X509_new.pod 3.0 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495
  1. =pod
  2. =head1 NAME
  3. X509_new, X509_new_ex,
  4. X509_free, X509_up_ref,
  5. X509_chain_up_ref - X509 certificate ASN1 allocation functions
  6. =head1 SYNOPSIS
  7. #include <openssl/x509.h>
  8. X509 *X509_new(void);
  9. X509 *X509_new_ex(OSSL_LIB_CTX *libctx, const char *propq);
  10. void X509_free(X509 *a);
  11. int X509_up_ref(X509 *a);
  12. STACK_OF(X509) *X509_chain_up_ref(STACK_OF(X509) *x);
  13. =head1 DESCRIPTION
  14. The X509 ASN1 allocation routines, allocate and free an
  15. X509 structure, which represents an X509 certificate.
  16. X509_new_ex() allocates and initializes a X509 structure with a
  17. library context of I<libctx>, property query of <propq> and a reference
  18. count of B<1>. Many X509 functions such as X509_check_purpose(), and
  19. X509_verify() use this library context to select which providers supply the
  20. fetched algorithms (SHA1 is used internally).
  21. X509_new() is similar to X509_new_ex() but sets the library context
  22. and property query to NULL. This results in the default (NULL) library context
  23. being used for any X509 operations requiring algorithm fetches.
  24. X509_free() decrements the reference count of B<X509> structure B<a> and
  25. frees it up if the reference count is zero. If B<a> is NULL nothing is done.
  26. X509_up_ref() increments the reference count of B<a>.
  27. X509_chain_up_ref() increases the reference count of all certificates in
  28. chain B<x> and returns a copy of the stack, or an empty stack if B<a> is NULL.
  29. =head1 NOTES
  30. The function X509_up_ref() if useful if a certificate structure is being
  31. used by several different operations each of which will free it up after
  32. use: this avoids the need to duplicate the entire certificate structure.
  33. The function X509_chain_up_ref() doesn't just up the reference count of
  34. each certificate. It also returns a copy of the stack, using sk_X509_dup(),
  35. but it serves a similar purpose: the returned chain persists after the
  36. original has been freed.
  37. =head1 RETURN VALUES
  38. If the allocation fails, X509_new() returns NULL and sets an error
  39. code that can be obtained by L<ERR_get_error(3)>.
  40. Otherwise it returns a pointer to the newly allocated structure.
  41. X509_up_ref() returns 1 for success and 0 for failure.
  42. X509_chain_up_ref() returns a copy of the stack or NULL if an error occurred.
  43. =head1 SEE ALSO
  44. L<d2i_X509(3)>,
  45. L<ERR_get_error(3)>,
  46. L<X509_CRL_get0_by_serial(3)>,
  47. L<X509_get0_signature(3)>,
  48. L<X509_get_ext_d2i(3)>,
  49. L<X509_get_extension_flags(3)>,
  50. L<X509_get_pubkey(3)>,
  51. L<X509_get_subject_name(3)>,
  52. L<X509_get_version(3)>,
  53. L<X509_NAME_add_entry_by_txt(3)>,
  54. L<X509_NAME_ENTRY_get_object(3)>,
  55. L<X509_NAME_get_index_by_NID(3)>,
  56. L<X509_NAME_print_ex(3)>,
  57. L<X509_sign(3)>,
  58. L<X509V3_get_d2i(3)>,
  59. L<X509_verify_cert(3)>
  60. =head1 HISTORY
  61. The function X509_new_ex() was added in OpenSSL 3.0.
  62. =head1 COPYRIGHT
  63. Copyright 2002-2021 The OpenSSL Project Authors. All Rights Reserved.
  64. Licensed under the Apache License 2.0 (the "License"). You may not use
  65. this file except in compliance with the License. You can obtain a copy
  66. in the file LICENSE in the source distribution or at
  67. L<https://www.openssl.org/source/license.html>.
  68. =cut