |
|
Peek at the newest error and optionally return file, line, function, data, and flags. |
|
Peek at the newest error and optionally return auxiliary data and flags. |
|
Peek at the newest error code and optionally its function name. |
|
Peek at the newest error code and optionally its source file/line. |
|
|
Peek at the newest error with file, line, data, and flags (deprecated). |
Unconditionally remove the newest error from the queue. |
|
Pop errors until (and including) the most recent mark set by ERR_set_mark(). |
|
Print and clear all queued OpenSSL errors to BIO |
|
Print and clear all queued errors, invoking |
|
Print and clear all queued OpenSSL errors to stdio stream |
|
Return the registered reason‐string for a packed error code. |
|
|
Remove the error queue for a process id (deprecated; use ERR_remove_thread_state). |
|
Free the error queue for a thread identifier (deprecated; automatic since 1.1.0). |
Attach source location debug information to the current error‐queue entry. |
|
Set library, reason, and optional formatted auxiliary data on the current error entry. |
|
Replace auxiliary data on the most recent error, taking ownership when flagged. |
|
Place a mark on the current topmost error‐queue entry. |
|
Remove previously registered error strings for library |
|
Push an error onto the thread's error queue with a printf‐style detail (va_list form). |
|
Duplicate a ESS CertIDv2. |
|
Free a ESS CertIDv2 and its contents. |
|
Allocate an empty ESS CertIDv2. |
|
Duplicate a ESS CertID. |
|
Free a ESS CertID and its contents. |
|
Allocate an empty ESS CertID. |
|
Duplicate a ESS IssuerSerial. |
|
Free a ESS IssuerSerial and its contents. |
|
Allocate an empty ESS IssuerSerial. |
|
Duplicate a ESS SigningCertificateV2 attribute. |
|
Free a ESS SigningCertificateV2 attribute and its contents. |
|
Return the ASN.1 item descriptor for ESS_SIGNING_CERT_V2. |
|
Allocate an empty ESS SigningCertificateV2 attribute. |
|
Duplicate a ESS SigningCertificate attribute. |
|
Free a ESS SigningCertificate attribute and its contents. |
|
Return the ASN.1 item descriptor for ESS_SIGNING_CERT. |
|
Allocate an empty ESS SigningCertificate attribute. |
|
|
Invoke |
Fetch an asymmetric cipher (encrypt/decrypt) algorithm from providers. |
|
Release a reference to a fetched asymmetric cipher algorithm. |
|
|
Return a human‐readable description of an asymmetric cipher algorithm. |
Return the primary algorithm name of an asymmetric cipher. |
|
Return the provider that implemented an asymmetric cipher algorithm. |
|
|
Return the OSSL_PARAM descriptors gettable from an asymmetric‐cipher context. |
Test whether an asymmetric cipher implementation matches a name. |
|
|
Call |
|
Describe OSSL_PARAM keys settable on asymmetric‐cipher contexts for |
Increment the reference count on a fetched asymmetric cipher algorithm. |
|
Derive a cipher key and IV from a password using the legacy EVP_BytesToKey KDF. |
|
|
Return the internal partial‐block buffer of a cipher context (deprecated). |
Return the EVP_CIPHER associated with a cipher context. |
|
Clear selected flag bits on a cipher context. |
|
Copy the cipher state from one context into another. |
|
Send a cipher‐specific control request to an EVP_CIPHER_CTX. |
|
Duplicate a cipher context, including its algorithm state. |
|
Free a cipher context and any associated resources. |
|
Return the cipher method currently associated with a cipher context. |
|
Return a new reference to the EVP_CIPHER used by a cipher context. |
|
|
Return the application‐specific pointer previously stored on a cipher context. |
|
Return the block size of the cipher bound to a cipher context. |
|
Return the cipher‐implementation private data pointer for |
|
Return the IV length in bytes for the cipher currently set on |
|
Return the key length currently configured on a cipher context. |
Return the NID of the cipher currently bound to a cipher context. |
|
Return the cipher‐specific "num" field of a cipher context. |
|
|
Copy the original IV from a cipher context into |
Retrieve algorithm parameters from a cipher context into |
|
|
Return the authentication tag length for an AEAD cipher context. |
|
Copy the current IV state from a cipher context into a buffer. |
Describe OSSL_PARAM keys gettable from the cipher currently bound to |
|
Test whether a cipher context is currently configured for encryption. |
|
|
Return a pointer to the IV stored in a cipher context (deprecated). |
|
Return a mutable pointer to the current IV in a cipher context (deprecated). |
Allocate an empty cipher context. |
|
|
Return the IV originally supplied when the cipher context was initialized (deprecated). |
Generate a random key suitable for the cipher currently set on |
|
Reset a cipher context to a reusable empty state without freeing it. |
|
|
Store an application pointer on a cipher context. |
|
Replace the cipher‐implementation private data pointer on |
Set flag bits on a cipher context without clearing existing flags. |
|
|
Set a variable‐length cipher's key length on a cipher context. |
Set the partial‐block offset counter stored in a cipher context. |
|
Enable or disable standard block‐cipher padding on a cipher context. |
|
Set provider parameters on an initialised cipher context. |
|
Return the OSSL_PARAM descriptors that may be set on an initialized cipher context. |
|
Test whether selected flag bits are set on a cipher context. |
|
Decode cipher AlgorithmIdentifier parameters from |
|
Invoke |
|
Invoke a callback for every cipher implementation available from providers. |
|
Invoke |
|
Fetch a cipher implementation from providers in a library context. |
|
Free a fetched or duplicated EVP_CIPHER method. |
|
Return a human‐readable description of a cipher algorithm. |
|
Return the primary name of a cipher algorithm. |
|
Return the provider that implements a cipher algorithm. |
|
Decode an IV from an ASN.1 OCTET STRING in |
|
Return the block size of a cipher in bytes. |
|
Return the capability and behavior flags of a cipher. |
|
Return the IV length in bytes required by a cipher. |
|
Return the default key length of a cipher in bytes. |
|
Return the cipher mode constant for a cipher method. |
|
Return the NID associated with a cipher algorithm. |
|
Retrieve algorithm‐level parameters from a cipher implementation. |
|
Return the OBJECT IDENTIFIER NID of a cipher (ignoring parameters). |
|
Describe OSSL_PARAM keys that may be retrieved from contexts of |
|
Return the OSSL_PARAM descriptors gettable from an EVP_CIPHER algorithm. |
|
|
Return the size of the cipher's legacy implementation context (deprecated). |
Test whether |
|
|
Duplicate a custom EVP_CIPHER method object (deprecated). |
|
Free a custom EVP_CIPHER created with EVP_CIPHER_meth_new() (deprecated). |
|
Return the cleanup callback previously set on a custom EVP_CIPHER method. |
|
Return the ctrl callback previously set on a custom EVP_CIPHER method (deprecated). |
|
Return the do_cipher callback from a custom EVP_CIPHER method (deprecated). |
|
Return the get_asn1_params callback previously set on a custom EVP_CIPHER method (deprecated). |
|
Return the init callback previously set on a custom EVP_CIPHER method (deprecated). |
|
Return the set_asn1_params callback previously set on a custom EVP_CIPHER method. |
|
Allocate a custom EVP_CIPHER method object (deprecated). |
|
Set the context‐cleanup callback on a custom EVP_CIPHER (deprecated). |
|
Set the ctrl callback on a custom EVP_CIPHER (deprecated). |
|
Set the encrypt/decrypt update callback on a custom EVP_CIPHER (deprecated). |
|
Set EVP_CIPH_* capability flags on a custom EVP_CIPHER (deprecated). |
|
Set the callback that exports cipher parameters into an ASN.1 type (deprecated). |
|
Set how many bytes of cipher‐specific context storage to allocate (deprecated). |
|
Set the key/IV initialization callback on a custom EVP_CIPHER (deprecated). |
|
Set the IV length advertised by a custom EVP_CIPHER method (deprecated). |
|
Set the ASN.1 parameter‐encoding callback on a custom EVP_CIPHER method (deprecated). |
Invoke a callback for every name synonym associated with a cipher. |
|
Encode cipher parameters (typically including the IV) from |
|
Encode the cipher context IV into an ASN.1 OCTET STRING inside |
|
Describe OSSL_PARAM keys that may be set on contexts of |
|
Increment the reference count on a fetched EVP_CIPHER. |
|
Encrypt or decrypt up to |
|
Finalize a cipher operation and write any remaining output bytes. |
|
Finalize a cipher operation (extended form) and write any remaining output. |
|
Initialize |
|
Initialise |
|
Initialise a cipher context with optional OSSL_PARAM settings. |
|
Encrypt or decrypt a chunk of data using a cipher context already set for either direction. |
|
Base64‐decode |
|
Finish a Base64 decode, flushing any remaining decoded bytes. |
|
Initialize a context for incremental Base64 decoding. |
|
Decode a chunk of Base64 input into |
|
Finish decryption and write any remaining plaintext (legacy wrapper). |
|
Finalize decryption and write any remaining plaintext (including padding removal). |
|
Initialize a cipher context for decryption (legacy ENGINE‐aware form). |
|
Initialize |
|
Initialize |
|
Decrypt a chunk of ciphertext into |
|
Hash |
|
Finalize a digest computation and write the message digest. |
|
Finalize an XOF digest and write |
|
Finalize a digest computation and write the message digest to |
|
Initialize a digest context for hashing with |
|
Initialise digest context |
|
Initialize a digest context with |
|
Sign |
|
Finalize a DigestSign operation and write the signature. |
|
Initialise |
|
Initialise a digest‐sign operation using a digest name and library context. |
|
Hash more message bytes into an initialized DigestSign context. |
|
Squeeze additional output from an XOF digest context (for example SHAKE). |
|
Hash more input bytes into an initialized message‐digest context. |
|
Verify |
|
Finish a DigestVerify operation by checking |
|
Initialise |
|
Initialize a digest‐verify operation with an explicit digest name and library context. |
|
Hash more message bytes into an initialized DigestVerify context. |
|
Copy a Base64 encode/decode context. |
|
Free a Base64 encode/decode context. |
|
Allocate a new Base64 encode/decode context. |
|
Return the number of pending (unflushed) bytes in an encode/decode context. |
|
Base64‐encode |
|
Flush remaining Base64‐encoded output from an encode context. |
|
Initialise a Base64 encode context for EVP_EncodeUpdate/Final. |
|
Base64‐encode a chunk of input, writing complete output lines to |
|
Finish encryption and write any remaining padded ciphertext bytes. |
|
Finalize encryption and write any remaining ciphertext (including padding). |
|
Initialize |
|
Initialize |
|
Initialize a cipher context for encryption with optional OSSL_PARAM settings. |
|
Encrypt |
|
Duplicate a KDF context, copying algorithm state where supported. |
|
Free a KDF context and its associated state. |
|
Return the output size produced by |
|
Retrieve gettable parameters from an EVP_KDF_CTX. |
|
Return the OSSL_PARAM descriptors that can be retrieved from a KDF context. |
|
Return the EVP_KDF method associated with a derivation context. |
|
Allocate a key‐derivation context for a fetched EVP_KDF. |
|
Reset a KDF context so it can be reconfigured and reused. |
|
Apply OSSL_PARAM values (salt, key, info, digest, …) to a KDF context. |
|
Describe parameters currently settable on an EVP_KDF_CTX instance. |
|
Derive keying material into |
|
Invoke |
|
Fetch a key‐derivation algorithm implementation from providers. |
|
Release a reference to a fetched EVP_KDF method. |
|
Return a human‐readable description of a KDF algorithm. |
|
Return the algorithm name of a KDF method. |
|
Return the provider that implemented a fetched EVP_KDF. |
|
Retrieve algorithm‐level OSSL_PARAM values from a fetched EVP_KDF. |
|
Return OSSL_PARAM descriptors that can be retrieved from an EVP_KDF_CTX. |
|
Describe the parameters that can be read from an EVP_KDF via EVP_KDF_get_params(). |
|
Test whether an EVP_KDF implementation is known by |
|
Invoke |
|
Describe context parameters that can be set before deriving with |
|
Increment the reference count on a fetched EVP_KDF method. |
|
Call |
|
Fetch a key‐encapsulation mechanism implementation from providers. |
|
Decrement the reference count of a fetched KEM and free it when it reaches zero. |
|
Return a human‐readable description of a fetched KEM algorithm. |
|
Return the primary name of a fetched KEM algorithm. |
|
Return the provider that implemented a fetched EVP_KEM algorithm. |
|
Return the context parameters that can be read from a KEM algorithm. |
|
Test whether a KEM implementation is known by a given name. |
|
Invoke |
|
Return the OSSL_PARAM descriptors settable on a KEM operation context. |
|
Increment the reference count on a fetched KEM algorithm. |
|
Invoke a callback for every key‐exchange algorithm available from providers. |
|
Fetch a key‐exchange algorithm implementation from providers. |
|
Free a fetched key‐exchange algorithm object. |
|
Return a human‐readable description of a key‐exchange algorithm. |
|
Return the primary name of a fetched key‐exchange algorithm. |
|
Return the provider that implements a key‐exchange algorithm. |
|
Return the context parameters that can be read from a key‐exchange algorithm. |
|
Test whether a key‐exchange implementation is known by |
|
Invoke a callback for every name associated with a key‐exchange algorithm. |
|
Return the OSSL_PARAM descriptors for parameters settable on a key‐exchange context. |
|
Increment the reference count on a key‐exchange algorithm object. |
|
Invoke |
|
Fetch a key‐management implementation from providers. |
|
Release a reference to a key‐management algorithm implementation. |
|
Return the OSSL_PARAM descriptors for key‐generation parameters settable on this keymgmt. |
|
Return a human‐readable description of a keymgmt implementation. |
|
Return the algorithm name of a key management method. |
|
Return the provider that implements a key management method. |
|
Describe parameters that can be read from keys managed by a keymgmt. |
|
Test whether a key‐management implementation is known under the given name. |
|
Invoke a callback for every name (including aliases) associated with a keymgmt. |
|
Return the OSSL_PARAM descriptors settable on an existing key via this keymgmt. |
|
Increment the reference count on a key management method. |
|
Duplicate a MAC context, including its current state. |
|
Free a MAC context and its associated resources. |
|
Return the EVP_MAC associated with a MAC context. |
|
|
Return the MAC block size for the algorithm bound to |
Return the MAC output size for the algorithm bound to |
|
Get parameters from a MAC context. |
|
Return the OSSL_PARAM descriptors gettable from a live MAC context. |
|
Allocate a new MAC operation context for |
|
Apply an OSSL_PARAM array of parameters to a MAC context. |
|
Return the OSSL_PARAM descriptors settable on a live MAC context. |
|
Invoke a callback for every MAC implementation available from activated providers. |
|
Fetch a MAC algorithm implementation from providers. |
|
Finish a MAC computation and write the authentication tag to a buffer. |
|
Finalize an XOF‐style MAC and write |
|
Release a reference to a fetched EVP_MAC. |
|
Return a human‐readable description of a MAC algorithm. |
|
Return one algorithm name for a fetched MAC implementation. |
|
Return the provider that implements a MAC algorithm. |
|
Retrieve algorithm parameters from a fetched MAC implementation. |
|
Return the OSSL_PARAM descriptors gettable from an EVP_MAC context. |
|
Return the OSSL_PARAM descriptors gettable from a fetched EVP_MAC algorithm. |
|
Initialize a MAC context with a key and optional algorithm parameters. |
|
Test whether a MAC implementation matches an algorithm name. |
|
Invoke a callback for every name (including aliases) associated with a MAC implementation. |
|
Describe OSSL_PARAM keys that may be set on MAC contexts for |
|
Increment the reference count on a fetched EVP_MAC. |
|
Feed more message bytes into a MAC computation. |
|
Clear flag bits on a digest context. |
|
Copy a digest context into a freshly allocated destination (legacy helper). |
|
Copy digest context state from |
|
Send a legacy control request to a digest context. |
|
Duplicate a digest context, including algorithm state and any associated key material. |
|
Free a digest context and release its resources. |
|
Return the digest method currently associated with a digest context. |
|
Return the digest method's private data pointer for a context. |
|
Return the digest method associated with |
|
Retrieve algorithm parameters from a digest context into |
|
Return the EVP_PKEY_CTX currently attached to a digest context. |
|
Describe OSSL_PARAM keys that can be retrieved from digest context |
|
|
Return the EVP_MD currently associated with a digest context (deprecated). |
Allocate a new digest context. |
|
Reset |
|
Set flag bits on a digest context without clearing existing flags. |
|
Set algorithm parameters on a digest context via an OSSL_PARAM array. |
|
Attach or clear the EVP_PKEY_CTX owned by a digest context (for DigestSign/DigestVerify). |
|
|
Override the update function used by a digest context (deprecated). |
Return the OSSL_PARAM descriptors for parameters settable on a digest context. |
|
Test whether the given flag bits are set on a digest context. |
|
|
Return the digest update function currently used by a digest context (deprecated). |
Invoke a callback for every digest name in the legacy algorithm table. |
|
Invoke a callback for every message digest provided in a library context. |
|
Call |
|
Fetch a digest implementation from providers. |
|
Free a fetched EVP_MD (decrement its reference count). |
|
Return a human‐readable description of a digest algorithm. |
|
Return the primary algorithm name of a message digest. |
|
Return the provider that implements a message‐digest algorithm. |
|
Return the internal block size of a message digest in bytes. |
|
Return the flag bits associated with a digest method. |
|
Fetch gettable algorithm parameters from a message‐digest method. |
|
Return the legacy public‐key NID associated with a digest method. |
|
Return the output size of a message digest in bytes. |
|
Return the NID identifying a message‐digest algorithm. |
|
Return the OSSL_PARAM descriptors gettable from an EVP_MD context. |
|
Describe the parameters that can be read from a message‐digest method. |
|
Test whether a digest implementation is known by |
|
|
Duplicate a custom EVP_MD method (deprecated). |
|
Free a custom EVP_MD method created with EVP_MD_meth_new (deprecated). |
|
Return the application‐data size reserved by a custom EVP_MD method (deprecated). |
|
Return the cleanup callback from a custom EVP_MD method (deprecated). |
|
Return the context‐copy callback from a custom EVP_MD method (deprecated). |
|
Return the ctrl callback installed on a custom EVP_MD method (deprecated). |
|
Return the final callback from a custom EVP_MD method (deprecated). |
|
Return the flag bits configured on a custom EVP_MD method (deprecated). |
|
Return the init callback from a custom EVP_MD method (deprecated). |
|
Return the input block size previously set on a custom EVP_MD method (deprecated). |
|
Return the digest output size previously set on a custom EVP_MD method (deprecated). |
|
Return the update callback previously set on a custom EVP_MD method (deprecated). |
|
Allocate a mutable EVP_MD method object for custom digests (deprecated). |
|
Set the private context data size for a custom EVP_MD method (deprecated). |
|
Set the cleanup callback on a custom EVP_MD method (deprecated). |
|
Set the context‐copy callback on a custom EVP_MD method (deprecated). |
|
Set the ctrl callback on a custom EVP_MD method (deprecated). |
|
Set the final callback on a custom EVP_MD method (deprecated). |
|
Set behaviour flags on a custom EVP_MD method (deprecated). |
|
Set the init callback on a custom EVP_MD method (deprecated). |
|
Set the input block size advertised by a custom EVP_MD method (deprecated). |
|
Set the digest output size on a custom EVP_MD method (deprecated). |
|
Set the update callback on a custom EVP_MD method (deprecated). |
Invoke a callback for every known name alias of a message digest. |
|
Return the OSSL_PARAM descriptors for parameters settable on an MD context. |
|
Increment the reference count on a fetched EVP_MD. |
|
Finalize an open (envelope decrypt) operation and write any remaining plaintext. |
|
Initialize envelope decryption: unwrap |
|
Initialize a cipher context for password‐based encryption from a PBE OID and parameters. |
|
Initialize a cipher context for password‐based encryption using a library context. |
|
Register a password‐based encryption algorithm by NID with cipher, digest, and keygen. |
|
Register a password‐based encryption algorithm by type and NIDs. |
|
Free the global password‐based encryption (PBE) algorithm registry. |
|
Look up a registered password‐based encryption (PBE) algorithm by NID. |
|
Look up a registered PBE algorithm, returning both classic and extended keygen callbacks. |
|
Return the PBE algorithm type and NID at index |
|
Derive a key with scrypt from a password and salt. |
|
Derive a key from a password using scrypt with an explicit library context. |
|
Convert PKCS#8 private key info into an EVP_PKEY using the default library context. |
|
Convert PKCS#8 private key info into an EVP_PKEY using a library context. |
|
Convert an EVP_PKEY into a PKCS#8 PrivateKeyInfo structure. |
|
|
Append octets to the HKDF info/context parameter on a PKEY HKDF context. |
|
Append seed bytes to the TLS1‐PRF seed on a key context. |
Send an algorithm‐specific control command to a key context. |
|
Send a named string control to a key context (for example "rsa_padding"). |
|
Send a control command with a uint64_t argument to a key context. |
|
Duplicate a public‐key algorithm context (not supported during keygen). |
|
Free an EVP_PKEY_CTX and release associated resources. |
|
|
Return the X9.42 KDF OID currently configured on a DH key context. |
|
Borrow the DH KDF User Keying Material pointer and return its length (deprecated). |
|
Get a pointer to the ECDH KDF user keying material on a key context (deprecated). |
Return the library context associated with a key algorithm context. |
|
Return the peer key previously set on a derive context. |
|
Return the primary EVP_PKEY associated with a key context. |
|
Return the property query string associated with a key context. |
|
Return the provider that supplies the algorithm implementation used by |
|
|
Return a non‐owning pointer to the RSA‐OAEP label configured on an EVP_PKEY_CTX. |
Copy the algorithm‐specific ID bytes from |
|
Return the length of an algorithm‐specific ID associated with a key context. |
|
|
Return the opaque application pointer previously stored on a key context. |
Return the keygen progress callback currently installed on a key context. |
|
Return the application‐private data pointer previously set on a key context. |
|
|
Get the message digest used for DH key‐derivation (KDF) on a key context. |
|
Return the configured DH KDF output length in bytes. |
|
Return the DH key‐derivation function type configured on |
|
Get the ECDH cofactor mode from a key context. |
|
Get the message digest used for the ECDH X9.63 KDF on a key context. |
|
Get the ECDH key‐derivation output length from a key‐exchange context. |
|
Return the ECDH key‐derivation function type configured on a key context. |
|
Copy the elliptic‐curve or DH group name from a key context into a caller buffer. |
|
Return a key‐generation progress info value previously published on |
Return the operation type currently configured on a key context. |
|
Retrieve parameters from a key context into an OSSL_PARAM array. |
|
|
Get the MGF1 digest configured for RSA‐PSS or RSA‐OAEP on a key context. |
|
Get the MGF1 digest algorithm name from an RSA EVP_PKEY_CTX. |
|
Get the RSA‐OAEP message‐digest algorithm from an EVP_PKEY_CTX. |
|
Get the RSA‐OAEP message‐digest algorithm name from an EVP_PKEY_CTX. |
|
Get the RSA padding mode configured on an EVP_PKEY_CTX. |
|
Get the RSA‐PSS salt length configured on an EVP_PKEY_CTX. |
|
Retrieve the message digest currently configured for signing or verifying with |
Return the OSSL_PARAM descriptors gettable from a key context. |
|
Decode a hex string to bytes and pass them to EVP_PKEY_CTX_ctrl as the p2 buffer. |
|
Test whether a key context is for the named key type. |
|
Set a digest algorithm on a key context by name for the given operation. |
|
Allocate a key context for operations with |
|
|
Allocate a key context for an algorithm fetched by name from providers. |
|
Allocate a key context for operations on an existing EVP_PKEY. |
Allocate a key context for algorithm |
|
|
Set the X9.42 KDF OID for DH key derivation, transferring ownership of |
|
Set the DH KDF User Keying Material, transferring ownership of |
|
Set the ECDH KDF user keying material, transferring ownership of |
|
Attach legacy keygen progress info used by some ENGINE implementations. |
|
Set the RSA‐OAEP label on an EVP_PKEY_CTX, transferring ownership of |
|
Set the HKDF input keying material (IKM) on a PKEY KDF context. |
|
Set the HKDF salt, replacing any previously set salt. |
Set an algorithm‐specific identity value on a key operation context (copied). |
|
|
Set the password for a PBE‐based EVP_PKEY_CTX derivation (PKCS#5 style). |
|
Set the RSA public exponent for key generation, copying |
|
Set the scrypt salt on a KDF key context (copies |
|
Set the TLS1‐PRF secret on a key context (copies |
|
Store an opaque application pointer on a key context. |
Install a progress callback for key/parameter generation on a context. |
|
Attach implementation‐private data to a key context. |
|
|
Set the message digest used for DH key‐derivation (KDF) on a key context. |
|
Set the output length in bytes of the DH key‐derivation function. |
|
Set the DH key‐derivation function type on an EVP_PKEY_CTX. |
Select named Diffie‐Hellman parameters (RFC 7919 / RFC 3526) by NID. |
|
Enable or disable leading‐zero padding of the DH shared secret to the prime length. |
|
|
Set the DH parameter‐generation generator (g) on |
|
Set the FIPS 186‐4 gindex used when generating DH parameters. |
|
Set the DH parameter‐generation prime (p) length in bits. |
|
Set a fixed seed for DH parameter generation (testing / reproducible params). |
|
Set the DH parameter‐generation subprime (q) length in bits. |
|
Select the DH parameter‐generation algorithm for a keygen/paramgen context. |
|
Select RFC 5114 DH parameters (sections 2.1–2.3) on a DHX key context. |
|
Select an RFC 5114 DHX (X9.42 DH) named parameter set on a keygen/paramgen context. |
|
Set the DSA prime modulus length in bits for parameter generation. |
|
Set the DSA parameter‐generation gindex (FIPS 186 verifiable g seed index). |
|
Set the digest used for DSA parameter generation on an EVP_PKEY_CTX. |
|
Select the digest for DSA parameter generation by name and property query. |
|
Set the DSA subprime (q) length in bits for parameter generation. |
|
Supply the seed used when generating FIPS 186‐style DSA parameters. |
|
Set the DSA parameter‐generation algorithm type by name. |
|
Select whether EC parameters are encoded as a named curve or explicitly. |
|
Set the named curve NID used when generating EC parameters or keys. |
|
Set whether ECDH key agreement multiplies by the curve cofactor. |
|
Set the message digest used for the ECDH X9.63 KDF on a key context. |
|
Set the ECDH key‐derivation output length for a key‐exchange context. |
|
Select the ECDH key‐derivation function type on a key‐exchange context. |
|
Set the elliptic‐curve / DH group name on a key or parameter context. |
Set the message digest used by the HKDF extract/expand stages. |
|
|
Select HKDF extract/expand mode on a key‐derivation EVP_PKEY_CTX. |
Select the KEM operation mode on a key context (for example "encapsulate"). |
|
Set the MAC key bytes on a keygen/paramgen EVP_PKEY_CTX (for example HMAC or Poly1305). |
|
Set parameters on a key context via an OSSL_PARAM array. |
|
|
Set the RSA modulus size in bits for key generation on an EVP_PKEY_CTX. |
|
Set how many primes to use when generating a multi‐prime RSA key. |
|
Set the RSA public exponent used when generating a key (deprecated). |
|
Set the MGF1 digest used for RSA‐PSS or RSA‐OAEP on a key context. |
|
Set the MGF1 digest for RSA‐PSS or RSA‐OAEP by algorithm name. |
|
Set the message digest used by RSA‐OAEP padding on a key context. |
|
Set the OAEP message digest by name on an RSA key context. |
|
Set the RSA padding mode on an EVP_PKEY_CTX. |
|
Set the message digest used when generating an RSA‐PSS key. |
|
Set the message digest used when generating an RSA‐PSS key via an EVP_PKEY_CTX. |
|
Set the MGF1 digest used when generating an RSA‐PSS key. |
Set the MGF1 digest name used when generating an RSA‐PSS key. |
|
|
Set the RSA‐PSS salt length used when generating an RSA‐PSS key. |
|
Set the RSA‐PSS salt length for sign/verify on |
|
Set the scrypt CPU/memory cost parameter N on a PKEY KDF context. |
|
Cap the memory scrypt may use during key derivation. |
|
Set the scrypt parallelization parameter p on a PKEY KDF context. |
|
Set the scrypt block‐size parameter r on a PKEY KDF context. |
|
Set the message digest used when signing or verifying with |
|
Select the digest used by a TLS1‐PRF EVP_PKEY_CTX. |
Describe OSSL_PARAM keys that may be set on key context |
|
Pass a NUL‐terminated string to EVP_PKEY_CTX_ctrl as the p2 argument. |
|
Quickly generate a key of algorithm |
|
Append a copy of |
|
|
Append an attribute identified by NID to an EVP_PKEY's attribute set. |
|
Append an attribute identified by OID to an EVP_PKEY's attribute set. |
|
Append an X509_ATTRIBUTE named by |
Register an EVP_PKEY_ASN1_METHOD in the global ASN.1 method table. |
|
Alias ASN.1 method NID |
|
Copy an EVP_PKEY_ASN1_METHOD from |
|
Find the ASN.1 method implementing a public‐key algorithm NID. |
|
Find an EVP_PKEY_ASN1_METHOD by PEM type string. |
|
Free an EVP_PKEY_ASN1_METHOD allocated with EVP_PKEY_asn1_new(). |
|
Return the registered EVP_PKEY_ASN1_METHOD at index |
|
Extract identifying metadata from an EVP_PKEY_ASN1_METHOD. |
|
Return the number of registered EVP_PKEY_ASN1_METHOD implementations. |
|
Allocate a new custom EVP_PKEY_ASN1_METHOD for algorithm |
|
Install the full‐key consistency check callback on an ASN.1 method. |
|
Set the control callback on an EVP_PKEY_ASN1_METHOD. |
|
Set the private‐key free callback on a custom EVP_PKEY_ASN1_METHOD. |
|
|
Install the raw private‐key export callback on an EVP_PKEY_ASN1_METHOD. |
|
Install a callback that exports the raw public key encoding from an EVP_PKEY. |
Install ASN.1 item sign and verify callbacks on an EVP_PKEY_ASN1_METHOD. |
|
Install parameter encode/decode, missing, copy, compare, and print callbacks on an ASN.1 method. |
|
|
Install a callback that validates algorithm parameters on an EVP_PKEY. |
Install PKCS#8 private‐key decode, encode, and print callbacks on an ASN.1 method. |
|
Install public‐key decode, encode, compare, print, size, and bits callbacks on an ASN.1 method. |
|
|
Install the public‐key consistency check callback on an ASN.1 method. |
|
Set the security‐bits callback on a custom EVP_PKEY_ASN1_METHOD. |
|
Install a callback that sets raw private‐key octets on an EVP_PKEY. |
|
Install a callback that sets raw public‐key octets on an EVP_PKEY. |
Install the X509_SIG_INFO setup callback on an EVP_PKEY_ASN1_METHOD. |
|
|
Assign a low‐level key object of |
Initialize authenticated decapsulation on |
|
Initialize authenticated key encapsulation using a peer public key and auth private key. |
|
Test whether a key type supports signing operations. |
|
Validate the key associated with a key context (public/private consistency checks). |
|
|
Compare two keys for equality including parameters when present (deprecated; use EVP_PKEY_eq). |
|
Compare the algorithm parameters of two keys (deprecated; use EVP_PKEY_parameters_eq). |
Copy algorithm parameters from one EVP_PKEY into another of the same type. |
|
Decapsulate a shared secret from a KEM ciphertext using a context from EVP_PKEY_decapsulate_init(). |
|
Initialise a key context for KEM decapsulation. |
|
Decrypt data using the private key bound to |
|
Initialise |
|
Initialize |
|
|
Decrypt a session key with a private key using the legacy EVP_PKEY path (deprecated). |
Remove and return an attribute from an EVP_PKEY by index. |
|
Derive a shared secret using a context initialized with EVP_PKEY_derive_init(). |
|
Initialize a key context for shared‐secret derivation (key exchange). |
|
Initialize |
|
Set the peer public key used by EVP_PKEY_derive() on a derivation context. |
|
|
Set the peer public key for derivation, optionally validating it first. |
|
Query whether digest |
Duplicate an EVP_PKEY (not supported for ENGINE‐based or raw keys). |
|
Perform key encapsulation: produce a wrapped key and a shared secret. |
|
Initialize a key context for a key‐encapsulation (KEM) encapsulate operation. |
|
Encrypt data with a public key using a context from EVP_PKEY_encrypt_init(). |
|
Initialise |
|
Initialize a key context for public‐key encryption with optional parameters. |
|
|
Encrypt a session key with a public key using the legacy EVP_PKEY path (deprecated). |
Compare two keys for equality of type, parameters, and key material. |
|
Export selected key parameters from an EVP_PKEY via a callback. |
|
Free an EVP_PKEY, decrementing its reference count. |
|
Build an EVP_PKEY (or parameters) from an OSSL_PARAM array after fromdata_init. |
|
Prepare a key context to import key material via EVP_PKEY_fromdata(). |
|
Return the OSSL_PARAM descriptors accepted by EVP_PKEY_fromdata() for |
|
Generate parameters or a key pair into *`ppkey` (unified keygen/paramgen entry). |
|
|
Return the legacy low‐level key pointer stored in an EVP_PKEY (deprecated). |
|
Return the DH key referenced by |
|
Return the DSA key referenced by |
|
Return a borrowed pointer to the EC_KEY held by |
|
Return the legacy RSA handle inside |
Return the EVP_PKEY_ASN1_METHOD associated with a key. |
|
Return a human‐readable description of the key type associated with an EVP_PKEY. |
|
|
Return the ENGINE associated with |
|
Return a pointer to the HMAC key material inside an EVP_PKEY (deprecated). |
|
Return a pointer to the Poly1305 key material inside an EVP_PKEY (deprecated). |
Return the provider that implements |
|
|
Return a pointer to the SipHash key material inside an EVP_PKEY (deprecated). |
Return the algorithm type name of a key (for example "RSA" or "EC"). |
|
|
Return a new reference to the DH key held by |
|
Return a new reference to the DSA key held by |
|
Return a new reference to the EC_KEY held by |
|
Return a new reference to the RSA key held by |
|
Allocate and return the encoded public‐key octet string for |
Return an attribute attached to an EVP_PKEY by index. |
|
Find the next attribute on an EVP_PKEY whose type NID equals |
|
Find the next attribute on an EVP_PKEY matching object identifier |
|
Return how many X509_ATTRIBUTE entries are attached to a key. |
|
Return the base EVP_PKEY type id for |
|
Return the cryptographic size of a key in bits (for example RSA modulus length). |
|
Fetch a named BIGNUM parameter from an EVP_PKEY. |
|
|
Write the default digest name recommended for signing with |
|
Return the default message‐digest NID associated with |
|
Return the EC point conversion form stored on an elliptic‐curve EVP_PKEY. |
Retrieve application‐specific data previously stored on an EVP_PKEY. |
|
Return the EC field type NID for an elliptic‐curve EVP_PKEY. |
|
Copy the elliptic‐curve or DH group name from a key into a caller buffer. |
|
Return the numeric type identifier of a public‐key object. |
|
Read an integer parameter from a key by OSSL_PKEY_PARAM name. |
|
|
Read an octet‐string parameter from a key by OSSL_PKEY_PARAM name. |
Retrieve key parameters from |
|
|
Export the raw private key bytes of |
|
Export the raw public key bytes of |
Return the estimated security strength of a key in bits. |
|
Return the maximum signature or related output size for a key in bytes. |
|
|
Fetch a named size_t parameter from an EVP_PKEY. |
|
Read a UTF‐8 string parameter from a key by OSSL_PKEY_PARAM name. |
Return the OSSL_PARAM descriptors for parameters retrievable from |
|
Test whether a public‐key object is known under the given algorithm name. |
|
Generate a key pair into *`ppkey` using an initialised keygen context. |
|
Initialise a key context for key‐pair generation. |
|
|
Register an application‐defined EVP_PKEY_METHOD (deprecated). |
|
Copy all callbacks and flags from one EVP_PKEY_METHOD to another (deprecated). |
|
Find a registered EVP_PKEY_METHOD by key type NID (deprecated). |
|
Free an application‐defined EVP_PKEY_METHOD allocated with EVP_PKEY_meth_new (deprecated). |
|
Return the registered EVP_PKEY_METHOD at index |
|
Read the algorithm id and flags from an EVP_PKEY_METHOD (deprecated). |
|
Retrieve the full key‐check callback from an EVP_PKEY_METHOD (deprecated). |
|
Retrieve the context‐cleanup callback from an EVP_PKEY_METHOD (deprecated). |
|
Retrieve the context‐copy callback from an EVP_PKEY_METHOD (deprecated). |
|
Return the number of registered EVP_PKEY_METHOD implementations (deprecated). |
|
Retrieve the ctrl / ctrl_str callbacks from an EVP_PKEY_METHOD (deprecated). |
|
Return the decrypt_init and decrypt callbacks from an EVP_PKEY_METHOD (deprecated). |
|
Retrieve derive_init / derive callbacks from an EVP_PKEY_METHOD (deprecated). |
|
Retrieve the custom digest callback from an EVP_PKEY_METHOD (deprecated). |
|
Retrieve the one‐shot digestsign callback from an EVP_PKEY_METHOD (deprecated). |
|
Retrieve the one‐shot digestverify callback from an EVP_PKEY_METHOD (deprecated). |
|
Retrieve public‐key encryption callbacks from an EVP_PKEY_METHOD (deprecated). |
|
Retrieve the init callback from an EVP_PKEY_METHOD (deprecated). |
|
Retrieve key‐generation callbacks from an EVP_PKEY_METHOD (deprecated). |
|
Retrieve the parameter‐check callback from an EVP_PKEY_METHOD (deprecated). |
|
Retrieve parameter‐generation callbacks from an EVP_PKEY_METHOD (deprecated). |
|
Retrieve the public‐key check callback from an EVP_PKEY_METHOD (deprecated). |
|
Retrieve the sign_init and sign callbacks from an EVP_PKEY_METHOD (deprecated). |
|
Retrieve digest‐context signing callbacks from an EVP_PKEY_METHOD (deprecated). |
|
Retrieve the verify‐init and verify callbacks from an EVP_PKEY_METHOD (deprecated). |
|
Retrieve the verify‐recover callbacks from an EVP_PKEY_METHOD (deprecated). |
|
Retrieve digest‐context verification callbacks from an EVP_PKEY_METHOD (deprecated). |
|
Allocate a new custom EVP_PKEY_METHOD for algorithm |
|
Unregister a previously added EVP_PKEY_METHOD from the global list (deprecated). |
|
Set the pairwise key‐consistency check callback on a custom EVP_PKEY_METHOD (deprecated). |
|
Set the context‐cleanup callback on a custom EVP_PKEY_METHOD (deprecated). |
|
Set the context‐copy callback on a custom EVP_PKEY_METHOD (deprecated). |
|
Set the ctrl / ctrl_str callbacks on an EVP_PKEY_METHOD (deprecated). |
|
Set public‐key decryption callbacks on an EVP_PKEY_METHOD (deprecated). |
|
Install key‐derivation init/derive callbacks on a legacy EVP_PKEY_METHOD. |
|
Set the digest_custom callback on a custom EVP_PKEY_METHOD (deprecated). |
|
Set the one‐shot DigestSign callback on an EVP_PKEY_METHOD (deprecated). |
|
Set the one‐shot DigestVerify callback on an EVP_PKEY_METHOD (deprecated). |
|
Set public‐key encryption callbacks on an EVP_PKEY_METHOD (deprecated). |
|
Set the context‐init callback on a custom EVP_PKEY_METHOD (deprecated). |
|
Set key‐generation callbacks on an EVP_PKEY_METHOD (deprecated). |
|
Set the domain‐parameter validation callback on an EVP_PKEY_METHOD (deprecated). |
|
Set parameter‐generation callbacks on an EVP_PKEY_METHOD (deprecated). |
|
Set the public‐component check callback on a custom EVP_PKEY_METHOD (deprecated). |
|
Set the signing callbacks on a custom EVP_PKEY_METHOD (deprecated). |
|
Set digest‐context signing callbacks on an EVP_PKEY_METHOD (deprecated). |
|
Set the signature‐verification callbacks on a custom EVP_PKEY_METHOD (deprecated). |
|
Set verify‐recover init/operation callbacks on a custom EVP_PKEY_METHOD (deprecated). |
|
Set digest‐context verification callbacks on an EVP_PKEY_METHOD (deprecated). |
Test whether an EVP_PKEY lacks required algorithm parameters. |
|
Allocate an empty EVP_PKEY object. |
|
|
Create an EVP_PKEY wrapping a CMAC key (deprecated). |
Create an EVP_PKEY holding a MAC key for HMAC, CMAC, Poly1305, or SipHash. |
|
|
Create an EVP_PKEY from raw private‐key octets (legacy NID/ENGINE form). |
|
Create an EVP_PKEY from raw private‐key octets using a named algorithm and library context. |
|
Create an EVP_PKEY from raw public key octets for algorithms that support that form. |
|
Create an EVP_PKEY from raw public‐key octets using a named algorithm and library context. |
Validate that the public and private components of a key form a consistent pair. |
|
Validate domain parameters associated with a key context. |
|
Perform a fast/lightweight validation of domain parameters on a key context. |
|
Compare the domain parameters of two keys for equality. |
|
Generate algorithm parameters into *`ppkey` using an initialised paramgen context. |
|
Initialise a key context for algorithm parameter generation. |
|
Print a key's domain parameters to a BIO in human‐readable form. |
|
Print the algorithm parameters of |
|
Print a private key (including private components) to a BIO. |
|
Print the private components of |
|
Print the public components of |
|
Print the public components of |
|
Validate the private key associated with a key context. |
|
Validate the public key associated with a key context. |
|
Perform a fast (non‐exhaustive) public‐key validity check. |
|
Control whether algorithm parameters are written when serializing |
|
|
Set the DH key referenced by an EVP_PKEY, incrementing the DH reference count. |
|
Set the DSA key referenced by an EVP_PKEY, incrementing the DSA reference count. |
|
Assign an EC_KEY to an EVP_PKEY, incrementing the EC_KEY reference count (deprecated). |
|
Set the RSA key referenced by an EVP_PKEY, incrementing the RSA reference count (deprecated). |
|
Set the public key on |
|
Associate an ENGINE with an EVP_PKEY for subsequent low‐level operations (deprecated). |
Set a named BIGNUM parameter on an EVP_PKEY. |
|
Store application‐specific data on an EVP_PKEY at a CRYPTO ex_data index. |
|
Set a named integer parameter on an EVP_PKEY. |
|
|
Set a named octet‐string parameter on an EVP_PKEY. |
Set multiple algorithm parameters on an EVP_PKEY from an OSSL_PARAM array. |
|
|
Set a named size_t parameter on an EVP_PKEY. |
Assign the algorithm type of an empty EVP_PKEY by NID / EVP_PKEY_* id. |
|
|
Assign the algorithm type of |
Assign the algorithm type of |
|
|
Set a UTF‐8 string algorithm parameter on an EVP_PKEY by name. |
Return the parameters that may be set on an EVP_PKEY. |
|
Create a signature over data using an initialized signing context. |
|
Initialize a key context for signing with the key bound to |
|
Initialize |
|
Export selected key components from an EVP_PKEY as a newly allocated OSSL_PARAM array. |
|
Map a public‐key type NID to its base algorithm type NID. |
|
|
Invoke |
Increment the reference count of an EVP_PKEY. |
|
Verify a signature over |
|
Initialise a key context for signature verification with the key bound to |
|
Initialise |
|
Recover the signed data from a signature (algorithms that support recovery, e.g. RSA). |
|
Initialize a key context for signature recovery (typically RSA). |
|
|
Initialize |
One‐shot digest of |
|
One‐shot MAC computation: fetch the algorithm, process |
|
Free an EVP_RAND_CTX and release associated resources. |
|
Return the EVP_RAND algorithm associated with RAND context |
|
Retrieve algorithm parameters from a RAND context into |
|
Return the OSSL_PARAM descriptors gettable from a live RAND context. |
|
Create a RAND context for |
|
Set parameters on a RAND context via an OSSL_PARAM array. |
|
Return the parameters that may be set on a RAND context. |
|
Increment the reference count on an EVP_RAND_CTX. |
|
Invoke a callback for every RAND implementation available from activated providers. |
|
Enable thread‐safe locking on a RAND context for concurrent use. |
|
Fetch a random‐number generator implementation from providers. |
|
Release a reference to an EVP_RAND obtained from EVP_RAND_fetch. |
|
Generate random bytes from a RAND context. |
|
Return a human‐readable description of a random‐number algorithm. |
|
Return the primary algorithm name of a fetched EVP_RAND. |
|
Return the provider that supplied a RAND implementation. |
|
Retrieve algorithm‐level parameters from a RAND implementation. |
|
Return the current lifecycle state of a RAND context. |
|
Return the current security strength in bits of a RAND context. |
|
Return the OSSL_PARAM descriptors for parameters gettable on a RAND context. |
|
Return the OSSL_PARAM descriptors that can be retrieved from an EVP_RAND algorithm. |
|
Instantiate (seed) an EVP_RAND_CTX so it can generate random bytes. |
|
Test whether a RAND implementation is known under the given name. |
|
Call |
|
Generate a nonce of |
|
Reseed a DRBG/RAND context with optional entropy and additional input. |
|
Return the OSSL_PARAM descriptors for parameters settable on a RAND context. |
|
Clear the instantiated state of a RAND context, returning it to uninitialised. |
|
Increment the reference count on a fetched EVP_RAND. |
|
Confirm whether the internal DRBG state of |
|
Call |
|
Fetch a signature algorithm implementation from providers. |
|
Free a fetched EVP_SIGNATURE method and release its provider reference. |
|
Return a human‐readable description of a signature algorithm implementation. |
|
Return the primary algorithm name of a signature implementation. |
|
Return the provider that implements a fetched EVP_SIGNATURE algorithm. |
|
|
Return the OSSL_PARAM descriptors gettable on a signature context for |
Test whether a signature algorithm implementation matches a name. |
|
Call |
|
|
Return the OSSL_PARAM descriptors settable on a signature context for |
Increment the reference count on a fetched EVP_SIGNATURE algorithm. |
|
Finalize a seal (envelope encrypt) operation and write any remaining ciphertext. |
|
Initialize a seal (envelope encrypt) operation for |
|
Finish a legacy Sign operation and write the signature using |
|
Finish a legacy Sign operation with an explicit library context and property query. |
|
Finish a verify operation by checking |
|
Verify a signature against the digest accumulated in |
|
Register built‐in algorithm modules with the EVP subsystem. |
|
Register |
|
Register |
|
Return the EVP_CIPHER for AES‐128 in CBC mode. |
|
|
Return the EVP_CIPHER for AES‐128‐CBC with HMAC‐SHA1 (TLS AEAD). |
|
Return the EVP_CIPHER for AES‐128‐CBC with HMAC‐SHA256 (TLS AEAD). |
Return the AES‐128 cipher in CCM mode. |
|
Return the EVP_CIPHER for AES‐128 in 1‐bit CFB mode. |
|
Return the EVP_CIPHER for AES‐128 in 128‐bit CFB mode. |
|
Return the EVP_CIPHER for AES‐128 in 8‐bit CFB mode. |
|
Return the AES‐128 cipher in CTR mode. |
|
Return the AES‐128 cipher in ECB mode. |
|
Return the EVP_CIPHER for AES‐128 in GCM mode. |
|
Return the AES‐128 cipher in OCB mode. |
|
Return the EVP_CIPHER for AES‐128 in OFB mode. |
|
Return the EVP_CIPHER for AES‐128 key wrap (RFC 3394). |
|
Return the AES‐128 cipher in key‐wrap‐with‐padding mode (RFC 5649). |
|
Return the EVP_CIPHER for AES‐128 in XTS mode. |
|
Return the AES‐192 cipher in CBC mode. |
|
Return the EVP_CIPHER for AES‐192 in CCM mode. |
|
Return the AES‐192 cipher in 1‐bit CFB mode. |
|
Return the EVP_CIPHER for AES‐192 in 128‐bit CFB mode. |
|
Return the AES‐192 cipher in 8‐bit CFB mode. |
|
Return the AES‐192 cipher in CTR mode. |
|
Return the EVP_CIPHER for AES‐192 in ECB mode. |
|
Return the AES‐192 cipher in GCM mode. |
|
Return the built‐in AES‐192 OCB authenticated‐encryption cipher method. |
|
Return the EVP_CIPHER for AES‐192 in OFB mode. |
|
Return the AES‐192 cipher in key‐wrap mode (RFC 3394). |
|
Return the AES‐192 cipher in key‐wrap‐with‐padding mode (RFC 5649). |
|
Return the EVP_CIPHER for AES‐256 in CBC mode. |
|
|
Return the EVP_CIPHER for AES‐256‐CBC with HMAC‐SHA1 (TLS AEAD). |
|
Return the EVP_CIPHER for AES‐256‐CBC with HMAC‐SHA256 (TLS AEAD). |
Return the EVP_CIPHER for AES‐256 in CCM mode. |
|
Return the AES‐256 cipher in 1‐bit CFB mode. |
|
Return the AES‐256 cipher in 128‐bit CFB mode. |
|
Return the AES‐256 cipher in 8‐bit CFB mode. |
|
Return the AES‐256 cipher in CTR mode. |
|
Return the EVP_CIPHER for AES‐256 in ECB mode. |
|
Return the EVP_CIPHER for AES‐256 in GCM mode. |
|
Return the EVP_CIPHER for AES‐256 in OCB mode. |
|
Return the EVP_CIPHER for AES‐256 in OFB mode. |
|
Return the EVP_CIPHER for AES‐256 key wrap (RFC 3394). |
|
Return the EVP_CIPHER for AES‐256 key wrap with padding (RFC 5649). |
|
Return the EVP_CIPHER for AES‐256 in XTS mode (IEEE 1619 / NIST SP 800‐38E). |
|
Return the built‐in ARIA‐128 CBC cipher method. |
|
Return the EVP_CIPHER for ARIA‐128 in CCM mode. |
|
Return the EVP_CIPHER for ARIA‐128 in 1‐bit CFB mode. |
|
Return the ARIA‐128 cipher in 128‐bit CFB mode. |
|
Return the ARIA‐128 cipher in 8‐bit CFB mode. |
|
Return the EVP_CIPHER for ARIA‐128 in CTR mode. |
|
Return the ARIA‐128 cipher in ECB mode. |
|
Return the ARIA‐128 cipher in GCM mode. |
|
Return the ARIA‐128 cipher in OFB mode. |
|
Return the EVP_CIPHER for ARIA‐192 in CBC mode. |
|
Return the EVP_CIPHER for ARIA‐192 in CCM mode. |
|
Return the ARIA‐192 cipher in 1‐bit CFB mode. |
|
Return the ARIA‐192 cipher in 128‐bit CFB mode. |
|
Return the ARIA‐192 cipher in 8‐bit CFB mode. |
|
Return the ARIA‐192 cipher in CTR mode. |
|
Return the EVP_CIPHER for ARIA‐192 in ECB mode. |
|
Return the EVP_CIPHER for ARIA‐192 in GCM mode. |
|
Return the EVP_CIPHER for ARIA‐192 in OFB mode. |
|
Return the EVP_CIPHER for ARIA‐256 in CBC mode. |
|
Return the ARIA‐256 cipher in CCM mode. |
|
Return the ARIA‐256 cipher in 1‐bit CFB mode. |
|
Return the EVP_CIPHER for ARIA‐256 in 128‐bit CFB mode. |
|
Return the ARIA‐256 cipher in 8‐bit CFB mode. |
|
Return the ARIA‐256 cipher in CTR mode. |
|
Return the ARIA‐256 cipher in ECB mode. |
|
Return the EVP_CIPHER for ARIA‐256 in GCM mode. |
|
Return the EVP_CIPHER for ARIA‐256 in OFB mode. |
|
Return the Blowfish cipher in CBC mode. |
|
Return the EVP_CIPHER for Blowfish in 64‐bit CFB mode. |
|
Return the Blowfish cipher in ECB mode. |
|
Return the Blowfish cipher in OFB mode. |
|
Return the EVP_MD for BLAKE2b‐512. |
|
Return the EVP_MD for BLAKE2s‐256. |
|
Return the Camellia‐128 cipher in CBC mode. |
|
Return the Camellia‐128 cipher in 1‐bit CFB mode. |
|
Return the EVP_CIPHER for Camellia‐128 in 128‐bit CFB mode. |
|
Return the Camellia‐128 cipher in 8‐bit CFB mode. |
|
Return the Camellia‐128 cipher in CTR mode. |
|
Return the EVP_CIPHER for Camellia‐128 in ECB mode. |
|
Return the Camellia‐128 cipher in OFB mode. |
|
Return the Camellia‐192 cipher in CBC mode. |
|
Return the Camellia‐192 cipher in 1‐bit CFB mode. |
|
Return the EVP_CIPHER for Camellia‐192 in 128‐bit CFB mode. |
|
Return the EVP_CIPHER for Camellia‐192 in 8‐bit CFB mode. |
|
Return the EVP_CIPHER for Camellia‐192 in CTR mode. |
|
Return the EVP_CIPHER for Camellia‐192 in ECB mode. |
|
Return the Camellia‐192 cipher in OFB mode. |
|
Return the Camellia‐256 cipher in CBC mode. |
|
Return the Camellia‐256 cipher in 1‐bit CFB mode. |
|
Return the Camellia‐256 cipher in 128‐bit CFB mode. |
|
Return the Camellia‐256 cipher in 8‐bit CFB mode. |
|
Return the EVP_CIPHER for Camellia‐256 in CTR mode. |
|
Return the Camellia‐256 cipher in ECB mode. |
|
Return the Camellia‐256 cipher in OFB mode. |
|
Return the CAST5 cipher in CBC mode. |
|
Return the EVP_CIPHER for CAST5 in 64‐bit CFB mode. |
|
Return the EVP_CIPHER for CAST5 in ECB mode. |
|
Return the CAST5 cipher in OFB mode. |
|
Return the ChaCha20 stream cipher. |
|
Return the EVP_CIPHER for ChaCha20‐Poly1305 AEAD. |
|
|
Enable or disable the FIPS constraint in a library context's default properties. |
|
Query whether the library context's default property query requires FIPS algorithms. |
Return the EVP_CIPHER for DES in CBC mode. |
|
Return the EVP_CIPHER for DES in 1‐bit CFB mode. |
|
Return the EVP_CIPHER for DES in 64‐bit CFB mode. |
|
Return the single‐DES cipher in 8‐bit CFB mode. |
|
Return the EVP_CIPHER for DES in ECB mode. |
|
Return the EVP_CIPHER for two‐key triple‐DES in CBC mode (alias of EVP_des_ede_cbc). |
|
Return the EVP_CIPHER for triple‐DES EDE with three keys in ECB mode. |
|
Return the built‐in Triple‐DES (EDE3) CBC cipher method. |
|
Return the EVP_CIPHER for three‐key triple‐DES in 1‐bit CFB mode. |
|
Return the EVP_CIPHER for triple‐DES EDE in 64‐bit CFB mode. |
|
Return the EVP_CIPHER for three‐key triple‐DES in 8‐bit CFB mode. |
|
Return the EVP_CIPHER for three‐key triple‐DES in ECB mode. |
|
Return the EVP_CIPHER for three‐key triple‐DES in OFB mode. |
|
Return the Triple‐DES key‐wrap cipher (RFC 3217). |
|
Return the EVP_CIPHER for two‐key triple‐DES in CBC mode. |
|
Return the two‐key triple‐DES cipher in 64‐bit CFB mode. |
|
Return the EVP_CIPHER for two‐key triple‐DES in ECB mode. |
|
Return the two‐key triple‐DES cipher in OFB mode. |
|
Return the single‐DES cipher in OFB mode. |
|
Return the DES‐X cipher in CBC mode. |
|
Return the EVP_CIPHER for the null (pass‐through) cipher. |
|
Look up a cipher algorithm by name (for example "AES‐256‐GCM"). |
|
Look up a message digest algorithm by name (e.g. "SHA256"). |
|
Return the process‐wide default password prompt string. |
|
Return the EVP_CIPHER for IDEA in CBC mode. |
|
Return the EVP_CIPHER for IDEA in 64‐bit CFB mode. |
|
Return the EVP_CIPHER for IDEA in ECB mode. |
|
Return the EVP_CIPHER for IDEA in OFB mode. |
|
Return the MD4 digest method (128‐bit output; legacy provider). |
|
Return the MD5 digest method (128‐bit output). |
|
Return the EVP_MD for the combined MD5‐SHA‐1 digest used by TLS 1.0/1.1. |
|
Return the null digest method (zero‐length digest, for testing/legacy use). |
|
Return the EVP_MD for MDC2. |
|
Return the RC2 cipher in CBC mode with a 40‐bit effective key. |
|
Return the EVP_CIPHER for RC2‐64 in CBC mode. |
|
Return the RC2 cipher in CBC mode. |
|
Return the RC2 cipher in 64‐bit CFB mode. |
|
Return the EVP_CIPHER for RC2 in ECB mode. |
|
Return the EVP_CIPHER for RC2 in OFB mode. |
|
Return the RC4 stream cipher. |
|
Return the EVP_CIPHER for RC4 with a 40‐bit effective key (legacy). |
|
Return the EVP_CIPHER for the RC4‐HMAC‐MD5 AEAD suite (TLS legacy). |
|
Prompt on the terminal for a password into |
|
Prompt for a password with a minimum and maximum length. |
|
Return the EVP_MD for RIPEMD‐160. |
|
Return the SEED cipher in CBC mode. |
|
Return the EVP_CIPHER for SEED in 128‐bit CFB mode. |
|
Return the SEED cipher in ECB mode. |
|
Return the SEED cipher in OFB mode. |
|
Set the default property query string used for algorithm fetches in |
|
Set the default password prompt string used by EVP password helpers. |
|
Return the SHA‐1 digest method (160‐bit output). |
|
Return the SHA‐224 digest method (224‐bit output). |
|
Return the SHA‐256 digest method (256‐bit output). |
|
Return the EVP_MD for SHA‐384. |
|
Return the EVP_MD for SHA3‐224. |
|
Return the built‐in SHA3‐256 message‐digest method. |
|
Return the EVP_MD for SHA3‐384. |
|
Return the SHA3‐512 digest method (512‐bit output). |
|
Return the SHA‐512 digest method (512‐bit output). |
|
Return the EVP_MD for SHA‐512/224 (truncated SHA‐512). |
|
Return the EVP_MD for SHA‐512/256. |
|
Return the EVP_MD for SHAKE128 (XOF). |
|
Return the SHAKE256 XOF digest method. |
|
Return the EVP_MD for SM3. |
|
Return the EVP_CIPHER for SM4 in CBC mode. |
|
Return the EVP_CIPHER for SM4 in 128‐bit CFB mode. |
|
Return the EVP_CIPHER for SM4 in CTR mode. |
|
Return the EVP_CIPHER for SM4 in ECB mode. |
|
Return the EVP_CIPHER for SM4 in OFB mode. |
|
Return the WHIRLPOOL digest method (512‐bit output; legacy provider). |
|
Free an EXTENDED_KEY_USAGE structure and its contents. |
|
Return the ASN.1 item descriptor for EXTENDED_KEY_USAGE. |
|
Allocate a new Extended Key Usage extension value. |
|
Free a GENERAL_NAMES structure and its contents. |
|
Return the ASN.1 item descriptor for GENERAL_NAMES. |
|
Allocate a new GeneralNames (SEQUENCE OF GeneralName) value. |
|
Compare two GENERAL_NAME values for equality. |
|
Duplicate a GENERAL_NAME structure. |
|
Free a GENERAL_NAME structure and its contents. |
|
Retrieve the OID and typed value from a GeneralName of type otherName. |
|
Return the typed payload pointer stored in a GeneralName. |
|
Return the ASN.1 item descriptor for GENERAL_NAME. |
|
Allocate a new GeneralName value. |
|
Print a GeneralName to a BIO in human‐readable form. |
|
Set a GeneralName to type otherName, taking ownership of |
|
Set the type and owned value pointer of a GeneralName. |
|
Free a general subtree value and its contents. |
|
Return the ASN.1 item descriptor for GENERAL_SUBTREE. |
|
Allocate a new general subtree (Name Constraints entry). |
|
Compute an HMAC over |
|
|
Copy the HMAC state from |
|
Free an HMAC context. |
|
Get the message digest associated with an HMAC context. |
|
Allocate a new HMAC context (deprecated; prefer EVP_MAC). |
|
Reset an HMAC context to a reusable empty state (deprecated; prefer EVP_MAC). |
|
Set flags on an HMAC context, forwarded to the underlying digest. |
|
Finalize an HMAC computation and write the MAC. |
|
Initialize an HMAC context with a key and digest (legacy). |
|
(Re)initialize an HMAC_CTX with key and digest (deprecated; prefer EVP_MAC). |
|
Absorb more message bytes into an HMAC context (deprecated; prefer EVP_MAC_update). |
|
Return the output length in bytes of the digest used by an HMAC context (deprecated). |
|
Encrypt or decrypt data with IDEA in CBC mode (deprecated; prefer EVP). |
|
Encrypt or decrypt data with IDEA in 64‐bit CFB mode (deprecated; prefer EVP). |
|
Encrypt one 8‐byte IDEA block in ECB mode (deprecated; prefer EVP). |
|
Encrypt one IDEA block in place using an expanded key schedule (deprecated; prefer EVP). |
|
Encrypt or decrypt data with IDEA in 64‐bit OFB mode (deprecated; prefer EVP). |
|
Return a short string describing the IDEA implementation (deprecated). |
|
Derive an IDEA decryption schedule from an encryption schedule (deprecated). |
|
Expand a 16‐byte IDEA key into an encryption key schedule (deprecated; prefer EVP). |
Free an IPAddressChoice structure and its contents. |
|
Return the ASN.1 item descriptor for IPAddressChoice. |
|
Allocate a new IPAddressChoice (inherit or explicit address ranges). |
|
Free an IPAddressFamily value and its contents. |
|
Return the ASN.1 item descriptor for IPAddressFamily. |
|
Allocate a new IPAddressFamily value. |
|
Free a IP address or address range (RFC 3779) and its contents. |
|
Return the ASN.1 item descriptor for IPAddressOrRange. |
|
Allocate an empty IP address or address range (RFC 3779). |
|
Free an IPAddressRange value and its contents. |
|
Return the ASN.1 item descriptor for IPAddressRange. |
|
Allocate a new IPAddressRange value. |
|
Free an ISSUER_SIGN_TOOL structure and its contents. |
|
Return the ASN.1 item descriptor for ISSUER_SIGN_TOOL. |
|
Allocate a new Issuer Signing Tool extension value. |
|
Free an Issuing Distribution Point value and its contents. |
|
Return the ASN.1 item descriptor for ISSUING_DIST_POINT. |
|
Allocate a new Issuing Distribution Point extension value. |
|
|
Compute the MD4 digest of |
|
Finish an MD4 message digest and write the 16‐byte result (deprecated). |
|
Initialize a low‐level MD4 digest context (deprecated; prefer EVP_DigestInit_ex). |
|
Apply the MD4 compression function to one 64‐byte block (deprecated). |
|
Absorb more message bytes into an MD4 digest context (deprecated). |
|
Compute the MD5 digest of |
|
Finish an MD5 message digest and write the 16‐byte result (deprecated). |
|
Initialize a low‐level MD5 digest context (deprecated; prefer EVP_DigestInit_ex). |
|
Apply the MD5 compression function to one 64‐byte block (deprecated). |
|
Absorb more message bytes into an MD5 digest context (deprecated). |
|
Compute the MDC‐2 digest of |
|
Finalise an MDC‐2 digest and write the 16‐byte result (deprecated). |
|
Initialise an MDC‐2 digest context (deprecated). |
|
Absorb more message bytes into an MDC‐2 digest context (deprecated). |
Check whether certificate subject names satisfy the given Name Constraints. |
|
Check whether the certificate Common Name satisfies Name Constraints. |
|
Free a Name Constraints extension value and its contents. |
|
Return the ASN.1 item descriptor for NAME_CONSTRAINTS. |
|
Allocate a new Name Constraints extension value. |
|
Free a NAMING_AUTHORITY value and its contents. |
|
Return the namingAuthorityId object identifier from a NAMING_AUTHORITY. |
|
Return the human‐readable naming authority text. |
|
Return the naming authority URL (IA5String). |
|
Return the ASN.1 item descriptor for NAMING_AUTHORITY. |
|
Allocate a new NAMING_AUTHORITY value. |
|
Set the naming authority OID, taking ownership of |
|
Set the authority text on a NAMING_AUTHORITY, taking ownership of |
|
Set the authority URL on a NAMING_AUTHORITY, taking ownership of |
|
|
Return the legacy Win32 CONF_METHOD (deprecated). |
Return the default NCONF_METHOD used by NCONF_new(NULL). |
|
Dump a CONF structure's sections and name/value pairs to a BIO. |
|
Write the contents of a CONF object to a FILE in name=value form. |
|
Free a CONF object and its contained values. |
|
Free configuration values stored in |
|
Return the library context associated with a CONF object. |
|
Look up a numeric value in a CONF object, reporting errors via the error stack. |
|
Return all name/value pairs belonging to a CONF section. |
|
Return the names of all sections present in a CONF object. |
|
Look up a string value in a CONF object. |
|
Load configuration values from a file into a CONF object. |
|
Load configuration data from a BIO into a CONF object. |
|
Load configuration name/value pairs from an open FILE. |
|
Allocate a CONF object using configuration method |
|
Allocate a CONF object associated with a library context. |
|
Free a Netscape Certificate Sequence and its contents. |
|
Return the ASN.1 item descriptor for NETSCAPE_CERT_SEQUENCE. |
|
Allocate an empty Netscape Certificate Sequence. |
|
Free a Netscape SPKAC structure and its contents. |
|
Return the ASN.1 item descriptor for NETSCAPE_SPKAC. |
|
Allocate an empty Netscape Signed Public Key And Challenge (SPKAC) structure. |
|
Decode a base64‐encoded Netscape SPKI structure from a string. |
|
Base64‐encode a Netscape Signed Public Key and Challenge structure. |
|
Free a Netscape Signed Public Key and Challenge (SPKI) and its contents. |
|
Extract the public key from a Netscape SPKI structure. |
|
Return the ASN.1 item descriptor for NETSCAPE_SPKI. |
|
Allocate an empty Netscape Signed Public Key and Challenge (SPKI). |
|
Print a human‐readable representation of a Netscape signed public key and challenge. |
|
Set the public key in a Netscape SPKI structure from |
|
Sign a Netscape SPKI with a private key and message digest. |
|
Verify the signature on a Netscape Signed Public Key and Challenge (SPKI) structure. |
|
Free a certificate‐policy notice reference and its contents. |
|
Return the ASN.1 item descriptor for NOTICEREF. |
|
Allocate an empty certificate‐policy notice reference (organization + notice numbers). |
|
Register a name‐to‐data mapping in the OBJ_NAME table (legacy aliases). |
|
Free OBJ_NAME entries of the given type (or all types). |
|
Invoke a callback for every OBJ_NAME of the given type (unsorted). |
|
Invoke a callback for every OBJ_NAME of the given type in sorted name order. |
|
Look up data associated with a named object of the given type. |
|
Initialize the OBJ_NAME table used for algorithm name aliases. |
|
Allocate a new OBJ_NAME type index with custom hash, compare, and free callbacks. |
|
Remove a name from the OBJ_NAME alias/lookup table. |
|
Add |
|
Register a signature OID as the combination of a digest and public‐key algorithm. |
|
Binary‐search a sorted array of fixed‐size elements using a comparator. |
|
Binary‐search a sorted object table with optional flags (internal helper). |
|
Compare two ASN1_OBJECT values. |
|
Register a new ASN.1 object identifier with short and long names. |
|
Load OID definitions from text lines read from |
|
Deep‐copy an ASN1_OBJECT. |
|
Look up the digest and public‐key NIDs that compose a signature algorithm. |
|
Look up the composite signature NID for a digest and public‐key algorithm pair. |
|
Return the DER‐encoded content octets of an ASN1_OBJECT. |
|
Return the length in bytes of an ASN.1 object's encoded OID content. |
|
Return the NID for an object long name. |
|
Allocate one or more new numeric object identifiers (NIDs). |
|
Return the long name string for a numeric object identifier (NID). |
|
Return the ASN1_OBJECT for a numeric identifier (NID). |
|
Return the short name string for a numeric object identifier (NID). |
|
Return the NID for an ASN1_OBJECT. |
|
Format an ASN1_OBJECT as text (dotted OID and/or registered name). |
|
Free the signature‐algorithm OID alias table populated by OBJ_add_sigid(). |
|
Look up the numeric object identifier (NID) for a short name string. |
|
Return the NID for a text object identifier. |
|
Parse a textual OID (dot notation or name) into an ASN1_OBJECT. |
|
Encode |
|
Insert extension |
|
Remove and return the basic‐response extension at index |
|
Free an OCSP BasicOCSPResponse and its contents. |
|
Decode the first basic‐response extension of type |
|
Return the basic‐response extension at index |
|
|
Find the next basic‐response extension with NID |
|
Find the next basic‐response extension with object identifier |
|
Find the next basic‐response extension with criticality |
Return the number of extensions on a basic OCSP response. |
|
Return the ASN.1 item descriptor for OCSP_BASICRESP. |
|
Allocate an empty OCSP BasicOCSPResponse. |
|
Duplicate an OCSP CertID structure. |
|
Free an OCSP CertID and its contents. |
|
Return the ASN.1 item descriptor for OCSP_CERTID. |
|
Allocate an empty OCSP CertID. |
|
Free a OCSP CertStatus and its contents. |
|
Return the ASN.1 item descriptor for OCSP_CERTSTATUS. |
|
Allocate an empty OCSP CertStatus. |
|
Free an OCSP CrlID extension value and its contents. |
|
Return the ASN.1 item descriptor for OCSP_CRLID. |
|
Allocate an empty OCSP CrlID extension value. |
|
Encode |
|
Insert extension |
|
Remove and return the single‐request extension at index |
|
Free an OCSP single Request entry and its contents. |
|
Decode the first single‐request extension of type |
|
Return the single‐request extension at index |
|
|
Find the next single‐request extension with NID |
|
Find the next single‐request extension with object identifier |
|
Find the next single‐request extension with criticality |
Return the number of extensions on a single OCSP request entry. |
|
Return the ASN.1 item descriptor for OCSP_ONEREQ. |
|
Allocate an empty OCSP single Request entry. |
|
Free a OCSP TBSRequest (OCSP_REQINFO) and its contents. |
|
Return the ASN.1 item descriptor for OCSP_REQINFO. |
|
Allocate an empty OCSP TBSRequest (OCSP_REQINFO). |
|
Encode |
|
Insert extension |
|
Remove and return the OCSP request extension at index |
|
Free an OCSP Request and its contents. |
|
Decode the first OCSP request extension of type |
|
Return the OCSP request extension at index |
|
|
Find the next OCSP request extension with NID |
|
Find the next OCSP request extension with object identifier |
|
Find the next OCSP request extension with criticality |
Return the number of extensions on an OCSP request. |
|
Return the ASN.1 item descriptor for OCSP_REQUEST. |
|
Allocate an empty OCSP Request. |
|
Print an OCSP request in human‐readable form to a BIO. |
|
Free an OCSP ResponseBytes and its contents. |
|
Return the ASN.1 item descriptor for OCSP_RESPBYTES. |
|
Allocate an empty OCSP ResponseBytes. |
|
Free a OCSP ResponseData and its contents. |
|
Return the ASN.1 item descriptor for OCSP_RESPDATA. |
|
Allocate an empty OCSP ResponseData. |
|
Free a OCSP ResponderID and its contents. |
|
Return the ASN.1 item descriptor for OCSP_RESPID. |
|
Test whether a ResponderID matches |
|
Test whether a ResponderID matches |
|
Allocate an empty OCSP ResponderID. |
|
Set a ResponderID to the SHA‐1 hash of |
|
|
Set a ResponderID to the SHA‐1 hash of |
Set a ResponderID to the subject name of |
|
Free a OCSP Response and its contents. |
|
Return the ASN.1 item descriptor for OCSP_RESPONSE. |
|
Allocate an empty OCSP Response. |
|
Print an OCSP response in human‐readable form to a BIO. |
|
Free an OCSP RevokedInfo and its contents. |
|
Return the ASN.1 item descriptor for OCSP_REVOKEDINFO. |
|
Allocate an empty OCSP RevokedInfo. |
|
Free an OCSP ServiceLocator extension value and its contents. |
|
Return the ASN.1 item descriptor for OCSP_SERVICELOC. |
|
Allocate an empty OCSP ServiceLocator extension value. |
|
Free an OCSP Signature and its contents. |
|
Return the ASN.1 item descriptor for OCSP_SIGNATURE. |
|
Allocate an empty OCSP Signature. |
|
Encode |
|
Insert extension |
|
Remove and return the SingleResponse extension at index |
|
Free an OCSP SingleResponse and its contents. |
|
Return the CertID from a SingleResponse. |
|
Decode the first SingleResponse extension of type |
|
Return the SingleResponse extension at index |
|
|
Find the next SingleResponse extension with NID |
|
Find the next SingleResponse extension with object identifier |
|
Find the next SingleResponse extension with criticality |
Return the number of extensions on an OCSP SingleResponse. |
|
Return the ASN.1 item descriptor for OCSP_SINGLERESP. |
|
Allocate an empty OCSP SingleResponse. |
|
Create an AcceptableResponses OCSP extension from OID strings. |
|
Create an ArchiveCutoff OCSP extension from a time string. |
|
Add a certificate to the optional certs field of a basic OCSP response. |
|
Add an OCSP nonce extension to a basic response. |
|
Append a SingleResponse with certificate status to a basic OCSP response. |
|
Sign a basic OCSP response with |
|
Sign a basic OCSP response using an initialized digest/sign context. |
|
Verify the signature and optional certificate path of a basic OCSP response. |
|
Build an OCSP CertID from issuer name/key material and a serial number. |
|
Return a human‐readable string for an OCSP CertStatus value. |
|
Build an OCSP CertID from a subject certificate and its issuer. |
|
Compare OCSP nonce extensions between a request and a basic response. |
|
Check that OCSP thisUpdate/nextUpdate times are acceptable relative to now. |
|
Copy the nonce extension from an OCSP request into a basic response. |
|
Create a CrlID OCSP extension from optional URL, CRL number, and time. |
|
Return a human‐readable string for a CRLReason / OCSP revocation reason code. |
|
Compare two OCSP CertID values for equality. |
|
Return borrowed pointers to the fields of an OCSP CertID. |
|
Compare only the issuer name/key hash fields of two OCSP CertIDs. |
|
Return the CertID from a single OCSP request entry. |
|
Append a CertID as a new single‐request entry, taking ownership of |
|
Add a certificate to the optional certs field of a signed OCSP request. |
|
Add an OCSP nonce extension to a request. |
|
Test whether an OCSP request carries an optional signature. |
|
Return the number of single‐request entries in an OCSP request. |
|
Return the single‐request entry at index |
|
Set the optional requestorName in an OCSP request to a directory name. |
|
Sign an OCSP request with |
|
Verify the signature on a signed OCSP request. |
|
Return the number of SingleResponse entries in a basic OCSP response. |
|
Find the next SingleResponse whose CertID matches |
|
Find a SingleResponse for |
|
Return the SingleResponse at index |
|
Return the optional certificate stack embedded in a basic OCSP response. |
|
Return internal pointers to the ResponderID fields of a basic OCSP response. |
|
Return the producedAt time from a basic OCSP response. |
|
Return the tbsResponseData from a basic OCSP response. |
|
Return the signature OCTET STRING from a basic OCSP response (borrowed). |
|
Locate the signer certificate for a basic OCSP response. |
|
Return the signature AlgorithmIdentifier from a basic OCSP response. |
|
Return a copy of the ResponderID from a basic OCSP response. |
|
Create an OCSP response with the given status and optional basic response. |
|
Extract and decode the BasicOCSPResponse from a successful OCSP response. |
|
Return the OCSPResponseStatus enumerated value from an OCSP response. |
|
Return a human‐readable string for an OCSPResponseStatus code. |
|
Send an OCSP request over HTTP via |
|
Create a non‐blocking HTTP request context for an OCSP exchange. |
|
Extract certificate status and related times from a SingleResponse. |
|
Create a ServiceLocator OCSP extension for |
|
Free an OPENSSL_INIT_SETTINGS object allocated with OPENSSL_INIT_new(). |
|
Allocate an OPENSSL_INIT_SETTINGS object for OPENSSL_init_crypto(). |
|
Set the application section name used when OPENSSL_init_crypto() loads config. |
|
|
Set CONF_modules_load_file() flags used when OPENSSL_init_crypto() loads config. |
|
Set the configuration file path used when OPENSSL_init_crypto() loads config. |
Delete the entry matching |
|
Call |
|
Invoke |
|
Return whether the last LHASH operation on |
|
Remove and free all entries from an LHASH without freeing the table itself. |
|
Free an LHASH table structure (does not free the caller‐owned entries). |
|
Return the load factor threshold that triggers LHASH contraction. |
|
Insert |
|
Allocate a new LHASH table using hash function |
|
|
Print per‐bucket node counts for an LHASH to |
|
Print per‐bucket node counts for a hash table to a BIO (deprecated). |
|
Print node‐usage / collision statistics for an LHASH to |
|
Print hash‐bucket usage / load statistics for a hash table to a BIO (deprecated). |
Return the number of entries stored in an LHASH table. |
|
Look up the entry matching |
|
Set the load factor threshold that triggers LHASH contraction. |
|
Install type‐safe thunk adapters used by DEFINE_LHASH_OF wrappers on |
|
|
Print summary statistics for an LHASH to |
|
Print summary statistics for a hash table to a BIO (deprecated). |
Hash a NUL‐terminated C string for use as an LHASH hash function. |
|
Convert an ASCII/ISO‐8859‐1 string to PKCS#12 BMPString form (zero‐extended UTF‐16BE). |
|
Register a handler to run during OPENSSL_cleanup(). |
|
Convert a byte buffer to a newly allocated colon‐separated hex string. |
|
Encode |
|
Map an RFC cipher suite name to the corresponding OpenSSL cipher name. |
|
Overwrite |
|
Deinitialize OpenSSL: run atexit handlers, free global crypto state, and stop threads. |
|
|
Load the named OpenSSL configuration file (deprecated; prefer CONF_modules_load_file). |
Abort the process after printing an internal OpenSSL assertion failure. |
|
|
Rebuild per‐process cryptographic state in a freshly forked child (deprecated). |
|
Resume OpenSSL internal state in the parent after a POSIX fork (deprecated). |
|
Prepare OpenSSL internal state before a POSIX fork (deprecated). |
Convert a time_t to UTC broken‐down time into caller‐provided storage. |
|
Add a day/second offset to a UTC struct tm in place. |
|
Compute the day/second difference between two broken‐down UTC times. |
|
Convert a single hexadecimal digit character to its 0–15 value. |
|
Decode a hexadecimal string into a newly allocated byte buffer. |
|
Decode a hex string into |
|
Return a static string describing a build or runtime configuration property. |
|
Perform legacy low‐level OpenSSL library initialization (prefer OPENSSL_init_crypto()). |
|
Initialize libcrypto with option flags and optional settings. |
|
Explicitly initialise libssl and libcrypto with the given options and settings. |
|
Report whether the process appears to be a non‐interactive Windows service. |
|
Report whether the process is running setuid/setgid (or otherwise "tainted"). |
|
Register OpenSSL's built‐in CONF modules (engines, providers, SSL, etc.). |
|
Deep‐copy a stack by duplicating each element with |
|
Remove and return the element at index |
|
Delete the first stack element whose pointer equals |
|
Shallow‐copy a stack (element pointers are duplicated, not deep‐copied). |
|
Find the first stack element that compares equal to |
|
Search for |
|
Search for |
|
Free a stack structure without freeing its elements. |
|
Insert |
|
Report whether a stack is marked sorted under its comparison function. |
|
Allocate an empty stack with an optional comparison function. |
|
Allocate an empty stack with no comparison function. |
|
Allocate a stack with comparison function |
|
Return the number of elements in a stack. |
|
Remove and return the last element of a stack. |
|
Pop and free every element, then free the stack. |
|
Append |
|
Ensure a stack's internal array can hold at least |
|
Replace the pointer at index |
|
Install a comparison function on a stack and mark it as unsorted. |
|
Remove and return the first element of a stack. |
|
Sort a stack in place using its comparison function. |
|
Insert |
|
Return the element at index |
|
Clear a stack to zero elements without freeing the element pointers. |
|
Case‐insensitive comparison of two NUL‐terminated C strings. |
|
Append |
|
Copy |
|
Case‐insensitive comparison of at most |
|
Return the length of |
|
Run per‐thread OpenSSL cleanup handlers for the calling thread in the default library context. |
|
Release per‐thread OpenSSL state associated with library context |
|
Convert a PKCS#12 BMPString (big‐endian UTF‐16 with zero high bytes) to a C string. |
|
Convert a PKCS#12 BMPString (big‐endian UTF‐16) to a UTF‐8 C string. |
|
Convert a UTF‐8 string to PKCS#12 BMPString form (big‐endian UTF‐16). |
|
Return OpenSSL build metadata (OPENSSL_VERSION_BUILD_METADATA). |
|
Return the OpenSSL library major version (OPENSSL_VERSION_MAJOR). |
|
Return the OpenSSL library minor version (OPENSSL_VERSION_MINOR). |
|
Return the OpenSSL library patch level (OPENSSL_VERSION_PATCH). |
|
Return the OpenSSL pre‐release label (OPENSSL_VERSION_PRE_RELEASE). |
|
|
Build and store a certificate chain for the CMP signer certificate. |
Free a CMP context and all resources it owns. |
|
|
Return the geninfo ITAV stack configured on the context. |
Return the library context associated with a CMP context. |
|
Return the newly obtained certificate from the last transaction, if any. |
|
Return the new public or private key stored on the context. |
|
Return the property query string used for algorithm fetching. |
|
Return the statusString text from the last CMP transaction. |
|
Return the trusted certificate store used to authenticate the CMP server. |
|
Return the untrusted certificate stack configured on the context. |
|
|
Return the validated CMP server certificate from the last transaction. |
Return a copy of CA certificates (caPubs) from the last certRep. |
|
Return a copy of extraCerts received in the last CMP message. |
|
Return a copy of the newly obtained certificate chain from the last transaction. |
|
|
Return the argument previously set for the certConf callback. |
Return the failInfo bit field from the last CMP transaction. |
|
|
Return the argument previously set for the HTTP transfer callback. |
Read a CMP context option (OSSL_CMP_OPT_*). |
|
Return the PKIStatus from the last CMP transaction stored on the context. |
|
|
Return the argument previously set for the message transfer callback. |
Allocate a CMP context with default options for client or server use. |
|
Print the OpenSSL error queue using the context logging callback. |
|
|
Append an ITAV to the geninfo field of outgoing CMP messages. |
|
Append an ITAV to the body of an outgoing General Message (genm). |
Append a certificate policy to the template policy extension. |
|
|
Append a Subject Alternative Name to the certificate template. |
Reset a CMP context to its initial state while retaining configuration. |
|
|
Test whether the context contains a Subject Alternative Name extension. |
|
Clear all geninfo ITAVs stored on the CMP context. |
Process a CMP request locally using the server callbacks on the context. |
|
Set the new key pair used in certificate‐request templates. |
|
Replace request extensions in the certificate template. |
|
Set the trusted certificate store used to authenticate the CMP server. |
|
Set the client CMP signer certificate on the context. |
|
|
Pin the expected sender DN for incoming CMP response verification. |
Set extra certificates sent in outgoing CMP messages. |
|
Set the intended issuer DN for the certificate template. |
|
|
Set a comma‐separated list of hosts that bypass the HTTP proxy. |
Set the old certificate referenced by a key‐update request. |
|
Set a PKCS#10 CSR used for P10CR certificate requests. |
|
Set the private key used to protect outgoing CMP messages. |
|
Set an HTTP proxy hostname for CMP transfer. |
|
Set the intended recipient DN placed in outgoing CMP PKIHeader fields. |
|
|
Set the reference value used for password‐based CMP message protection. |
Set the shared secret used for MAC‐based CMP message protection. |
|
Set the senderNonce placed in outgoing CMP PKIHeader fields. |
|
Set the serial number field in the certificate template. |
|
Set the CMP server hostname or IP address used for HTTP(S) transfer. |
|
Set the HTTP path component for CMP server requests. |
|
Pin the expected CMP server certificate for response verification. |
|
Set the subject DN in the certificate template. |
|
Set the transactionID placed in outgoing CMP PKIHeader fields. |
|
Set untrusted certificates used when validating CMP server messages. |
|
|
Register the certificate‐confirmation callback for the CMP client. |
|
Set the opaque argument passed to the certConf callback. |
Set the HTTP BIO callback used for CMP message transfer. |
|
|
Set the opaque argument passed to the HTTP transfer callback. |
Register a CMP logging callback for this context. |
|
Set a CMP context option (OSSL_CMP_OPT_*). |
|
Set the TCP port used for CMP HTTP(S) transfer. |
|
|
Replace the message transfer callback used by the CMP client. |
|
Set the opaque argument passed to the message transfer callback. |
Build a CRMF CertReqMsg from fields stored on the CMP context. |
|
Format the PKIStatusInfo from a CMP context into a human‐readable string. |
|
|
Return the geninfo ITAV stack from a CMP PKIHeader. |
Return the recipNonce from a CMP PKIHeader. |
|
Return the transactionID from a CMP PKIHeader. |
|
Allocate an ITAV with the given infoType and infoValue, taking ownership of both. |
|
Duplicate an OSSL_CMP_ITAV structure. |
|
Free an OSSL_CMP_ITAV structure and its infoType and infoValue contents. |
|
Extract the CA certificate stack from a caCerts ITAV. |
|
Extract the certProfile name list from a certProfile ITAV. |
|
Extract the root CA certificate from a rootCaCert ITAV. |
|
|
Extract root CA key‐update certificates from a rootCaKeyUpdate ITAV. |
Return the infoType OID from an ITAV. |
|
Return the infoValue from an ITAV. |
|
Create a certProfile ITAV from a stack of profile name strings. |
|
Create a caCerts ITAV containing a copy of the given CA certificate stack. |
|
Create a rootCaCert ITAV optionally containing a root CA certificate. |
|
|
Create a rootCaKeyUpdate ITAV with optional transition certificates. |
|
Push an ITAV onto a stack, creating the stack if *`itav_sk_p` is NULL. |
Set the infoType and infoValue of an ITAV, taking ownership of both pointers. |
|
Duplicate an OSSL_CMP_MSG structure. |
|
Free an OSSL_CMP_MSG structure and its contents. |
|
|
Return the public key from the certificate template of a certificate‐request message. |
Return the PKIHeader from a CMP message. |
|
Return the PKIBody choice id of a CMP message. |
|
Send a CMP request over HTTP(S) to the server configured in |
|
Return the ASN.1 item descriptor for OSSL_CMP_MSG. |
|
Allocate an empty OSSL_CMP_MSG structure. |
|
Load a DER‐encoded CMP message from a file. |
|
Copy the context senderNonce into a CMP message recipNonce field. |
|
|
Copy the context transactionID into a CMP message header. |
Write a CMP message to a file in DER encoding. |
|
Free an OSSL_CMP_PKIHEADER structure and its contents. |
|
Return the ASN.1 item descriptor for OSSL_CMP_PKIHEADER. |
|
Allocate an empty OSSL_CMP_PKIHEADER structure. |
|
Duplicate an OSSL_CMP_PKISI structure. |
|
Free an OSSL_CMP_PKISI structure and its contents. |
|
Return the ASN.1 item descriptor for OSSL_CMP_PKISI. |
|
Allocate an empty OSSL_CMP_PKISI structure. |
|
Return the ASN.1 item descriptor for OSSL_CMP_PKISTATUS. |
|
Free a CMP server context and its resources. |
|
|
Return the embedded CMP context from a server context. |
|
Return the application custom context pointer from a server context. |
Register server‐side CMP message processing callbacks. |
|
|
Register delayed‐delivery and transaction‐cleanup callbacks on a server context. |
Allocate a CMP server context with default options. |
|
|
Enable accepting IR/CR/KUR requests with POPO raVerified. |
|
Enable accepting CMP requests without protection or with invalid protection. |
|
Enable or disable granting implicitConfirm in certRep messages. |
|
Enable sending unprotected CMP error and negative response messages. |
Process a CMP request using the callbacks registered in |
|
Allocate a PKIStatusInfo with status, optional failInfo, and statusString text. |
|
Default certificate‐confirmation callback that validates the new certificate chain. |
|
Execute a CMP General Message (genm) transaction and return response ITAVs. |
|
Execute a CMP Revocation Request (RR) transaction using context fields. |
|
Execute a CMP certificate request transaction (IR/CR/KUR/P10CR). |
|
Request CA certificates from the CMP server via genm/genp and verify the response. |
|
Request a root CA key update via genm/genp and verify the response. |
|
Flush pending CMP log output and release the default CMP logging channel. |
|
Open the default CMP logging channel (stderr) if not already open. |
|
Print the OpenSSL error queue via a CMP logging callback. |
|
Format a CMP log record (component, location, severity, message) onto a BIO. |
|
Format a PKIStatusInfo structure into a human‐readable string. |
|
Start or continue a deferred CMP certificate request (pollReq flow). |
|
Validate that |
|
Verify protection and header fields of an incoming CMP message. |
|
Duplicate an OSSL_CRMF_CERTID structure. |
|
Free an OSSL_CRMF_CERTID structure and its contents. |
|
Create an OSSL_CRMF_CERTID from an issuer name and serial number. |
|
Return the issuer name from a CRMF CertId. |
|
|
Return the serial number from a CRMF CertId. |
Return the ASN.1 item descriptor for OSSL_CRMF_CERTID. |
|
Allocate an empty OSSL_CRMF_CERTID structure. |
|
Populate selected fields of a CRMF CertTemplate. |
|
Free an OSSL_CRMF_CERTTEMPLATE structure and its contents. |
|
|
Return the X.509 extensions from a CRMF CertTemplate. |
|
Return the issuer name from a CRMF CertTemplate. |
|
Return the public key from a CRMF CertTemplate. |
|
Return the serial number from a CRMF CertTemplate. |
|
Return the subject name from a CRMF CertTemplate. |
Return the ASN.1 item descriptor for OSSL_CRMF_CERTTEMPLATE. |
|
Allocate an empty OSSL_CRMF_CERTTEMPLATE structure. |
|
Free an OSSL_CRMF_ENCRYPTEDVALUE structure and its contents. |
|
|
Decrypt the certificate held in an EncryptedValue. |
Return the ASN.1 item descriptor for OSSL_CRMF_ENCRYPTEDVALUE. |
|
Allocate an empty OSSL_CRMF_ENCRYPTEDVALUE structure. |
|
Free an OSSL_CRMF_MSGS stack and its contents. |
|
Return the ASN.1 item descriptor for OSSL_CRMF_MSGS. |
|
Allocate an empty OSSL_CRMF_MSGS stack. |
|
Verify proof‐of‐possession on a CRMF CertReqMessages sequence. |
|
|
Append a SinglePubInfo to a PKIPublicationInfo pubInfos list. |
Create and set the Proof‐of‐Possession field in a CRMF CertReqMsg. |
|
Duplicate an OSSL_CRMF_MSG structure. |
|
Free an OSSL_CRMF_MSG structure and its contents. |
|
|
Return the authenticator regCtrl from a CRMF CertReqMsg, if present. |
|
Return the oldCertID regCtrl from a CRMF CertReqMsg, if present. |
|
Return the pkiPublicationInfo regCtrl from a CRMF CertReqMsg, if present. |
|
Return the protocolEncrKey regCtrl from a CRMF CertReqMsg, if present. |
|
Return the regToken regCtrl from a CRMF CertReqMsg, if present. |
|
Return the first certReq regInfo from a CRMF CertReqMsg, if present. |
|
Return the first utf8Pairs regInfo from a CRMF CertReqMsg, if present. |
Return the certTemplate from a CRMF CertReqMsg. |
|
Return the certReqId from a CRMF CertReqMsg. |
|
Return the ASN.1 item descriptor for OSSL_CRMF_MSG. |
|
Allocate an empty OSSL_CRMF_MSG structure. |
|
Append an X.509 extension to the certTemplate of a CRMF CertReqMsg. |
|
|
Set publication method and optional location in a SinglePubInfo. |
Set X.509 extensions in the certTemplate of a CRMF CertReqMsg. |
|
Set optional validity times in the certTemplate of a CRMF CertReqMsg. |
|
|
Set the authenticator regCtrl in a CRMF CertReqMsg. |
|
Set the oldCertID regCtrl in a CRMF CertReqMsg. |
|
Set the pkiPublicationInfo regCtrl in a CRMF CertReqMsg. |
|
Set the protocolEncrKey regCtrl in a CRMF CertReqMsg. |
|
Set the regToken regCtrl in a CRMF CertReqMsg. |
|
Add a copy of a certReq regInfo value to a CRMF CertReqMsg. |
|
Set the utf8Pairs regInfo in a CRMF CertReqMsg. |
|
Set the publication action in a PKIPublicationInfo. |
Set the certReqId field in a CRMF CertReqMsg. |
|
Free an OSSL_CRMF_PBMPARAMETER structure and its contents. |
|
Return the ASN.1 item descriptor for OSSL_CRMF_PBMPARAMETER. |
|
Allocate an empty OSSL_CRMF_PBMPARAMETER structure. |
|
Free an OSSL_CRMF_PKIPUBLICATIONINFO structure and its contents. |
|
Return the ASN.1 item descriptor for OSSL_CRMF_PKIPUBLICATIONINFO. |
|
Allocate an empty OSSL_CRMF_PKIPUBLICATIONINFO structure. |
|
Free an OSSL_CRMF_SINGLEPUBINFO structure and its contents. |
|
Return the ASN.1 item descriptor for OSSL_CRMF_SINGLEPUBINFO. |
|
Allocate an empty OSSL_CRMF_SINGLEPUBINFO structure. |
|
Compute a Password‐Based MAC (PBM) for CRMF POPO using the given parameters, message, and secret. |
|
Create a PBMParameter for password‐based MAC POPO (RFC 4211 section 4.4). |
|
Attach a fetched decoder implementation to a decoder context. |
|
Add decoder implementations that feed already‐attached decoders (build chains). |
|
Free a decoder context and invoke any registered cleanup callback. |
|
Return the cleanup callback currently set on a decoder context. |
|
Return the construct callback currently set on a decoder context. |
|
|
Return the construct‐data pointer currently set on a decoder context. |
|
Return how many decoder implementations are currently attached to |
Create an empty decoder context for chaining and running decoders. |
|
|
Create a decoder context preconfigured to decode an EVP_PKEY. |
Register a cleanup callback invoked from OSSL_DECODER_CTX_free(). |
|
Register a callback invoked when a decoded object is constructed. |
|
|
Attach opaque application data passed to the construct and cleanup callbacks. |
|
Set the expected ASN.1 structure name for the encoded input. |
|
Set the starting input type that limits which decoder chains are considered. |
Apply an OSSL_PARAM array to all decoders currently attached to |
|
Supply a passphrase for decrypting encoded private‐key input. |
|
|
Set an OSSL_PASSPHRASE_CALLBACK used to prompt for a passphrase. |
|
Set a UI method for passphrase prompting on a decoder context. |
|
Set a legacy PEM password callback used to prompt for a passphrase. |
Set the key/component selection mask for decoding (OSSL_KEYMGMT_SELECT_*). |
|
|
Return the decoder implementation associated with a decoder instance. |
|
Return the provider decoder context for a decoder instance. |
|
Return the input‐structure name configured for a decoder instance. |
|
Return the input‐type name configured for a decoder instance. |
Invoke a callback for every decoder provided by activated providers. |
|
Export a reference from a decoder instance via a provider export callback. |
|
Fetch a decoder implementation from providers by algorithm name. |
|
Decrement the reference count of a fetched decoder and free it at zero. |
|
Run decoding from a BIO into objects handled by the context's construct callback. |
|
Run decoding from a memory buffer, advancing *`pdata` past consumed bytes. |
|
Run decoding from a FILE stream (same as OSSL_DECODER_from_bio() with a file BIO). |
|
Return a human‐readable description of a fetched decoder. |
|
Return the primary algorithm name used to fetch a decoder. |
|
Return the property definition string of a fetched decoder. |
|
Return the provider that supplies a fetched decoder. |
|
Retrieve parameters from a decoder into an OSSL_PARAM array. |
|
Return descriptors for parameters that can be retrieved from a decoder. |
|
Test whether a decoder implements the algorithm identified by |
|
Invoke a callback for every name/synonym associated with a decoder. |
|
|
Return descriptors for parameters that can be set on a decoder context. |
Increment the reference count of a fetched decoder. |
|
Return the short name of a built‐in elliptic curve given its NID. |
|
Add an encoder implementation to an encoder context's chain. |
|
Add encoder implementations that continue an already‐attached encoder chain. |
|
Free an encoder context and invoke any registered cleanup callback. |
|
|
Return how many encoder implementations are currently attached to |
Create an empty encoder context for chaining and running encoders. |
|
|
Create an encoder context preconfigured to encode an EVP_PKEY. |
Select the cipher used to encrypt encoded private‐key material. |
|
Register a cleanup callback invoked from OSSL_ENCODER_CTX_free(). |
|
Register the constructor that builds the provider‐side object to encode. |
|
|
Associate opaque construct data passed to the encoder construct callback. |
|
Set the desired output structure name for the encoder chain (for example "pkcs8"). |
|
Set the ending output type that a complete encoder chain must produce. |
Apply an OSSL_PARAM array to an encoder context. |
|
Set a passphrase used when the encoder encrypts private‐key output. |
|
|
Set an OSSL_PASSPHRASE_CALLBACK used to prompt for a passphrase. |
|
Set a UI method for passphrase prompting on an encoder context. |
|
Set a legacy PEM password callback used to prompt for a passphrase. |
Set the key/component selection mask for encoding (OSSL_KEYMGMT_SELECT_*). |
|
|
Return the OSSL_ENCODER implementation bound to an encoder instance. |
|
Return the provider encoder context for an encoder instance. |
|
Return the output‐structure name for an encoder instance (for example "pkcs8"). |
|
Return the output type name for an encoder instance (for example "DER" or "PEM"). |
Invoke a callback for every encoder provided by activated providers. |
|
Fetch an encoder implementation from providers by algorithm name. |
|
Decrement the reference count of a fetched encoder and free it at zero. |
|
Return a human‐readable description of an encoder implementation. |
|
Return the primary algorithm name used to fetch an encoder. |
|
Return the property definition string of a fetched encoder. |
|
Return the provider that supplies a fetched encoder. |
|
Retrieve parameters from an encoder into an OSSL_PARAM array. |
|
Return descriptors for parameters that can be retrieved from an encoder. |
|
Test whether an encoder implements the algorithm identified by |
|
Invoke a callback for every name/synonym associated with an encoder. |
|
|
Return the OSSL_PARAM descriptors that may be set on an encoder context. |
Run encoding for a context and write the result to a BIO. |
|
Run encoding for a context and write the result into a memory buffer. |
|
Run encoding for a context and write the result to a FILE stream. |
|
Increment the reference count of a fetched encoder. |
|
Free a saved error‐state object and its duplicated auxiliary data. |
|
Allocate an empty saved error‐state object. |
|
Append errors saved in |
|
Copy the current thread's error queue into |
|
|
Move errors above the most recent mark from the thread queue into |
Verify that |
|
|
Build an ESS SigningCertificate attribute from a signer cert and optional chain. |
|
Build an ESS SigningCertificateV2 attribute using digest |
Free an HPKE context and clear associated secrets. |
|
Return the AEAD sequence number that will be used on the next seal/open call. |
|
Create an HPKE context for the given mode, suite, and sender/receiver role. |
|
Set the sender authentication private key for AUTH / PSKAUTH modes. |
|
Set the sender authentication public key for AUTH / PSKAUTH modes. |
|
Override the sender's ephemeral IKM used inside OSSL_HPKE_encap() (deterministic). |
|
Set the pre‐shared key and PSK identifier for PSK / PSKAUTH modes. |
|
Set the AEAD sequence number used on the next seal/open call (receivers only). |
|
Decapsulate a sender's encapsulated key and derive the shared HPKE secrets. |
|
Encapsulate to a recipient public key and derive sender HPKE secrets. |
|
Derive an exporter secret from an established HPKE context (after encap/decap). |
|
Return the ciphertext size needed to seal a plaintext of length |
|
Produce GREASE‐like random encap and ciphertext buffers sized for an HPKE suite. |
|
|
Return the encapsulated public‐key size produced by OSSL_HPKE_encap() for |
|
Return the recommended IKM length for deterministic key generation with |
Generate an HPKE recipient key pair for |
|
Decrypt ciphertext with AEAD using secrets derived by a prior OSSL_HPKE_decap(). |
|
Encrypt plaintext with AEAD using secrets derived by a prior OSSL_HPKE_encap(). |
|
Parse a comma‐separated "kem,kdf,aead" string into an OSSL_HPKE_SUITE. |
|
Test whether the local build supports the given HPKE suite. |
|
|
Append an HTTP request header name/value pair to an HTTP request context. |
Exchange the prepared HTTP request and response, retrying non‐blocking I/O until done or timeout. |
|
Free an HTTP request context and its owned BIO/state. |
|
|
Return the internal memory BIO that accumulates the HTTP request headers for |
|
Return the number of response body bytes accumulated so far. |
Continue a non‐blocking HTTP request/response exchange on |
|
|
Exchange an HTTP request non‐blockingly and decode the response body as ASN.1. |
Allocate a low‐level HTTP request context bound to write and read BIOs. |
|
|
Finalize the request by attaching an ASN.1 DER body and Content‐Type/Length headers. |
|
Configure response Content‐Type, ASN.1, timeout, and keep‐alive expectations on |
|
Limit how many HTTP response header lines |
|
Cap the maximum HTTP response body length accepted by |
|
Set the first HTTP request line (method and request‐target) on |
Choose an HTTP(S) proxy string, applying no_proxy exclusions and environment defaults. |
|
Close the HTTP connection and free the request context. |
|
Perform the HTTP exchange and return a BIO of the response body. |
|
Perform an HTTP GET and return a memory BIO holding the response body. |
|
Test whether an HTTP request context still has a keep‐alive connection. |
|
Open an HTTP (or HTTPS) connection and allocate a request context. |
|
Parse an http or https URL into allocated component strings. |
|
Perform an HTTP CONNECT through a proxy on an already‐connected BIO. |
|
Configure the HTTP request path, headers, body, and response expectations on |
|
Open (or reuse), send one HTTP request, receive the response, and optionally keep the connection. |
|
Free a library context and its associated provider/algorithm state. |
|
|
Return the process‐wide global default OSSL_LIB_CTX (not thread‐local). |
Load providers and configuration directives from |
|
Allocate a new OpenSSL library context (provider / property scope). |
|
Create a child library context mirroring providers from a provider's parent context. |
|
|
Allocate an OSSL_LIB_CTX wired to core BIO upcalls from a provider dispatch table. |
Set the thread‐local default OSSL_LIB_CTX used when NULL is passed for libctx. |
|
Free an OSSL_PARAM builder allocated by OSSL_PARAM_BLD_new(). |
|
Allocate an empty OSSL_PARAM builder. |
|
Append a BIGNUM parameter by reference (must remain valid until OSSL_PARAM_BLD_to_param()). |
|
|
Append a BIGNUM parameter padded to exactly |
Append a double‐precision floating‐point parameter to a builder. |
|
Append a signed int parameter to a builder (stored by value). |
|
Append a signed 32‐bit integer parameter to a builder. |
|
Append a signed 64‐bit integer parameter to a builder. |
|
Append a signed long parameter to a builder (stored by value). |
|
|
Append an octet‐string pointer parameter that remains referenced until OSSL_PARAM_free(). |
|
Append an octet‐string parameter by reference until OSSL_PARAM_BLD_to_param(). |
|
Append a size_t parameter to a builder (stored by value). |
|
Append a time_t parameter to a builder (stored by value). |
Append an unsigned int parameter to a builder (stored by value). |
|
Append an unsigned 32‐bit integer parameter to a builder. |
|
Append an unsigned 64‐bit integer parameter to a builder. |
|
Append an unsigned long parameter to a builder. |
|
|
Append a UTF‐8 string pointer parameter that remains referenced until OSSL_PARAM_free(). |
|
Append a UTF‐8 string parameter by reference until OSSL_PARAM_BLD_to_param(). |
Convert a built‐up parameter builder into a newly allocated OSSL_PARAM array. |
|
Allocate and fill an OSSL_PARAM from a textual key/value using a param definition list. |
|
Construct an OSSL_PARAM describing an arbitrary‐precision integer in |
|
Construct an OSSL_PARAM describing a double located at |
|
Construct the terminating OSSL_PARAM sentinel for a parameter array. |
|
Construct an OSSL_PARAM that locates a signed int value. |
|
Construct an OSSL_PARAM describing a signed 32‐bit integer buffer. |
|
Construct an OSSL_PARAM describing a signed 64‐bit integer buffer. |
|
Construct an OSSL_PARAM that locates a signed long int value. |
|
Construct an OSSL_PARAM that references an existing octet buffer via pointer. |
|
|
Construct an OSSL_PARAM describing an octet‐string buffer. |
Construct an OSSL_PARAM that locates a size_t value. |
|
Construct an OSSL_PARAM describing a time_t integer buffer. |
|
Construct an OSSL_PARAM that locates an unsigned int value. |
|
Construct an OSSL_PARAM describing an unsigned 32‐bit integer buffer. |
|
Construct an OSSL_PARAM describing an unsigned 64‐bit integer at |
|
Construct an OSSL_PARAM that locates an unsigned long value. |
|
Construct an OSSL_PARAM describing a pointer to a UTF‐8 string buffer. |
|
|
Construct an OSSL_PARAM describing a UTF‐8 string buffer. |
Deep‐copy an OSSL_PARAM array, including owned string/octet buffers. |
|
Free an OSSL_PARAM array allocated by OSSL_PARAM_dup() or OSSL_PARAM_merge(). |
|
Decode an unsigned integer OSSL_PARAM into a newly allocated BIGNUM. |
|
Read a floating‐point value from an OSSL_PARAM into |
|
Read an integer parameter value from |
|
Read a signed 32‐bit integer from an OSSL_PARAM. |
|
Read a signed 64‐bit integer from an OSSL_PARAM. |
|
Read a long integer parameter value from |
|
Return a pointer to the octet data referenced by an OSSL_PARAM_OCTET_PTR parameter. |
|
Copy an OSSL_PARAM octet‐string value into a caller buffer. |
|
|
Return a pointer to the octet‐string contents of an OSSL_PARAM without copying. |
Read an OSSL_PARAM value as a size_t. |
|
Read a time_t value from an integer OSSL_PARAM. |
|
Read an unsigned int parameter value from |
|
Read an unsigned 32‐bit integer from an OSSL_PARAM. |
|
Read an OSSL_PARAM value as a uint64_t (with allowed integer type coercion). |
|
Read an unsigned long integer from an OSSL_PARAM. |
|
Read a UTF‐8 pointer parameter without copying the string. |
|
Copy a UTF‐8 string OSSL_PARAM into a caller‐provided or allocated buffer. |
|
|
Return a pointer to the UTF‐8 contents of an OSSL_PARAM without copying. |
Find the first OSSL_PARAM in |
|
Find the first OSSL_PARAM in a const array whose key matches |
|
Merge two OSSL_PARAM arrays, with |
|
Test whether an OSSL_PARAM was written (modified) by a set/get operation. |
|
Encode a BIGNUM into an unsigned‐integer OSSL_PARAM buffer. |
|
Clear the modified flag on every element of an OSSL_PARAM array. |
|
Write a double into the storage located by |
|
Store a signed int into an OSSL_PARAM integer buffer. |
|
Store an int32_t value into an integer OSSL_PARAM. |
|
Store an int64_t into an OSSL_PARAM integer buffer. |
|
Write |
|
Set an OSSL_PARAM that references an existing octet buffer without copying. |
|
Copy |
|
Store a size_t value into an integer OSSL_PARAM. |
|
Store a time_t into an OSSL_PARAM integer buffer. |
|
Write an unsigned int into the storage located by |
|
Store a uint32_t into an OSSL_PARAM integer buffer. |
|
Store a uint64_t into an OSSL_PARAM integer buffer. |
|
Write |
|
Set a UTF‐8 pointer parameter to refer to |
|
Write a NUL‐terminated UTF‐8 string into an OSSL_PARAM destination. |
|
Register a built‐in provider init function under |
|
Report whether a named provider is available in a library context. |
|
Invoke a callback for every provider available in a library context. |
|
|
Return the default filesystem search path for loading providers (borrowed). |
Return the provider's dispatch table of core functions (borrowed). |
|
Return the registered name of a provider (borrowed). |
|
Return the provider's opaque provider‐context pointer (borrowed). |
|
Query a named provider capability via a callback. |
|
Fetch provider parameters into a caller‐supplied OSSL_PARAM array. |
|
Return the gettable parameter descriptors for a provider (borrowed). |
|
Load a provider by name into a library context. |
|
Load a provider by name with an optional parameter array. |
|
Query algorithms a provider implements for an operation. |
|
Run the provider's self‐test routine, if implemented. |
|
|
Set the default filesystem search path used when loading providers. |
Try to load a provider by name, optionally keeping fallback providers. |
|
Try to load a provider with parameters, optionally keeping fallback providers. |
|
Unload a provider, running its teardown and releasing its resources. |
|
Release algorithm results previously returned by OSSL_PROVIDER_query_operation(). |
|
Return the SSL_METHOD for non‐thread‐assisted QUIC client use. |
|
Return the SSL_METHOD for thread‐assisted QUIC client use. |
|
Free an OSSL_SELF_TEST object allocated by OSSL_SELF_TEST_new(). |
|
Retrieve the self‐test callback previously set on a library context. |
|
Allocate an OSSL_SELF_TEST handle that invokes |
|
Signal the start of a self‐test block (callback phase "Start"). |
|
Optionally corrupt the first byte of |
|
Signal the end of a self‐test block with pass/fail (callback phase "Pass" or "Fail"). |
|
Register a callback invoked during provider self‐test operations. |
|
Free a STACK_OF(X509) and the certificates it owns (sk_X509_pop_free). |
|
Free an OSSL_STORE_INFO and the object it owns. |
|
Return the X.509 certificate from a store object (borrowed). |
|
Return the CRL from a store object (borrowed). |
|
Return the name string from an OSSL_STORE_INFO_NAME object (borrowed). |
|
|
Return the optional description for an OSSL_STORE_INFO_NAME (borrowed). |
Return the key‐parameter EVP_PKEY from a store object (borrowed). |
|
Return the key EVP_PKEY from a store object (borrowed). |
|
Return the public‐key EVP_PKEY from a store object (borrowed). |
|
Return the typed object pointer from a store info when |
|
Return a new reference to the X.509 certificate from a store object. |
|
Return a new reference to the CRL from a store object. |
|
Return a copy of the name string from an OSSL_STORE_INFO_NAME object. |
|
|
Return a copy of the optional description for an OSSL_STORE_INFO_NAME. |
Return a new reference to the key‐parameter EVP_PKEY from a store object. |
|
Return a new reference to the key EVP_PKEY from a store object. |
|
Return a new reference to the public‐key EVP_PKEY from a store object. |
|
Return the OSSL_STORE_INFO_* type code of a store object. |
|
Create an OSSL_STORE_INFO that takes ownership of |
|
Create an OSSL_STORE_INFO holding an X.509 certificate (takes ownership of |
|
Create an OSSL_STORE_INFO holding a CRL (takes ownership of |
|
Create an OSSL_STORE_INFO_NAME holding |
|
Create an OSSL_STORE_INFO holding key parameters (takes ownership of |
|
Create an OSSL_STORE_INFO holding a key (takes ownership of |
|
Create an OSSL_STORE_INFO holding a public key (takes ownership of |
|
|
Attach an optional description string to an OSSL_STORE_INFO_NAME. |
Return a static string name for an OSSL_STORE_INFO_* type code. |
|
|
Invoke a callback for every store loader provided in a library context. |
Fetch a provider‐based OSSL_STORE loader for a URI scheme. |
|
Release a reference to a store loader. |
|
|
Return a human‐readable description of a fetched store loader (borrowed). |
|
Return the ENGINE associated with a deprecated store loader (borrowed). |
|
Return the property definition string of a fetched store loader (borrowed). |
Return the provider that implements a fetched store loader (borrowed). |
|
|
Return the URI scheme registered for a deprecated store loader (borrowed). |
Test whether a store loader implements the given URI scheme name. |
|
|
Invoke a callback for every scheme name of a store loader. |
|
Allocate a deprecated ENGINE‐based store loader for |
|
Set the attach callback on a deprecated ENGINE‐based store loader. |
|
Set the close callback on a deprecated ENGINE‐based store loader. |
|
Set the ctrl callback on a deprecated ENGINE‐based store loader. |
|
Set the eof callback on a deprecated ENGINE‐based store loader. |
|
Set the error callback on a deprecated ENGINE‐based store loader. |
|
Set the expect callback on a deprecated ENGINE‐based store loader. |
|
Set the find callback on a deprecated ENGINE‐based store loader. |
|
Set the load callback on a deprecated ENGINE‐based store loader. |
|
Set the open callback on a deprecated ENGINE‐based store loader. |
|
Set the open_ex callback on a deprecated ENGINE‐based store loader. |
Increment the reference count on a fetched store loader. |
|
Build a search criterion matching an alias string. |
|
|
Build a search criterion matching an issuer name and serial number. |
|
Build a search criterion matching a key fingerprint. |
Build a search criterion matching a subject (certs) or issuer (CRLs) name. |
|
Free an OSSL_STORE_SEARCH criterion (does not free caller‐owned inputs). |
|
Return the fingerprint or alias byte string from a search criterion (borrowed). |
|
Return the digest method from a key‐fingerprint search criterion (borrowed). |
|
Return the X509_NAME from a by‐name or issuer‐serial search criterion (borrowed). |
|
Return the serial number from an issuer‐serial search criterion (borrowed). |
|
Return the alias string from a search criterion (borrowed). |
|
Return the OSSL_STORE_SEARCH_BY_* type of a search criterion. |
|
Open an OSSL_STORE channel that reads from a BIO using a named scheme. |
|
Close an OSSL_STORE channel and free its context. |
|
|
Send a loader‐specific or common control command to an open store (deprecated). |
Delete the object identified by |
|
|
Invoke a callback for every registered store loader (deprecated). |
Test whether an open store has no more objects to load. |
|
Test whether the last store operation recorded an error on |
|
Restrict an open store to a single expected OSSL_STORE_INFO_* type. |
|
Attach a search criterion to an open store before loading. |
|
Load the next object from an open OSSL_STORE channel. |
|
Open an OSSL_STORE channel for the given URI. |
|
Open an OSSL_STORE channel with an explicit library context and parameters. |
|
|
Register a deprecated ENGINE‐based store loader; prefer OSSL_STORE_LOADER_fetch(). |
Test whether the loader for an open store supports a search type. |
|
|
Unregister a deprecated ENGINE‐based store loader by URI scheme. |
|
va_list form of OSSL_STORE_ctrl() (deprecated). |
Return the built‐in default TLSv1.2 (and earlier) cipher‐list string. |
|
Return the built‐in default TLSv1.3 ciphersuite list string. |
|
Return the current maximum thread‐pool size configured for a library context. |
|
Return bitmask of thread features supported by this OpenSSL build. |
|
Parse |
|
Exported provider entry point; each provider module must define this symbol. |
|
Set the maximum number of threads the OpenSSL thread pool may use for |
|
Sleep the calling thread for approximately |
|
Begin a locked trace output group for |
|
Test whether a trace channel is currently attached for |
|
End a locked trace output group and release the trace BIO channel. |
|
Map an OSSL_TRACE_CATEGORY_* number to its canonical name string. |
|
Map a trace category name to its OSSL_TRACE_CATEGORY_* number. |
|
Enable tracing for |
|
Attach a BIO as the simple trace channel for |
|
Set the text printed before each trace group for |
|
Set the text printed after each trace group for |
|
Write |
|
Compare two otherName values by type OID and typed value. |
|
Free an OTHERNAME structure and its contents. |
|
Return the ASN.1 item descriptor for OTHERNAME. |
|
Allocate a new otherName GeneralName payload. |
|
Return a descriptive string about the running OpenSSL build. |
|
Return the packed OpenSSL version number (OPENSSL_VERSION_NUMBER). |
|
Free a PKCS#5 PBES2 parameter structure and its contents. |
|
Return the ASN.1 item descriptor for PBE2PARAM. |
|
Allocate an empty PKCS#5 PBES2 parameter structure. |
|
Free a PKCS#5 PBES1 parameter structure (salt and iteration count) and its contents. |
|
Return the ASN.1 item descriptor for PBEPARAM. |
|
Allocate an empty PKCS#5 PBES1 parameter structure (salt and iteration count). |
|
Free a PKCS#5 PBKDF2 parameter structure and its contents. |
|
Return the ASN.1 item descriptor for PBKDF2PARAM. |
|
Allocate an empty PKCS#5 PBKDF2 parameter structure. |
|
Read a named PEM object from a FILE and decode it with |
|
Read a named PEM object from a BIO and decode it with |
|
Encode an ASN.1 object with |
|
Encode an ASN.1 object with |
|
Finalize a PEM signing operation and write the signature. |
|
Initialize an EVP_MD_CTX for signing with digest |
|
Absorb more message bytes into a PEM signing digest context. |
|
Read certificates, CRLs, and keys from a PEM FILE into X509_INFO objects. |
|
Read successive PEM objects from a BIO into a stack of X509_INFO. |
|
|
Read successive PEM X509_INFO objects (cert, CRL, and/or key) from a BIO with an explicit library context. |
Read certificates, CRLs, and keys from a PEM FILE with a library context. |
|
Write the certificate, CRL, and/or private key from an X509_INFO as PEM. |
|
Read a named PEM object from a BIO, decrypting if needed, and return its DER bytes. |
|
Read a named PEM object from a BIO into secure memory, decrypting if needed. |
|
Default pem_password_cb that prompts on the terminal (or copies |
|
Append a DEK‐Info encapsulation header (cipher name and hex IV) to a PEM header. |
|
Decrypt PEM payload bytes in place using cipher info and a password callback. |
|
Parse a PEM encapsulation header for cipher and IV (legacy PEM encryption). |
|
Append a Proc‐Type encapsulation header line to a PEM header buffer. |
|
Read one PEM object from a FILE, returning name, header, and decoded data. |
|
|
Read Diffie‐Hellman domain parameters from a PEM‐encoded FILE (deprecated). |
|
Read a traditional DSA private key from a PEM‐encoded FILE (deprecated). |
|
Read a DSA SubjectPublicKeyInfo from a PEM‐encoded FILE (deprecated). |
|
Read DSA domain parameters from a PEM‐encoded FILE (deprecated). |
|
Read EC domain parameters (ECPKParameters) from a PEM‐encoded FILE (deprecated). |
|
Read an EC private key from a PEM‐encoded FILE (deprecated). |
|
Read an EC SubjectPublicKeyInfo from a PEM‐encoded FILE (deprecated). |
Read a Netscape certificate sequence from a PEM‐encoded FILE stream. |
|
Read a PKCS#7 structure from a PEM‐encoded FILE stream. |
|
Read a PKCS#8 encrypted private‐key envelope (X509_SIG) from a PEM‐encoded FILE. |
|
|
Read a PKCS#8 PrivateKeyInfo from a PEM‐encoded FILE stream. |
Read a SubjectPublicKeyInfo public key from a PEM‐encoded FILE. |
|
Read a SubjectPublicKeyInfo public key from a PEM FILE with a library context. |
|
Read a private key from a PEM‐encoded FILE (traditional or PKCS#8). |
|
Read a private key from a PEM‐encoded FILE with an explicit library context. |
|
|
Read a traditional RSA private key from a PEM‐encoded FILE (deprecated). |
|
Read a traditional PKCS#1 RSA public key from a PEM‐encoded FILE (deprecated). |
|
Read an RSA SubjectPublicKeyInfo from a PEM‐encoded FILE (deprecated). |
Read an SSL_SESSION from a PEM‐encoded FILE stream. |
|
Read an X.509 certificate from a PEM‐encoded FILE stream. |
|
Read a trusted X.509 certificate (with aux trust info) from a PEM FILE. |
|
Read an X.509 CRL from a PEM‐encoded FILE stream. |
|
Read an X.509 SubjectPublicKeyInfo from a PEM‐encoded FILE stream. |
|
Read a certificate request from a PEM‐encoded FILE stream. |
|
Read one PEM object from a BIO, returning name, header, and decoded data. |
|
|
Read Diffie‐Hellman domain parameters from a PEM‐encoded BIO (deprecated). |
|
Read a traditional DSA private key from a PEM‐encoded BIO (deprecated). |
|
Read a DSA SubjectPublicKeyInfo from a PEM‐encoded BIO (deprecated). |
|
Read DSA domain parameters from a PEM‐encoded BIO (deprecated). |
|
Read EC domain parameters (ECPKParameters) from a PEM‐encoded BIO (deprecated). |
|
Read an EC private key from a PEM‐encoded BIO (deprecated). |
|
Read an EC SubjectPublicKeyInfo from a PEM‐encoded BIO (deprecated). |
|
Read a Netscape certificate sequence from a PEM‐encoded BIO. |
Read a PKCS#7 structure from a PEM‐encoded BIO. |
|
Read a PKCS#8 encrypted private‐key envelope (X509_SIG) from a PEM‐encoded BIO. |
|
|
Read a PKCS#8 PrivateKeyInfo from a PEM‐encoded BIO. |
Read a SubjectPublicKeyInfo public key from a PEM‐encoded BIO. |
|
Read a SubjectPublicKeyInfo public key from a PEM BIO with a library context. |
|
Read algorithm parameters (e.g. DH/DSA) from PEM into an EVP_PKEY. |
|
Read algorithm parameters (e.g. DH/DSA) from PEM into an EVP_PKEY with a library context. |
|
Read a private key from a PEM‐encoded BIO (traditional or PKCS#8). |
|
Read a private key from a PEM‐encoded BIO with an explicit library context. |
|
|
Read a traditional RSA private key from a PEM‐encoded BIO (deprecated). |
|
Read a traditional PKCS#1 RSA public key from a PEM‐encoded BIO (deprecated). |
|
Read an RSA SubjectPublicKeyInfo from a PEM‐encoded BIO (deprecated). |
Read an SSL_SESSION from a PEM‐encoded BIO. |
|
Read an X.509 certificate from a PEM‐encoded BIO. |
|
Read a trusted X.509 certificate (with aux trust info) from a PEM BIO. |
|
Read an X.509 CRL from a PEM‐encoded BIO. |
|
Read an X.509 SubjectPublicKeyInfo from a PEM‐encoded BIO. |
|
Read a certificate request from a PEM‐encoded BIO. |
|
Read one PEM object from a BIO with controllable decoding behaviour. |
|
Write a PEM object (header, optional headers, and base64 body) to a FILE. |
|
|
Write Diffie‐Hellman domain parameters to a FILE in PEM form (deprecated). |
|
Write Diffie‐Hellman X9.42 domain parameters to a FILE in PEM form (deprecated). |
|
Write a traditional DSA private key to a FILE in PEM form (deprecated). |
|
Write a DSA SubjectPublicKeyInfo to a FILE in PEM form (deprecated). |
|
Write DSA domain parameters to a FILE in PEM form (deprecated). |
|
Write EC domain parameters (ECPKParameters) to a FILE in PEM form (deprecated). |
|
Write an EC private key to a FILE in PEM form (deprecated). |
|
Write an EC SubjectPublicKeyInfo to a FILE in PEM form (deprecated). |
|
Write a Netscape certificate sequence to a FILE stream in PEM form. |
Write a PKCS#7 structure to a FILE stream in PEM form. |
|
Write a PKCS#8 encrypted private‐key envelope (X509_SIG) to a FILE in PEM form. |
|
Write a private key as PEM PKCS#8 EncryptedPrivateKeyInfo (PKCS#5 v2.0). |
|
Write a private key as PEM PKCS#8 using a PKCS#5 v1.5 / PKCS#12 PBE NID. |
|
|
Write a PKCS#8 PrivateKeyInfo to a FILE stream in PEM form. |
Write a SubjectPublicKeyInfo public key to a FILE in PEM form. |
|
Write a SubjectPublicKeyInfo public key to a FILE with a library context. |
|
Write a private key to a FILE as PEM, preferring PKCS#8 EncryptedPrivateKeyInfo. |
|
Write a private key to a FILE as PEM with an explicit library context. |
|
|
Write a traditional RSA private key to a FILE in PEM form (deprecated). |
|
Write a traditional PKCS#1 RSA public key to a FILE in PEM form (deprecated). |
|
Write an RSA SubjectPublicKeyInfo to a FILE in PEM form (deprecated). |
Write an SSL_SESSION to a FILE stream in PEM form. |
|
Write an X.509 certificate to a FILE stream in PEM form. |
|
Write a trusted X.509 certificate (with aux trust info) to a FILE as PEM. |
|
Write an X.509 CRL to a FILE stream in PEM form. |
|
Write an X.509 SubjectPublicKeyInfo to a FILE stream in PEM form. |
|
Write a certificate request to a FILE stream in PEM form. |
|
Write a certificate request using the legacy "NEW CERTIFICATE REQUEST" PEM label. |
|
Write a PEM object (header, optional headers, and base64 body) to a BIO. |
|
Stream‐encode an ASN.1 value as a PEM object, optionally pulling content from |
|
Write a CMS ContentInfo as a PEM CMS message, optionally streaming content from |
|
|
Write Diffie‐Hellman domain parameters to a BIO in PEM form (deprecated). |
|
Write Diffie‐Hellman X9.42 domain parameters to a BIO in PEM form (deprecated). |
|
Write a traditional DSA private key to a BIO in PEM form (deprecated). |
|
Write a DSA SubjectPublicKeyInfo to a BIO in PEM form (deprecated). |
|
Write DSA domain parameters to a BIO in PEM form (deprecated). |
|
Write EC domain parameters (ECPKParameters) to a BIO in PEM form (deprecated). |
|
Write an EC private key to a BIO in PEM form (deprecated). |
|
Write an EC SubjectPublicKeyInfo to a BIO in PEM form (deprecated). |
|
Write a Netscape certificate sequence to a BIO in PEM form. |
Write a PKCS#7 structure to a BIO in PEM form. |
|
Write a PKCS#7 structure as PEM, streaming content from |
|
Write a PKCS#8 encrypted private‐key envelope (X509_SIG) to a BIO in PEM form. |
|
Write a private key as PEM PKCS#8 EncryptedPrivateKeyInfo (PKCS#5 v2.0). |
|
|
Write a private key as PEM PKCS#8 using a PKCS#5 v1.5 / PKCS#12 PBE NID. |
|
Write a PKCS#8 PrivateKeyInfo to a BIO in PEM form. |
Write a SubjectPublicKeyInfo public key to a BIO in PEM form. |
|
Write a SubjectPublicKeyInfo public key to a BIO with a library context. |
|
Write algorithm parameters from an EVP_PKEY to a BIO in PEM form. |
|
Write a private key to a BIO as PEM, preferring PKCS#8 EncryptedPrivateKeyInfo. |
|
Write a private key to a BIO as PEM with an explicit library context. |
|
|
Write a private key to a BIO using the legacy "traditional" PEM private‐key format. |
|
Write a traditional RSA private key to a BIO in PEM form (deprecated). |
|
Write a traditional PKCS#1 RSA public key to a BIO in PEM form (deprecated). |
|
Write an RSA SubjectPublicKeyInfo to a BIO in PEM form (deprecated). |
Write an SSL_SESSION to a BIO in PEM form. |
|
Write an X.509 certificate to a BIO in PEM form. |
|
Write a trusted X.509 certificate (with aux trust info) to a BIO as PEM. |
|
Write an X.509 CRL to a BIO in PEM form. |
|
Write an X.509 SubjectPublicKeyInfo to a BIO in PEM form. |
|
Write a certificate request to a BIO in PEM form. |
|
|
Write a certificate request using the legacy "NEW CERTIFICATE REQUEST" PEM label. |
Return the ASN.1 item descriptor for a SEQUENCE OF PKCS7 (authSafes). |
|
Free a PKCS12_BAGS structure and its contents. |
|
Return the ASN.1 item descriptor for PKCS12_BAGS. |
|
Allocate an empty PKCS12_BAGS structure. |
|
Free a PKCS12_MAC_DATA structure and its contents. |
|
Return the ASN.1 item descriptor for PKCS12_MAC_DATA. |
|
Allocate an empty PKCS12_MAC_DATA structure. |
|
Register PKCS#12 PBE algorithms (historical no‐op; algorithms are built in). |
|
Initialise a cipher context for PKCS#12 PBE encryption or decryption. |
|
Initialise a cipher context for PKCS#12 PBE encryption or decryption. |
|
Return the ASN.1 item descriptor for a SEQUENCE OF PKCS12_SAFEBAG. |
|
Create an unencrypted keyBag safeBag from PKCS#8 private key info. |
|
Create a pkcs8ShroudedKeyBag safeBag wrapping an already‐encrypted PKCS#8 key. |
|
Create a certBag safeBag containing the supplied certificate. |
|
Create a crlBag safeBag containing the supplied CRL. |
|
|
Create an encrypted pkcs8ShroudedKeyBag safeBag from PKCS#8 private key info. |
|
Create an encrypted pkcs8ShroudedKeyBag safeBag from PKCS#8 private key info. |
Create a secretBag safeBag with the supplied ASN.1 value. |
|
Free a PKCS12_SAFEBAG structure and its contents. |
|
Get a PKCS#12 safeBag attribute value by NID. |
|
Return the attribute stack attached to a safeBag without copying it. |
|
Retrieve the ASN.1 object contained within a safeBag. |
|
Get the type of the object contained within a safeBag as an OID. |
|
Return the PKCS#8 private key info from a keyBag or pkcs8ShroudedKeyBag. |
|
Return the encrypted PKCS#8 structure from a pkcs8ShroudedKeyBag safeBag. |
|
Retrieve the nested safeBags from a safeContentsBag. |
|
Return the safeBag type OID without copying it. |
|
Extract an X.509 certificate from a certBag safeBag. |
|
Extract an X.509 certificate from a certBag safeBag with a library context. |
|
Extract an X.509 CRL from a crlBag safeBag. |
|
Extract an X.509 CRL from a crlBag safeBag with a library context. |
|
Get the type of the object contained within a safeBag. |
|
Get the safeBag type as an NID. |
|
Return the ASN.1 item descriptor for PKCS12_SAFEBAG. |
|
Allocate an empty PKCS12_SAFEBAG structure. |
|
Assign a stack of X509_ATTRIBUTEs to a safeBag. |
|
Add a PKCS#12 attribute to a safeBag by NID. |
|
Add a PKCS#12 attribute to a safeBag by name. |
|
Add a Microsoft CSP Name attribute (ASCII) to a safeBag. |
|
Create a certBag safeBag and append it to a stack of safeBags. |
|
Add a PKCS#9 friendlyName attribute (ASCII) to a safeBag. |
|
Add a PKCS#9 friendlyName attribute (BMPString) to a safeBag. |
|
Add a PKCS#9 friendlyName attribute (UTF‐8) to a safeBag. |
|
Create a key safeBag and append it to a stack of safeBags. |
|
Create a key safeBag and append it to a stack of safeBags. |
|
Add a PKCS#9 localKeyID attribute to a safeBag. |
|
Pack safeBags into a PKCS#7 contentInfo and append it to a stack of safes. |
|
Pack safeBags into a PKCS#7 contentInfo and append it to a stack of safes. |
|
Create a PKCS#12 structure from a stack of PKCS#7 authSafes contentInfos. |
|
Create a PKCS#12 structure from a stack of PKCS#7 authSafes contentInfos. |
|
Create a secretBag safeBag and append it to a stack of safeBags. |
|
Create a PKCS#12 structure from a key, certificate, and optional CA stack (default library context). |
|
Create a PKCS#12 structure from a key, certificate, and optional CA stack. |
|
Create a PKCS#12 structure with an optional per‐safeBag callback. |
|
Decrypt the PKCS#8 shrouded key in a pkcs8ShroudedKeyBag safeBag. |
|
Decrypt the PKCS#8 shrouded key in a pkcs8ShroudedKeyBag safeBag. |
|
Free a PKCS12 structure and its contents. |
|
Generate the HMAC for a PKCS#12 object using configured MAC parameters. |
|
Retrieve MAC value and MAC‐parameter fields from a PKCS#12 PFX. |
|
|
Retrieve a PKCS#12 safeBag attribute by NID (deprecated; use PKCS12_SAFEBAG_get0_attr()). |
Retrieve an attribute by NID from a stack of X509_ATTRIBUTEs. |
|
Retrieve the PKCS#9 friendlyName from a safeBag as a UTF‐8 string. |
|
Create an empty PKCS#12 structure. |
|
Create an empty PKCS#12 structure with a library context. |
|
Return the ASN.1 item descriptor for PKCS12. |
|
Decrypt an ASN.1 octet string and decode the embedded object. |
|
Decrypt an ASN.1 octet string and decode the embedded object. |
|
Encode an ASN.1 object and encrypt the result. |
|
Encode an ASN.1 object and encrypt the result using a library context. |
|
Pack an ASN.1 object into a certBag or crlBag safeBag. |
|
Derive key material using the PKCS#12 key‐generation function (ASCII passphrase). |
|
Derive key material using the PKCS#12 key‐generation function (ASCII passphrase). |
|
Derive key material using the PKCS#12 key‐generation function (BMPString passphrase). |
|
Derive key material using the PKCS#12 key‐generation function (BMPString passphrase). |
|
Derive key material using the PKCS#12 key‐generation function (UTF‐8 passphrase). |
|
Derive key material using the PKCS#12 key‐generation function (UTF‐8 passphrase). |
|
Test whether a PKCS#12 PFX carries an integrity MAC. |
|
Allocate an empty PKCS12 structure. |
|
Change the password protecting a PKCS#12 structure. |
|
Encode a stack of PKCS#7 authSafes contentInfos into a PKCS#12 structure. |
|
Pack a stack of safeBags into a PKCS#7 data ContentInfo. |
|
Pack safeBags into a PKCS#7 encrypted‐data ContentInfo (default library context). |
|
Pack safeBags into a PKCS#7 encrypted‐data ContentInfo. |
|
Parse a PKCS#12 structure and extract key, certificate, and CA certificates. |
|
Encrypt or decrypt a buffer using a PKCS#12 PBE algorithm. |
|
Encrypt or decrypt a buffer using a PKCS#12 PBE algorithm. |
|
Compute and store the MAC and MAC parameters in a PKCS#12 object. |
|
Set MAC parameters in a PKCS#12 object without computing the MAC. |
|
Unpack the authSafes PKCS#7 contentInfos from a PKCS#12 structure. |
|
Unpack safeBags from a PKCS#7 data ContentInfo. |
|
Unpack safeBags from a PKCS#7 encrypted‐data ContentInfo. |
|
Verify the HMAC of a PKCS#12 object. |
|
|
Generate a PKCS #1 mask using MGF1 with digest |
Register the built‐in PKCS#5 password‐based encryption algorithms with the EVP PBE table. |
|
Derive a PBE key and IV and initialize |
|
Derive a key and IV for password‐based encryption and initialize |
|
Derive a key from a password with PBKDF2‐HMAC (RFC 2898) using |
|
Derive a key from a password with PBKDF2‐HMAC‐SHA1 (RFC 2898). |
|
Build a PKCS#5 PBES2 AlgorithmIdentifier for |
|
Build a PKCS#5 PBES2 AlgorithmIdentifier for |
|
Build a PBES2 AlgorithmIdentifier with explicit IV and library context. |
|
Build a PBES2 AlgorithmIdentifier that derives the key with scrypt. |
|
Build an AlgorithmIdentifier for PKCS#5 PBE with |
|
Set a PKCS#5 PBE algorithm OID and parameters into an existing X509_ALGOR. |
|
Set a PBES1 AlgorithmIdentifier (OID, iteration count, and salt) with a library context. |
|
Build a PKCS#5 PBE AlgorithmIdentifier using an explicit library context. |
|
Build an X509_ALGOR describing PBKDF2 key‐derivation parameters. |
|
Build an X509_ALGOR describing PBKDF2 parameters (library‐context aware). |
|
Derive a key and IV from a PKCS#5 v2 PBE AlgorithmIdentifier and initialize |
|
Derive a key and IV with PKCS#5 PBES2 and initialize |
|
Initialize |
|
Initialize |
|
Return the ASN.1 item descriptor used when signing PKCS#7 authenticated attributes. |
|
Return the ASN.1 item descriptor used when verifying PKCS#7 authenticated attributes. |
|
Free a PKCS#7 DigestedData structure and its contents. |
|
Return the ASN.1 item descriptor for PKCS7_DIGEST. |
|
Allocate an empty PKCS#7 DigestedData structure. |
|
Free a PKCS#7 EncryptedData and its contents. |
|
Return the ASN.1 item descriptor for PKCS7_ENCRYPT. |
|
Allocate an empty PKCS#7 EncryptedData. |
|
Free a PKCS#7 EncryptedContentInfo and its contents. |
|
Return the ASN.1 item descriptor for PKCS7_ENC_CONTENT. |
|
Allocate an empty PKCS#7 EncryptedContentInfo. |
|
Free a PKCS#7 EnvelopedData structure and its contents. |
|
Return the ASN.1 item descriptor for PKCS7_ENVELOPE. |
|
Allocate an empty PKCS#7 EnvelopedData structure. |
|
Digest the DER encoding of a PKCS7_ISSUER_AND_SERIAL structure. |
|
Free a PKCS#7 IssuerAndSerialNumber and its contents. |
|
Return the ASN.1 item descriptor for PKCS7_ISSUER_AND_SERIAL. |
|
Allocate an empty PKCS#7 IssuerAndSerialNumber. |
|
Free a PKCS#7 recipient info structure and its contents. |
|
Return a non‐owning pointer to a recipient info's key‐encryption algorithm. |
|
Return the ASN.1 item descriptor for PKCS7_RECIP_INFO. |
|
Allocate an empty PKCS#7 recipient info structure. |
|
Populate a PKCS#7 recipient info from a recipient certificate. |
|
Free a PKCS#7 SignedData and its contents. |
|
Return the ASN.1 item descriptor for PKCS7_SIGNED. |
|
Allocate an empty PKCS#7 SignedData. |
|
Free a PKCS#7 SignerInfo and its contents. |
|
Return non‐owning pointers to a signer info's key and digest/signature algorithms. |
|
Return the ASN.1 item descriptor for PKCS7_SIGNER_INFO. |
|
Allocate an empty PKCS#7 SignerInfo. |
|
Populate a PKCS#7 signer info with certificate, key, and digest algorithm. |
|
Compute and store the signature for a prepared PKCS#7 signer info. |
|
Free a PKCS#7 SignedAndEnvelopedData structure and its contents. |
|
Return the ASN.1 item descriptor for PKCS7_SIGN_ENVELOPE. |
|
Allocate an empty PKCS#7 SignedAndEnvelopedData structure. |
|
Add a signing‐time authenticated attribute, taking ownership of |
|
Add a PKCS#9 messageDigest authenticated attribute to a SignerInfo. |
|
Add a PKCS#9 contentType authenticated attribute to a PKCS#7 signer info. |
|
Attach an S/MIME capabilities attribute to a PKCS#7 signer info. |
|
Add an unauthenticated attribute to a PKCS#7 signer info. |
|
Add a certificate to a PKCS#7 SignedData or SignedAndEnvelopedData structure. |
|
Add a certificate revocation list to a PKCS#7 SignedData or SignedAndEnvelopedData structure. |
|
Create a recipient info from |
|
Add a recipient info structure to a PKCS#7 enveloped‐data object. |
|
Create a signer info from |
|
Add an authenticated (signed) attribute to a PKCS#7 signer info. |
|
Attach a prepared signer info to a PKCS#7 SignedData or SignedAndEnvelopedData structure. |
|
Find the certificate in |
|
Allocate nested content of type |
|
Perform a control operation on a PKCS#7 object (for example set/get detached signature). |
|
Create a BIO that decrypts/verifies PKCS#7 content for reading. |
|
Finalize PKCS#7 content processing after data has been written through |
|
Create a BIO chain for writing content into a PKCS#7 structure (digest/encrypt filters). |
|
Verify a PKCS#7 signed content digest against a signer info and certificate store. |
|
Decrypt a PKCS#7 envelopedData (or signed‐and‐enveloped) structure for a recipient. |
|
Extract the message‐digest OCTET STRING from a set of authenticatedAttributes. |
|
Deep‐copy a PKCS#7 structure (PKCS7_dup). |
|
Create a PKCS#7 envelopedData encrypting |
|
Create a PKCS#7 envelopedData encrypting |
|
Finalize a PKCS#7 structure by digesting content from a BIO and completing signatures or encryption. |
|
Free a PKCS#7 structure and its contents. |
|
Return the signer certificates used by PKCS7_verify() without duplicating them. |
|
Return an unauthenticated attribute of type |
|
Return the issuer‐and‐serial of signer info |
|
Return an ASN.1 octet string from a PKCS#7 structure. |
|
Return a signed attribute of type |
|
Return the signer infos from a signed or signed‐and‐enveloped PKCS#7 structure. |
|
Return the SMIMECapabilities attribute from a PKCS#7 signer info. |
|
Return the ASN.1 item descriptor for PKCS7. |
|
Allocate an empty PKCS#7 structure. |
|
Allocate an empty PKCS#7 structure with an explicit library context and property query. |
|
Print a PKCS#7 structure to a BIO. |
|
Set a PKCS#7 content type to an ASN.1 OTHER content value, transferring ownership of |
|
Replace the unauthenticated attributes on a PKCS#7 signer info. |
|
Set the content‐encryption cipher on an enveloped or encrypted PKCS#7 structure. |
|
Set the inner content of a SignedData / DigestedData PKCS#7 to |
|
Set the message‐digest algorithm on a DigestedData PKCS#7 structure. |
|
Replace the authenticatedAttributes of a signer info with a copy of |
|
Set the PKCS#7 content type and allocate the corresponding content structure. |
|
Create a PKCS#7 signed‐data structure using the default library context. |
|
Add a signer to an existing SignedData PKCS#7 created for incremental signing. |
|
Create a PKCS#7 signed‐data structure, with library context and property query. |
|
Verify one PKCS#7 signer info's signature against content digested from |
|
Append a simple SMIMECapabilities AlgorithmIdentifier for |
|
Prepare a PKCS#7 structure for streaming BER output and return content‐boundary pointers. |
|
Extract the TSTInfo content from a PKCS#7 time‐stamp token. |
|
Return whether a PKCS#7 content type is not one of the standard PKCS#7 content NIDs. |
|
Verify a PKCS#7 signedData structure and optionally write the content. |
|
Free a PKCS#8 PrivateKeyInfo structure and its contents. |
|
Return the ASN.1 item descriptor for PKCS8_PRIV_KEY_INFO. |
|
Allocate an empty PKCS#8 PrivateKeyInfo structure. |
|
Add a Microsoft key‐usage attribute to PKCS#8 private key info. |
|
Decrypt a PKCS#8 encrypted private key. |
|
Decrypt a PKCS#8 encrypted private key using a library context. |
|
Encrypt a PKCS#8 private key info structure (default library context). |
|
Encrypt a PKCS#8 private key info structure. |
|
Retrieve a PKCS#8 private‐key attribute by NID. |
|
Append a copy of an attribute to a PKCS#8 PrivateKeyInfo. |
|
|
Append an attribute identified by NID |
|
Append an attribute identified by |
Extract algorithm and private‐key octets from a PKCS#8 PrivateKeyInfo. |
|
Return the attribute stack embedded in a PKCS#8 PrivateKeyInfo. |
|
Set the algorithm, version, parameters, and encoded private key on a PKCS#8 PrivateKeyInfo. |
|
Encrypt PKCS#8 private key info using a pre‐built PBE algorithm. |
|
Encrypt PKCS#8 private key info using a pre‐built PBE algorithm. |
|
Free a PKEY_USAGE_PERIOD structure and its contents. |
|
Return the ASN.1 item descriptor for PKEY_USAGE_PERIOD. |
|
Allocate a new Private Key Usage Period extension value. |
|
Free a certificate policy information value and its contents. |
|
Return the ASN.1 item descriptor for POLICYINFO. |
|
Allocate an empty certificate policy information (POLICYINFO) value. |
|
Free a policy qualifier information value and its contents. |
|
Return the ASN.1 item descriptor for POLICYQUALINFO. |
|
Allocate a new certificate policy qualifier information value. |
|
Free a Policy Constraints extension value and its contents. |
|
Return the ASN.1 item descriptor for POLICY_CONSTRAINTS. |
|
Allocate a new Policy Constraints extension value. |
|
Return the ASN.1 item descriptor for POLICY_MAPPINGS. |
|
Free a policy mapping value and its contents. |
|
Return the ASN.1 item descriptor for POLICY_MAPPING. |
|
Allocate a new policy mapping value. |
|
Free a PROFESSION_INFO value and its contents. |
|
Return the additional profession info octet string from a PROFESSION_INFO. |
|
Return the naming authority from a PROFESSION_INFO. |
|
Return the profession item strings from a PROFESSION_INFO. |
|
Return the profession OID stack from a PROFESSION_INFO. |
|
|
Return the registration number from a PROFESSION_INFO without duplicating it. |
Return the ASN.1 item descriptor for PROFESSION_INFO. |
|
Allocate a new PROFESSION_INFO value. |
|
Set the additionalProfessionInfo OCTET STRING on a PROFESSION_INFO, taking ownership of |
|
Set the naming authority on a PROFESSION_INFO, taking ownership of |
|
Set the profession items (titles) on a PROFESSION_INFO, taking ownership of |
|
Set the profession OIDs on a PROFESSION_INFO, taking ownership of |
|
|
Set the registration number on a PROFESSION_INFO, taking ownership of |
Free a PROXY_CERT_INFO_EXTENSION structure and its contents. |
|
Return the ASN.1 item descriptor for PROXY_CERT_INFO_EXTENSION. |
|
Allocate a new Proxy Certificate Information extension value. |
|
Free a PROXY_POLICY structure and its OID/policy octets. |
|
Return the ASN.1 item descriptor for PROXY_POLICY. |
|
Allocate a new PROXY_POLICY structure. |
|
|
Return the built‐in OpenSSL legacy RAND_METHOD (deprecated). |
Mix additional bytes into the PRNG state with an estimated entropy amount. |
|
Fill a buffer with cryptographically strong random bytes from the public CSPRNG. |
|
Fill a buffer with public CSPRNG bytes using a library context and strength. |
|
Build the default path for the PRNG seed file into a caller‐provided buffer. |
|
Return the shared primary DRBG for a library context (used to reseed public/private DRBGs). |
|
Return the thread‐local private DRBG used by RAND_priv_bytes() for a library context. |
|
Return the thread‐local public DRBG used by RAND_bytes() for a library context. |
|
|
Return the currently selected legacy RAND_METHOD used for PRNG operations. |
Keep OS random devices open across forks when |
|
Mix up to |
|
Reseed the PRNG by polling trusted system entropy sources. |
|
Generate private random bytes using a separate DRBG instance from RAND_bytes(). |
|
Like RAND_priv_bytes(), with an explicit library context and security strength. |
|
|
Fill a buffer with bytes that need not be cryptographically strong (deprecated). |
Mix |
|
Install |
|
Install |
|
Configure the primary DRBG algorithm type for a library context. |
|
|
Select an ENGINE as the source of the legacy RAND_METHOD (deprecated). |
|
Install the legacy RAND_METHOD used by RAND_bytes and related APIs (deprecated). |
Select the seed source used by the primary RNG in a library context. |
|
Report whether the PRNG has been sufficiently seeded for RAND_bytes(). |
|
Write a seed file containing entropy from the CSPRNG for later RAND_load_file() use. |
|
|
Encrypt or decrypt with RC2 in CBC mode (deprecated). |
|
Encrypt or decrypt with RC2 in 64‐bit CFB mode (deprecated). |
|
Decrypt one RC2 block held as two host‐endian longs (deprecated). |
|
Encrypt or decrypt one RC2 block in ECB mode (deprecated). |
|
Encrypt one RC2 block held as two host‐endian longs (deprecated). |
|
Encrypt or decrypt with RC2 in 64‐bit OFB mode (deprecated). |
|
Expand a raw RC2 key into an RC2_KEY schedule (deprecated). |
|
Encrypt or decrypt |
|
Return a short string describing compiled RC4 implementation options (deprecated). |
|
Initialize an RC4_KEY from a variable‐length key (deprecated; prefer EVP_CIPHER). |
|
Compute the RIPEMD‐160 digest of |
|
Finalise a RIPEMD‐160 digest into a 20‐byte buffer (deprecated; prefer EVP_DigestFinal_ex). |
|
Initialize a RIPEMD‐160 hashing context (deprecated; prefer EVP_DigestInit_ex). |
|
Process one 64‐byte RIPEMD‐160 block into the context chaining state (deprecated). |
|
Absorb |
|
Deep‐copy an RSA private key (RSAPrivateKey_dup) (deprecated). |
|
Return the ASN.1 item descriptor for PKCS#1 RSAPrivateKey (deprecated). |
|
Duplicate an RSA public key via ASN.1 encode/decode (deprecated). |
Free RSA‐OAEP algorithm parameters and their contents. |
|
Return the ASN.1 item descriptor for RSA_OAEP_PARAMS. |
|
Allocate empty RSA‐OAEP algorithm parameters. |
|
|
Return the built‐in OpenSSL RSA_METHOD implementing PKCS#1 operations (deprecated). |
Deep‐copy RSA‐PSS algorithm parameters. |
|
Free RSA‐PSS algorithm parameters and their contents. |
|
Return the ASN.1 item descriptor for RSA_PSS_PARAMS. |
|
Allocate empty RSA‐PSS algorithm parameters. |
|
|
Derive an RSA key from ANSI X9.31 intermediate values (deprecated). |
|
Generate an RSA key pair using the X9.31 prime‐generation method (deprecated). |
|
Return the X9.31 hash algorithm identifier byte for digest NID |
|
Return the bit length of an RSA modulus (deprecated; use EVP_PKEY_get_bits). |
|
Disable RSA blinding on |
|
Enable RSA blinding on |
|
Validate consistency of an RSA key's public/private components (deprecated). |
|
Validate RSA key components with an optional progress callback (deprecated). |
|
Clear the given flag bits on an RSA key object (deprecated). |
|
Return the flag bits from the RSA_METHOD currently bound to |
|
Free an RSA key and its BIGNUM components (deprecated). |
|
Generate an RSA key pair (very old API; deprecated — prefer RSA_generate_key_ex). |
|
Generate a two‐prime RSA key pair into an existing RSA object (deprecated). |
|
Generate a multi‐prime RSA key pair (deprecated). |
|
Borrow pointers to the RSA CRT parameters d mod (p‐1), d mod (q‐1), and qˆ‐1 mod p (deprecated). |
|
Return the RSA private exponent d (deprecated). |
|
Return CRT exponent d mod (p‐1) without duplicating it (deprecated). |
|
Return CRT exponent d mod (q‐1) without duplicating it (deprecated). |
|
Return the public exponent e of an RSA key without transferring ownership (deprecated). |
|
Return the ENGINE set on an RSA key (deprecated). |
|
Return the prime factors p and q of an RSA key without transferring ownership (deprecated). |
|
Return CRT coefficient qˆ‐1 mod p without duplicating it (deprecated). |
|
Get const pointers to the RSA modulus and exponents (deprecated). |
|
Get const pointers to multi‐prime CRT exponents and coefficients (deprecated). |
|
Fill |
|
Return the RSA modulus n (deprecated). |
|
Return the first prime factor (p) of an RSA key without transferring ownership. |
|
Return the RSA‐PSS parameters associated with an RSA key (deprecated). |
|
Return the second prime factor (q) of an RSA key without transferring ownership. |
|
Return the current default RSA_METHOD (deprecated). |
|
Return application data previously stored on an RSA key at CRYPTO_EX index |
|
Return the RSA_METHOD currently associated with an RSA key (deprecated). |
|
Return how many extra primes beyond p and q a multi‐prime RSA key has (deprecated). |
|
Return whether an RSA key is multi‐prime or two‐prime (deprecated). |
|
Duplicate an RSA_METHOD structure (deprecated). |
|
Free an RSA_METHOD allocated with RSA_meth_new() (deprecated). |
|
Return the application pointer previously attached to an RSA_METHOD. |
|
Return the descriptive name stored on an RSA_METHOD (deprecated). |
|
Return the BN modular‐exponentiation callback from an RSA_METHOD (deprecated). |
|
Return the finish/cleanup callback from an RSA_METHOD (deprecated). |
|
Return the flag mask stored on an RSA_METHOD (deprecated). |
|
Return the init callback previously set on an RSA_METHOD (deprecated). |
|
Return the key‐generation callback from a custom RSA_METHOD (deprecated). |
|
Return the CRT modular‐exponentiation callback from an RSA_METHOD (deprecated). |
|
Return the multi‐prime key‐generation callback from an RSA_METHOD (deprecated). |
|
Return the private‐decrypt callback from an RSA_METHOD (deprecated). |
|
Return the private‐encrypt (signing) callback from an RSA_METHOD (deprecated). |
|
Return the public‐decrypt callback from an RSA_METHOD (deprecated). |
|
Return the public‐encrypt callback installed on a custom RSA_METHOD (deprecated). |
|
Return the high‐level sign callback from an RSA_METHOD (deprecated). |
|
Return the high‐level verify callback from an RSA_METHOD (deprecated). |
|
Allocate a new RSA_METHOD with the given name and flags (deprecated). |
|
Attach application data to an RSA_METHOD without copying (deprecated). |
|
Set the descriptive name stored on an RSA_METHOD (deprecated). |
|
Set the CRT modular‐exponentiation callback on an RSA_METHOD (deprecated). |
|
Set the finish/cleanup callback on an RSA_METHOD (deprecated). |
|
Replace the flag mask stored on an RSA_METHOD. |
|
Install the init callback on an RSA_METHOD (deprecated). |
|
Set the key‐generation callback on a custom RSA_METHOD (deprecated). |
|
Set the CRT modular‐exponentiation callback on a custom RSA_METHOD (deprecated). |
|
Set the multi‐prime key‐generation callback on a custom RSA_METHOD (deprecated). |
|
Set the private‐decrypt callback on a custom RSA_METHOD (deprecated). |
|
Set the private‐encrypt (signing) callback on a custom RSA_METHOD (deprecated). |
|
Set the public‐decrypt callback on a custom RSA_METHOD (deprecated). |
|
Set the public‐encrypt callback on a custom RSA_METHOD (deprecated). |
|
Set the private‐key signing callback on an RSA_METHOD (deprecated). |
|
Set the signature‐verification callback on a custom RSA_METHOD (deprecated). |
|
Allocate and initialise an empty RSA key object (deprecated; use EVP_PKEY‐RSA). |
|
Allocate an RSA object that uses |
|
Return the historical "null" RSA_METHOD stub (deprecated; always returns NULL since 1.1.1). |
|
Apply PKCS#1 OAEP padding using SHA‐1 / MGF1‐SHA‐1 defaults (deprecated). |
|
Apply PKCS#1 OAEP padding with explicit message and MGF1 digests (deprecated). |
|
Encode an EMSA‐PSS padded block for RSA signature (deprecated). |
|
Encode an EMSA‐PSS padded block using an explicit MGF1 hash (deprecated). |
|
Encode a DigestInfo or similar block with PKCS #1 v1.5 type‐1 padding for RSA signatures (deprecated). |
|
Encode a message with PKCS #1 v1.5 encryption padding (type 2) (deprecated). |
|
Apply ANSI X9.31 padding to a message block (deprecated). |
|
Copy |
|
Verify PKCS#1 OAEP padding and recover the encoded message (deprecated). |
|
Verify PKCS#1 OAEP padding with explicit digests and recover the message (deprecated). |
|
Verify and remove PKCS#1 v1.5 type‐1 (signing) padding (deprecated). |
|
Decode and verify PKCS #1 v1.5 type‐2 (encryption) padding (deprecated). |
|
Verify ANSI X9.31 padding and recover the message (deprecated). |
|
Verify "no padding" by copying |
Dispatch an RSA‐specific control operation on an EVP_PKEY_CTX. |
|
|
Print RSA key components to a BIO with indentation (deprecated). |
|
Print RSA key components to a FILE with indentation (deprecated). |
|
Decrypt |
|
RSA private‐key encryption (raw primitive / signing‐style) (deprecated). |
|
RSA public‐key decryption / signature recovery (deprecated). |
|
Encrypt |
|
Estimate the security strength of |
|
Set the CRT parameters on an RSA key, transferring ownership (deprecated). |
|
Set the RSA prime factors p and q, transferring ownership of the BIGNUMs (deprecated). |
|
Set the RSA modulus and exponents, transferring ownership of the BIGNUMs (deprecated). |
|
Set multi‐prime RSA factors, exponents, and CRT coefficients (deprecated). |
|
Set the default RSA_METHOD used when creating new RSA keys (deprecated; not thread‐safe). |
|
Store application data on an RSA key at CRYPTO_EX index |
|
Set flag bits on an RSA key object (deprecated). |
|
Bind an RSA_METHOD implementation to an RSA key object (deprecated). |
|
Create and attach a BN_BLINDING factor for RSA private operations (deprecated). |
|
Create an RSA signature with PKCS#1 DigestInfo wrapping (deprecated). |
|
Sign an ASN.1 OCTET STRING payload with RSA (deprecated). |
|
Return the RSA modulus size in bytes (deprecated). |
|
Return which of the given flag bits are currently set on an RSA object. |
|
Increment the reference count of an RSA key object (deprecated). |
|
Verify an RSASSA‐PKCS1‐v1_5 signature over digest |
|
Verify an RSA signature that wraps a DigestInfo‐style ASN.1 OCTET STRING (deprecated). |
|
Verify an RSA‐PSS encoded message EM against a message hash (deprecated). |
|
Verify a PKCS#1 PSS‐encoded digest using an explicit MGF1 hash (deprecated). |
Free a PKCS#5 scrypt parameter structure and its contents. |
|
Return the ASN.1 item descriptor for SCRYPT_PARAMS. |
|
Allocate an empty PKCS#5 scrypt parameter structure. |
|
Free a stack of SCTs and the SCTs themselves. |
|
Pretty‐print a stack of SCTs to a BIO, optionally resolving log names. |
|
Validate a list of SCTs against a policy evaluation context. |
|
Free an SCT and its underlying data. |
|
Return a pointer to the extension data embedded in an SCT. |
|
Get the log ID that an SCT came from. |
|
Get a pointer to the signature bytes of an SCT. |
|
Get the log entry type of an SCT. |
|
Return the NID of the signature algorithm used by an SCT. |
|
Get the origin of an SCT (TLS extension, OCSP response, and so on). |
|
Get the timestamp of an SCT. |
|
Get the last validation result stored on an SCT. |
|
Get the Certificate Transparency version of an SCT. |
|
Create a new, blank Signed Certificate Timestamp. The caller must free it with SCT_free(). |
|
Create an SCT from base64‐encoded log id, extensions, and signature fields. |
|
Pretty‐print a single Signed Certificate Timestamp to a BIO. |
|
Set SCT extensions by taking ownership of the given buffer. |
|
Set the CT log ID on an SCT, transferring ownership of |
|
Set the SCT signature by taking ownership of the given buffer. |
|
Set the SCT extensions field by copying |
|
Set the CT log ID on an SCT by copying |
|
Set the SCT signature by copying |
|
Set the log entry type of an SCT. |
|
Set the signature algorithm NID used by an SCT. |
|
Record where an SCT was obtained (TLS extension, OCSP, X.509 extension, etc.). |
|
Set the timestamp of an SCT. |
|
Set the Certificate Transparency version of an SCT. |
|
Validate an SCT against a policy evaluation context. |
|
Get a text description of an SCT's validation status. |
|
|
Encrypt or decrypt data with SEED in CBC mode (deprecated; prefer EVP). |
|
Encrypt or decrypt data with SEED in 128‐bit CFB mode (deprecated; prefer EVP). |
|
Decrypt one 16‐byte SEED block (deprecated; prefer EVP). |
|
Encrypt or decrypt one 16‐byte SEED block in ECB mode (deprecated; prefer EVP). |
|
Encrypt one 16‐byte SEED block (deprecated; prefer EVP). |
|
Encrypt or decrypt data with SEED in 128‐bit OFB mode (deprecated; prefer EVP). |
|
Expand a 16‐byte SEED key into a SEED_KEY_SCHEDULE (deprecated; prefer EVP). |
Compute the SHA‐1 digest of |
|
|
Finalize a SHA‐1 digest into |
|
Initialize a low‐level SHA‐1 digest context (deprecated; prefer EVP_DigestInit_ex). |
|
Process one SHA‐1 compression round on a full 64‐byte block (deprecated). |
|
Absorb |
Compute the SHA‐224 digest of |
|
|
Place the SHA‐224 digest into |
|
Initialize a SHA‐224 digest context (deprecated; prefer EVP_DigestInit_ex). |
|
Absorb message bytes into a SHA‐224 context (deprecated; prefer EVP_DigestUpdate). |
Compute the SHA‐256 digest of |
|
|
Finalise a SHA‐256 digest and write the 32‐byte hash. |
|
Initialise a SHA‐256 digest context (deprecated; prefer EVP_DigestInit_ex). |
|
Process one 64‐byte SHA‐256 block into digest state |
|
Absorb message bytes into a SHA‐256 context (deprecated; prefer EVP_DigestUpdate). |
Compute the SHA‐384 digest of |
|
|
Finalise a SHA‐384 digest and write the 48‐byte hash (deprecated). |
|
Initialize a SHA‐384 digest context (deprecated; prefer EVP_DigestInit). |
|
Absorb message bytes into a SHA‐384 context (deprecated; prefer EVP_DigestUpdate). |
Compute the SHA‐512 digest of |
|
|
Finalize a SHA‐512 digest and write SHA512_DIGEST_LENGTH bytes to |
|
Initialize a SHA‐512 digest context (deprecated; prefer EVP_DigestInit). |
|
Process one SHA‐512 block into |
|
Absorb message bytes into a SHA‐512 context (deprecated; prefer EVP_DigestUpdate). |
Copy |
|
Parse an S/MIME message into an ASN.1 structure described by |
|
Parse an S/MIME message into an ASN.1 structure described by |
|
Parse an S/MIME message from a BIO into a CMS_ContentInfo. |
|
Parse an S/MIME message into a CMS_ContentInfo, with optional flags and reuse. |
|
Parse an S/MIME message into a PKCS#7 structure using the default library context. |
|
Parse an S/MIME message into a PKCS#7 structure, optionally reusing |
|
Strip MIME headers from a text/plain S/MIME part and copy the body to |
|
Write an ASN.1 CMS/PKCS#7 value as an S/MIME message (default library context). |
|
Write an ASN.1 CMS/PKCS#7 value as an S/MIME message with library context. |
|
Write a CMS_ContentInfo as an S/MIME (MIME) message to |
|
Write a PKCS#7 object in S/MIME (PEM/CMS) form to a BIO. |
|
|
Compute the client public value A = gˆa mod N. |
|
Compute the SRP client public value A for |
|
Compute the server public value B = gˆb + k*v (mod N) for TLS‐SRP (default library context; deprecated). |
|
Compute the server public value B = gˆb + k*v (mod N) for TLS‐SRP. |
|
Compute the client session key K for TLS‐SRP (deprecated). |
|
Compute the client session key K for TLS‐SRP. |
|
Compute the SRP server shared secret S = (A*vˆu)ˆb mod N (deprecated). |
|
Compute the SRP scrambling parameter u = H(A, B) using the default library context (deprecated). |
|
Compute the SRP scrambling parameter u = H(PAD(A) || PAD(B)). |
|
Compute x = H(s, H(user:pass)) using the default library context (deprecated). |
|
Compute the private exponent x = H(s, H(user:pass)) for TLS‐SRP. |
|
Append a user entry to an SRP verifier database (ownership transfers on success). |
|
Free an SRP verifier database and its contents. |
|
Look up an SRP user entry, synthesizing one from |
|
Look up an SRP user entry without transferring ownership (deprecated). |
|
Load SRP verifier entries from a text verifier file into a database. |
|
Allocate an SRP verifier database, optionally copying |
|
Verify that the client public value A is non‐zero modulo N. |
|
Verify that the server public value B is non‐zero modulo N. |
|
Test whether |
|
Create base64‐encoded SRP salt and verifier strings (default library context; deprecated). |
|
Create SRP salt and verifier BIGNUMs for a user/password. |
|
Create SRP salt and verifier BIGNUMs for a user/password. |
|
Create base64‐encoded SRP salt and verifier strings for a user/password. |
|
Return built‐in RFC 5054 SRP group parameters for a textual group id (deprecated). |
|
Free an SRP_user_pwd structure and owned fields. |
|
Allocate an empty SRP_user_pwd structure. |
|
Assign salt and verifier BIGNUMs to an SRP_user_pwd (ownership transfers on success). |
|
Set the user identifier and optional info string on an SRP_user_pwd. |
|
Set the SRP group parameters on a user verifier entry (caller retains ownership of |
Write a human‐readable description of a cipher suite into a buffer. |
|
Look up a cipher suite by its two‐byte TLS cipher ID. |
|
Return the NID of the authentication method used by a cipher suite. |
|
Return the number of secret bits used by a cipher suite. |
|
Return the NID of the bulk cipher algorithm used by a cipher suite. |
|
Return the NID of the MAC digest used by a cipher for record protection. |
|
Return the handshake digest used by a cipher suite. |
|
Return the OpenSSL‐internal 32‐bit identifier for cipher |
|
Return the NID of the key‐exchange method used by a cipher suite. |
|
Return the OpenSSL display name of a cipher suite. |
|
Return the two‐octet TLS protocol cipher suite identifier. |
|
Return the protocol version name associated with a cipher suite (for example "TLSv1.2"). |
|
Report whether a cipher suite uses an AEAD construction. |
|
Return the standard RFC name of a cipher suite. |
|
Register a compression method globally for all SSL operations in the process. |
|
Return the name of an SSL_COMP compression method entry. |
|
|
Return the global stack of available SSL/TLS integrated compression methods. |
Return the wire identifier of an SSL_COMP compression method entry. |
|
Return the display name of a compression COMP_METHOD. |
|
|
Replace the global stack of SSL/TLS compression methods, transferring ownership of |
Clear selected SSL_CONF_FLAG_* bits on a configuration context. |
|
Finalise configuration on an SSL_CONF_CTX after all SSL_CONF_cmd() calls. |
|
Free an SSL_CONF_CTX and any associated command state. |
|
Allocate and initialise an SSL_CONF_CTX for SSL_CONF_* configuration commands. |
|
Set the command‐name prefix recognised by subsequent SSL_CONF_cmd() calls. |
|
Set SSL_CONF_FLAG_* bits on a configuration context. |
|
Bind an SSL_CONF_CTX so subsequent SSL_CONF_cmd calls apply to |
|
Bind an SSL_CTX so subsequent SSL_CONF_cmd() calls configure that context. |
|
Apply a configuration command (option plus optional value) to an SSL_CONF_CTX. |
|
Process at most two SSL configuration command‐line arguments from |
|
Return the value type expected by SSL_CONF_cmd() for a given command name. |
|
|
Free SRP parameters stored on an SSL_CTX (deprecated). |
|
Initialize the deprecated SRP context embedded in an SSL_CTX. |
Append a CA subject name from a certificate to an SSL context's peer CA list. |
|
Add a CA subject name to the context's client‐CA list sent when requesting a client certificate. |
|
|
Register older‐style custom extension handlers for TLS/DTLS clients. |
Register a custom TLS extension for client and/or server using the extended callback API. |
|
|
Register a custom TLS extension handler for the server role on an SSL context. |
Add a session to an SSL context's internal session cache. |
|
Perform a low‐level control operation that takes a function‐pointer argument on an SSL context. |
|
Verify that the private key configured on an SSL_CTX matches its certificate. |
|
Clear selected SSL_OP_* option bits on an SSL context. |
|
Pre‐compress all certificates configured on a server SSL_CTX with algorithm |
|
Apply a named configuration section from a previously loaded config file to an SSL_CTX. |
|
Report whether Certificate Transparency validation is enabled on an SSL context. |
|
Perform a low‐level control operation on an SSL context. |
|
Clear selected DANE option flags on an SSL_CTX. |
|
Initialize shared DANE TLSA authentication state on an SSL context. |
|
Map a DANE TLSA matching type to a digest algorithm for a context. |
|
Set selected DANE option flags on an SSL_CTX. |
|
Enable Certificate Transparency validation on an SSL context (inherited by new connections). |
|
Remove sessions from the context's internal cache that have expired by |
|
Decrement the reference count of an SSL_CTX and free it when it reaches zero. |
|
Return the list of CA names the context will advertise to peers. |
|
Return the local certificate configured on an SSL context (if any). |
|
|
Retrieve the local client certificate type extension values configured on an SSL context. |
Return the CT log store installed on an SSL context. |
|
Return a non‐owning pointer to an SSL context's verification parameters. |
|
Return the private key configured on an SSL context (if any). |
|
|
Return the application pointer passed as |
|
Retrieve the local server certificate type extension values configured on an SSL context. |
Get a copy of a compressed certificate configured on an SSL_CTX. |
|
Return the certificate verification store associated with an SSL_CTX. |
|
Return the preference‐ordered stack of ciphers configured on an SSL context. |
|
|
Return the stack of CA names the context will send when requesting a client certificate. |
|
Return the client‐certificate callback installed on an SSL_CTX. |
|
Return the default PEM password callback currently set on an SSL context. |
|
Return the userdata pointer passed to the context's default PEM password callback. |
Retrieve application‐specific data previously stored on an SSL_CTX. |
|
Return the information callback currently set on an SSL context. |
|
Return the TLS key‐logging callback previously set on an SSL context. |
|
|
Return the maximum early‐data bytes configured on an SSL context. |
Return how many TLSv1.3 session tickets servers from a context are configured to send. |
|
Return the option bitmask currently set on an SSL context. |
|
Return the quiet‐shutdown setting of an SSL context. |
|
|
Return the opaque argument passed to the context's TLS 1.3 record‐padding callback. |
|
Return the recv_max_early_data limit configured on an SSL context. |
Return the security callback currently installed on an SSL context. |
|
Return the security level currently configured on an SSL context. |
|
Return the SSL_METHOD used to create an SSL context. |
|
Return the default session lifetime configured on |
|
Return the certificate verification callback set on an SSL context. |
|
Return the maximum depth of certificate chain verification for an SSL context. |
|
Return the peer certificate verification mode currently set on an SSL context. |
|
|
Return whether a client custom extension of type |
Load trusted CA certificates from a hashed directory into an SSL context. |
|
Load trusted CA certificates from a PEM file into an SSL context. |
|
Load trusted CA certificates from a PEM file and/or hashed directory into an SSL context. |
|
Load trusted CA certificates from a store URI into an SSL context. |
|
Create a new SSL_CTX for connections using method |
|
Create an SSL_CTX using an explicit library context and property query. |
|
Remove a session from an SSL context's internal session cache and mark it non‐resumable. |
|
Return the external session‐cache lookup callback installed on an SSL_CTX. |
|
Return the new‐session callback previously set on |
|
|
Return the session‐remove callback previously set on an SSL context. |
Set the external session‐lookup callback used when a session id is not in the internal cache. |
|
Set the callback invoked when a new session is negotiated for caching. |
|
|
Set the callback invoked when a session is removed from an SSL context cache. |
Return a pointer to the context's internal SSL_SESSION LHASH cache. |
|
Set the list of CA names sent to the peer for an SSL context (takes ownership). |
|
Install a CT log store on an SSL context, transferring ownership of |
|
|
Set the application pointer passed as |
Set ephemeral DH parameters for a context, transferring ownership of |
|
|
Set the preferred TLSv1.3 certificate compression algorithms for an SSL context (RFC 8879). |
Replace the context certificate store, incrementing |
|
|
Set the client certificate type extension values for an SSL context (RFC 7250). |
Install a pre‐compressed certificate blob on a server SSL context. |
|
Copy verification parameters into an SSL context. |
|
|
Set the server certificate type values advertised by an SSL_CTX (RFC 7250). |
|
Set a server callback that decides whether to accept TLSv1.3 early data for a context. |
Set the ALPN protocol list advertised or offered by an SSL context. |
|
|
Register the server callback that selects an ALPN protocol during the handshake. |
Set the asynchronous completion callback inherited by SSL objects from a context. |
|
|
Set the user argument passed to the context's asynchronous completion callback. |
Pad TLS 1.3 records written from a context up to a multiple of a block size. |
|
Install a certificate‐selection callback invoked during handshake certificate setup. |
|
Replace the context certificate store, taking ownership of |
|
|
Replace the built‐in peer certificate verification procedure with an application callback. |
Set the TLSv1.2‐and‐below cipher list for an SSL context. |
|
Set the TLSv1.3 ciphersuite list for an SSL context. |
|
|
Set the list of CA names sent to clients when requesting a client certificate. |
|
Install a callback that supplies a client certificate during handshake. |
|
Set an ENGINE used to obtain a client certificate when a server requests one. |
|
Install a server callback invoked after each ClientHello is parsed. |
|
Set the callback that generates DTLS HelloVerifyRequest cookies. |
|
Set the callback that verifies DTLS HelloVerifyRequest cookies. |
|
Register a Certificate Transparency validation callback for an SSL context. |
|
Load a Certificate Transparency log list from a file and append it to the context store. |
|
Load the default Certificate Transparency log list file into the context store. |
|
Set the default password callback used when loading encrypted PEM material into a context. |
|
Set userdata passed to the context's default PEM password callback. |
|
Set the default read‐buffer size used for new connections from a context (pipelining). |
|
Load only the default hashed CA directory into an SSL context's trust store. |
|
Load only the default CA certificate file into an SSL context's trust store. |
|
Load the default CA file, directory, and store into an SSL context's trust store. |
|
Load the default trusted certificate store into an SSL context. |
Store application‐specific data on an SSL_CTX at a previously allocated index. |
|
|
Set the callback used to generate new session IDs for server SSL objects from a context. |
Set the information callback used by SSL objects created from a context. |
|
Configure a callback that logs TLS key material for debugging (e.g. Wireshark). |
|
|
Set the maximum early‐data bytes a server context may accept or advertise. |
Install a callback that observes SSL/TLS/QUIC protocol messages on new connections. |
|
|
Set the Next Protocol Negotiation (NPN) selection callback for clients. |
|
Set the Next Protocol Negotiation (NPN) advertisement callback for servers. |
|
Register a context‐wide callback that decides whether new sessions may be resumed. |
Set how many TLSv1.3 session tickets servers created from a context send after a full handshake. |
|
Set additional SSL_OP_* option bits on an SSL context (bitwise OR). |
|
|
Enable or disable sending the TLSv1.3 Post‐Handshake Authentication ClientHello extension. |
|
Set the client PSK identity/key callback used by connections from |
|
Set the TLSv1.3 PSK find‐session callback for SSL objects created from a context (server). |
|
Set the PSK identity callback used by server SSL objects from a context. |
|
Set the PSK use‐session callback for client SSL objects from a context. |
Set the X509 purpose on an SSL context's verification parameters. |
|
Set quiet‐shutdown mode for SSL objects created from a context. |
|
|
Install a callback that chooses TLS 1.3 record padding for connections from a context. |
|
Set the opaque argument passed to the context's TLS 1.3 record‐padding callback. |
|
Set how many rejected early‐data bytes a server context will skip before aborting. |
Install a security‐policy callback used by connections created from a context. |
|
Set the security level used to constrain algorithms and parameters on an SSL context. |
|
|
Set the server‐side session‐id context within which sessions may be reused for a context. |
|
Register callbacks that attach and consume application data in TLS session tickets. |
|
Set the user argument passed to all SRP callbacks on a context (deprecated). |
|
Set a client callback that supplies the SRP password (deprecated). |
|
Set the default SRP password for clients created from a context (deprecated). |
|
Set the minimum acceptable SRP prime length in bits for a context (deprecated). |
|
Set the default SRP username for clients created from a context (deprecated). |
|
Set the server callback invoked when an SRP username appears in ClientHello (deprecated). |
|
Set a client callback that verifies server SRP group parameters (deprecated). |
|
Replace the SSL_METHOD used by an SSL_CTX (deprecated). |
|
Register the callback that generates cookies for TLS 1.3 HelloRetryRequest / DTLS cookie exchange. |
|
Set the callback that verifies a TLS 1.3 stateless HelloRetryRequest cookie. |
Set the default session timeout for |
|
|
Set the maximum fragment length mode advertised by an SSL context (RFC 6066). |
|
Set the TLS session‐ticket key callback using EVP cipher and MAC contexts. |
|
Set the DTLS use_srtp extension protection profiles for a context. |
|
Set a deprecated callback that supplies ephemeral DH parameters for server connections from a context. |
Set the default X509 trust purpose NID for certificate verification on a context. |
|
Set peer certificate verification mode and optional callback for an SSL context. |
|
Set the maximum depth of CA certificates allowed above the peer for context‐wide verification. |
|
Increment the reference count on an SSL_CTX. |
|
Assign an EVP_PKEY private key to an SSL context. |
|
Install a private key of type |
|
Load a private key from a file into an SSL context. |
|
|
Assign an RSA private key to an SSL context (deprecated; use SSL_CTX_use_PrivateKey). |
|
Load an RSA private key from a DER buffer into an SSL context (deprecated). |
|
Load the first RSA private key from a file into an SSL context (deprecated). |
Assign a certificate, private key, and optional chain onto an SSL context. |
|
Set the end‐entity certificate used by an SSL context. |
|
Load a certificate into an SSL context from a DER encoding. |
|
|
Load a PEM certificate chain from |
Load a certificate from a file into an SSL context. |
|
|
Set the PSK identity hint advertised by a TLS server context. |
Load serverinfo TLS extensions (SSL_SERVERINFOV1 format) into an SSL context. |
|
Load serverinfo TLS extensions in V1 or V2 format into an SSL context. |
|
Load PEM‐encoded serverinfo TLS extensions from a file into an SSL context. |
|
Duplicate an SSL_SESSION; the copy is not owned by any session cache. |
|
Decrement the reference count of an SSL_SESSION and free it when it reaches zero. |
|
Retrieve the ALPN protocol selected for a session and its length. |
|
Return the cipher suite stored on an SSL_SESSION. |
|
Return the SNI hostname associated with a session, if the server acknowledged SNI. |
|
Return the session‐id context bytes associated with a session. |
|
Return the peer certificate stored in an SSL session (borrowed pointer). |
|
Return the peer's raw public key (RFC 7250) stored on an SSL session, if any. |
|
Obtain a pointer to the session ticket bytes stored on a session. |
|
Retrieve application data previously stored with a session ticket. |
|
Return the compression method identifier negotiated for a session. |
|
Retrieve application data previously stored on an SSL_SESSION. |
|
Return the session identifier bytes of an SSL_SESSION. |
|
Copy the session master secret into a caller buffer (sensitive; avoid exposing). |
|
|
Return the maximum early‐data (0‐RTT) size allowed for a session. |
|
Return the Maximum Fragment Length extension mode negotiated for a session. |
|
Return the protocol version number recorded in an SSL session. |
|
Return the session‐ticket lifetime hint in seconds. |
Return the session creation time as seconds since the Epoch. |
|
Return the session creation time as a time_t (Y2038‐safe counterpart to SSL_SESSION_get_time). |
|
Return the inactivity timeout (in seconds) configured for an SSL session. |
|
Report whether a session ticket is present on a session. |
|
Report whether a session may be used for resumption / PSK. |
|
Allocate a new empty SSL_SESSION structure. |
|
Print a human‐readable summary of an SSL_SESSION to a BIO. |
|
Print a human‐readable summary of an SSL_SESSION to a FILE. |
|
Print session keying material to a BIO in NSS keylog format. |
|
Set the ALPN protocol recorded on a session to a copy of |
|
Set the SNI hostname stored on a session to a copy of |
|
Set the session ID bytes stored on an SSL_SESSION. |
|
Set the session ID context used to restrict session reuse. |
|
Set the master secret on an SSL session by copying |
|
Attach application data that will be stored inside a TLS session ticket. |
|
Associate a cipher suite with an SSL_SESSION (for example when building a PSK session). |
|
Store application data on an SSL_SESSION at a CRYPTO_EX index. |
|
|
Set the maximum early‐data (0‐RTT) size advertised for a session. |
|
Set the protocol version recorded on an SSL_SESSION. |
Set the creation time of an SSL_SESSION (seconds since the Unix epoch). |
|
Set the session creation time as a time_t (Y2038‐safe counterpart to SSL_SESSION_set_time). |
|
Set the inactivity timeout recorded on an SSL session. |
|
Increment the reference count of an SSL_SESSION. |
|
|
Free SRP parameters stored on an SSL connection (deprecated). |
|
Initialise SRP fields inside SSL object |
Wait for a TLS/SSL client to initiate the handshake on a server connection. |
|
Dequeue an incoming remotely initiated QUIC stream from a connection. |
|
Add an additional expected DNS hostname for peer certificate name checks. |
|
Append a CA subject name from a certificate to this connection's peer CA list. |
|
Add a CA subject name to the client‐CA list sent when requesting a client certificate. |
|
|
Append subject names from every certificate file in |
Add a DANE TLSA record matching raw public key |
|
|
Append subject names from PEM certificates in a file to an existing stack. |
Historical no‐op retained for compatibility; the SSL config module registers automatically. |
|
|
Load certificate subjects from an OSSL_STORE URI into a name stack. |
Return a short letter code for a TLS/SSL alert description. |
|
Return a long human‐readable description of a TLS/SSL alert reason code. |
|
Return a short string for an SSL/TLS alert level. |
|
Return a long human‐readable description of a TLS/SSL alert type. |
|
Allocate (or keep) the read and write record buffers for an SSL connection. |
|
Build a BIO_POLL_DESCRIPTOR that refers to SSL object |
|
Parse a wire‐format cipher suite list into SSL_CIPHER and SCSV stacks. |
|
Perform a low‐level control operation that takes a function‐pointer argument on an SSL connection. |
|
Clear certificates and related chain material configured on an SSL connection. |
|
Check whether certificate |
|
Verify that the private key configured on an SSL matches its certificate. |
|
Reset an SSL object so it can be reused for another connection. |
|
Clear selected SSL_OP_* option bits on an SSL connection. |
|
Return the cipher_suites field from the ClientHello being processed. |
|
|
Return the raw compression_methods field from a parsed ClientHello. |
Return a pointer to a specific extension's payload in a parsed ClientHello. |
|
|
Return the legacy_version field from the ClientHello being processed. |
Return the ClientHello Random field from a client‐hello callback context. |
|
|
Return the session_id field from the ClientHello being processed. |
|
Allocate and return the list of extension types present in a ClientHello. |
|
Copy ClientHello extension type values in the order they appeared. |
Report whether the ClientHello being processed used the SSLv2 wire format. |
|
Return the numeric protocol version advertised by the client in ClientHello. |
|
Pre‐compress all certificates configured on a server SSL connection with algorithm |
|
Apply a named configuration section from a previously loaded config file to an SSL. |
|
Initiate the TLS/SSL handshake as a client on an already configured connection. |
|
Copy the session, method, certificate, and session‐id context from one SSL object to another. |
|
Report whether Certificate Transparency validation is enabled on an SSL connection. |
|
Perform a low‐level control operation on an SSL connection (prefer typed helpers/macros). |
|
Clear DANE authentication feature flags on an SSL connection. |
|
Enable DANE TLSA authentication for a connection (must be called before the handshake). |
|
Set selected DANE option flags on an SSL connection. |
|
Add a DANE TLSA record used to authenticate the peer on a connection. |
|
Drive the TLS/SSL handshake to completion on a connection already set to connect or accept state. |
|
Duplicate an SSL object that is still in its initial (pre‐handshake) state. |
|
Deep‐copy a stack of CA subject names. |
|
Enable Certificate Transparency validation on an SSL connection. |
|
Export keying material derived from the connection's exporter secret. |
|
|
Export keying material derived from the early exporter master secret. |
Report whether OpenSSL has built‐in handling for a TLS extension type. |
|
Decrement the reference count of an SSL connection and free it when it reaches zero. |
|
Free the read and write record buffers associated with an SSL connection. |
|
Return the list of CA names configured to be sent to the peer. |
|
Return the ALPN protocol selected during the handshake. |
|
Retrieve the local client certificate type extension values configured on an SSL connection. |
|
Return the QUIC connection SSL for a stream, or |
|
Return the internal SSL_DANE state for |
|
Return the matching DANE‐TA / DANE‐EE authority depth and optional anchors. |
|
Return the matching DANE TLSA record fields after successful authentication. |
|
Return the name of the key‐exchange group negotiated on |
|
Return the Next Protocol Negotiation (NPN) protocol selected on this connection. |
|
Return a non‐owning pointer to an SSL connection's verification parameters. |
|
Return the list of CA names the peer advertised for client authentication. |
|
Return the peer's leaf certificate without incrementing its reference count. |
|
Return the peer's negotiated raw public key (RFC 7250), if any. |
|
Return the signed certificate timestamps (SCTs) received on this connection. |
|
Return the peer certificate DNS name or subject CN that matched a configured reference identifier. |
|
Return the application pointer passed as |
|
Retrieve the local server certificate type extension values configured on an SSL connection. |
|
Return the verified peer certificate chain including the end‐entity certificate. |
|
Copy the pre‐compressed certificate stored for algorithm |
|
Return the peer's end‐entity X509 certificate, incrementing its reference count. |
|
Return the current SSL_SESSION for |
|
Return the preference‐ordered stack of enabled ciphers that would be sent in a ClientHello. |
|
Return the SSL_CTX from which an SSL connection was created. |
|
|
Return how many incoming QUIC streams are waiting to be accepted. |
Retrieve every file descriptor an async SSL operation is waiting on. |
|
Query the current asynchronous operation status for an SSL connection. |
|
Return whether a QUIC connection SSL object is in blocking mode. |
|
Return the local certificate selected (or most recently set) for a connection. |
|
Retrieve async wait fds added or removed since the previous query. |
|
Return the name of the n‐th enabled cipher for a connection (0‐based preference order). |
|
Return the preference‐ordered stack of ciphers available on an SSL connection. |
|
Return the CA names offered for client authentication on this connection. |
|
Return the stack of ciphers offered by the client (server‐side only). |
|
Copy the TLS ClientHello random value from a connection. |
|
Retrieve why a terminated QUIC connection was closed. |
|
Return the cipher suite currently in use on an established connection. |
|
Return the compression method negotiated for sending on a connection. |
|
Return the compression method used for expanding (decompressing) received records. |
|
Return the default PEM password callback currently set on an SSL connection. |
|
|
Return the user‐data pointer passed to an SSL object's PEM password callback. |
Return the default session timeout for the protocol negotiated on a connection. |
|
Report whether early data was accepted, rejected, or never sent on a connection. |
|
Map a TLS/SSL I/O return value to a detailed error / retry code. |
|
Report when an SSL object next needs timer‐driven processing (DTLS/QUIC). |
|
Retrieve application‐specific data previously stored on an SSL object. |
|
|
Return the ex_data index used to retrieve the SSL pointer from an X509_STORE_CTX. |
Return the file descriptor linked to an SSL object's read BIO (or the shared fd). |
|
Copy up to |
|
Return the measured TLS handshake round‐trip time in microseconds when available. |
|
Return the info callback previously set on an SSL with SSL_set_info_callback(). |
|
Return the type of any pending TLS 1.3 / QUIC key update that has not yet been sent. |
|
Return the maximum early‐data bytes configured on an SSL connection. |
|
|
Return the negotiated client certificate type for a connection (RFC 7250). |
|
Return the negotiated server certificate type for a connection (RFC 7250). |
Return how many TLSv1.3 session tickets a server connection will send after a full handshake. |
|
Return the option bitmask currently set on an SSL connection. |
|
Return the certificate chain as sent by the peer (not necessarily the verified chain). |
|
Copy the peer's Finished handshake message hash into |
|
|
Get the NID of the signature type the peer used to sign TLS handshake messages. |
Return the cipher suite negotiated for upcoming use but not yet active. |
|
Return the local private key configured on |
|
Return the PSK identity used during the connection setup. |
|
Return the PSK identity hint used during the connection setup. |
|
Return whether quiet‐shutdown mode is enabled on an SSL connection. |
|
Return the read BIO currently attached to an SSL connection. |
|
Report whether an SSL connection will read ahead on its underlying BIO. |
|
|
Return the opaque argument passed to a connection's TLS 1.3 record‐padding callback. |
|
Return the recv_max_early_data limit configured on an SSL connection. |
Return the file descriptor linked to an SSL object's read BIO. |
|
Fill |
|
Return the security callback currently installed on a connection. |
|
Return the security level that constrains algorithms on a connection. |
|
Return the SRTP protection profile negotiated on an SSL/DTLS connection. |
|
Copy the TLS server random value from an SSL connection into a buffer. |
|
Return the server name indication (SNI) hostname associated with an SSL connection. |
|
Return the type of the server name indication currently associated with a connection. |
|
Return the SSL_SESSION currently associated with a connection (no reference bump). |
|
Format the shared (mutually supported) ciphers into a colon‐separated name string. |
|
Get a shared (mutually supported) signature algorithm by index. |
|
Return the shutdown state bit‐mask of an SSL connection. |
|
Get a peer‐supported signature algorithm by index. |
|
Get the NID of the signature type used locally to sign TLS handshake messages. |
|
|
Return the SRP prime N configured on a connection (deprecated). |
|
Return the SRP generator configured on a connection (deprecated). |
|
Return the optional SRP user‐info string for a connection (deprecated). |
|
Return the SRP username associated with a connection (deprecated). |
Return the stack of SRTP protection profiles configured on an SSL connection. |
|
Return the SSL_METHOD currently associated with an SSL connection. |
|
Return the current TLS/DTLS/QUIC handshake state enumeration for |
|
Return the QUIC stream ID for a stream SSL, or for a connection with a default stream. |
|
|
Get the application error code from a non‐normal QUIC stream receive abort. |
Return the overall state of the receiving part of a QUIC stream. |
|
Return the QUIC stream type of an SSL connection or stream object. |
|
|
Get the application error code from a non‐normal QUIC stream send abort. |
Return the overall state of the sending part of a QUIC stream. |
|
Read a uint64 feature/value identified by |
|
Return the certificate verification callback set on an SSL connection. |
|
Return the maximum depth of the peer certificate chain that will be verified. |
|
Return the peer certificate verification mode currently set on an SSL connection. |
|
Return the result code from verifying the peer's X509 certificate. |
|
Return the protocol version name negotiated on a connection. |
|
Return the write BIO currently attached to an SSL connection. |
|
Return the file descriptor linked to an SSL object's write BIO. |
|
Obtain a poll descriptor indicating when the SSL object can usefully write to the network. |
|
Return the TLS group name registered for a group identifier on this connection. |
|
Advance an SSL object's event state (DTLS timers, QUIC event loop helper). |
|
Test whether a session ID is already present in the parent context's internal session cache. |
|
Check whether an SSL object has any buffered record data (processed or not). |
|
Return whether no SSL/TLS handshake has been initiated yet on a connection. |
|
Test whether an SSL object is currently performing a handshake. |
|
Inject a received UDP datagram into a QUIC SSL object's network BIO path. |
|
Test whether an SSL object is a connection (or non‐QUIC) rather than a QUIC stream. |
|
Test whether an SSL object is using the DTLS protocol. |
|
Test whether the connection is ready for fully protected application data. |
|
Report whether a connection is using QUIC (as opposed to TLS or DTLS). |
|
Report whether an SSL object was created as a server endpoint. |
|
Test whether a QUIC stream SSL object was created locally (client‐initiated locally). |
|
Report whether a connection is using SSL/TLS (as opposed to DTLS or QUIC). |
|
Schedule a TLS 1.3 / QUIC key update of the requested type on |
|
Read certificates from a file and return a stack of their subject names. |
|
|
Read certificates from a file and return a stack of their subject names (provider‐aware). |
Report whether the SSL object wants to read from the network BIO. |
|
Report whether the SSL object wants to write to the network BIO. |
|
Create a new SSL connection object that inherits settings from an SSL_CTX. |
|
Queue generation of a new TLSv1.3 NewSessionTicket message on a server connection. |
|
Create a new locally initiated QUIC stream on a QUIC connection. |
|
Copy up to |
|
Peek at application data from an SSL/TLS connection without consuming it. |
|
Return how many processed application‐data bytes are buffered and ready to read. |
|
Poll readiness conditions for one or more SSL/BIO poll descriptors (e.g. QUIC). |
|
Read application data from a TLS/SSL connection into a buffer. |
|
Read TLSv1.3 early data on a server connection (must be the first I/O call). |
|
Read application data from a TLS/SSL connection, reporting the byte count via an out parameter. |
|
Schedule a full renegotiation of the current TLS ≤ 1.2 connection. |
|
Schedule a renegotiation that attempts to resume the current session (TLS ≤ 1.2). |
|
Test whether a renegotiation (or renegotiation request) is scheduled but not yet performed. |
|
Return a short two‐letter string for the SSL object's current read state. |
|
Return a long descriptive string for the SSL object's current read state. |
|
Select an ALPN/NPN protocol from a server list given client preferences. |
|
Send file contents over TLS using kernel sendfile where available. |
|
Query whether the handshake reused an existing SSL session. |
|
Set the list of CA names sent to the peer on this connection (takes ownership). |
|
Set the read BIO for an SSL connection, transferring ownership of |
|
Set the application pointer passed as |
|
Set ephemeral DH parameters for a connection, transferring ownership of |
|
Set the write BIO for an SSL connection, transferring ownership of |
|
Set the preferred certificate‐compression algorithms for an SSL connection. |
|
Set the client certificate type extension values for an SSL connection (RFC 7250). |
|
Install a pre‐compressed certificate blob on a server SSL connection. |
|
Set the expected DNS hostname used for certificate name checks (and SNI). |
|
Set the initial UDP peer address used to establish a QUIC client connection. |
|
Copy verification parameters into an SSL connection. |
|
Set the list of server certificate types this connection is willing to use. |
|
Replace the SSL_CTX associated with an existing SSL connection object. |
|
Configure an SSL object to behave as a server (accept) endpoint. |
|
|
Set a server callback that decides whether to accept TLSv1.3 early data on a connection. |
Set the ALPN protocol list advertised by a client SSL connection. |
|
Set the asynchronous completion callback on an SSL connection. |
|
Set the user argument passed to an SSL object's asynchronous completion callback. |
|
Attach read and write BIOs to an SSL connection, transferring ownership as appropriate. |
|
Pad TLS 1.3 application records for |
|
Enable or disable blocking mode on a QUIC connection SSL object. |
|
Install a certificate‐selection callback invoked before a cert is used in the handshake. |
|
Set the TLSv1.2‐and‐below cipher list for a single SSL connection. |
|
Set the TLSv1.3 ciphersuite list for an SSL connection. |
|
Set the list of CA names sent when requesting a client certificate on a connection. |
|
Configure an SSL object to operate as a TLS client. |
|
Register a Certificate Transparency validation callback for an SSL connection. Invoked after ServerHelloDone to validate received SCTs; a non‐positive callback result aborts the handshake. Setting a CT callback also requests an OCSP stapled response. |
|
|
Deprecated no‐op retained for ABI compatibility; previously toggled SSL debug output. |
Set the default PEM password callback used when loading keys on an SSL. |
|
|
Set the user‐data pointer passed to an SSL object's PEM password callback. |
|
Set the default read‐buffer size used for pipelined reads on a connection. |
Configure how the default QUIC stream behaves for an SSL connection. |
|
Store application‐specific data on an SSL connection at an ex_data index. |
|
Attach a bidirectional file descriptor as the I/O channel of an SSL connection. |
|
Set the callback used to generate new session IDs for a server SSL connection. |
|
Set X509_CHECK_FLAG_* host‐checking flags for certificate hostname matching. |
|
Configure whether a QUIC connection automatically accepts or rejects peer‐initiated streams. |
|
Set the information callback used to observe state changes, alerts, and errors on a connection. |
|
Set the maximum early‐data bytes for a single SSL connection. |
|
Install a callback that observes SSL/TLS/QUIC protocol messages on one connection. |
|
|
Register a callback that decides whether a session may be resumed. |
Set how many NewSessionTicket messages a TLSv1.3 server connection should send. |
|
Set additional SSL_OP_* option bits on an SSL connection (bitwise OR). |
|
Enable or disable TLSv1.3 post‐handshake authentication on a connection. |
|
Set the TLSv1.2‐and‐below PSK client callback on an SSL connection. |
|
|
Set the TLSv1.3 PSK find‐session callback on an SSL connection (server). |
Set the PSK identity callback used by a TLS server SSL object. |
|
|
Set the TLSv1.3 PSK use‐session callback on an SSL connection (client). |
Set the X509 purpose on an SSL connection's verification parameters. |
|
Enable or disable quiet shutdown (skip sending close_notify) on a connection. |
|
Enable or disable read‐ahead buffering on SSL |
|
Install a TLS 1.3 record‐padding callback on a connection. |
|
|
Set the opaque argument passed to a connection's TLS 1.3 record‐padding callback. |
|
Set how many rejected early‐data bytes a server SSL will skip before aborting. |
Attach a file descriptor as the read channel of an SSL connection. |
|
Install a callback that filters crypto choices according to security policy. |
|
Set the security level used to constrain algorithms and parameters on a connection. |
|
Attach a session to an SSL object for client‐side resumption. |
|
Set the server‐side session‐id context for a single SSL connection. |
|
Install an EAP‐FAST session‐secret callback that supplies the TLS master secret. |
|
Attach opaque session‐ticket extension data to a client SSL connection. |
|
|
Install a callback that processes the TLS session‐ticket extension on an SSL. |
Set the shutdown state bit‐mask on an SSL connection. |
|
|
Set SRP group parameters, salt, verifier, and info on a server connection (deprecated). |
|
Set SRP server parameters for |
Replace the TLS/SSL method used by an existing SSL connection. |
|
|
Set the maximum fragment length mode for an SSL connection. |
Set the DTLS use_srtp extension protection profiles for a connection. |
|
|
Set a deprecated callback that supplies ephemeral DH parameters for a server connection. |
Set the X509 trust setting on an SSL connection's verification parameters. |
|
Set a configurable uint64 parameter on an SSL object (feature negotiation or generic). |
|
Set peer certificate verification mode and optional verify callback on a connection. |
|
Set the maximum depth of the peer certificate chain that will be verified on a connection. |
|
Override the stored peer‐certificate verification result on a connection. |
|
Attach a file descriptor as the write channel of an SSL connection. |
|
Shut down an active TLS/DTLS or QUIC connection (close_notify / connection close). |
|
Shut down a TLS/DTLS or QUIC connection with optional extended arguments. |
|
|
Finish server‐side SRP parameter setup after the username is known (deprecated). |
Return a short string describing the current overall state of an SSL connection. |
|
Return a long descriptive string for the current SSL state. |
|
Attempt a stateless (cookie) DTLS listen / HelloVerifyRequest exchange. |
|
Signal normal end‐of‐stream on the sending part of a QUIC stream. |
|
Reset a QUIC stream associated with |
|
Message‐callback style tracer for SSL/TLS protocol records (for SSL_CTX_set_msg_callback). |
|
Increment the reference count of an SSL connection object. |
|
Assign a private key to an SSL connection (reference count incremented). |
|
Load a private key of type |
|
Load the first private key from a file into an SSL connection. |
|
|
Assign an RSA private key to an SSL connection (deprecated; use SSL_use_PrivateKey). |
|
Load an RSA private key from a DER encoding into an SSL connection (deprecated). |
|
Load an RSA private key from a PEM/DER file into an SSL connection (deprecated). |
Configure an SSL object's certificate, private key, and optional chain. |
|
Assign an X509 certificate to an SSL connection (reference count incremented). |
|
Load a DER‐encoded X.509 certificate into an SSL connection. |
|
Load a PEM certificate chain from |
|
Load the first certificate from a file into an SSL connection. |
|
Set the PSK identity hint advertised by a TLS server connection. |
|
|
Request TLSv1.3 post‐handshake client authentication from a server SSL. |
Return the numeric protocol version negotiated on a connection. |
|
Report whether an SSL connection is paused waiting for an async crypto job. |
|
Return the non‐blocking I/O want state of an SSL connection. |
|
Write application data from a buffer to a TLS/SSL connection. |
|
Write early data (0‐RTT) on a client SSL connection before the handshake completes. |
|
Write application data from a buffer to a TLS/SSL connection (size_t length). |
|
Write application data to a TLS/SSL/QUIC connection with extended write flags. |
|
Free a Strong Extranet (SXNET) identifier and its contents. |
|
Return the ASN.1 item descriptor for SXNETID. |
|
Allocate a new Strong Extranet (SXNET) identifier. |
|
Add a Strong Extranet zone/user id using an ASN.1 INTEGER zone number. |
|
Add a Strong Extranet zone/user id using an ASCII zone number. |
|
Add a Strong Extranet zone/user id using an unsigned long zone number. |
|
Free an SXNET structure and its contents. |
|
Look up the user id for a zone given as an ASN.1 INTEGER. |
|
Look up the user id for a zone given as an ASCII decimal string. |
|
Look up the user id for a zone given as an unsigned long. |
|
Return the ASN.1 item descriptor for SXNET. |
|
Allocate a new Strong Extranet (SXNET) extension value. |
|
Free a TLS Feature extension value and its contents. |
|
Allocate an empty TLS Feature extension value (stack of feature integers). |
|
Return a client‐only SSL_METHOD that negotiates the highest mutually supported TLS version. |
|
Return an SSL_METHOD that negotiates the highest mutually supported TLS version. |
|
Return a server‐only SSL_METHOD that negotiates the highest mutually supported TLS version. |
|
|
Return the deprecated TLSv1.1 client‐only method (prefer TLS_client_method). |
|
Return the deprecated TLSv1.1 client‐or‐server method (prefer TLS_method). |
|
Return the deprecated TLSv1.1 server‐only method (prefer TLS_server_method). |
|
Return the SSL_METHOD for a TLS 1.2 client‐only stack (deprecated). |
|
Return an SSL_METHOD for TLSv1.2 only (client and server; deprecated). |
|
Return a server‐only SSL_METHOD restricted to TLS 1.2 (deprecated; prefer TLS_server_method). |
|
Return the deprecated TLSv1.0 client‐only method (prefer TLS_client_method). |
|
Return a client‐or‐server SSL_METHOD restricted to TLS 1.0 (deprecated; prefer TLS_method). |
|
Return the deprecated TLSv1.0 server‐only method (prefer TLS_server_method). |
Duplicate a time‐stamp Accuracy. |
|
Free a time‐stamp Accuracy and its contents. |
|
Return the optional microseconds component of a time‐stamp accuracy. |
|
Return the optional milliseconds component of a time‐stamp accuracy. |
|
Return the seconds component of a time‐stamp accuracy structure. |
|
Allocate an empty time‐stamp Accuracy. |
|
Set the optional microseconds component of a time‐stamp accuracy. |
|
Set the optional milliseconds component of a time‐stamp accuracy. |
|
Set the seconds component of a time‐stamp accuracy structure. |
|
Print an ASN.1 INTEGER in decimal form to a BIO. |
|
Resolve the CONF section name used for TSA settings. |
|
Load a single X.509 certificate from a PEM file for TSA configuration. |
|
Load a stack of X.509 certificates from a PEM file for TSA configuration. |
|
Load a private key from a PEM file for TSA signing. |
|
Set TSTInfo Accuracy seconds/millis/micros on a response context from CONF. |
|
Load and set additional certificates included with TSA responses from CONF. |
|
|
Set genTime clock precision digits on a response context from CONF. |
Set the ENGINE crypto device name from configuration for TSA operations. |
|
Set the default TSA policy OID on a response context from CONF. |
|
Set the default OpenSSL ENGINE by name for time‐stamp configuration helpers. |
|
Add acceptable request digests listed in CONF to a response context. |
|
|
Configure whether ESS cert‐id attributes include the certificate chain from CONF. |
|
Set the ESS signing‐certificate digest algorithm from CONF. |
Enable or disable the TSTInfo ordering flag from CONF. |
|
Add acceptable TSA policies listed in CONF to a response context. |
|
Configure the serial‐number callback on a response context from CONF. |
|
Load and set the TSA signer certificate on a response context from CONF. |
|
Set the TSA signer digest on a response context from CONF. |
|
Load and set the TSA signer private key on a response context from CONF. |
|
Enable including the TSA name in generated TSTInfo structures from CONF. |
|
Duplicate a time‐stamp message imprint. |
|
Free a time‐stamp message imprint and its contents. |
|
Return the hash AlgorithmIdentifier from a message imprint (borrowed). |
|
Return the hashed message octets from a message imprint. |
|
Allocate an empty time‐stamp message imprint. |
|
Print a message imprint (algorithm and hash) to a BIO. |
|
Set the hash AlgorithmIdentifier of a message imprint. |
|
Set the hashed message octets of a message imprint. |
|
Print an ASN.1 object identifier in textual form to a BIO. |
|
Insert an extension into a time‐stamp request. |
|
Remove and return the request extension at index |
|
Duplicate a time‐stamp request. |
|
Free all extensions attached to a time‐stamp request. |
|
Free a time‐stamp request (TS_REQ) and its contents. |
|
Return whether the request asks the TSA to include certificates. |
|
Return the time‐stamp request extension at index |
|
Find the next request extension with NID |
|
Find the next request extension with object identifier |
|
|
Find the next request extension with criticality |
Return the number of extensions in a time‐stamp request. |
|
Decode the first request extension of type |
|
Return the extension stack from a time‐stamp request. |
|
Return the message imprint from a time‐stamp request. |
|
Return the optional nonce from a time‐stamp request (borrowed). |
|
Return the optional TSA policy OID from a time‐stamp request. |
|
Return the version field of a time‐stamp request. |
|
Allocate an empty time‐stamp request (TS_REQ). |
|
Print a human‐readable dump of a time‐stamp request to a BIO. |
|
Set whether the TSA should include its signing certificate in the response. |
|
Set the message imprint of a time‐stamp request. |
|
Set the optional nonce in a time‐stamp request. |
|
Set the optional TSA policy OID requested in a time‐stamp request. |
|
Set the version field of a time‐stamp request (typically 1). |
|
Initialise a verification context from the imprint, policy, and nonce of a request. |
|
|
Add a PKIFailureInfo bit to the status info of a response context. |
OR additional TS_RESP_CTX_* behaviour flags into a response context. |
|
Add an acceptable message‐digest algorithm for incoming requests. |
|
Add an acceptable TSA policy OID in addition to the default policy. |
|
Free a time‐stamp response context and associated resources. |
|
Return the parsed time‐stamp request associated with a response context. |
|
Return the TSTInfo being built in a response context (for extension callbacks). |
|
Allocate a time‐stamp response context using the default library context. |
|
Allocate a time‐stamp response context with an explicit library context. |
|
Set the Accuracy values included in generated TSTInfo structures. |
|
Set additional certificates included with generated time‐stamp responses. |
|
|
Set how many fractional‐second digits are included in genTime. |
|
Set the default TSA policy OID used when the request omits a policy. |
|
Set the digest used for ESS signing‐certificate attributes in responses. |
|
Install a callback that handles request extensions while building TSTInfo. |
|
Install the callback that supplies serial numbers for new TSTInfo structures. |
|
Set the TSA signing certificate used when creating responses. |
|
Set the message digest used when signing the PKCS#7 time‐stamp token. |
|
Set the private key used to sign time‐stamp responses. |
|
Set the response status and optional statusString text (unconditionally). |
|
Set status info only while the current status is still TS_STATUS_GRANTED. |
Install the callback that supplies the genTime value for new TSTInfo structures. |
|
Create a signed time‐stamp response for the DER request read from |
|
Duplicate a time‐stamp response. |
|
Free a time‐stamp response (TS_RESP) and its contents. |
|
Return the PKIStatusInfo from a time‐stamp response. |
|
Return the PKCS#7 time‐stamp token from a response. |
|
Return the parsed TSTInfo from a time‐stamp response. |
|
Allocate an empty time‐stamp response (TS_RESP). |
|
Print a human‐readable dump of a time‐stamp response to a BIO. |
|
Set the PKIStatusInfo of a time‐stamp response. |
|
Attach a signed time‐stamp token and parsed TSTInfo to a response. |
|
Verify a time‐stamp response against the criteria in |
|
Verify the signer certificate and signature of a PKCS#7 time‐stamp token. |
|
Verify a PKCS#7 time‐stamp token against the criteria in |
|
Duplicate a time‐stamp PKIStatusInfo. |
|
Free a time‐stamp PKIStatusInfo and its contents. |
|
|
Return the optional PKIFailureInfo bit string from a status‐info structure. |
Return the PKIStatus integer from a status‐info structure. |
|
Return the optional statusString texts from a status‐info structure. |
|
Allocate an empty time‐stamp PKIStatusInfo. |
|
Print a human‐readable dump of a TS_STATUS_INFO structure to a BIO. |
|
Set the PKIStatus integer in a status‐info structure. |
|
Insert an extension into a TSTInfo structure. |
|
Remove and return the TSTInfo extension at index |
|
Duplicate a time‐stamp token info. |
|
Free all extensions attached to a TSTInfo structure. |
|
Free a time‐stamp token info (TSTInfo) and its contents. |
|
Return the optional accuracy field from a TSTInfo structure. |
|
Return the TSTInfo extension at index |
|
|
Find the next TSTInfo extension with NID |
|
Find the next TSTInfo extension with object identifier |
|
Find the next TSTInfo extension with criticality |
|
Return the number of extensions in a TSTInfo structure. |
Decode the first TSTInfo extension of type |
|
Return the extension stack from a TSTInfo structure. |
|
|
Return the message imprint from a TSTInfo structure. |
Return the optional nonce echoed from the request in a TSTInfo structure. |
|
Return the ordering flag from a TSTInfo structure. |
|
|
Return the TSA policy OID from a TSTInfo structure. |
Return the serial number from a TSTInfo structure. |
|
Return the genTime time‐stamp instant from a TSTInfo structure. |
|
Return the optional TSA name from a TSTInfo structure. |
|
Return the version field from a TSTInfo structure. |
|
Allocate an empty time‐stamp token info (TSTInfo). |
|
Print a human‐readable dump of a TSTInfo structure to a BIO. |
|
Set the optional accuracy field of a TSTInfo structure. |
|
|
Set the message imprint in a TSTInfo structure. |
Set the optional nonce echoed from the request in a TSTInfo structure. |
|
Set the ordering flag indicating whether time‐stamps from this TSA are ordered. |
|
|
Set the TSA policy OID in a TSTInfo structure. |
Set the serial number uniquely identifying a time‐stamp token. |
|
Set the genTime time‐stamp instant in a TSTInfo structure. |
|
Set the optional TSA name in a TSTInfo structure. |
|
Set the version field of a TSTInfo structure (typically 1). |
|
Add TS_VFY_* bits to the verification flags. |
|
Release resources held by a verification context and clear it for reuse. |
|
Free a verification context allocated by TS_VERIFY_CTX_new(). |
|
Initialize a verification context to a cleared empty state. |
|
Allocate an empty time‐stamp verification context. |
|
Set the untrusted certificate stack used when verifying a time‐stamp token. |
|
Set the BIO of raw data used when TS_VFY_DATA is enabled. |
|
Replace the verification flags with |
|
Set the expected message imprint used when TS_VFY_IMPRINT is enabled. |
|
Set the trusted certificate store used when verifying a time‐stamp token. |
|
Print an X509_ALGOR AlgorithmIdentifier to a BIO. |
|
Print a stack of X.509 extensions in human‐readable form to a BIO. |
|
Build a hash index on column |
|
Free a text database and all stored rows. |
|
Look up a row by the value of indexed field |
|
Insert a row into a text database and update any indexes. |
|
Read a text database from a BIO into memory. |
|
Write a text database to a BIO in comma‐separated row format. |
|
Return OpenSSL's built‐in console UI_METHOD (machine/OS‐dependent prompting). |
|
Prompt for a passphrase, using |
|
Prompt for a passphrase into |
|
|
Build a temporary UI_METHOD that wraps a PEM password callback. |
Add an error message string to a UI for display (pointer stored, not copied). |
|
Add informational text shown with other prompts (pointer used verbatim). |
|
Add a yes/no prompt that stores one OK or Cancel character in |
|
Add a prompt that collects a string into a caller‐owned result buffer. |
|
Store application user data on a UI, replacing any previous pointer. |
|
Add a string prompt whose result must match |
|
Build a heap‐allocated prompt string for an input description and optional object name. |
|
Allocate a new UI_METHOD with the given name. |
|
Send a parameterised control command to a UI (or query UI state). |
|
Destroy a UI_METHOD created with UI_create_method(). |
|
Add an error/info string, duplicating |
|
Add informational text after copying |
|
Add a boolean prompt, copying the prompt strings into |
|
Add a string prompt, duplicating |
|
Duplicate |
|
Add a password prompt that must match |
|
Free a UI and any duplicated strings, results, and related storage. |
|
Return the optional action description for a boolean UI_STRING. |
|
Return the string to present to the user for a UI_STRING (prompt, info, or error). |
|
Return the result text for a UI prompt by its add‐index. |
|
Return the user‐entered result string stored on a prompt UI_STRING. |
|
Return the reference string a verify prompt's result must match. |
|
Return the application user data last set with UI_add_user_data or UI_dup_user_data. |
|
Return the process‐wide default UI_METHOD used by UI_new(). |
|
Retrieve application‐specific ex_data previously stored on a UI. |
|
Return the input flags associated with a UI_STRING. |
|
Return the UI_METHOD currently associated with a UI instance. |
|
Return the length in bytes of the result text for a UI prompt by its add‐index. |
|
Return the maximum allowed length of the result for a prompt UI_STRING. |
|
Return the minimum accepted result length for a UI string prompt. |
|
Return the length in bytes of the result stored on a prompt UI_STRING. |
|
Return which kind of UI prompt or message a UI_STRING represents. |
|
Return the closer callback previously set on a UI_METHOD. |
|
Return the user‐data destructor callback previously set on a UI_METHOD. |
|
Return the user‐data duplicator callback previously set on a UI_METHOD. |
|
Return application ex_data previously stored on a UI_METHOD. |
|
Return the flusher callback previously set on a UI_METHOD. |
|
Return the opener callback previously set on a UI_METHOD. |
|
|
Return the prompt‐constructor callback previously set on a UI_METHOD. |
Return the reader callback previously set on a UI_METHOD. |
|
Return the writer callback previously set on a UI_METHOD. |
|
Set the closer callback that ends a UI session (for example closes a tty or window). |
|
Set callbacks used by UI_dup_user_data() to copy and free method user data. |
|
Store application‐specific ex_data on a UI_METHOD at index |
|
Set the flusher callback that presents accumulated UI output (for example shows a dialog). |
|
Set the opener callback that starts a UI session (for example opens a tty or window). |
|
|
Set the callback that builds prompt strings for a UI_METHOD. |
Set the reader callback that collects input for each UI_STRING prompt. |
|
Set the writer callback that outputs each UI_STRING (prompt label, info, or error). |
|
Allocate a new UI that uses the process‐wide default UI_METHOD. |
|
Create a new UI that uses the given method instead of the default. |
|
Return a no‐op UI_METHOD that performs no prompting. |
|
Run the UI method to present prompts and collect answers for all added strings. |
|
Change the process‐wide default UI_METHOD used by UI_new(). |
|
Store application‐specific ex_data on a UI at index |
|
Replace the UI_METHOD associated with an existing UI instance. |
|
Store a NUL‐terminated prompt result on a UI_STRING (length taken from the string). |
|
Store a prompt result of explicit length on a UI_STRING. |
|
Free a user notice policy qualifier and its contents. |
|
Return the ASN.1 item descriptor for USERNOTICE. |
|
Allocate an empty user notice policy qualifier. |
|
Decode one Unicode code point from a UTF‐8 byte sequence. |
|
Encode one Unicode code point as UTF‐8. |
|
|
Compute the WHIRLPOOL digest of |
|
Absorb |
|
Finalise a WHIRLPOOL digest into a 64‐byte buffer (deprecated; prefer EVP_DigestFinal_ex). |
|
Initialize a low‐level WHIRLPOOL digest context (deprecated; prefer EVP_DigestInit_ex). |
|
Absorb more message bytes into a WHIRLPOOL digest context (deprecated). |
Add CRL extensions described by a config section to a CRL. |
|
Add all extensions from a configuration section to a CRL. |
|
Add all extensions from an LHASH configuration section to a certificate request (legacy). |
|
Add all extensions from a configuration section to a certificate request. |
|
Register a custom X.509v3 extension method. |
|
Alias an existing X.509v3 extension method under a new NID. |
|
Add all extensions from an LHASH configuration section to a certificate (legacy). |
|
Register a NULL‐terminated list of custom X.509v3 extension methods. |
|
Add all extensions from a configuration section to a certificate. |
|
Add all extensions from a configuration section to an extension stack. |
|
Unregister and free all dynamically added custom X.509v3 extension methods. |
|
Create an X.509v3 extension from a named LHASH configuration value (legacy). |
|
Create an X.509v3 extension from an LHASH configuration by NID (legacy). |
|
Decode the ASN.1 value of an X509_EXTENSION into its extension‐specific C structure. |
|
Look up the registered X509V3_EXT_METHOD for an X509_EXTENSION by its OID. |
|
Look up the registered X509V3_EXT_METHOD for an extension NID. |
|
Build an X509_EXTENSION by encoding an extension‐specific structure. |
|
Create an X.509v3 extension from a named configuration value. |
|
Create an X.509v3 extension from a configuration value identified by NID. |
|
Print a single X.509v3 extension in human‐readable form to a BIO. |
|
Print a single X.509v3 extension in human‐readable form to a FILE stream. |
|
Print a stack of CONF_VALUE extension values to a BIO with indentation. |
|
Populate an X509_NAME from a stack of configuration DN name/value pairs. |
|
Encode extension structure |
|
Add the built‐in standard X509v3 extension definitions (legacy compatibility). |
|
Append a name/value pair to a CONF_VALUE stack used by X509v3 helpers. |
|
Append a boolean CONF_VALUE named |
|
Append a boolean CONF_VALUE named |
|
Append a name/value pair whose value is the decimal form of an ASN1_INTEGER. |
|
Append a name/value pair whose value is an unsigned‐char C string to a CONF_VALUE stack. |
|
Free a CONF_VALUE previously produced for X.509v3 configuration helpers. |
|
Print a stack of X.509v3 extensions to a BIO with an optional section title. |
|
Decode the first (or next) extension of type |
|
Load a named configuration section via the context's CONF method. |
|
Look up a configuration string via the X509V3_CTX database method. |
|
Parse a CONF_VALUE as a boolean into an ASN.1 boolean integer. |
|
Parse a CONF_VALUE as an integer into a newly allocated ASN1_INTEGER. |
|
Parse a comma‐separated name[=value]list into a stack of CONF_VALUE entries. |
|
Free a CONF_VALUE section previously returned by X509V3_get_section(). |
|
Attach a legacy LHASH configuration database to an extension context. |
|
Fill an X509V3_CTX with the certificates, request, CRL, and flags used when building extensions. |
|
Set the issuer private key used as a fallback when building authority key identifiers. |
|
Attach an NCONF configuration database to an extension context. |
|
Free a string previously returned by X509V3_get_string() using the context's conf method. |
|
Return the ASN.1 item descriptor for X509_ALGORS. |
|
Compare two AlgorithmIdentifier values for equality. |
|
Copy an AlgorithmIdentifier into an existing X509_ALGOR object. |
|
Deep‐copy an X509_ALGOR (AlgorithmIdentifier). |
|
Free an X.509 AlgorithmIdentifier and its contents. |
|
Borrow pointers to the algorithm OID and parameter from an X509_ALGOR. |
|
Return the ASN.1 item descriptor for X509_ALGOR. |
|
Allocate an empty X.509 AlgorithmIdentifier. |
|
Set the algorithm OID and parameter of an X509_ALGOR, transferring ownership. |
|
Set an X509_ALGOR to identify a message digest algorithm. |
|
Return the number of values held by an X509_ATTRIBUTE. |
|
Create an X.509 Attribute from a NID and a single ASN.1 value. |
|
Create or reuse an X.509 Attribute identified by NID with typed data. |
|
Create or reuse an X.509 Attribute identified by OID with typed data. |
|
Create an X509_ATTRIBUTE from a textual OID/name and value bytes. |
|
Deep‐copy an X.509 Attribute. |
|
Free an X.509 Attribute and its contents. |
|
Return the typed value pointer for attribute entry |
|
Return the object identifier that names an X509_ATTRIBUTE. |
|
Return the ASN.1 value at index |
|
Return the ASN.1 item descriptor for X509_ATTRIBUTE. |
|
Allocate an empty X.509 Attribute structure. |
|
Set the attribute value from typed bytes (copies |
|
Set the OID of attribute |
|
Free certificate auxiliary info and its contents. |
|
Return the ASN.1 item descriptor for X509_CERT_AUX. |
|
Allocate empty certificate auxiliary info (trust/reject/alias/keyid). |
|
Free a X.509 TBSCertificate (X509_CINF) structure and its contents. |
|
Return the ASN.1 item descriptor for X509_CINF. |
|
Allocate an empty X.509 TBSCertificate (X509_CINF) structure. |
|
Free a X.509 CRL information (tbsCertList) structure and its contents. |
|
Return the ASN.1 item descriptor for X509_CRL_INFO. |
|
Allocate an empty X.509 CRL information (tbsCertList) structure. |
|
Free a custom CRL method allocated by X509_CRL_METHOD_new(). |
|
Allocate a custom CRL method with optional init, free, lookup, and verify callbacks. |
|
Append revoked‐certificate entry |
|
Encode |
|
Insert a duplicate of extension |
|
Check that a CRL satisfies Suite B signature/algorithm constraints. |
|
Compare two CRLs by issuer name. |
|
Remove and return the extension at index |
|
Construct a delta CRL listing revocations in |
|
Compute a digest of the DER encoding of an entire X.509 CRL. |
|
Deep‐copy an X.509 certificate revocation list. |
|
Free an X.509 CRL and its contents. |
|
Find a revoked‐certificate entry in a CRL matching certificate |
|
Find a revoked‐certificate entry in a CRL by serial number. |
|
Return the stack of extensions on a CRL (crlExtensions), if any. |
|
Return the thisUpdate (lastUpdate) time of a CRL without copying. |
|
Return the nextUpdate time of a CRL, if present. |
|
Obtain internal pointers to a CRL's signature value and signature algorithm. |
|
Return the mutable stack of revoked‐certificate entries in a CRL. |
|
Return the CRL extension at index |
|
Find the next extension on a CRL with the given NID. |
|
Find the next CRL extension whose OID equals |
|
|
Find a CRL extension by criticality flag, searching after |
Return the number of extensions on a CRL. |
|
Decode the first (or next) CRL extension with NID |
|
Return the issuer X509_NAME of a certificate revocation list. |
|
|
Return the CRL thisUpdate time (deprecated alias of X509_CRL_get0_lastUpdate). |
Return the method‐specific application data previously set on a CRL. |
|
|
Return the nextUpdate field of a CRL (deprecated; prefer X509_CRL_get0_nextUpdate). |
Return the NID of the signature algorithm used on CRL |
|
Return the numerical version field of an X.509 CRL. |
|
Return the ASN.1 item descriptor for X509_CRL. |
|
Load an X.509 CRL in ASN.1/DER form via HTTP from |
|
Compare two CRLs by issuer name and signature value. |
|
Allocate an empty X.509 Certificate Revocation List. |
|
Allocate an empty X509_CRL associated with a library context. |
|
Print a human‐readable CRL dump to BIO |
|
Print a human‐readable CRL to a BIO, with name‐printing flags. |
|
Print a CRL to a FILE using default formatting. |
|
Set the thisUpdate field of a certificate revocation list. |
|
Set the nextUpdate time on a certificate revocation list by copying |
|
Install the default custom CRL method used when looking up revoked entries. |
|
Set the issuer distinguished name on a certificate revocation list. |
|
Attach method‐specific application data to a CRL for its X509_CRL_METHOD callbacks. |
|
Set the version field of a certificate revocation list. |
|
Sign a certificate revocation list with a private key and digest. |
|
Sign a CRL using an initialized digest/signing context. |
|
Sort the revoked‐certificate entries of a CRL by serial number. |
|
Increment the reference count on a CRL. |
|
Verify a CRL's signature with the issuer public key |
|
Return the ASN.1 item descriptor for X509_EXTENSIONS. |
|
Create (or reuse) an X509_EXTENSION with the given NID, criticality, and octet data. |
|
Create (or reuse) an X509_EXTENSION with OID |
|
Deep‐copy an X.509 certificate extension. |
|
Free a X.509 extension and its contents. |
|
Report whether an X.509 extension is marked critical. |
|
Return the OCTET STRING payload of an X.509 extension. |
|
Return the OID identifying an X.509v3 extension's type. |
|
Return the ASN.1 item descriptor for X509_EXTENSION. |
|
Allocate an empty X.509 extension. |
|
Set whether an X.509v3 extension is marked critical. |
|
Set the OCTET STRING data of an X.509v3 extension (duplicated internally). |
|
Set the extension OID on an X509_EXTENSION, copying |
|
Free an X509_INFO and any certificate, CRL, or key it owns. |
|
Allocate an empty X509_INFO (certificate/CRL/key PEM bundle entry). |
|
Look up a certificate or CRL by alias / friendly name through a lookup method. |
|
Look up a certificate or CRL in a lookup method by fingerprint. |
|
Look up a certificate in a lookup method by issuer name and serial number. |
|
Look up a certificate or CRL by subject name via a lookup method. |
|
Look up a certificate or CRL by subject name with an explicit library context. |
|
Invoke the control method of an X509_LOOKUP (no explicit library context). |
|
Invoke the control method of an X509_LOOKUP with an explicit library context. |
|
Return the built‐in lookup method that loads certificates and CRLs from PEM/DER files. |
|
Free an X509_LOOKUP and its method‐specific state. |
|
Return the method‐specific opaque data attached to an X509_LOOKUP. |
|
Return the X509_STORE that owns a lookup object. |
|
Return the built‐in lookup method that loads certificates and CRLs from a hashed directory. |
|
Initialize an X509_LOOKUP by invoking its method's init callback. |
|
Free an X509_LOOKUP_METHOD previously created with X509_LOOKUP_meth_new(). |
|
Return the control callback registered on an X509_LOOKUP_METHOD. |
|
Return the free callback registered on an X509_LOOKUP_METHOD. |
|
|
Return the get‐by‐alias callback from an X509_LOOKUP_METHOD. |
|
Return the get‐by‐fingerprint function pointer installed on a lookup method. |
|
Return the get‐by‐issuer‐and‐serial callback from an X509_LOOKUP_METHOD. |
|
Return the get‐by‐subject callback from an X509_LOOKUP_METHOD. |
Return the initialization callback registered on an X509_LOOKUP_METHOD. |
|
|
Return the new‐item callback from an X509_LOOKUP_METHOD. |
Return the shutdown callback registered on an X509_LOOKUP_METHOD. |
|
Allocate a new custom X509_LOOKUP_METHOD with the given method name. |
|
Install the control callback on an X509_LOOKUP_METHOD. |
|
Set the method callback that frees a lookup context's method‐specific state. |
|
|
Set the get‐by‐alias callback on an X509_LOOKUP_METHOD. |
|
Set the get‐by‐fingerprint callback on an X509_LOOKUP_METHOD. |
|
Set the get‐by‐issuer‐and‐serial callback on an X509_LOOKUP_METHOD. |
|
Set the get‐by‐subject callback on an X509_LOOKUP_METHOD. |
Set the initialization callback on an X509_LOOKUP_METHOD. |
|
|
Set the per‐LOOKUP instance constructor callback on an X509_LOOKUP_METHOD. |
Set the shutdown callback for a custom X509_LOOKUP_METHOD. |
|
Create a new X509_LOOKUP using the given lookup method. |
|
Attach method‐specific opaque data to an X509_LOOKUP. |
|
Shut down a lookup object, releasing method‐specific resources via its shutdown callback. |
|
Return the X509_LOOKUP_METHOD that loads certificates/CRLs via OSSL_STORE URIs. |
|
|
Create an X509_NAME_ENTRY from an attribute NID and value bytes. |
|
Create an X509_NAME_ENTRY from an ASN1_OBJECT, string type, and value. |
|
Create an X509_NAME_ENTRY from a textual attribute name and value bytes. |
Deep‐copy an X509_NAME_ENTRY. |
|
Free a X.509 Name entry (AttributeTypeAndValue) and its contents. |
|
Return the attribute value string of an X509_NAME_ENTRY. |
|
Return the attribute type OID of an X509_NAME_ENTRY. |
|
Return the ASN.1 item descriptor for X509_NAME_ENTRY. |
|
Allocate an empty X.509 Name entry (AttributeTypeAndValue). |
|
Return the RDN set index of a name entry within its X509_NAME. |
|
Set the attribute value of an X509_NAME_ENTRY. |
|
Set the attribute type OID of an X509_NAME_ENTRY. |
|
Insert a copy of name entry |
|
|
Add an RDN attribute identified by |
|
Add an RDN attribute identified by ASN.1 object |
|
Add a name entry identified by field name |
Compare two X.509 distinguished names for equality. |
|
Remove and return the name entry at index |
|
Compute a digest of the DER encoding of an X.509 Name (DN). |
|
Deep‐copy an X.509 Name (distinguished name). |
|
Return the number of X509_NAME_ENTRY values in a distinguished name. |
|
Free a X.509 distinguished name (Name) and its contents. |
|
Return a pointer to the cached DER encoding of an X509_NAME. |
|
Return the name entry at index |
|
|
Find the next X509_NAME entry matching a NID after |
|
Find the next name entry whose attribute type matches an ASN1_OBJECT. |
|
Copy the UTF‐8/text value of the first name entry with NID |
|
Copy the first RDN text matching OID |
Hash an X.509 Name for directory lookup using SHA‐1 via |
|
Return the legacy MD5‐based hash of an X509_NAME (old subject_hash algorithm). |
|
Return the ASN.1 item descriptor for X509_NAME. |
|
Allocate an empty X.509 distinguished name (Name). |
|
Format an X509_NAME as a legacy one‐line slash‐separated string. |
|
Print an X.509 distinguished name to a BIO with legacy oneline‐style wrapping. |
|
Print a human‐readable X509_NAME to a BIO with customizable formatting flags. |
|
Print an X509_NAME to a FILE with indentation and XN_FLAG_* formatting. |
|
Replace *`xn` with a duplicate of |
|
Free an X509_OBJECT and release any referenced certificate or CRL. |
|
Return the certificate stored in an X509_OBJECT, if any. |
|
Return the CRL stored in an X509_OBJECT, if any. |
|
Return whether an X509_OBJECT holds a certificate, CRL, or nothing. |
|
Find the first X509_OBJECT in a stack whose subject matches |
|
Allocate an empty X509_OBJECT container for a certificate or CRL. |
|
Find the first X509_OBJECT in |
|
Find an X509_OBJECT in |
|
Store a certificate in an X509_OBJECT, taking a reference to |
|
Store a CRL in an X509_OBJECT, taking a reference to |
|
Increment the reference count on the certificate or CRL held by an X509_OBJECT. |
|
Free an X509_PKEY and its encrypted‐key contents. |
|
Allocate an empty X509_PKEY structure for encrypted private‐key packaging. |
|
Print a certificate policy tree node (OID, criticality, qualifiers) to a BIO. |
|
Deep‐copy an X509_PUBKEY (SubjectPublicKeyInfo) structure. |
|
Compare two X509_PUBKEY structures for equality. |
|
Free a X.509 SubjectPublicKeyInfo (X509_PUBKEY) and its contents. |
|
Decode an X509_PUBKEY into an EVP_PKEY with an incremented reference count. |
|
Return the EVP_PKEY decoded from an X509_PUBKEY without incrementing its refcount. |
|
Return pointers to the algorithm and bit‐string components of a SubjectPublicKeyInfo. |
|
Return the ASN.1 item descriptor for X509_PUBKEY. |
|
Allocate an empty X.509 SubjectPublicKeyInfo (X509_PUBKEY). |
|
Allocate an empty X509_PUBKEY associated with a library context and property query. |
|
Set an X509_PUBKEY from an EVP_PKEY, allocating or replacing *`x` as needed. |
|
Set algorithm and encoded public‐key bits on |
|
Set the encoded public‐key bit string on an X509_PUBKEY, transferring ownership of |
|
Register or replace a certificate purpose entry in the purpose table. |
|
Free all dynamically registered purpose table entries. |
|
Return the purpose table entry at a numeric index. |
|
Return the long human‐readable name of a purpose table entry. |
|
Return the short name of a purpose table entry. |
|
Look up a purpose table index by purpose identifier. |
|
Look up a purpose table index by short name. |
|
Return how many entries are in the X509_PURPOSE table. |
|
Return the purpose identifier from a purpose table entry. |
|
Return the default trust identifier associated with a purpose entry. |
|
Store a purpose identifier after validating it against the purpose table. |
|
Free an X.509 certificate request info structure and its contents. |
|
Return the ASN.1 item descriptor for X509_REQ_INFO. |
|
Allocate an empty X.509 certificate request info (tbsRequest) structure. |
|
Append a duplicate of |
|
|
Append an attribute identified by NID to a certificate request. |
|
Append an attribute identified by OID |
|
Add an attribute named by |
Embed a copy of extension stack |
|
Add a stack of extensions to a certificate request under attribute OID |
|
Check that |
|
Remove and return the attribute at index |
|
Digest the DER encoding of a certificate request with hash |
|
Deep‐copy an X.509 certificate signing request. |
|
Test whether |
|
Free a X.509 certificate signing request and its contents. |
|
Return the Distinguishing ID attached to a certificate request, if any. |
|
Return the request subject public key without incrementing its reference count. |
|
Return internal pointers to a request's signature value and AlgorithmIdentifier. |
|
Collect email addresses from a certificate request's subject and subjectAltName. |
|
Return the X509_PUBKEY structure holding the request's subject public key. |
|
Return the X.509 request attribute at index |
|
Find the next X.509 request attribute with the given NID. |
|
Find the next certificate‐request attribute whose OID equals |
|
Return the number of attributes in a certificate request. |
|
Return the NID list used when locating extensions embedded in a certificate request. |
|
Return the first stack of X.509 extensions found in a certificate request's attributes. |
|
Return a new EVP_PKEY copy of the public key from a certificate request. |
|
Return the NID of the digest used in a request's signature AlgorithmIdentifier. |
|
Return the subject name of a certificate request. |
|
Return the version field of a certificate request (0 for v1). |
|
Return the ASN.1 item descriptor for X509_REQ. |
|
Allocate an empty X.509 certificate signing request. |
|
Allocate an empty X509_REQ associated with a library context and property query. |
|
Print a certificate request to a BIO using default name/content flags. |
|
Print a certificate request to a BIO with name and content formatting flags. |
|
Print a certificate request to a FILE using default formatting. |
|
Attach a Distinguishing ID to a certificate request, transferring ownership of |
|
Set the request signature bit string, transferring ownership of |
|
Set the signature AlgorithmIdentifier on a certificate request by copying |
|
Set the global list of NIDs recognized as certificate‐request extension attributes. |
|
Set the public key on a certificate request from |
|
Set the subject name of a certificate request by copying |
|
Set the version field of a certificate request. |
|
Sign a certificate request with a private key and message digest. |
|
Sign certificate request |
|
Build a self‐signed X.509 certificate from a certificate request. |
|
Verify a certificate request's signature with public key |
|
Verify a certificate request's signature with an explicit library context. |
|
Encode an extension value and add it to a revoked‐certificate entry. |
|
Insert a copy of extension |
|
Remove and return the extension at index |
|
Deep‐copy a CRL revoked‐certificate entry. |
|
Free a CRL revoked‐certificate entry and its contents. |
|
Return the stack of extensions on a CRL revoked‐entry, if any. |
|
Return the revocation date of a revoked‐certificate entry. |
|
Return the serial number of a revoked‐certificate entry without copying it. |
|
Return the extension at index |
|
|
Find the next revoked‐entry extension whose NID equals |
|
Find the next revoked‐entry extension whose OID equals |
|
Find the next revoked‐entry extension with criticality |
Return the number of X.509v3 extensions on a revoked‐certificate entry. |
|
Decode the first matching extension of type |
|
Return the ASN.1 item descriptor for X509_REVOKED. |
|
Allocate an empty CRL revoked‐certificate entry. |
|
Set the revocation time on a revoked‐entry object, copying |
|
Set the certificate serial number on a revoked‐entry object, copying |
|
Read digest NID, public‐key NID, security bits, and flags from X509_SIG_INFO. |
|
Populate an X509_SIG_INFO with digest NID, public‐key NID, security bits, and flags. |
|
Free an X.509 signature structure and its contents. |
|
Borrow const pointers to the AlgorithmIdentifier and digest octets of an X509_SIG. |
|
Borrow mutable pointers to the AlgorithmIdentifier and digest octets of an X509_SIG. |
|
Return the ASN.1 item descriptor for X509_SIG. |
|
Allocate an empty X.509 signature (algorithm + digest) structure. |
|
Release verification state inside |
|
Free an X509_STORE_CTX and release resources it owns. |
|
Return an internal pointer to the certificate being verified. |
|
Return the verified certificate chain built for |
|
|
Return the CRL currently being considered during revocation checking. |
|
Return the issuer certificate currently being considered during chain building. |
Return the verification parameters associated with a store context. |
|
|
Return the parent store context when |
|
Return the policy tree built during verification of |
Return the raw public key being verified, if any. |
|
Return the X509_STORE associated with a verification context. |
|
Return the stack of untrusted certificates associated with a verification context. |
|
Return certificates from the store whose subject name matches |
|
Return a new reference to the verified certificate chain built for |
|
Retrieve CRLs from the store behind |
|
Find a candidate issuer certificate for |
|
|
Look up a certificate or CRL by subject name via the store of |
|
Return the cert‐against‐CRL check callback installed on a store context. |
|
Return the check_crl callback currently installed on a verification context. |
|
Return the check_issued callback currently installed on a verification context. |
|
Return the certificate‐policy check callback installed on a store context. |
|
Return the revocation‐checking callback installed on a verification context. |
Return the cleanup callback installed on a store context. |
|
|
Return the certificate currently being examined during verification. |
Return the verification error code stored in a context. |
|
|
Return the certificate‐chain depth at which the current verification error occurred. |
|
Retrieve application‐specific ex_data previously stored on a verification context. |
|
Return whether an explicit certificate policy was required/found during verification. |
|
Return the get_crl callback currently installed on a verification context. |
|
Return the get_issuer callback currently installed on a verification context. |
|
Return the lookup_certs callback currently installed on a verification context. |
|
Return the CRL‐lookup callback installed on a store context. |
|
Return how many certificates at the start of the chain were untrusted. |
|
Look up a certificate or CRL by subject name and return a new X509_OBJECT wrapper. |
Return the chain‐verification callback installed on a store context. |
|
|
Return the verify‐result callback installed on a store context. |
Initialize a verification context for validating |
|
Initialise a verification context to validate raw public key |
|
Allocate an empty X509_STORE_CTX using the default library context. |
|
Allocate an empty X509_STORE_CTX using an explicit library context. |
|
|
Default verify callback that prints diagnosis details when verification fails. |
Inherit purpose and trust onto a store context, falling back to defaults when unset. |
|
Provide an additional CRL stack for revocation checks on |
|
Attach DANE authentication state to a certificate verification context. |
|
Transfer ownership of verification parameters to a store context. |
|
Set a raw public key as the verification target, transferring ownership of |
|
|
Use a stack of certificates as the trusted set for a verification context. |
Set the untrusted intermediate certificate stack used during chain building. |
|
|
Transfer ownership of a verified certificate chain into a store context. |
Set the end‐entity certificate that |
|
|
Set the certificate in |
|
Set the CRL reason bitmask associated with the current revocation check on |
Apply a named built‐in X509_VERIFY_PARAM set to a store context. |
|
Limit how deep an X509_STORE_CTX certificate chain may grow during verification. |
|
Set the current verification error code on a store context. |
|
|
Set the certificate‐chain depth associated with the current verification error. |
|
Store application ex_data on a verification context at index |
OR additional X509_V_FLAG_* verification flags into |
|
|
Override the get‐CRL callback on a verification context. |
Set the intended certificate purpose for a verification context. |
|
Override the validation time used when checking certificate/CRL validity on |
|
Set the trust setting used when verifying with a store context. |
|
Override the default chain‐verify function on a verification context. |
|
|
Install a verify callback on a store context (overrides the store default). |
Verify the certificate chain prepared in an X509_STORE_CTX. |
|
Add a certificate to an X509_STORE's trusted‐certificate cache. |
|
Add a CRL to an X509_STORE's cache. |
|
Attach a new X509_LOOKUP of method |
|
Free an X509_STORE and release its references to certificates, CRLs, and lookups. |
|
Return the internal cache of certificates and CRLs held by a store. |
|
Return the verification parameters associated with a certificate store. |
|
Return a new stack of every X.509 certificate currently cached in a store. |
|
Return a deep‐copied snapshot of every object cached in an X509_STORE. |
|
Return the cert‐against‐CRL check callback installed on a store. |
|
Return the CRL‐check callback installed on a certificate store. |
|
Return the check‐issued callback installed on a certificate store. |
|
Return the certificate‐policy check callback installed on a store. |
|
Return the certificate‐revocation check callback installed on a store. |
|
Return the cleanup callback installed on X509_STORE |
|
Retrieve application data previously stored on an X509_STORE. |
|
Return the get‐CRL callback installed on a certificate store. |
|
Return the get‐issuer callback currently installed on a certificate store. |
|
Return the certificate‐by‐name lookup callback installed on an X509_STORE. |
|
Return the CRL‐lookup callback installed on a certificate store. |
|
Return the chain‐verify callback installed on a certificate store. |
|
Return the verify‐result callback installed on a certificate store. |
|
Load trusted certificates from a PEM/DER file into a store. |
|
Load trusted certificates from a PEM/DER file into a store, with provider selection. |
|
Load trusted certificates from a PEM file and/or a hashed certificate directory. |
|
Load trusted certificates from |
|
Load trusted certificates from every file in a hashed directory into a store. |
|
Load trusted certificates from an OSSL_STORE URI into a store. |
|
Load trusted certificates from an OSSL_STORE URI, with provider selection. |
|
Acquire a write lock on an X509_STORE for thread‐safe mutation. |
|
Allocate a new X.509 certificate store for trusted certificates and CRLs. |
|
Copy verification parameters from |
|
Install the cert‐against‐CRL check callback used by verifications from this store. |
|
Install a callback that verifies CRLs for a certificate store. |
|
Install the check‐issued callback used by verifications from this store. |
|
Install the certificate‐policy check callback used by verifications from this store. |
|
Install the certificate‐revocation check callback used by verifications from this store. |
|
Install a cleanup callback inherited by X509_STORE_CTX objects from this store. |
|
Load the default system CA file and directory into certificate store |
|
|
Load the default CA file, directory, and store into |
Set the maximum untrusted chain depth for verifications using |
|
Store application ex_data on an X509_STORE at index |
|
Set verification behaviour flags on an X509_STORE (OR of X509_V_FLAG_*). |
|
Install the CRL‐retrieval callback inherited by contexts created from this store. |
|
Set the get‐issuer callback used by store contexts created from |
|
Install the certificate‐by‐name lookup callback used by verifications from this store. |
|
Install the CRL‐by‐name lookup callback used by verifications from this store. |
|
Set the default certificate purpose applied when verifying with this store. |
|
Set the default trust setting applied when verifying with this store. |
|
Install the chain‐verify callback used by store contexts created from |
|
Install the verify‐result callback inherited by contexts created from this store. |
|
Release a write lock previously taken with X509_STORE_lock(). |
|
Increment the reference count on an X509_STORE. |
|
Register a custom X509_TRUST checking method under |
|
Free all dynamically registered X509_TRUST table entries. |
|
Return the X509_TRUST table entry at index |
|
Return the short name of an X509_TRUST table entry. |
|
Return the table index of the X509_TRUST entry with trust id |
|
Return the number of entries in the global X509_TRUST table. |
|
Return the flag bits associated with an X509_TRUST table entry. |
|
Return the trust purpose identifier of an X509_TRUST table entry. |
|
Store a trust identifier if it is a known X509_TRUST id. |
|
Install a process‐wide default trust‐checking callback. |
|
Free an X509_VAL structure and its contents. |
|
Return the ASN.1 item descriptor for X509_VAL. |
|
Allocate a new X509_VAL (notBefore/notAfter validity interval). |
|
Append a certificate policy OID to a verification parameter set (takes ownership). |
|
Register |
|
Append an expected DNS/IP hostname for name checks without clearing existing hosts. |
|
Clear X509_V_FLAG_* bits from verification parameters. |
|
Free an X509_VERIFY_PARAM and any associated host/email/IP data. |
|
Return a built‐in X509_VERIFY_PARAM by table index. |
|
Return the expected RFC822 email address set on verification parameters. |
|
Return an expected hostname previously set for name checks. |
|
Return the name associated with an X509_VERIFY_PARAM object. |
|
Return the peer DNS hostname or subject CN that matched a configured name check. |
|
|
Return a newly allocated ASCII form of the expected IP address for name checks. |
|
Return the authentication security level required by verification parameters. |
Return how many named entries are in the global X509_VERIFY_PARAM table. |
|
Return the maximum certificate‐chain depth allowed by verification parameters. |
|
Return the verification flag mask stored in |
|
Return the hostname‐checking flags stored in verification parameters. |
|
|
Return the inheritance‐control flags stored in |
Return the verification time stored in a parameter set. |
|
Copy unset fields from |
|
Look up a built‐in named X509_VERIFY_PARAM by name. |
|
Move the peername string from |
|
Allocate a new certificate‐verification parameter object with default settings. |
|
Copy all verification settings from |
|
Set the expected RFC822 mailbox for certificate name checks. |
|
Set the expected DNS/IP hostname for name checks, clearing any previous hosts. |
|
Set the expected IP address for certificate name checks (binary form). |
|
|
Set the expected IP address from a NUL‐terminated ASCII string. |
Set the name of an X509_VERIFY_PARAM (used when inheriting named defaults). |
|
Replace the user certificate‐policy OID set on verification parameters. |
|
|
Set the authentication security level required during verification. |
Set the maximum depth of untrusted CA certificates allowed above the leaf. |
|
OR additional X509_V_FLAG_* bits into verification parameters. |
|
Set hostname‐checking flags used with X509_VERIFY_PARAM_set1_host(). |
|
|
Set inheritance flags controlling which fields copy from |
Set the certificate purpose checked during verification. |
|
Set the verification reference time used as "now" for validity checks. |
|
Set the trust setting used when verifying certificates with |
|
Free the global table of named X509_VERIFY_PARAM entries. |
|
Encode |
|
Append an OID to a certificate's auxiliary reject list. |
|
Append an OID to a certificate's auxiliary trust list. |
|
Add a certificate to a stack of X.509 certificates under |
|
Append certificates from |
|
Insert a duplicate of extension |
|
Return the friendly‐name alias attached to a certificate, if any. |
|
Set the friendly‐name alias on a certificate's auxiliary data (copied). |
|
Print certificate auxiliary trust/reject/alias information to a BIO. |
|
Build a certificate chain for |
|
|
Classify the key usage / type bits implied by a certificate and key (deprecated). |
Verify that certificate |
|
Duplicate a certificate stack and up‐ref every certificate it contains. |
|
Verify that an Authority Key Identifier matches an issuer certificate. |
|
Report whether a certificate appears to be a CA certificate. |
|
Check whether a certificate's subjectAltName/subject email matches |
|
Check whether a certificate matches a DNS host name. |
|
Check whether a certificate's subjectAltName contains an IP address in binary form. |
|
Check whether a certificate's subjectAltName contains an IP address given as text. |
|
Check whether |
|
Verify that |
|
Check whether a certificate is suitable for a given purpose (or as a CA for that purpose). |
|
Evaluate whether a certificate is trusted for a given trust id. |
|
Compare two X.509 certificates by hash and canonical DER encoding. |
|
Compare an ASN.1 Time against the current time. |
|
Compare an ASN.1 Time against time_t |
|
Compare a verification reference time against a notBefore/notAfter window. |
|
Remove and return the certificate extension at index |
|
Compute a message digest of the DER encoding of an X.509 certificate. |
|
Digest a certificate using its signature hash (or a documented fallback). |
|
Deep‐copy an X.509 certificate. |
|
Free a stack of email strings returned by X509_get1_email or X509_REQ_get1_email. |
|
|
Find a certificate in a stack by issuer name and serial number. |
Find the first certificate in a stack whose subject name equals |
|
Free an X.509 certificate and its contents. |
|
Return the authorityCertIssuer names from the Authority Key Identifier extension. |
|
Return the authorityKeyIdentifier keyIdentifier value from a certificate. |
|
Return the authorityCertSerialNumber from the Authority Key Identifier extension. |
|
Return the distinguishing id OCTET STRING attached to certificate |
|
Return the certificate extensions stack without duplicating it. |
|
Return the notAfter validity time of a certificate. |
|
Return the notBefore validity time of a certificate without copying it. |
|
Return the certificate subject public key without incrementing its reference count. |
|
Return the subject public key BIT STRING from a certificate. |
|
Return the stack of reject OIDs from a certificate's auxiliary data. |
|
Return a borrowed pointer to certificate |
|
Return internal pointers to a certificate's signature value and AlgorithmIdentifier. |
|
Return the subjectKeyIdentifier extension value from a certificate. |
|
Return the signature AlgorithmIdentifier from the TBSCertificate. |
|
Return the stack of explicit trust object identifiers attached to a certificate. |
|
Return pointers to the issuer and subject unique identifiers, if present. |
|
Collect email addresses from a certificate's subject and subjectAltName. |
|
Extract OCSP responder URIs from a certificate's Authority Information Access extension. |
|
Return the certificate's SubjectPublicKeyInfo as an X509_PUBKEY (for i2d_X509_PUBKEY). |
|
Return the default OpenSSL certificates area directory path. |
|
Return the default colon‐separated list of hashed CA certificate directories. |
|
|
Return the environment variable name for overriding the default CA directory list. |
Return the default path of the trusted CA certificate file (SSL_CERT_FILE default). |
|
|
Return the environment‐variable name that overrides the default certificate file path. |
Return the default directory path used for private‐key files. |
|
Retrieve application ex_data previously stored on a certificate. |
|
Return the extension at index |
|
Find the next extension on a certificate matching NID |
|
Find the next extension on a certificate matching ASN.1 object |
|
Find a certificate extension by criticality flag, searching after |
|
Return the number of extensions present on a certificate. |
|
Decode the first (or next) certificate extension with NID |
|
Return the cached Extended Key Usage bits from a certificate. |
|
Return the cached X.509v3 extension summary flags for a certificate. |
|
Return the issuer distinguished name of an X.509 certificate. |
|
Return the cached Key Usage bits from a certificate. |
|
Return the basicConstraints pathLenConstraint of a certificate. |
|
Return the proxy path length constraint from a proxy certificate. |
|
Decode and return the certificate subject public key with an incremented reference count. |
|
Copy missing algorithm parameters into |
|
Return the mutable serial number field of a certificate. |
|
Retrieve digest NID, public‐key NID, security bits, and flags for a certificate signature. |
|
Return the NID of the digest used in a certificate's signature AlgorithmIdentifier. |
|
Return the EVP public‐key type implied by a certificate's signature algorithm. |
|
Return the subject name of a certificate. |
|
Return the X.509 version field of a certificate. |
|
Return a mutable pointer to the certificate's notAfter validity time. |
|
Return the mutable notBefore validity time of a certificate. |
|
Set an ASN1_TIME to the current time plus a second offset (GMT). |
|
Compare two certificates by issuer name and serial number. |
|
Hash a certificate's issuer name and serial number into a 32‐bit value. |
|
Compare the issuer names of two certificates. |
|
Return a hash of a certificate's issuer distinguished name. |
|
Return the legacy MD5‐based hash of a certificate's issuer name. |
|
Return the ASN.1 item descriptor for X509. |
|
Return the subject key identifier attached to a certificate, if any. |
|
Set the key identifier on a certificate's auxiliary data (copied). |
|
Load certificates and CRLs from |
|
|
Load certificates and CRLs from a PEM |
Load certificates from |
|
Load certificates from |
|
Load CRLs from |
|
Download an X.509 certificate from |
|
Allocate an empty X.509 certificate. |
|
Allocate an empty X.509 certificate with an explicit library context. |
|
Print OCSP subject/public‐key hashes for a certificate to a BIO. |
|
Build an X.509 certificate policy tree for a chain and optional user policy OIDs. |
|
Return a policy node at index |
|
Return how many policy nodes are present at a policy‐tree level. |
|
Return the parent policy‐tree node of |
|
Return the policy OID associated with a certificate policy tree node. |
|
|
Return the policy qualifiers associated with a policy‐tree node. |
Free a certificate policy tree allocated by X509_policy_check(). |
|
Return a level of a certificate policy tree by index. |
|
Return the authority‐constrained policy set (valid policy nodes) of a policy tree. |
|
|
Return the user‐policy nodes from a certificate policy tree. |
Return how many levels a certificate policy tree contains. |
|
Print an X.509 certificate to a BIO using default formatting. |
|
Print an X.509 certificate to a BIO with name and content flags. |
|
Print an X.509 certificate to a FILE with name and content flags. |
|
Print a human‐readable certificate dump to a stdio FILE. |
|
Compute a digest of the DER‐encoded public key of an X.509 certificate. |
|
Clear all auxiliary reject‐object OIDs attached to a certificate. |
|
Test whether |
|
Attach a SMIME/CMS distinguishing identifier to a certificate, transferring ownership of |
|
Set the notAfter validity time on an X.509 certificate. |
|
Set the notBefore validity instant on a certificate (copies |
|
Store application ex_data on a certificate at index |
|
Set a certificate's issuer name by copying |
|
Mark a certificate as a proxy certificate (EXFLAG_PROXY) for non‐RFC3820 proxies. |
|
Set the proxy path length constraint on a certificate marked as a proxy. |
|
Set the public key on an X.509 certificate. |
|
Set a certificate's serial number by copying |
|
Set the subject distinguished name on an X.509 certificate. |
|
Set the X.509 certificate version field. |
|
Sign an X509 certificate with a private key and message digest. |
|
Sign certificate |
|
Hex‐dump an ASN.1 signature BIT/OCTET STRING to a BIO with indentation. |
|
Print a signature algorithm and optional signature value to a BIO. |
|
Compare the subject names of two certificates. |
|
Hash a certificate's subject name for OpenSSL certificate‐directory lookup. |
|
Return the legacy MD5‐based hash of a certificate's subject name. |
|
Report whether an extension OID is one that OpenSSL's verifier critically understands. |
|
Adjust an ASN1_TIME by a second offset relative to |
|
Adjust an ASN.1 Time by day and second offsets from a reference time_t. |
|
Build a certificate request from a certificate's subject and public key. |
|
Clear all explicit trust object identifiers previously set on a certificate. |
|
Report whether a certificate has auxiliary trust information attached. |
|
Increment the reference count on an X509 certificate. |
|
Verify a certificate's signature with the issuer public key |
|
Discover and validate a certificate chain based on parameters in |
|
Return a human‐readable string for an X509_V_ERR_* verification error code. |
|
Append a duplicate of |
|
Create an attribute by NID and append a copy to a STACK_OF(X509_ATTRIBUTE). |
|
Create an attribute by OID and append a copy to a STACK_OF(X509_ATTRIBUTE). |
|
Create an attribute by name and append a copy to a STACK_OF(X509_ATTRIBUTE). |
|
Remove and return the attribute at index |
|
Return attribute data matching an OID from a stack of X509_ATTRIBUTE values. |
|
Return the attribute at a zero‐based index in an attribute stack. |
|
Find the next attribute in a stack with the given NID. |
|
Find the next attribute in a stack whose OID equals |
|
Return the number of attributes in an X509_ATTRIBUTE stack. |
|
Insert a duplicate of an extension into an X.509v3 extension stack. |
|
Mark an address family in an IPAddrBlocks value as inheriting from the issuer. |
|
Add an IP address prefix to an IPAddrBlocks (RFC 3779) extension value. |
|
Add an inclusive IP address range to an IPAddrBlocks value. |
|
Sort and merge an IPAddrBlocks value into RFC 3779 canonical form. |
|
Return the Address Family Identifier from an IPAddressFamily entry. |
|
Expand an IPAddressOrRange into inclusive |
|
Report whether an IPAddrBlocks value uses inheritance from the issuer. |
|
Test whether an IPAddrBlocks value is already in RFC 3779 canonical form. |
|
Test whether IP address block set |
|
Validate RFC 3779 IP address blocks along the certification path in |
|
|
Validate that IP address blocks in |
|
Add a single AS number or an inclusive AS number range to an ASIdentifiers value. |
Mark an ASIdentifiers choice as inheriting from the issuer. |
|
Sort and merge an ASIdentifiers value into RFC 3779 canonical form. |
|
Test whether an ASIdentifiers value uses inheritance for ASNUM or RDI. |
|
Test whether an ASIdentifiers value is already in RFC 3779 canonical form. |
|
Test whether AS identifier set |
|
Validate RFC 3779 AS identifier nesting along a certificate chain in a store context. |
|
|
Validate that AS identifiers in |
Remove and return the extension at index |
|
Return the extension at index |
|
Find an extension by NID in a stack of X509_EXTENSION. |
|
Find the next extension in |
|
Find the next X509 extension with a given critical flag in a stack. |
|
Return the number of extensions in an X.509v3 extension stack. |
|
Insert a name/value pair into a CONF section (internal CONF helper). |
|
Free the internal LHASH and CONF_VALUE entries stored in |
|
Look up a numeric value in the internal CONF data store (legacy helper). |
|
Look up a section CONF_VALUE in the internal CONF data store. |
|
Return the CONF_VALUE stack for |
|
Look up a string in the internal CONF data store (legacy helper). |
|
Allocate the internal LHASH used to store CONF values (internal helper). |
|
Create a new named section in the internal CONF data store. |
|
Convert |
|
Convert |
|
Encode a dotted‐decimal OID string into DER content octets. |
|
Read a colon‐separated hex ENUMERATED from |
|
Read a colon‐separated hex INTEGER from |
|
Read a colon‐separated hex ASN.1 string from |
|
Parse a string into a GENERAL_NAME of the requested type. |
|
Convert an ASCII IPv4 or IPv6 address to an OCTET STRING for GeneralName iPAddress. |
|
Convert an ASCII IP address or CIDR prefix to an OCTET STRING for name constraints. |
|
Decode a Microsoft PVK private key from a BIO. |
|
Decode a Microsoft PVK private key from a BIO with a library context. |
|
Decode a Microsoft MSBLOB private key from a memory buffer. |
|
Decode a Microsoft MSBLOB private key from a BIO. |
|
Decode a Microsoft MSBLOB public key from a memory buffer. |
|
Decode a Microsoft MSBLOB public key from a BIO. |
|
Decode an AccessDescription from DER. |
|
Decode an ADMISSIONS value from DER. |
|
Decode an ADMISSION_SYNTAX from DER. |
|
Decode an ASIdOrRange from DER. |
|
Decode an ASIdentifierChoice from DER. |
|
Decode an ASIdentifiers extension from DER. |
|
Decode an ASN.1 BIT STRING from DER. |
|
Decode a ASN.1 BMPString from DER. |
|
Decode an ASN.1 ENUMERATED from DER. |
|
Decode an ASN.1 GeneralizedTime from DER. |
|
Decode an ASN.1 GeneralString from DER. |
|
Decode an ASN.1 IA5String from DER. |
|
Decode an ASN.1 INTEGER from DER. |
|
Decode an ASN.1 NULL from DER. |
|
Decode an ASN.1 OBJECT identifier from DER. |
|
Decode an ASN.1 OCTET STRING from DER. |
|
Decode an ASN1_PRINTABLE string from DER. |
|
Decode an ASN.1 PrintableString from DER. |
|
Decode an ASN.1 SEQUENCE OF ANY from DER into a stack of ASN1_TYPE values. |
|
Decode an ASN.1 SET OF ANY from DER into a stack of ASN1_TYPE values. |
|
Decode a ASN.1 TeletexString (T61String) from DER. |
|
Decode a ASN.1 time value (UTCTime or GeneralizedTime) from DER. |
|
Decode an ASN.1 ANY / ASN1_TYPE value from DER. |
|
Decode an ASN.1 INTEGER that must be treated as unsigned (no leading 0x00 ignored). |
|
Decode an ASN.1 UniversalString from DER. |
|
Decode an ASN.1 UTCTime from DER. |
|
Decode an ASN.1 UTF8String from DER. |
|
Decode an ASN.1 VisibleString from DER. |
|
Decode an AS number range from DER. |
|
Decode an Authority Information Access extension value from DER. |
|
Decode an Authority Key Identifier extension value from DER. |
|
Decode a private key from DER, detecting the algorithm automatically. |
|
Decode a private key from DER, auto‐detecting the algorithm, using a library context. |
|
Decode a Basic Constraints extension value from DER. |
|
Decode a DER‐encoded certificatePolicies extension into a CERTIFICATEPOLICIES stack. |
|
Decode a CMS ContentInfo from DER. |
|
Decode a CMS ReceiptRequest from DER. |
|
Decode a CMS ContentInfo from a BIO in DER form. |
|
Decode a CRL Distribution Points extension value from DER. |
|
|
Decode Diffie‐Hellman domain parameters from DER (deprecated). |
|
Decode Diffie‐Hellman X9.42 domain parameters (with q/j/seed) from DER (deprecated). |
Decode a DirectoryString from DER. |
|
Decode a DisplayText (ASN.1 string CHOICE) from DER. |
|
Decode a CRL distribution point from DER. |
|
Decode a distribution point name from DER. |
|
|
Decode a DSA private key from DER (deprecated). |
|
Decode a DSA private key in DER form from a BIO (deprecated). |
|
Read a DER‐encoded DSA private key from a FILE (deprecated). |
|
Decode a DSA public key from DER (deprecated). |
|
Decode a DSA public key from SubjectPublicKeyInfo DER (deprecated). |
|
Read a DSA public key in SubjectPublicKeyInfo form from a BIO (deprecated). |
|
Read a DSA public key in SubjectPublicKeyInfo DER form from a FILE (deprecated). |
Decode a DSA signature (r, s) from DER. |
|
|
Decode DSA domain parameters from DER (deprecated). |
Decode an ECDSA signature from DER. |
|
Decode EC domain parameters (EcpkParameters) from DER into an EC_GROUP. |
|
|
Decodes ec parameter from a memory buffer. |
|
Decodes a private key from a memory buffer. |
|
Read a DER‐encoded EC private key from a BIO (deprecated). |
|
Decode an EC private key in SEC1 DER form from a FILE (deprecated). |
|
Decode an EC public key from SubjectPublicKeyInfo DER (deprecated). |
|
Read a DER‐encoded SubjectPublicKeyInfo EC public key from a BIO (deprecated). |
|
Read an EC public key in SubjectPublicKeyInfo DER form from a FILE (deprecated). |
Decode an EDI party name from DER. |
|
Decode a ESS CertID from DER. |
|
Decode a ESS CertIDv2 from DER. |
|
Decode a ESS IssuerSerial from DER. |
|
Decode a ESS SigningCertificate attribute from DER. |
|
Decode a ESS SigningCertificateV2 attribute from DER. |
|
Decode an Extended Key Usage extension value from DER. |
|
Decode a GeneralName from DER. |
|
Decode a GeneralNames value from DER. |
|
Decode an IPAddressChoice from DER. |
|
Decode an IPAddressFamily from DER. |
|
Decode a IP address or address range (RFC 3779) from DER. |
|
Decode an IPAddressRange from DER. |
|
Decode an Issuer Signing Tool extension value from DER. |
|
Decode an Issuing Distribution Point extension value from DER. |
|
Decode algorithm parameters of the given key type from DER into an EVP_PKEY. |
|
Decode algorithm parameters from a BIO into an EVP_PKEY of the given type. |
|
Decode a NAMING_AUTHORITY from DER. |
|
Decode a Netscape Certificate Sequence from DER. |
|
Decode a Netscape SPKAC from DER. |
|
Decode a Netscape Signed Public Key and Challenge (SPKI) from DER. |
|
Decode a certificate‐policy notice reference from DER. |
|
Decode an OCSP BasicOCSPResponse from DER. |
|
Decode an OCSP CertID from DER. |
|
Decode a OCSP CertStatus from DER. |
|
Decode an OCSP CrlID extension value from DER. |
|
Decode an OCSP single Request entry from DER. |
|
Decode a OCSP TBSRequest (OCSP_REQINFO) from DER. |
|
Decode an OCSP Request from DER. |
|
Decode an OCSP ResponseBytes from DER. |
|
Decode a OCSP ResponseData from DER. |
|
Decode a OCSP ResponderID from DER. |
|
Decode a OCSP Response from DER. |
|
Decode an OCSP RevokedInfo from DER. |
|
Decode an OCSP ServiceLocator extension value from DER. |
|
Decode an OCSP Signature from DER. |
|
Decode an OCSP SingleResponse from DER. |
|
Decode an OSSL_CMP_MSG from DER. |
|
Decode a DER‐encoded CMP message from a BIO. |
|
Decode an OSSL_CMP_PKIHEADER from DER. |
|
Decode an OSSL_CMP_PKISI from DER. |
|
Decode an OSSL_CRMF_CERTID from DER. |
|
Decode an OSSL_CRMF_CERTTEMPLATE from DER. |
|
Decode an OSSL_CRMF_ENCRYPTEDVALUE from DER. |
|
Decode an OSSL_CRMF_MSG from DER. |
|
Decode an OSSL_CRMF_MSGS sequence from DER. |
|
Decode an OSSL_CRMF_PBMPARAMETER from DER. |
|
Decode an OSSL_CRMF_PKIPUBLICATIONINFO from DER. |
|
Decode an OSSL_CRMF_SINGLEPUBINFO from DER. |
|
Decode an otherName value from DER. |
|
Decode a PKCS#5 PBES2 parameter structure from DER. |
|
Decode a PKCS#5 PBES1 parameter structure (salt and iteration count) from DER. |
|
Decode a PKCS#5 PBKDF2 parameter structure from DER. |
|
Decode a PKCS12 structure from DER. |
|
Decode a PKCS12_BAGS structure from DER. |
|
Decode a PKCS12_MAC_DATA structure from DER. |
|
Decode a PKCS12_SAFEBAG structure from DER. |
|
Read and decode a PKCS12 structure from a BIO. |
|
Read and decode a PKCS12 structure from a FILE. |
|
Decode a PKCS#7 structure from DER. |
|
Decode a PKCS#7 DigestedData structure from DER. |
|
Decode a PKCS#7 EncryptedData from DER. |
|
Decode a PKCS#7 EncryptedContentInfo from DER. |
|
Decode a PKCS#7 EnvelopedData structure from DER. |
|
Decode a PKCS#7 IssuerAndSerialNumber from DER. |
|
Decode a PKCS#7 recipient info structure from DER. |
|
Decode a PKCS#7 SignedData from DER. |
|
Decode a PKCS#7 SignerInfo from DER. |
|
Decode a PKCS#7 SignedAndEnvelopedData structure from DER. |
|
Decode a DER‐encoded PKCS#7 structure from a BIO. |
|
Decode a PKCS#7 structure from a FILE stream in DER form. |
|
Decode a DER PKCS#8 private key (encrypted or plain) from a BIO. |
|
Decode a DER PKCS#8 private key (encrypted or plain) from a FILE. |
|
Decode a PKCS#8 PrivateKeyInfo from DER. |
|
|
Decode a PKCS#8 PrivateKeyInfo structure in DER form from a BIO. |
|
Decode a PKCS#8 PrivateKeyInfo structure from a FILE. |
Decode a PKCS#8 encrypted private key (X509_SIG) in DER form from a BIO. |
|
Decode a PKCS#8 encrypted private key (X509_SIG) in DER form from a FILE. |
|
Decode a Private Key Usage Period extension value from DER. |
|
Decode a certificate policy information value from DER. |
|
Decode a policy qualifier information value from DER. |
|
Decode a PROFESSION_INFO from DER. |
|
Decode a PROXY_CERT_INFO_EXTENSION structure from DER. |
|
Decode a PROXY_POLICY from DER. |
|
Decode an EVP_PKEY from SubjectPublicKeyInfo DER. |
|
Read a DER‐encoded SubjectPublicKeyInfo into an EVP_PKEY from a BIO. |
|
Decode a SubjectPublicKeyInfo from DER with an explicit library context. |
|
Read a DER‐encoded SubjectPublicKeyInfo into an EVP_PKEY from a BIO with library context. |
|
Decode an EVP_PKEY in SubjectPublicKeyInfo form from a FILE, with library context. |
|
Decode an EVP_PKEY in SubjectPublicKeyInfo form from a FILE. |
|
Decode a private key of the given algorithm from DER using the default library context. |
|
Read a private key in traditional or PKCS#8 DER form from a BIO. |
|
Decode a private key of type |
|
Read a private key from a BIO with an explicit library context and property query. |
|
Read a private key in traditional or PKCS#8 DER form from a FILE with library context. |
|
Read a private key in traditional or PKCS#8 DER form from a FILE. |
|
Decode a public key of the given type from DER into an EVP_PKEY. |
|
|
Decode an RSA private key from DER in PKCS#1 RSAPrivateKey form (deprecated). |
|
Decode an RSA private key in PKCS#1 DER form from a BIO (deprecated). |
|
Read a DER‐encoded RSA private key from a FILE (deprecated). |
|
Decode an RSA public key from DER in PKCS#1 RSAPublicKey form (deprecated). |
|
Decode an RSA public key in PKCS#1 RSAPublicKey form from a BIO (deprecated). |
|
Decode an RSA public key in PKCS#1 RSAPublicKey form from a FILE (deprecated). |
Decode RSA‐OAEP parameters from DER. |
|
Decode RSA‐PSS parameters from DER. |
|
|
Decode an RSA public key from SubjectPublicKeyInfo DER (deprecated). |
|
Decode an RSA public key (SubjectPublicKeyInfo) in DER form from a BIO (deprecated). |
|
Read an RSA public key in SubjectPublicKeyInfo DER form from a FILE (deprecated). |
Decode a PKCS#5 scrypt parameter structure from DER. |
|
Decode a DER‐encoded list of Signed Certificate Timestamps. |
|
Decode an SSL_SESSION from its ASN.1 DER encoding. |
|
Decode an SSL_SESSION from DER with an explicit library context. |
|
Decode an SXNET (Strong Extranet) value from DER. |
|
Decode an SXNETID from DER. |
|
Decode a time‐stamp Accuracy from DER. |
|
Decode a time‐stamp message imprint from DER. |
|
Decode a message imprint from a BIO containing DER. |
|
Decode a message imprint from a FILE stream containing DER. |
|
Decode a time‐stamp request from DER. |
|
Decode a time‐stamp request from a BIO containing DER. |
|
Decode a time‐stamp request from a FILE stream containing DER. |
|
Decode a time‐stamp response from DER. |
|
Decode a time‐stamp response from a BIO containing DER. |
|
Decode a time‐stamp response from a FILE stream containing DER. |
|
Decode a time‐stamp PKIStatusInfo from DER. |
|
Decode a time‐stamp token info from DER. |
|
Decode TSTInfo from a BIO containing DER. |
|
Decode TSTInfo from a FILE stream containing DER. |
|
Decode a user notice policy qualifier from DER. |
|
Decode an X.509 certificate from DER. |
|
Decode an X.509 AlgorithmIdentifier from DER. |
|
Decode a SEQUENCE OF X509_ALGOR (AlgorithmIdentifiers) from DER. |
|
Decode an X.509 Attribute from DER. |
|
Decode an X.509 certificate with trusted‐certificate auxiliary data from DER. |
|
Decode certificate auxiliary info from DER. |
|
Decode a X.509 TBSCertificate (X509_CINF) structure from DER. |
|
Decode an X.509 CRL from DER. |
|
Decode a X.509 CRL information (tbsCertList) structure from DER. |
|
Decode an X.509 CRL in DER form from a BIO. |
|
Decode an X.509 CRL in DER form from a FILE. |
|
Decode a X.509 extension from DER. |
|
Decode a SEQUENCE OF X509_EXTENSION from DER. |
|
Decode a X.509 distinguished name (Name) from DER. |
|
Decode a X.509 Name entry (AttributeTypeAndValue) from DER. |
|
Decode a X.509 SubjectPublicKeyInfo (X509_PUBKEY) from DER. |
|
Decode an X509_PUBKEY (SubjectPublicKeyInfo) in DER form from a BIO. |
|
Read a DER‐encoded SubjectPublicKeyInfo (X509_PUBKEY) from a FILE. |
|
Decode a X.509 certificate signing request from DER. |
|
Decode an X.509 certificate request info structure from DER. |
|
Decode a DER‐encoded certificate request from a BIO. |
|
Decode an X.509 certificate request in DER form from a FILE. |
|
Decode a CRL revoked‐certificate entry from DER. |
|
Decode an X.509 signature structure from DER. |
|
Decode an X509_VAL (certificate validity interval) from DER. |
|
Decode an X.509 certificate in DER form from a BIO. |
|
Decode an X.509 certificate in DER form from a FILE. |
|
Write the accessMethod OID of an AccessDescription to a BIO. |
|
Write an ASN.1 ENUMERATED to a BIO as hexadecimal ASCII text. |
|
Write an ASN.1 INTEGER to a BIO as hexadecimal ASCII text. |
|
Write an OBJECT IDENTIFIER to a BIO as a dotted name or numeric OID text. |
|
Write an ASN.1 string's content to a BIO as uppercase hexadecimal digits. |
|
Encode a private key in Microsoft PVK format and write it to a BIO. |
|
Encode a private key in Microsoft PVK format using an explicit library context. |
|
Encode a private key in Microsoft MSBLOB format and write it to a BIO. |
|
Encode a public key in Microsoft MSBLOB format and write it to a BIO. |
|
Encode an AccessDescription to DER. |
|
Encode an ADMISSIONS value to DER. |
|
Encode an ADMISSION_SYNTAX to DER. |
|
Encode an ASIdOrRange to DER. |
|
Encode an ASIdentifierChoice to DER. |
|
Encode an ASIdentifiers extension to DER. |
|
Encode an ASN.1 BIT STRING to DER. |
|
Encode a ASN.1 BMPString to DER. |
|
Encode an ASN.1 ENUMERATED to DER. |
|
Encode an ASN.1 GeneralizedTime to DER. |
|
Encode an ASN.1 GeneralString to DER. |
|
Encode an ASN.1 IA5String to DER. |
|
Encode an ASN.1 INTEGER to DER. |
|
Encode an ASN.1 NULL to DER. |
|
Encode an ASN.1 OBJECT identifier to DER. |
|
Encode an ASN.1 OCTET STRING to DER. |
|
Encode an ASN1_PRINTABLE string to DER. |
|
Encode an ASN.1 PrintableString to DER. |
|
Encode a stack of ASN1_TYPE values as an ASN.1 SEQUENCE OF ANY in DER. |
|
Encode a stack of ASN1_TYPE values as an ASN.1 SET OF ANY in DER. |
|
Encode a ASN.1 TeletexString (T61String) to DER. |
|
Encode a ASN.1 time value (UTCTime or GeneralizedTime) to DER. |
|
Encode an ASN.1 ANY / ASN1_TYPE value to DER. |
|
Encode an ASN.1 UniversalString to DER. |
|
Encode an ASN.1 UTCTime to DER. |
|
Encode an ASN.1 UTF8String to DER. |
|
Encode an ASN.1 VisibleString to DER. |
|
Stream‐encode an ASN.1 value to |
|
Encode an AS number range to DER. |
|
Encode an AuthorityInfoAccess syntax value to DER. |
|
Encode an Authority Key Identifier extension value to DER. |
|
Encode a Basic Constraints extension value to DER. |
|
Encode a Certificate Policies extension value to DER. |
|
Encode a CMS ContentInfo to DER. |
|
Encode a CMS ReceiptRequest to DER. |
|
Encode a CMS ContentInfo to a BIO in DER form. |
|
Stream a CMS ContentInfo to |
|
Encode a CRL Distribution Points extension value to DER. |
|
|
Encode Diffie‐Hellman domain parameters to DER (deprecated). |
|
Encode Diffie‐Hellman X9.42 domain parameters (with q/j/seed) to DER (deprecated). |
Encode a DirectoryString to DER. |
|
Encode a DisplayText (ASN.1 string CHOICE) to DER. |
|
DER‐encode a DistributionPoint structure. |
|
Encode a distribution point name to DER. |
|
|
Encode a DSA private key to DER (deprecated). |
|
Write a DER‐encoded DSA private key to a BIO (deprecated). |
|
Write a DER‐encoded DSA private key to a FILE stream (deprecated). |
|
Encode a DSA public key to DER (deprecated). |
|
Encode a DSA public key as SubjectPublicKeyInfo DER (deprecated). |
|
Write a DSA public key as SubjectPublicKeyInfo DER to a BIO (deprecated). |
|
Write a DSA public key in SubjectPublicKeyInfo DER form to a FILE (deprecated). |
Encode a DSA signature (r, s) to DER. |
|
|
Encode DSA domain parameters to DER (deprecated). |
Encode an ECDSA signature (r, s) to DER. |
|
Encode EC domain parameters (EcpkParameters) from an EC_GROUP to DER. |
|
|
Encodes ec parameter and stores the result in a buffer. |
|
Encodes a private key object and stores the result in a buffer. |
|
Write an EC private key in SEC1 ECPrivateKey DER form to a BIO (deprecated). |
|
Write an EC private key in SEC1 ECPrivateKey DER form to a FILE (deprecated). |
|
Encode an EC public key as SubjectPublicKeyInfo DER (deprecated). |
|
Write an EC public key as SubjectPublicKeyInfo DER to a BIO (deprecated). |
|
Write an EC public key in SubjectPublicKeyInfo DER form to a FILE (deprecated). |
Encode an EDI party name to DER. |
|
Encode a ESS CertID to DER. |
|
Encode a ESS CertIDv2 to DER. |
|
Encode a ESS IssuerSerial to DER. |
|
Encode a ESS SigningCertificate attribute to DER. |
|
Encode a ESS SigningCertificateV2 attribute to DER. |
|
Encode an Extended Key Usage extension value to DER. |
|
Encode a GeneralName to DER. |
|
Encode a GeneralNames value to DER. |
|
Encode an IPAddressChoice to DER. |
|
Encode an IPAddressFamily to DER. |
|
Encode a IP address or address range (RFC 3779) to DER. |
|
Encode an IPAddressRange to DER. |
|
Encode an ISSUER_SIGN_TOOL value to DER. |
|
Encode an Issuing Distribution Point extension value to DER. |
|
Encode algorithm parameters from an EVP_PKEY to DER. |
|
Encode algorithm parameters from an EVP_PKEY to a BIO in DER form. |
|
Encode a NAMING_AUTHORITY to DER. |
|
Encode a Netscape Certificate Sequence to DER. |
|
Encode a Netscape SPKAC to DER. |
|
Encode a Netscape Signed Public Key and Challenge (SPKI) to DER. |
|
Encode a certificate‐policy notice reference to DER. |
|
Encode an OCSP BasicOCSPResponse to DER. |
|
Encode an OCSP CertID to DER. |
|
Encode a OCSP CertStatus to DER. |
|
Encode an OCSP CrlID extension value to DER. |
|
Encode an OCSP single Request entry to DER. |
|
Encode a OCSP TBSRequest (OCSP_REQINFO) to DER. |
|
Encode an OCSP Request to DER. |
|
Encode an OCSP ResponseBytes to DER. |
|
Encode a OCSP ResponseData to DER. |
|
Encode a OCSP ResponderID to DER. |
|
Encode a OCSP Response to DER. |
|
Encode an OCSP RevokedInfo to DER. |
|
Encode an OCSP ServiceLocator extension value to DER. |
|
Encode an OCSP Signature to DER. |
|
Encode an OCSP SingleResponse to DER. |
|
Encode an OSSL_CMP_MSG to DER. |
|
Encode a CMP message to DER and write it to a BIO. |
|
Encode an OSSL_CMP_PKIHEADER to DER. |
|
Encode an OSSL_CMP_PKISI to DER. |
|
Encode an OSSL_CRMF_CERTID to DER. |
|
Encode an OSSL_CRMF_CERTTEMPLATE to DER. |
|
Encode an OSSL_CRMF_ENCRYPTEDVALUE to DER. |
|
Encode an OSSL_CRMF_MSG to DER. |
|
Encode an OSSL_CRMF_MSGS sequence to DER. |
|
Encode an OSSL_CRMF_PBMPARAMETER to DER. |
|
Encode an OSSL_CRMF_PKIPUBLICATIONINFO to DER. |
|
Encode an OSSL_CRMF_SINGLEPUBINFO to DER. |
|
Encode an otherName value to DER. |
|
Encode a PKCS#5 PBES2 parameter structure to DER. |
|
Encode a PKCS#5 PBES1 parameter structure (salt and iteration count) to DER. |
|
Encode a PKCS#5 PBKDF2 parameter structure to DER. |
|
Encode a PKCS12 structure to DER. |
|
Encode a PKCS12_BAGS structure to DER. |
|
Encode a PKCS12_MAC_DATA structure to DER. |
|
Encode a PKCS12_SAFEBAG structure to DER. |
|
Encode a PKCS12 structure to DER and write it to a BIO. |
|
Encode a PKCS12 structure to DER and write it to a FILE. |
|
Encode a PKCS#7 structure to DER. |
|
Encode a PKCS#7 DigestedData structure to DER. |
|
Encode a PKCS#7 EncryptedData to DER. |
|
Encode a PKCS#7 EncryptedContentInfo to DER. |
|
Encode a PKCS#7 EnvelopedData structure to DER. |
|
Encode a PKCS#7 IssuerAndSerialNumber to DER. |
|
Encode a PKCS#7 structure to DER using indefinite‐length (NDEF) constructed encoding. |
|
Encode a PKCS#7 recipient info structure to DER. |
|
Encode a PKCS#7 SignedData to DER. |
|
Encode a PKCS#7 SignerInfo to DER. |
|
Encode a PKCS#7 SignedAndEnvelopedData structure to DER. |
|
Write a DER‐encoded PKCS#7 structure to a BIO. |
|
Output a PKCS#7 structure in BER format, streaming content from |
|
Write a DER‐encoded PKCS#7 structure to a FILE. |
|
Write a private key as an unencrypted PKCS#8 PrivateKeyInfo DER blob to a BIO. |
|
Write |
|
Encode a private key as DER PKCS#8 and write it to a BIO. |
|
Encode a private key as DER PKCS#8 and write it to a FILE. |
|
Encode a private key as DER PKCS#8 using a PKCS#5 v1.5 / PKCS#12 PBE NID. |
|
Encode a private key as DER PKCS#8 using a PKCS#5 v1.5 / PKCS#12 PBE NID. |
|
Encode a PKCS#8 PrivateKeyInfo to DER. |
|
|
Write an unencrypted PKCS#8 PrivateKeyInfo structure to a BIO in DER form. |
|
Write an unencrypted PKCS#8 PrivateKeyInfo structure to a FILE in DER form. |
Write an encrypted PKCS#8 private key (X509_SIG) in DER form to a BIO. |
|
Encode a PKCS#8 encrypted private key (X509_SIG) to DER and write it to a FILE. |
|
Encode a Private Key Usage Period extension value to DER. |
|
Encode a certificate policy information value to DER. |
|
Encode a policy qualifier information value to DER. |
|
Encode a PROFESSION_INFO to DER. |
|
Encode a Proxy Certificate Information extension value to DER. |
|
Encode a PROXY_POLICY to DER. |
|
Encode an EVP_PKEY as SubjectPublicKeyInfo DER. |
|
Encode an EVP_PKEY as SubjectPublicKeyInfo DER and write it to a BIO. |
|
Encode an EVP_PKEY as SubjectPublicKeyInfo DER and write it to a FILE. |
|
Encode the private key from an EVP_PKEY to DER in the algorithm‐native private‐key format. |
|
Write a private key in traditional DER form to a BIO. |
|
Write a private key to a FILE in traditional (type‐specific) DER form. |
|
Encode the public key from an EVP_PKEY to DER in the algorithm‐native public‐key format. |
|
|
Encode an RSA private key to DER in PKCS#1 RSAPrivateKey form (deprecated). |
|
Write an RSA private key in PKCS#1 DER form to a BIO (deprecated). |
|
Write an RSA private key in PKCS#1 DER form to a FILE (deprecated). |
|
Encode an RSA public key to DER in PKCS#1 RSAPublicKey form (deprecated). |
|
Write an RSA public key in PKCS#1 RSAPublicKey DER form to a BIO (deprecated). |
|
Write an RSA public key in PKCS#1 RSAPublicKey DER form to a FILE (deprecated). |
Encode RSA‐OAEP parameters to DER. |
|
Encode RSA‐PSS parameters to DER. |
|
|
Encode an RSA public key as SubjectPublicKeyInfo DER (deprecated). |
|
Write an RSA public key as SubjectPublicKeyInfo DER to a BIO (deprecated). |
|
Write an RSA public key to a FILE as a SubjectPublicKeyInfo DER blob (deprecated). |
Encode a PKCS#5 scrypt parameter structure to DER. |
|
Serialize a stack of SCTs to DER and return the encoded length. |
|
Encode an SSL_SESSION into its ASN.1 DER representation (i2d style). |
|
Encode an SXNET value to DER. |
|
Encode an SXNETID value to DER. |
|
Encode a time‐stamp Accuracy to DER. |
|
Encode a time‐stamp message imprint to DER. |
|
Encode a message imprint as DER to a BIO. |
|
Encode a message imprint as DER to a FILE stream. |
|
Encode a time‐stamp request to DER. |
|
Encode a time‐stamp request as DER to a BIO. |
|
Encode a time‐stamp request as DER to a FILE stream. |
|
Encode a time‐stamp response to DER. |
|
Encode a time‐stamp response as DER to a BIO. |
|
Encode a time‐stamp response as DER to a FILE stream. |
|
Encode a time‐stamp PKIStatusInfo to DER. |
|
Encode a time‐stamp token info to DER. |
|
Encode TSTInfo as DER to a BIO. |
|
Encode TSTInfo as DER to a FILE stream. |
|
Encode a USERNOTICE structure to DER. |
|
Encode an X.509 certificate to DER. |
|
Encode an X.509 AlgorithmIdentifier to DER. |
|
Encode a SEQUENCE OF X509_ALGOR (AlgorithmIdentifiers) to DER. |
|
Encode an X.509 Attribute to DER. |
|
Encode an X.509 certificate plus trusted‐certificate auxiliary data to DER. |
|
Encode certificate auxiliary info to DER. |
|
Encode a X.509 TBSCertificate (X509_CINF) structure to DER. |
|
Encode an X.509 CRL to DER. |
|
Encode a X.509 CRL information (tbsCertList) structure to DER. |
|
Write an X.509 CRL to a BIO in DER form. |
|
Write a DER‐encoded X.509 CRL to a FILE stream. |
|
Encode a X.509 extension to DER. |
|
Encode a SEQUENCE OF X509_EXTENSION to DER. |
|
Encode a X.509 distinguished name (Name) to DER. |
|
Encode a X.509 Name entry (AttributeTypeAndValue) to DER. |
|
Encode a X.509 SubjectPublicKeyInfo (X509_PUBKEY) to DER. |
|
Encode an X509_PUBKEY (SubjectPublicKeyInfo) to DER and write it to a BIO. |
|
Encode an X509_PUBKEY (SubjectPublicKeyInfo) to DER and write it to a FILE. |
|
Encode a X.509 certificate signing request to DER. |
|
Encode an X.509 certificate request info structure to DER. |
|
Write a certificate request to a BIO in DER form. |
|
Write an X.509 certificate request to a FILE in DER form. |
|
Encode a CRL revoked‐certificate entry to DER. |
|
Encode an X.509 signature structure to DER. |
|
Encode an X509_VAL to DER. |
|
Write an X.509 certificate to a BIO in DER form. |
|
Write an X.509 certificate to a FILE in DER form. |
|
Re‐encode the to‐be‐signed CRL body of |
|
Re‐encode the TBS (to‐be‐signed) portion of a certificate request to DER. |
|
Re‐encode a certificate's TBSCertificate to DER, refreshing the cached encoding. |
|
|
Encodes an ec public key in an octet string. |
Serialize an SCT to TLS format. |
|
Serialize a stack of SCTs to TLS format and return the encoded length. |
|
Convert an ASN1_ENUMERATED to a newly allocated decimal string. |
|
Convert an ASN1_ENUMERATED to a name string using |
|
Convert an ASN1_IA5STRING to a newly allocated C string. |
|
Convert an ASN1_INTEGER to a newly allocated decimal string. |
|
Format an ASN.1 OCTET STRING as a hexadecimal configuration string. |
|
Convert an ASN1_UTF8STRING to a newly allocated C string. |
|
Format an ASN.1 OBJECT IDENTIFIER into a textual OID name or dotted decimal form. |
|
Convert an ASN1_BIT_STRING into named CONF_VALUE entries using |
|
Append a GeneralName to a configuration name/value stack for extension printing. |
|
Convert a GeneralNames set into a configuration name/value stack. |
|
|
Decodes an ec public key from a octet string. |
Decode a single Signed Certificate Timestamp from TLS wire format (RFC 6962). |
|
Decode a TLS‐format (not DER) list of SCTs from |
|
Parse a configuration string into an ASN.1 IA5String. |
|
Parse a decimal (or 0x‐prefixed hex) string into a newly allocated ASN1_INTEGER. |
|
Parse a configuration string into an ASN.1 OCTET STRING. |
|
Parse a configuration string into an ASN.1 UTF8String. |
|
|
|
Build an ASN.1 BIT STRING from named bit configuration values. |
|
Parse a single configuration name/value into a GENERAL_NAME. |
|
Parse configuration name/value pairs into a GeneralNames set. |
|
Parse a configuration name/value into a GENERAL_NAME, optionally reusing |
Variables
Name |
Description |
256‐byte table mapping EBCDIC code points to ASCII (exported as _openssl_os_toascii). |
|
256‐byte table mapping ASCII code points to EBCDIC (exported as _openssl_os_toebcdic). |
Macros
Name |
Description |
Encoding flag: omit domain parameters when encoding an EC key. |
|
Encoding flag: omit the public key when encoding an EC key. |
|
EVP_PKEY ctrl: select the digest used by the TLS PRF KDF. |
|
Detect operating systems. This probably needs completing. The result is that at least one OPENSSL_SYS_os macro should be defined. However, if none is defined, Unix is assumed. |
|
Version of the dynamic ENGINE ABI expected by this OpenSSL build. |
|
RSA_METHOD flag marking the method as FIPS‐validated and usable in FIPS mode. |
|
Compatibility alias for X509_REQ_get_pubkey(). |
|
Compatibility alias for X509_get_pubkey(). |
Created with MrDocs